Chinese Firm Says It Did All It Could Ahead of Cyber-Attack

Advertisement
By Associated Press | Updated: 26 October 2016 17:59 IST

A Chinese electronics maker that has recalled products sold in the US said Tuesday it did all it could to prevent a massive cyber-attack that briefly blocked access to websites including Twitter and Netflix.

Hangzhou Xiongmai Technology has said some of its web-connected cameras and digital recorders became compromised because customers failed to change their default passwords.

Liu Yuexin, Xiongmai's marketing director, told The Associated Press that Xiongmai and other companies across the home surveillance equipment industry were made aware of the vulnerability in April 2015. Liu said Xiongmai moved quickly to plug the gaps and should not be singled out for criticism.

Advertisement

"We don't know why there is a spear squarely pointed at our chest," Liu said.

Advertisement

The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represent a cyber-security nightmare. The convenience of being able to control home electronics via the web also leaves them more vulnerable to malicious intruders, experts say.

Unidentified hackers seized control of gadgets including Xiongmai's on Friday and directed them to launch an attack that temporarily disrupted access to a host of sites, ranging from Twitter and Netflix to Amazon and Spotify, according to US web security researchers.

Advertisement

The "distributed denial-of-service" attack targeted servers run by Dyn Inc., an internet company located in Manchester, New Hampshire. These types of attacks work by overwhelming targeted computers with junk data so that legitimate traffic can't get through.

"The issue with the consumer-connected device is that there is nearly no firewall between devices and the public internet," said Tracy Tsai, an analyst at Gartner, adding that many consumers leave the default setting on devices for ease of use without knowing the dangers.

Advertisement

Researchers at the New York-based cyber-security firm Flashpoint said most of the junk traffic heaped on Dyn came from internet-connected cameras and video-recording devices that had components made by Xiongmai. Those components had little security protection, so devices they went into became easy to exploit.

In an acknowledgement of its products' role in the hack, Xiongmai said in a statement Monday that it would recall products sold in the US before April 2015 to demonstrate "social responsibility." It said products sold after that date had been patched and no longer constitute a danger.

The company, which also makes dashboard cameras and computer chips, said it would recall several models of web-connected cameras and has offered customers a software security fix. The recall will apply only to devices sold under Xiongmai's name. As an original equipment manufacturer, close to 95 percent of the company's products are sold by other firms that repackage its devices under their own brand names, said Liu, the marketing director.

Liu refused to specify how many units the company expected to recall from the US other than that it could be in the thousands.

Xiongmai and Dahua, a video surveillance manufacturer also based in the eastern Chinese tech hub of Hangzhou, first came under scrutiny several weeks ago after Flashpoint assessed that hackers had controlled their devices to attack the website of cyber-security writer Brian Krebs, among other targets. Dahua has responded by saying it is dedicated to testing vulnerabilities, and has offered discounts for replacement equipment.

Xiongmai has adopted a less conciliatory stance. It downplayed its culpability this week, saying that as even the world's largest technology companies experience security lapses, "we are not afraid to also experience it once."

Xiongmai also slammed as "completely untrue, malicious and defamatory" reports about its products and appended to its statement a letter from its lawyers threatening litigation.

Mark James, an expert with Slovakia-based security company ESET, said that he doubted Xiongmai could be held liable for an attack such as Friday's, but that the company's officials "obviously recognize a concern here."

"Hopefully other manufacturers will follow suit and take a look at what they can do to increase security of their own products," he said.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Pro Max, Reno 15 Pro Launched Globally Alongside Reno 15
  2. Here's How Much the Realme 16 Pro Series Could Cost in India
  3. Beauty (2025) OTT Release Date: When and Where to Watch it Online?
  4. Samsung Could Add a Second Supplier for Galaxy A57's OLED Displays
  5. Vivo V70 Visits IMDA Database; Could Launch Soon With These Features
  6. MediaTek Dimensity 7100 Chipset Launched For Mid-Ranged Phones
  7. Hearing Static Noise on Your iPhone 17 Pro Max? You're Not Alone
  8. LG Just Unveiled These New Xboom Speaker Models Ahead of CES 2026
  9. Cyberpunk 2 Said to Launch in Q4 2030 With a Budget of $416 Million
  1. Vivo V70 Presence on IMDA Certification Database Points to Imminent Release
  2. MediaTek Dimensity 7100 Chipset Launched For Mid-Ranged Phones, Brings Efficiency Gains
  3. JWST Reveals Powerful Winds and Dense Atmosphere on Scorching Exoplanet TOI-561b
  4. New Year 2026 Scam Alert: This WhatsApp Greeting Could Wipe Your Bank Account
  5. Apple Fitness+ Teaser Hints at New Features Coming in January 2026
  6. An AI Pen? Jony Ive and OpenAI’s Secret Hardware Project Details Leak
  7. Oppo Reno 15 Pro Max, Reno 15 Pro With Dimensity 8450 SoC Launched Globally, Reno 15 Tags Along: Price, Specifications
  8. Hell’s Paradise Season 2 OTT Release Date Revealed: When and Where to Watch it Online?
  9. Xiaomi 17 Ultra, Xiaomi 17 Tipped to Launch in India in March; Xiaomi 17T Could Follow in April
  10. Beauty (2025) OTT Release Date: When and Where to Watch Ankith Koyya and Nilakhi Patra Starrer Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.