Cisco to Pay $8.6 Million for Selling Surveillance Software It Knew Was Vulnerable to Hackers

The settlement marks the first time a company has been forced to pay out under a US whistleblower law for not having adequate cyber-security protections.

Advertisement
By Agence France-Presse | Updated: 1 August 2019 15:41 IST

Cisco has agreed to pay $8.6 million (roughly Rs. 59 crores) to settle a claim that it sold video surveillance software it knew was vulnerable to hackers to hospitals, airports, schools, state governments and federal agencies.

The tech giant continued to sell the software and didn't fix the massive security weakness for about four years after a whistleblower alerted the company about it in 2008, according to a settlement unsealed Wednesday with the Justice Department and 15 states as well as the District of Columbia.

Hackers could use the flaw not just to spy on video footage but to turn surveillance cameras on and off, delete footage and even potentially compromise other connected physical security systems such as alarms or locks - all without being detected, according to Hamsa Mahendranathan, an attorney at Constantine Cannon, which represented whistleblower James Glenn.

Advertisement

The security weakness was also easy to find and exploit, said Michael Ronickher, another Contantine Cannon attorney.

Advertisement

"It was like the moment in the heist movies when a person types on a laptop for 30 seconds and says 'I'm in,' " Ronickher said.

There's no evidence that the bug was actually exploited to spy on Cisco customers' cameras, the company said in a statement. "We are pleased to have resolved" the dispute, a Cisco spokesman said. "There was no allegation or evidence that any unauthorised access to customers' video occurred as a result of the architecture."

Advertisement

Glenn's lawyers noted, however, that it's possible the hackers compromised the cameras but weren't discovered. "We don't want to give the impression we think this happened a lot," Ronickher said. "As far as we know no major breaches resulted from this. But it was left unaddressed for [four] years."

The settlement marks the first time a company has been forced to pay out under a federal whistleblower law for not having adequate cyber-security protections.

Advertisement

It also comes as the federal government is doing a top-to-bottom review of its multibillion-dollar contracting efforts, which officials have said were never designed to deal with cyber-security. The concern is that the government may be inadvertently greenlighting a slew of hackable products for purchase by federal agencies - many of which are then also bought by states and government grant recipients such as schools and hospitals.

That was the case with the flawed Cisco software. The US Secret Service, Federal Emergency Management Agency and military services were among the federal agencies that purchased it. And prisons and police departments, including the New York City Police Department, also bought it through grants, Mahendranathan said.

Given recent digital attacks on hospitals, local governments and schools, the pervasiveness of weak software is an urgent concern, the lawyers argued. "This video surveillance software . . . is supposed to make us safer, making the vulnerabilities at issue all the more troubling," Mahendranathan said.

Glenn, who was working for a Cisco partner in Denmark when he alerted the company to the issue, filed the lawsuit in the U.S. District Court for the Western District of New York under the False Claims Act. That law effectively allows individuals to sue on the behalf of the government if they believe a government contractor is committing fraud. The government can join the suit later and collect most of the proceeds.

In this case, the federal and state governments who joined will collect 80 percent of the $8.6 million award while Glenn and his attorneys will take 20 percent, his lawyers said.

Glenn, during his work at a Cisco subcontractor called NetDesign over the course of 2008, sent the company "detailed reports . . . revealing that anyone with a moderate grasp of network security could exploit this software" but never got a response, his attorneys said.

Glenn was fired by NetDesign in 2009, his attorneys said. They are not alleging that dismissal was in retaliation for pointing out the flaw. He filed the whistleblower lawsuit two years later.

"He tried to fix this through the appropriate channels before he ever thought about filing a lawsuit," Ronickher said. "This is usually the last resort for people who find things that just aren't being fixed."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cisco
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  2. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  3. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  4. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  5. OnePlus 15R Review
  6. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  7. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan
  8. JWST observations may unlock new clues about dark matter
  9. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  10. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  1. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  2. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  3. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
  4. Infinix Xpad Edge Launched With 13.2-Inch Display, 8,000mAh Battery: Price, Specifications
  5. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  6. The Villainess Is Adored by the Prince of the Neighbor Kingdom OTT Release Date: Know When and Where to Watch This Japanese Anime Series Online
  7. Easygoing Defense by the Optimistic Lord Anime to Stream on Crunchyroll in January 2026
  8. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  9. Pornhub User Data Reportedly Stolen by Hacker Group ShinyHunters, Threaten to Expose
  10. Apple's Foldable iPhone Bears Resemblance to iPad Mini in Leaked CAD Renders
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.