Cisco to Pay $8.6 Million for Selling Surveillance Software It Knew Was Vulnerable to Hackers

The settlement marks the first time a company has been forced to pay out under a US whistleblower law for not having adequate cyber-security protections.

Advertisement
By Agence France-Presse | Updated: 1 August 2019 15:41 IST

Cisco has agreed to pay $8.6 million (roughly Rs. 59 crores) to settle a claim that it sold video surveillance software it knew was vulnerable to hackers to hospitals, airports, schools, state governments and federal agencies.

The tech giant continued to sell the software and didn't fix the massive security weakness for about four years after a whistleblower alerted the company about it in 2008, according to a settlement unsealed Wednesday with the Justice Department and 15 states as well as the District of Columbia.

Hackers could use the flaw not just to spy on video footage but to turn surveillance cameras on and off, delete footage and even potentially compromise other connected physical security systems such as alarms or locks - all without being detected, according to Hamsa Mahendranathan, an attorney at Constantine Cannon, which represented whistleblower James Glenn.

Advertisement

The security weakness was also easy to find and exploit, said Michael Ronickher, another Contantine Cannon attorney.

Advertisement

"It was like the moment in the heist movies when a person types on a laptop for 30 seconds and says 'I'm in,' " Ronickher said.

There's no evidence that the bug was actually exploited to spy on Cisco customers' cameras, the company said in a statement. "We are pleased to have resolved" the dispute, a Cisco spokesman said. "There was no allegation or evidence that any unauthorised access to customers' video occurred as a result of the architecture."

Advertisement

Glenn's lawyers noted, however, that it's possible the hackers compromised the cameras but weren't discovered. "We don't want to give the impression we think this happened a lot," Ronickher said. "As far as we know no major breaches resulted from this. But it was left unaddressed for [four] years."

The settlement marks the first time a company has been forced to pay out under a federal whistleblower law for not having adequate cyber-security protections.

Advertisement

It also comes as the federal government is doing a top-to-bottom review of its multibillion-dollar contracting efforts, which officials have said were never designed to deal with cyber-security. The concern is that the government may be inadvertently greenlighting a slew of hackable products for purchase by federal agencies - many of which are then also bought by states and government grant recipients such as schools and hospitals.

That was the case with the flawed Cisco software. The US Secret Service, Federal Emergency Management Agency and military services were among the federal agencies that purchased it. And prisons and police departments, including the New York City Police Department, also bought it through grants, Mahendranathan said.

Given recent digital attacks on hospitals, local governments and schools, the pervasiveness of weak software is an urgent concern, the lawyers argued. "This video surveillance software . . . is supposed to make us safer, making the vulnerabilities at issue all the more troubling," Mahendranathan said.

Glenn, who was working for a Cisco partner in Denmark when he alerted the company to the issue, filed the lawsuit in the U.S. District Court for the Western District of New York under the False Claims Act. That law effectively allows individuals to sue on the behalf of the government if they believe a government contractor is committing fraud. The government can join the suit later and collect most of the proceeds.

In this case, the federal and state governments who joined will collect 80 percent of the $8.6 million award while Glenn and his attorneys will take 20 percent, his lawyers said.

Glenn, during his work at a Cisco subcontractor called NetDesign over the course of 2008, sent the company "detailed reports . . . revealing that anyone with a moderate grasp of network security could exploit this software" but never got a response, his attorneys said.

Glenn was fired by NetDesign in 2009, his attorneys said. They are not alleging that dismissal was in retaliation for pointing out the flaw. He filed the whistleblower lawsuit two years later.

"He tried to fix this through the appropriate channels before he ever thought about filing a lawsuit," Ronickher said. "This is usually the last resort for people who find things that just aren't being fixed."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cisco
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  2. Anthropic's First Indian Office in Bengaluru Is Now Open
  3. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  4. Google Reveals When You Can Expect Android 17 to Arrive on Your Pixel Phone
  5. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  6. Oppo Find X10 Series Could Debut This Year With This iPhone-Like Feature
  7. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  1. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  2. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  3. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  4. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  5. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  6. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  7. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  8. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  9. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
  10. Samsung’s 'Wide' Galaxy Z Fold Design Revealed via Leaked One UI 9 Animations
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.