News: 1589920591

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Rogue ADT tech spied on hundreds of customers in their homes via CCTV – including me, says teen girl

(2020/05/19)


A technician at ADT remotely accessed hundreds of customers' CCTV cameras to spy on people in their own homes, the burglar-alarm biz has admitted.

At least one of the victims was a teenage girl, and another a young mother, according to court filings.

Last month, an ADT customer in Dallas, Texas, spotted and reported an unexpected email address listed as an admin user on their home security system. An internal investigation revealed it was the personal email of one of its employees, and he had seemingly used it to view the home's camera system nearly a hundred times.

A probe found the same technician had made himself an admin on 220 customers' accounts, meaning he could lock and unlock doors remotely, as well as access the live feed of cameras connected to the ADT network. His access is said to have stretched back seven years.

When ADT dug into the logs, it became clear their rogue insider had been regularly spying on customers, including, it is claimed, accessing the video feed from the bedroom of one teenage girl dozens of times. That teenager this week sued ADT for negligence and emotional distress, seeking a class-action lawsuit against the US corp, and naming the technician in question: it is alleged Telesforo Aviles was responsible.

The allegations are the stuff of nightmares: the [1]lawsuit [PDF] details how the teenage daughter and her mother were initially uncomfortable about the idea of installing security cameras inside their house, though ADT “reassured them both that the security system was perfectly safe,” according to court filings, and a technician later fitted the kit.

But then, on April 24, “ADT called to explain that one of its technicians had gained access" to her mother's account "and had been watching" the mother and daughter "on approximately 73 different occasions,” according to court filings.

Her lawsuit then alleges, "based upon the cameras’ wide-angle lens and placement, the ADT employee had an opportunity to watch at least" the teenager "nude, in various states of undress, getting ready for bed, and moments of physical intimacy."

Fool me once

An [2]almost identical [PDF] lawsuit has been filed by a second person – a young mother – whose security system installation “included an indoor security camera with a wide-angle view that provided a visual of a bathroom, entryway, family room and dining space, stairs, and into the master bedroom.”

Scottish court issues damages to couple over distress caused by neighbour's use of CCTV [3]READ MORE

To its credit, when ADT heard about the unauthorized access, it did the right thing: it fired the worker, reported him to the cops, and then contacted all those affected explaining the situation.

According to ADT, its unnamed technician abused a service mode function while physically present in customers’ homes in the Dallas area to add his personal email address – a feature that is “neither necessary nor permitted,” and which the company will remove in an upcoming software update. ADT technicians do not have remote access to that function, but once the technician was included on the system, he could access the surveillance gear remotely.

Understandably, however, customers are furious it happened in the first place and went unnoticed for seven years. “This type of access could only occur because ADT failed to implement adequate procedures that would prevent non-household members from adding non-household email addresses,” reads the teenager's lawsuit.

“Similarly, ADT failed to monitor consumers’ accounts and promptly alert them anytime a new email was added to their accounts. Countless checks could have been in place to prevent or at least stop this conduct. Instead, this breach came to light only by luck and happenstance.”

Her lawsuit also noted that there is every reason to believe that other ADT technicians have similarly abused the system: ADT says it is carrying out a detailed investigation and audit to make sure there are no other instances.

“Our customers trust ADT with their safety and protection. We understand that this incident jeopardizes that trust and is entirely unacceptable,” the company acknowledged in an [4]statement .

“We will make extraordinary efforts to earn back that trust. Our investigation is ongoing; we will continue to review all our customer accounts until we can be sure no one else’s privacy is at risk. In addition, we’ve already implemented technical and procedural solutions to help keep this abuse of access from ever happening again.”

The manufacturer has also said it will “review all of our processes, technical systems and hiring practices to strengthen our account security and customer privacy even more, and we’ve engaged third-party experts to assist in that review.”

In a message to The Register today, ADT said: "We deeply regret what happened to the 220 customers affected by this incident and have contacted them to help resolve their concerns. We are supporting law enforcement’s investigation of the former employee and are committed to helping bring justice to those impacted by his improper actions." ®



[1] https://regmedia.co.uk/2020/05/19/adt-spycam-lawsuit.pdf

[2] https://regmedia.co.uk/2020/05/19/adt-second-spy-lawsuit.pdf

[3] https://www.theregister.co.uk/2017/02/10/scottish_court_issues_damages_to_couple_over_distress_caused_by_neighbours_use_of_cctv/

[4] https://www.adt.com/adt-privacy-notice

His own email?

The Man Who Fell To Earth

No smart.

Chris G

Wow! What a creep. It does point to a certain laxity on the part of ADT in the first place to ensure that any unauthorised access was not possible.

From the article, it mentioned they were going to remove the unauthorised email address via a software update, that seems to indicate that access may still be possible by other means.

Perhaps they should consider a full security audit on their kit?

"ADT failed to monitor consumers’ accounts"

Pascal Monett

Right. Absolutely true. Just like White Star Lines failed to put enough lifeboats for all passengers.

ADT is guilty of trusting its employees. A harsh lesson, and one that will bring down a raft of restrictions and technical difficulties that will indeed make it impossible in the future to do such things as spy on an underage girl. And that is undoubtedly a good thing. However, given that ADT threw the book at the guy and delivered him to the police, and pledged to do what was necessary to keep this from ever happening again, I do not see that that ADT should shoulder all the blame.

Honestly, the technician was there to install the system. He has authority to define the email addresses that have access. Internal procedures already forbade any unrecognized manipulations, what more do you want ? The creep cheated. The system is not at fault.

Now, ADT is going to have to modify the installation procedure to ensure that the technician has a list of approved email addresses, shows them to the customer and gets a signed approval, in order to ensure that this does not happen again. Because of one asshole, countless time and money will be employed to get customer approval of every address added to the system.

That's exactly why we need laws : because of the 0.0001% of assholes who ruin everything for everyone.

Re: "ADT failed to monitor consumers’ accounts"

Glen 1

"That's exactly why we need laws : because of the 0.0001% of assholes who ruin everything for everyone."

Something something social distancing Covid-19

Sykowasp

Creepy peeper.

Although as a parent (or more generally, a person who tries to think things through) I think I would push back on cameras in bedrooms/bathrooms regardless.

And yes, the key thing about systems is that the owner should be notified when new accounts are added, maybe get a monthly report of users on the system, and more. Full audit trails of every configuration option too. I don't know if ADT have centralised access to accounts or if they're managed within the home only - but duplicate email addresses on multiple home installs could be flagged and investigated as well. I.e., basic business reports could have found this issue far earlier, but nobody thought that an employee would actually be tempted by the thought of some sneaky voyeurism?

Camera in bedroom?

simkin

What morons would put a camera in a bedroom in the first place?

Re: Camera in bedroom?

vogon00

Errrrrrrrr....morons?

Re: Camera in bedroom?

Androgynous Cow Herd

The moronic kind

Jamesit

I agree with the comments able him being a creep. But WTF would someone have a security camera in their bedroom?!???!

Anonymous Coward

Yup. Seriously – I would not put a camera in my bedroom and then expect nobody to see the footage. I mean, even if it were used to solve a break-in or something, someone would have to go through all the other footage to find the pertinent bit, which would inevitably include things I'd really rather people did not see. CCTV has no place in bedrooms at all. They don't even do that in prisons, FFS.

And this is why I don't do cloud based access.

Anonymous Coward

Yes I have CCTV at home and I can add a further 17 network cameras and 6 physical cameras onto it. But as good as the system is, I have it behind my firewall, running off a box I trust and can review access to at any time.

Also, if I was ever going to add any cameras inside the house, they'd be on the ground floor or at worst, the stairs pointing down them. Never in any of our bedrooms. What goes on in there needs never be recorded... (Well except for that one video... But that's besides the point).

As tragic as this is it could have been avoided if the temptation wasn't there due to cameras in private locations.

That doesn't however remove that ADT allowed this to happen. Human weakness will always bring down these high ideals.

Re: And this is why I don't do cloud based access.

Anonymous Coward

. Never in any of our bedrooms. What goes on in there needs never be recorded... (Well except for that one video... But that's besides the point).

Could you upload it so we can judge for ourselves?

edris90

They roll the dice on external security Services vs developing and administratoring in their own.... now they're upset that a piece of paper and a company namedl did not protect them from basic realities. When you outsource you lose control and are completely at the mercy of whatever underpaid disgruntled workers the contracted company managed to retain.

the only people that should ever have physical access or be involved with the installation operation of your security system is you and the other occupants of the house.

If you need to access your remote camera feeds, use a VPN gateway.

If There's cameras in the bedroom then you can be pretty sure the dad is watching his daughter masturbate.

The future lies ahead.