India had tightened CCTV security requirements amid concerns that compromised cameras could expose sensitive footage or become cybersecurity entry points
India had tightened CCTV security requirements amid concerns that compromised cameras could expose sensitive footage or become cybersecurity entry points

Amazon, Flipkart review CCTV listings after 'security concerns' flagged

The e-commerce platforms had started checking internet-connected security cameras after hundreds of models were found without required government approval

Amazon and Walmart-owned Flipkart have begun reviewing internet-connected security cameras sold on their Indian platforms after an investigation found that hundreds of models were being offered without the approvals required under the country's tightened CCTV security regime.

More than 700 of about 770 internet-connected security camera listings examined on the two platforms were for models that did not appear on the Bureau of Indian Standards' public database of approved brands or cameras, according to a Reuters analysis. The platforms are now checking listings offered by third-party sellers and brands, with products lacking the necessary approval expected to be removed.

Hundreds of models flagged

The scale of the apparent compliance gap is significant because India introduced stricter security requirements for CCTV cameras amid concerns over the possibility of sensitive footage being accessed or transferred without authorisation.

Since April 2025, CCTV cameras covered by the compulsory registration regime have been required to comply with essential security requirements. The framework involves testing of hardware and software and scrutiny of security-critical components before compliant products can be registered for sale.

The requirements include checks related to the system-on-chip, firmware, printed circuit board assemblies, network interfaces and physical interfaces. Manufacturers are also required to provide information that allows testing laboratories to assess supply-chain security and potential vulnerabilities.

Despite the requirements, the analysis found hundreds of camera models available through major e-commerce platforms without appearing on the relevant approved-product database.

Listings start disappearing

At least a dozen listings had been removed from the platforms since Tuesday. These included at least two models belonging to Hikvision's EZVIZ brand, which were subsequently shown as unavailable on Amazon.

Amazon declined to comment on the review, while Flipkart did not respond to queries cited in the report. The Bureau of Indian Standards also did not immediately comment on the listings.

Hundreds of products, however, continued to be available online as of Thursday.

The review puts the focus on how e-commerce marketplaces verify whether electronic products offered by third-party sellers meet mandatory Indian certification and cybersecurity requirements.

Why CCTV cameras pose a risk

Unlike conventional cameras that merely record footage locally, many modern surveillance cameras are permanently connected to WiFi networks and cloud services. Users can watch live footage remotely through smartphones or other internet-connected devices.

That convenience also creates potential vulnerabilities. A poorly secured camera can potentially allow unauthorised access to video feeds or provide an entry point into a wider network.

Gulshan Rai, who served as the government's cybersecurity chief between 2015 and 2019, described the sale of unapproved cameras as a serious concern, pointing out that a compromised device could pose both surveillance and cybersecurity risks.

The government's security requirements are intended to examine such vulnerabilities before devices enter the Indian market.

Chinese brands among listings

The review found at least eight WiFi camera models from Chinese manufacturers Hikvision and Zhejiang Dahua Technology on Amazon that did not appear to have the required approval.

Hikvision and Dahua together accounted for around 30 per cent of India's security camera market last year, according to Counterpoint Research data cited in the report. Neither company responded to requests for comment.

The two manufacturers have previously faced restrictions in the United States, where federal agencies are barred from procuring certain equipment made by them over security concerns.

The Indian requirements, however, apply on the basis of compliance with domestic testing and certification standards rather than nationality alone.

138 listings from one brand

Another company examined was Maizic Smarthomes, which markets itself as an Indian artificial intelligence-based security camera brand.

None of its 138 WiFi camera offerings found on Amazon appeared on the government approval database examined in the investigation. Some of the products were cameras integrated into ordinary-looking light bulbs.

One such product advertised the ability to connect to WiFi and allow users to watch live footage remotely from anywhere through a smartphone or tablet.

Maizic co-founder Santosh Kumar Singh said the company had removed the WiFi functionality that enabled remote live feeds from its cameras while it awaited government approval. The devices would instead be limited to direct connectivity with nearby mobile devices until certification was obtained.

Espionage concerns behind rules

India's increased scrutiny of surveillance equipment comes amid broader concerns about the security of internet-connected cameras and the possibility of footage from sensitive locations being accessed from outside the country.

Those concerns acquired added urgency after Delhi Police said in April that it had uncovered a Pakistan-linked espionage network involving Chinese-made SIM-enabled CCTV cameras installed near military locations in northern India. Police alleged that live footage from the cameras was being transmitted to handlers in Pakistan.

The episode highlighted how ordinary surveillance devices can become a security vulnerability when deployed near sensitive installations or connected through insecure networks.

The government's security framework seeks to address such risks by requiring manufacturers to disclose and test security-critical hardware and software and demonstrate compliance before their cameras can legally enter the market.

Platforms face compliance question

The findings have also raised questions about marketplace oversight. E-commerce platforms host large numbers of third-party sellers, making the verification of licences, certification marks and regulatory approvals a continuing compliance challenge.

Amazon had already acted against at least one camera seller before the latest review. In July, it informed a seller that a camera listing was being removed for lacking the necessary approval marks after a complaint from a Bureau of Indian Standards official.

The latest review is broader, covering security-camera listings across the platforms.

Amazon is also reported to have decided to remove the dedicated page for Dahua's Imou brand, which featured indoor and outdoor WiFi cameras and promotional material.

With internet-connected cameras increasingly used in homes, shops, offices, residential complexes and public spaces, the issue goes beyond product certification. The review has put the security of the devices themselves — and the footage they continuously collect — at the centre of India's expanding cybersecurity concerns.

Responsive Banner
Fact Net
www.fact.net.in