TL;DR: BePrime, a Mexican cybersecurity firm serving corporations like Iberdrola, ArcelorMittal, Whirlpool, and Alsea (Starbucks, Domino’s, Vips), got hacked on April 20, 2026 because its admin accounts didn’t have multifactor authentication. The attacker, using the alias “dylanmarly”, stole 12.6 GB of data including plaintext credentials and security audit reports, took control of 1,858 Cisco Meraki network devices, and accessed live surveillance camera feeds at client offices. BePrime’s response was to threaten legal action against journalists covering the breach. A cybersecurity company that couldn’t manage basic MFA is now trying to intimidate the press instead of explaining what happened to the companies paying it to keep them safe.

No Two-Factor. 1,858 Devices Compromised.

On April 20, 2026, a threat actor posted a data dump on a cybercrime forum with an uncomfortable claim: they’d breached BePrime, a managed security services provider based in Mexico, by walking through admin accounts that lacked multifactor authentication [1] [2].

The entry point was embarrassingly basic. BePrime’s privileged administrator accounts (the ones with the keys to everything) had no MFA enabled. No second factor. No authenticator app. No hardware token. Just a username and password standing between an attacker and the security infrastructure of multiple Fortune 500 companies [2] [3].

Once inside, the attacker found Cisco Meraki API keys and used them to take control of 1,858 network devices (switches, routers, and access points), giving them access to traffic flowing through more than 2,600 connected devices [2] [3]. That’s not a breach. That’s the entire network, handed over because someone skipped step one of cybersecurity hygiene.

Security researcher Alberto Daniel Hill put it bluntly: “The irony that a firm selling cybersecurity was breached for not having two-factor authentication results in a total loss of trust” [3].

They Watched the Security Cameras

Here’s where it gets worse.

BePrime managed Cisco Meraki Vision surveillance systems for its clients. The stolen API keys didn’t just give the attacker network access. They opened live video surveillance feeds. The attacker published screenshots of the Meraki Vision panel showing camera feeds overlooking office workspaces at client locations [1] [2].

Think about that. A cybersecurity company’s job is to protect its clients’ physical and digital security. Instead, because of a missing checkbox on an admin panel, an unauthorized person was watching employees work through their office cameras.

The 12.6 GB data dump included [2] [3]:

  • Plaintext credentials: passwords stored without proper hashing
  • Transaction records: financial data from client operations
  • Security audit reports (pentests): detailed documentation of client vulnerabilities, essentially a roadmap for future attacks
  • Live surveillance camera access: via the Meraki Vision platform

The pentest reports are especially dangerous. Those documents describe exactly where client systems are weak, written by BePrime’s own security teams. In the hands of an attacker, they’re a target list.

Who Was Exposed: Starbucks, Whirlpool, Iberdrola, ArcelorMittal

BePrime provides connectivity and managed security services to some of the largest corporations operating in Latin America [2] [3]:

  • Iberdrola: Spanish energy multinational, one of the world’s largest electricity utilities
  • ArcelorMittal: the world’s largest steel manufacturer
  • Whirlpool: global home appliance manufacturer
  • Alsea: Latin America’s largest restaurant operator, running Starbucks, Domino’s Pizza, and Vips locations across Mexico and the region

None of these companies chose to have their surveillance cameras accessible to random hackers on a cybercrime forum. None of them chose to have their security audit reports leaked. They paid BePrime to prevent exactly this.

This is the supply chain problem in physical form. You can lock down your own systems, run your own penetration tests, enforce your own MFA policies, and still get burned because the company you hired to protect you couldn’t protect itself.

BePrime’s Response: Threaten the Reporters

When a cybersecurity company gets breached, the standard playbook is straightforward: acknowledge the incident, explain the scope, describe the remediation, and be transparent with affected clients.

BePrime chose a different path.

The company acknowledged a “cybersecurity incident” on April 21 and said it had engaged Cisco Talos for remediation [1]. It claimed “there is no evidence of any impact on Be Prime’s operational continuity or on our clients’ operations” [1], a statement hard to reconcile with 1,858 compromised network devices and live camera feeds published on a hacker forum.

Then came the threats. BePrime announced it would initiate legal proceedings against journalists and media outlets that published “false, inaccurate, or out-of-context information” about the breach [1] [2] [3].

The company didn’t specify what was false. It didn’t correct any specific claims. It just warned reporters that covering the story could mean a lawsuit.

That didn’t land well. The Electronic Frontier Foundation, Reporters Without Borders, and the Committee to Protect Journalists have all emphasized that credible incident response “must never intimidate the press or independent researchers” [2]. Threatening the people telling your clients what happened is not a security strategy. It’s a cover-up strategy.

The Bigger Pattern: Your Security Vendor Is a Liability

BePrime is not an isolated case. It’s the latest in an accelerating pattern of security companies becoming the attack vector:

  • Vercel (April 2026): Breached through a third-party AI tool, with ShinyHunters demanding $2M for stolen data
  • Anthropic MCP (April 2026): Design-level remote code execution flaw affecting 200,000+ AI servers, dismissed as “expected behavior”
  • SolarWinds (2020): The breach that rewrote the playbook: a compromised IT management tool gave Russian intelligence access to 18,000 organizations including the U.S. Treasury and Department of Homeland Security

When you hire a managed security provider, you’re giving them deep access to your network, your cameras, your device fleet, your vulnerability data. If they get popped, you get popped. And you had no say in whether they bothered to turn on MFA.

What You Can Do

  • Ask your vendors about MFA: If the company managing your network security doesn’t enforce multifactor authentication on all privileged accounts, find a new vendor. This is the bare minimum
  • Demand third-party audits: Don’t just trust that your security provider follows its own advice. Ask for SOC 2 reports, independent penetration test results, and evidence of access controls
  • Review camera system access: If your surveillance system is managed by a third party, know who has API access. Check if those credentials are rotated. Ask what happens if the vendor gets breached
  • Segment your network: If a managed service provider has access to your devices, ensure that access is limited and segmented. The attacker shouldn’t be able to jump from network switches to camera feeds
  • Check your pentest storage: Your vulnerability assessments are a roadmap for attackers. Know where those reports live, who has access, and whether they’re encrypted at rest

References

  1. The Register: Crook Claims to Leak ‘Video Surveillance Footage’ of Firms (April 21, 2026)
  2. Rankiteo: Iberdrola, BePrime, ArcelorMittal and Alsea: Breach at Cybersecurity Company Exposes Client Data and Surveillance Systems (April 2026)
  3. Escudo Digital: Breach at Cybersecurity Company Exposes Client Data and Surveillance Systems (April 2026)