
Israeli startup Toka—backed by Andreessen Horowitz—has drawn fresh scrutiny after reporting indicated it wants to help U.S. agencies compromise Wi‑Fi-connected security cameras and other internet-of-things (IoT) devices. The company’s pitch, as described by TechCrunch, reflects a broader shift in cybersecurity and surveillance interest: while much public attention has focused on phones and personal devices, the next wave of intrusions increasingly targets the networked sensors and cameras that sit in homes, businesses, and public spaces.
The latest concern is not simply that Toka performs “cyber” work, but that its capabilities can be used to reach devices people rely on for security and monitoring. TechCrunch reported that the company is now attracting growing attention for hacking other kinds of devices, including security cameras and additional IoT products that connect over Wi‑Fi. The report positions this as an escalation from earlier controversy surrounding camera footage access.
Toka’s background has already made it a flashpoint. The company had previously gained attention through a 2022 Haaretz article detailing claims about obtaining—then even deleting—security camera footage. According to TechCrunch, that history has become part of the context for its current outreach, as policymakers and privacy advocates weigh the implications of offensive access to video systems that are commonly used for evidence in investigations.
In an effort to distinguish itself from other high-profile surveillance vendors, Toka has publicly sought to avoid the kind of scrutiny aimed at well-known Israeli spyware firms. TechCrunch reported that the company promised it does business only with governments from a “select list of countries” that it says have good records on civil liberties and corruption. That stance mirrors a common strategy among surveillance-adjacent vendors—offering assurances about customer vetting—yet critics argue that assurances do not address the end-use problem: once tools can access devices, misuse risks remain.
Toka’s efforts at boundary-setting have also been tested by its international footprint. TechCrunch noted that the company has been listed as attending a conference in the United Arab Emirates in 2021. Around the same period, it also hired a vice president of international sales who had previously worked for Cellebrite, another controversial Israeli cyber firm. Toka told TechCrunch it does not have clients in the UAE and that it monitors its international sales closely. Even with those explanations, the episode underscores how easily controversies can attach to vendor networks and personnel histories.
For the U.S., the prospect of working with a firm specializing in camera and IoT hacking raises tactical questions for agencies and strategic questions for oversight. Camera systems are often deployed widely, configured by consumers and small businesses, and maintained through a mix of consumer firmware and vendor updates. Any method for penetrating those devices—particularly if it can be paired with deletion or concealment—could complicate digital forensics, evidence handling, and transparency requirements.
The TechCrunch reporting places Toka within that contested ecosystem. It describes Toka as an Israeli startup backed by Andreessen Horowitz and specializing in hacking categories that can affect everyday surveillance infrastructure. While the report does not claim specific U.S. operations, it frames the company’s ambitions around helping U.S. agencies access devices such as Wi‑Fi-connected cameras and other IoT equipment—work that, if pursued, would bring offensive capability into the physical-world systems that increasingly underpin public and private safety functions.
The risk profile for IoT security is different from traditional computing. Cameras and sensors often run embedded software with limited user control, and they may remain unpatched for long periods. This can create persistent pathways for intrusion, especially if attackers can exploit vulnerabilities in network protocols, default credentials, or third-party integrations. As interest rises in these targets, companies operating in the offensive security space may see increasing demand from governments seeking broader reach.
Toka’s case illustrates how surveillance-related technology can become entwined with broader debates about legality and governance. The company’s attempt to separate itself from entities like NSO Group—identified in the TechCrunch context as U.S.-sanctioned—signals that reputational risk and regulatory pressure matter to buyers and intermediaries alike. It also suggests that procurement processes may be influenced by narratives about “civil liberties” screening, even as the technical reality remains that device compromise is inherently invasive.
Beyond the immediate controversy, the shift toward hacking cameras and IoT devices sits alongside a larger trend: technology firms and insurers increasingly rely on data streams and networked systems to operate. Though these developments are not the same as offensive hacking, they highlight why connected devices have become central to modern infrastructure and why vulnerabilities—whether in security systems or in the communications layers that feed analytics—can have outsized consequences. The same connectivity that enables telematics and digital operations also creates an expanded surface area for attackers.
That context can be seen in other sectors where data-driven technology is being integrated into operations. For example, UK fleet insurer Flock has launched “Jay,” described as an AI expert for fleet customers using live telematics and claims data to help identify risks and monitor performance. This kind of connected-model approach depends on stable data pipelines and device integrity. While the insurance use case is benign, it demonstrates how quickly society grows dependent on networks and endpoint devices—dependencies that offensive cyber efforts can exploit if governance and protections are weak.
As Toka seeks U.S.-linked opportunities, the debate will likely intensify around verification, accountability, and oversight—especially regarding what “good track records” mean in practice. The company’s insistence that it monitors international sales and has no clients in the UAE, coupled with its attendance at an international conference and the hiring of an executive with Cellebrite experience, suggests that its public narrative is likely to remain contested.
In the end, the central question is whether governments can balance operational needs with safeguards that prevent misuse. If a firm built for device compromise moves deeper into agency relationships, privacy advocates, watchdogs, and lawmakers may push for clearer rules about authorization, auditing, and limits on use cases. Until then, Toka’s push to extend hacking ambitions from cameras to broader IoT ecosystems may serve as another indicator that the battleground for surveillance is moving from screens to infrastructure—and from phones to the small, networked devices that quietly record daily life.
SHOP AMAZON BEST SELLERS, CLICK TO BUY FROM AMAZON.
SHOP AMAZON BEST SELLERS, CLICK TO BUY FROM AMAZON.










