Copy article

Man accidentally seizes control of 6,700 robot vacuums worldwide while trying to steer his own with a game console controller

ended 24. February 2026

AI strategist Sammy Azdoufal used an AI coding tool to reverse engineer his DJI Romo robot vacuum's communication protocol. Instead of connecting only to his own £1,600 device, the app handed him live access to approximately 6,700 vacuums across 24 countries, including camera feeds, microphone audio, detailed floor plans, and IP addresses revealing approximate home locations. He hadn't breached DJI's systems, he'd simply extracted his own device's authentication token, and DJI's servers returned data from thousands of other customers.  The flaw stemmed from backend cloud permission controls rather than local device hardware.

DJI has since deployed automatic patches, though the discoverer says additional weaknesses remain, including the ability to view video feeds without a security PIN. Inc The core problem was not encryption but that all data was stored in plain text, readable by anyone who gained server access. 

This follows a pattern. In late 2025, an engineer discovered his iLife A11 vacuum was constantly sending telemetry to the manufacturer without consent, and when he blocked it, the maker issued a remote kill command that bricked the device. In February 2026, a smart sleep mask was found broadcasting real-time brainwave data from users worldwide to an unsecured server, with shared credentials that also enabled sending electrical impulses to sleeping strangers. 

The UK's PSTI Act (in force since April 2024) requires IoT manufacturers to eliminate default passwords, publish vulnerability reporting contacts, and state minimum security update periods, with fines up to £10m or 4% of global revenue. It currently covers only three of twelve recommended security principles and does not impose a general obligation to make products secure.

We want your views

  • Should IoT devices that carry cameras or microphones face mandatory independent security audits before they reach the market?
  • When a device stores your floor plans, live video and location data in plain text on a cloud server, is "convenience" still a defensible trade-off?
  • Should manufacturers be legally liable for privacy breaches caused by architectural negligence, not just data breaches from external attacks?
  • Is the UK's PSTI Act fit for purpose when it covers barely a quarter of recognised IoT security standards?
  • At what point does putting an always-on camera and microphone in someone's home, secured by shared credentials, cross the line from product failure into institutional recklessness?

 

3 responses from the Newspage community

Copy all

Star Quote
Copy

A man wanted to drive his robot vacuum with a PlayStation controller. Thirty minutes later, he had live cameras, microphones, and floor plans from thousands of homes across 24 countries. He didn't crack a thing. He used his own login, and the system just handed him the keys to everyone else's house.

The uncomfortable question is not whether smart devices are convenient. It's whether you'd install a camera and microphone in your bedroom if the manufacturer told you upfront that your data would be stored in plain text on a shared server, accessible to anyone with a valid customer token. Because that is exactly what happened here. They just didn't mention it.
Copy

6,700 silent spies switched on with a single slip. That’s not innovation, it’s negligence on an industrial scale. This wasn’t a Hollywood hack; it was one authentication token and a backend that handed over homes across 24 countries like party favours. The real scandal isn’t just sloppy code, it’s that cameras and microphones are being sold without mandatory, independent security checks before they hit British bedrooms. The UK’s £10m fines sound tough, but if firms can ship products that share plain-text data, the rules clearly lack real teeth. Until audits are compulsory, convenience will keep trumping common sense, and consumers will keep paying the privacy price.
Copy

While there is a certain dark comedy in accidentally conquering a global fleet of robots with a game controller, this exposes the terrifying fragility of the 'smart' home.

We frequently uncover exactly this kind of negligence. Companies obsess over shiny front-end features while leaving backend permissions wide open. We often find that what is sold as 'proprietary AI magic' is actually running on insecure infrastructure that a junior dev could crack.

Storing floor plans and live video feeds in plain text isn't a bug; it is institutional recklessness. It proves that for many manufacturers, user privacy is an afterthought to speed-to-market.

The PSTI Act is currently a paper tiger. If you are putting a camera and microphone in someone’s living room, 'trust us' isn't a valid security policy. Mandatory independent security audits aren't 'red tape', they are the only thing standing between your privacy and a live broadcast.