Man accidentally seizes control of 6,700 robot vacuums worldwide while trying to steer his own with a game console controller
AI strategist Sammy Azdoufal used an AI coding tool to reverse engineer his DJI Romo robot vacuum's communication protocol. Instead of connecting only to his own £1,600 device, the app handed him live access to approximately 6,700 vacuums across 24 countries, including camera feeds, microphone audio, detailed floor plans, and IP addresses revealing approximate home locations. He hadn't breached DJI's systems, he'd simply extracted his own device's authentication token, and DJI's servers returned data from thousands of other customers. The flaw stemmed from backend cloud permission controls rather than local device hardware.
DJI has since deployed automatic patches, though the discoverer says additional weaknesses remain, including the ability to view video feeds without a security PIN. Inc The core problem was not encryption but that all data was stored in plain text, readable by anyone who gained server access.
This follows a pattern. In late 2025, an engineer discovered his iLife A11 vacuum was constantly sending telemetry to the manufacturer without consent, and when he blocked it, the maker issued a remote kill command that bricked the device. In February 2026, a smart sleep mask was found broadcasting real-time brainwave data from users worldwide to an unsecured server, with shared credentials that also enabled sending electrical impulses to sleeping strangers.
The UK's PSTI Act (in force since April 2024) requires IoT manufacturers to eliminate default passwords, publish vulnerability reporting contacts, and state minimum security update periods, with fines up to £10m or 4% of global revenue. It currently covers only three of twelve recommended security principles and does not impose a general obligation to make products secure.
We want your views
- Should IoT devices that carry cameras or microphones face mandatory independent security audits before they reach the market?
- When a device stores your floor plans, live video and location data in plain text on a cloud server, is "convenience" still a defensible trade-off?
- Should manufacturers be legally liable for privacy breaches caused by architectural negligence, not just data breaches from external attacks?
- Is the UK's PSTI Act fit for purpose when it covers barely a quarter of recognised IoT security standards?
- At what point does putting an always-on camera and microphone in someone's home, secured by shared credentials, cross the line from product failure into institutional recklessness?


