
In May 2026, French researcher Sammy Azdoulal discovered he could view live footage from millions of cameras worldwide — just by clicking a link. No hacking required.
Affected brands — Arenti, Boifun, ieGeek, CloudEdge, Wyze, and Petcube — all shared underlying technology from a single Chinese manufacturer, Meari Technology, spreading one vulnerability across many products at once.
baby monitors and home security cameras left open to live viewing by anyone with a link.
The security checks meant to confirm "is this really your camera" were either missing entirely or trivially easy to bypass — leaving millions of homes exposed through three distinct failures.
A free account with no special privileges could receive alert notifications from other people's cameras entirely.
A digital password that should have required login was left wide open — anyone with a device's serial number could look up its location and details.
Motion-triggered images — including from children's bedrooms — were stored on public cloud with no login required, protected only by weak, reversible scrambling instead of real encryption.
This is not an isolated mistake. A security research firm tested 9 popular baby monitors and found that 8 earned a failing security grade — and price was no guarantee of safety.
Security is rarely the first priority when a budget smart device is designed. More expensive models often just added more features on top of the same weak underlying protection.
The manufacturer has said it is addressing the issues — public disclosure often does lead to genuine fixes. But any internet-connected camera carries a baseline risk that a traditional, non-connected monitor simply does not.

Treating any internet-connected camera with basic caution is a habit worth building now.
Change it immediately after setup — default passwords are widely known to attackers.
If your brand was named in recent research, check the manufacturer's website for a firmware update.
Look for independently reviewed security track records, not just price or features.
A camera that stores footage on-device means fewer places your footage can be exposed.
Especially in bedrooms — if it's off, it can't be watched.
A few simple questions can meaningfully reduce your risk before purchasing any smart camera. None of these require technical expertise — a manufacturer's website or support team can usually answer all three.
Does the manufacturer release security updates promptly when problems are found, or go silent for months?
Does the product require a unique password at setup, or does it ship with an easily guessed default many buyers never change?
Is footage stored locally on the device, or automatically uploaded to a cloud server you don't control?

The same risk applies to every internet-connected camera in a home — not just baby monitors. Video doorbells, pet cameras, indoor security cameras, and outdoor cameras all share the same basic technology and often the same weaknesses.
Walk through your home and list every internet-connected camera. For each one, ask:

A few minutes spent tightening these settings today is a small price for the ongoing reassurance that a device meant to bring peace of mind is not quietly working against the very privacy it was bought to protect.
Stay Informed. Stay Protected.
If you've got a baby monitor, doorbell camera, or any smart camera at home, here's the no-fuss version of what you need to do right now:
Don't leave the camera on the password it came with out of the box. Pick something unique — not "admin" or "1234".
Check the manufacturer's app or website for any updates. If your brand was in the news (Arenti, Boifun, ieGeek, CloudEdge, Wyze, Petcube), do this first.
Walk around your house and write down every camera connected to the internet. Check each one: unique password? Firmware up to date? Reputable brand?
Especially in bedrooms. If it's not switched on, it can't be watched. Simple as that.
Next time you're shopping for a smart camera, look for one with good security reviews — not just the cheapest option on the shelf.
Not sure what some of these tech terms mean? Here's a quick guide written for everyday Australians — no IT degree required.
Think of this like a secret passcode that a device uses to prove it's allowed to access a service. In this story, that passcode was left unlocked — like leaving your front door key under the mat with a sign pointing to it.
Instead of saving photos or videos on your device at home, they get sent over the internet and stored on someone else's computer (a "server"). Handy, but it means your footage lives somewhere you don't fully control.
The password a device comes with straight out of the box — usually something obvious like "admin" or "123456". Attackers know these passwords and try them first. Always change it to something unique.
A way of scrambling data so that only the right person can read it. Proper encryption means even if someone intercepts your footage, it looks like gibberish to them. Weak encryption is like locking a door with a rubber band.
The built-in software that runs your camera or smart device. Manufacturers release updates to fix security problems — like how your phone gets software updates. Keeping firmware current is one of the easiest ways to stay protected.
Any camera that sends footage or alerts over the internet — including baby monitors with apps, video doorbells, pet cameras, and home security cameras. If you can check it on your phone from anywhere, it's internet-connected.
Saving footage directly onto a memory card inside the device itself, rather than sending it to the cloud. Your footage stays in your home, which means fewer places it could be accessed by someone else.
A unique code printed on your device (like a VIN on a car). In this security flaw, knowing a camera's serial number was enough for someone to look up its location and details — without needing a password.
A weakness in a device or software that could allow someone to access it without permission. Security researchers look for these flaws and report them so manufacturers can fix them before bad actors exploit them.
When a security researcher finds a flaw, they often tell the manufacturer privately first — giving them time to fix it before making the details public. This is called responsible disclosure, and it's the right way the system is supposed to work.
Is Someone Watching?