The Dark Side of Smart Homes: How Hackers Could Access Your Cameras, Speakers and Doorbells

Protect your smart home: Tips to mitigate cybersecurity risks

smart home devices
Hackers could turn your smart home against you: The security risks behind cameras, speakers and doorbells Photo by Jakub Zerdzicki: Pexels

Smart home devices are designed to make homes feel safer, but connections that let owners check a camera or unlock a door remotely can create another route for attackers.

Security researchers warn that cameras, video doorbells, speakers and connected devices can be exposed through weak passwords, outdated software, insecure remote-access settings or vulnerabilities in apps and cloud services.

Experts today says the risk is real, particularly where remote access and default credentials remain enabled. Yet homeowners do not need to unplug every smart device. Much of the risk can be reduced with sensible configuration, regular updates, stronger authentication and network separation.

The issue is wider than whether somebody can watch a camera feed. A compromised device may reveal when people are home, or provide a route towards other devices. The practical question is how homeowners can reduce exposure.

Why Smart Home Devices Can Become an Entry Point

The most obvious concern with a hacked security camera is that someone could watch the footage. In reality, the consequences can extend further, particularly when several connected devices share the same home network.

Ashley Allen, a PhD researcher at the University of Hertfordshire who also works as a senior security engineer, has researched vulnerabilities in connected security products. His PhD work has identified 14 previously unknown vulnerabilities across smart locks, smart padlocks and smart burglar alarms.

Allen says the threat to cameras is real, but the risk can often be reduced through proper configuration.

'Smart security device manufacturers often, ironically, treat security as an afterthought,' he says. 'This can mean enabling remote access by default, shipping devices with default usernames and passwords, and contain outdated and vulnerable software components.'

Internet-connected cameras can be particularly exposed when remote access is switched on and the device still uses default credentials. The UK's National Cyber Security Centre warns that some smart cameras have historically been shipped with passwords that are well known or easy to guess, allowing criminals to access them remotely.

Allen also points to IP-enabled cameras as a particular concern. These devices can be reached through an internet-connected IP address, meaning an attacker does not necessarily have to be physically outside the property to attempt an attack.

Services such as Shodan can be used to search for internet-connected devices, although simply appearing in such a search does not mean a device is vulnerable. The real problem comes when an exposed device combines remote access with weak or unchanged credentials.

Physical proximity can create another route for some products. Allen says attackers near a property may be able to attempt connections through Bluetooth. Standard Bluetooth range is limited, although specialist hardware can extend that distance considerably.

The type of technology inside the device also matters. Alex Heng, Director of Interlock, a smart lock and home security retailer in Singapore, says consumers need to look beyond the label of a product and understand how it communicates.

'The honest answer is it depends entirely on which protocol the device uses to talk to the outside world,' they say.

Wi-Fi devices such as many cameras, speakers and doorbells commonly communicate with a manufacturer's cloud service. That means security is not simply a question of whether the home Wi-Fi network is protected. The app, account system and cloud infrastructure operated by the manufacturer also become part of the security picture.

Zigbee and Thread devices can present a different exposure because they commonly communicate through a local mesh network rather than connecting directly to the internet. Bluetooth products can also have a smaller remote attack surface because many attacks require physical proximity.

That does not make one technology automatically safe. It means homeowners should understand what happens to their data after a device connects.

There is already evidence that these concerns are not merely theoretical. Bitdefender previously found a vulnerability in the setup process for an Amazon Ring Video Doorbell Pro that could expose a user's Wi-Fi password under particular circumstances. Amazon subsequently fixed the problem and pushed an automatic update.

Researchers have also raised questions about the security claims and cloud architecture of other major smart-home brands. The lesson is not that one particular manufacturer should automatically be avoided. Rather, Allen argues that consumers should examine how companies respond when flaws are discovered.

'All software contains vulnerabilities, and it is how they are dealt with that should determine whether to trust the vendor,' he says.

That is an important distinction. A company with publicly disclosed vulnerabilities is not automatically less trustworthy than one with a spotless public record. A previously undiscovered flaw may simply not have been found yet.

How To Make Your Smart Home Harder To Hack

The first step is simple: change any default password immediately.

The NCSC recommends replacing default passwords on smart cameras with strong alternatives and keeping device software updated. Two-factor authentication or multi-factor authentication should also be enabled wherever it is offered.

Allen recommends using two-factor authentication because it can protect an account even if someone obtains the username and password. Where available, they suggest preferring a hardware security key or biometric authentication over SMS, because text-message authentication can be affected by SIM-swap attacks.

The next step is to look at remote access. If a homeowner never needs to view a camera while away from home, there may be little reason to expose that functionality.

The NCSC specifically advises users to consider whether remote access is necessary and recommends reviewing router settings such as Universal Plug and Play and port forwarding, which can increase exposure when misconfigured.

Network separation is another useful defence.

Kevin Walker, founder of Black Swan Cyber Security Solutions, has around 30 years of IT experience, including more than 20 years supporting organisations with technology and cyber security. He recommends treating smart-home equipment differently from trusted computers and phones.

'Don't give every device the same level of trust,' Walker says.

A camera, doorbell or smart speaker does not normally need unrestricted access to a laptop containing personal documents and family photographs. Where a router supports it, Walker recommends placing IoT devices on a separate network, SSID, guest network or VLAN, ideally with isolation between the smart devices and the main home network.

This approach will not fix a vulnerable camera, but it can limit what an attacker can reach if that camera is compromised.

Firmware updates are equally important. Owners should install security updates promptly and enable automatic updates where the manufacturer provides the option. If a manufacturer has stopped supporting an older device, replacing it may eventually become the safer choice.

This is becoming easier to assess in the UK. Since 29 April 2024, the UK's Product Security and Telecommunications Infrastructure regime has imposed baseline security requirements on relevant internet-connected consumer products.

Manufacturers must provide information about how security vulnerabilities can be reported and publish the minimum period for which security updates will be provided.

Buyers should therefore check the promised support period before purchasing a cheap camera or doorbell. Price and image quality should not be the only considerations. Recently, per a report by IBTimes UK, even the FBI and Google have cracked down on hackers using Smart TVs to get data.

Independent testing can help. Which? security camera testing says it assesses cameras for security flaws as well as performance, and its latest testing reports that 14% of the models it has tested over the years have had security issues.

Allen also recommends looking at a manufacturer's vulnerability history and its response to security researchers. They argue that consumers should pay attention to whether companies work with independent researchers, explain what happened when a vulnerability is found, and provide clear instructions for fixing or mitigating the problem.

For users who want stronger control over footage, local storage and end-to-end encryption are worth investigating. End-to-end encryption means that only the intended endpoints can decrypt the communication, reducing the number of places where an attacker could potentially intercept readable footage.

Local storage can reduce reliance on a manufacturer's cloud, although it does not automatically make a device secure. A poorly protected local camera can still be attacked through its network connection.

There is no realistic promise of a completely hack-proof smart home. The more useful goal is to reduce unnecessary exposure and make a successful attack harder.

Heng recommends putting cameras and speakers on a separate Wi-Fi network, keeping firmware updated and checking the cloud platform behind a device rather than judging security solely by its wireless protocol.

The concern among consumers is already substantial. Deloitte found that 52% of smart-home users surveyed were worried that someone could gain control of their connected devices. Its research also found that the likelihood of a breach increased as households added more connected devices.

For homeowners, the practical response is not panic. It is maintenance.

Change default credentials, use unique passwords, enable multi-factor authentication, update firmware, disable remote features that are not needed, review router settings and isolate IoT devices from trusted computers where possible. Before buying something new, investigate its update policy, security history and independent reviews.

The BSI Kitemark programme also offers independent testing and certification for smart-home IoT products, including security cameras, doorbells, locks and home hubs.

A smart doorbell should make a home easier to monitor, not create an invisible route into it. The technology itself is not necessarily the problem.

The real risk comes from treating a connected device as though it were just another household appliance, when in reality it is a small computer with access to the internet, the home network and, in many cases, some of the most private parts of daily life.


Frequently Asked Questions

  • Why are smart home devices vulnerable to attacks?
    Smart home devices can be vulnerable due to weak passwords, outdated software, insecure remote-access settings, and vulnerabilities in apps and cloud services.
  • How can I protect my smart home devices from being hacked?
    You can protect your devices by changing default passwords, enabling two-factor authentication, updating software regularly, and separating IoT devices from trusted networks.
  • What should I consider before buying a smart home device?
    Consider the manufacturer's security update policy, vulnerability response history, and independent reviews of the device's security features.