Can baby monitors be hacked? How to protect yours
Last updated October 6, 2026.
The short answer
Yes. Wi-Fi baby monitors and home cameras can be hacked, and it has happened to real families. The good news is that most break-ins come from a handful of fixable problems: reused passwords, missing two-step login, old firmware and cameras that sit on the same network as everything else.
What has actually happened
A few well-documented cases show the pattern.
- Ring, December 2019. Days after a family in Mississippi installed a Ring camera in their 8-year-old daughter's bedroom, a stranger used it to play music and talk to her. Ring said the incident was not caused by a breach of its own systems.1
- The FTC's case against Ring, 2023. The Federal Trade Commission said Ring failed to protect customers against credential stuffing and brute-force attacks, that hackers reached about 55,000 US customers' accounts, and that some used two-way audio to harass children. Ring agreed to pay $5.8 million for refunds.2
- Nest, January 2019. A family in Orinda, California heard a fake missile alert broadcast through their Nest camera. Google said two-step verification would have prevented it.3
- Wyze, February 2024. A glitch during outage recovery sent about 13,000 Wyze customers thumbnails from other people's cameras.4
- eufy, January 2025. New York's Attorney General secured $450,000 from distributors of eufy cameras after finding some video streams were unencrypted and viewable without logging in.5
Researchers have found the same weak spots in baby monitors for years. In 2015, Rapid7 tested nine internet-connected baby monitors and gave eight of them an F, citing problems such as hidden hard-coded passwords and unencrypted video.6 In 2020, Bitdefender reported flaws in the iBaby M6S that could expose stored video and owners' details.7 The FTC's first case about an everyday connected product, in 2013, involved TRENDnet cameras whose private feeds, including sleeping babies, were exposed online.8
How cameras get broken into
Notice what most of these cases have in common. Very few involve a hacker "breaking through" a home router. They fall into three groups:
- Account takeover. Someone logs in to the camera's cloud account with a password leaked from another site. This happens entirely outside your home.
- Flaws in the device or the company's cloud. Hard-coded passwords, unencrypted streams or a server mistake. You can't fix these yourself, but you can choose brands that patch quickly and keep firmware current.
- A weak home network. Default router passwords, a shared Wi-Fi password that dozens of people know, and every device on one flat network, so a compromised gadget can reach your laptops and phones.
Seven steps that make your monitor much harder to misuse
- Use a unique password for the camera app. Never reuse a password from another site. A password manager makes this easy.
- Turn on two-step login. It is the single step that would have stopped many of the account takeovers above.
- Update the firmware and the app. Turn on automatic updates if the camera offers them.
- Prefer a local-only monitor if you don't need remote viewing. A monitor that talks directly to its parent unit, without the internet, removes the cloud account from the picture.
- Buy from makers that support their products. Look for a clear update policy. The UK now bans guessable default passwords on smart devices,9 and the US Cyber Trust Mark label is still being put in place.10
- Put cameras on their own network. The FBI has advised isolating internet-connected devices on their own protected networks,11 and CISA suggests a guest network for smart devices that only need the internet.12 If a camera is ever compromised, separation limits what it can reach.
- Know what's connected. Check your router's device list now and then, and remove anything you don't recognize.
What a router can and can't do
Be wary of anyone who says a product makes a camera impossible to hack. A router can't protect a camera's cloud account, and it can't patch a flaw in the camera's firmware. What a good router can do is the network part: keep cameras apart from the devices that hold your family's life, and stop unknown devices from quietly joining.
That's the job Rio was built for. Rio puts cameras and baby monitors in their own SecureRoom, walled off from your phones and laptops by default, and every new device that joins your Wi-Fi waits for your approval in the app. Pair it with steps 1 to 3 above and you've covered both sides. See how Rio sets up a family's rooms.
Frequently asked questions
Can someone hack my baby monitor from outside my house?
Yes, if the monitor connects to the internet. Most real cases involved someone logging in to the camera's cloud account with a reused or leaked password, which doesn't require being near your home. Monitors that only talk to their own parent unit, without Wi-Fi, are much harder to reach remotely.
How do I know if my baby monitor has been hacked?
Warning signs include voices or sounds you didn't make, the camera moving on its own, settings or passwords that changed, unfamiliar logins in the app's history, and alerts about sign-ins from new devices. If you see any of these, change the password, turn on two-step login and update the firmware.
Are non-Wi-Fi baby monitors safer?
They remove the biggest risk, which is a cloud account someone can log in to from anywhere. Their trade-off is that you can't check in from your phone when you're away from home.
Does a separate network really help?
It limits the damage if a camera is ever compromised. The FBI has recommended isolating internet-connected devices on their own networks, so a weak gadget can't reach your computers and phones. It does not protect the camera's cloud account, so you still need a unique password and two-step login.
Sources
- NBC News, Man hacks Ring camera in 8-year-old girl's bedroom, December 2019. https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8-year-old-girl-s-bedroom-n1100586
- Federal Trade Commission, FTC says Ring employees illegally surveilled customers, failed to stop hackers from taking control of users' cameras, May 31, 2023. https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-says-ring-employees-illegally-surveilled-customers-failed-stop-hackers-taking-control-users
- CBS San Francisco, Nest security camera false alarm in Orinda, January 2019. https://www.cbsnews.com/sanfrancisco/news/nest-security-camera-false-alarm-orinda-family-nuclear-attack/
- CBS News, Wyze camera breach let 13,000 customers peek into other homes, February 20, 2024. https://www.cbsnews.com/news/wyze-camera-breach-let-13000-customers-peek-into-others-homes/
- New York State Attorney General, Attorney General James secures $450,000 from companies selling home security cameras, January 28, 2025. https://ag.ny.gov/press-release/2025/attorney-general-james-secures-450000-companies-selling-home-security-cameras
- Rapid7, FAQ on baby monitor vulnerability disclosure, September 2015. https://www.rapid7.com/globalassets/external/docs/rapid7-faq-on-baby-monitor-disclosure.pdf
- Bitdefender Labs, Severe vulnerability in iBaby Monitor M6S camera, February 26, 2020. https://www.bitdefender.com/en-us/blog/labs/severe-vulnerability-in-ibaby-monitor-m6s-camera-leads-to-remote-access-to-video-storage-bucket
- Federal Trade Commission, Marketer of internet-connected home security video cameras settles FTC charges, September 4, 2013. https://www.ftc.gov/news-events/news/press-releases/2013/09/marketer-internet-connected-home-security-video-cameras-settles-ftc-charges-it-failed-protect
- UK Government, New laws to protect consumers from cyber criminals come into force in the UK, April 29, 2024. https://www.gov.uk/government/news/new-laws-to-protect-consumers-from-cyber-criminals-come-into-force-in-the-uk
- Federal Communications Commission, Cyber Trust Mark Lead Administrator public notice, April 13, 2026. https://docs.fcc.gov/public/attachments/DOC-420764A1.pdf
- FBI Internet Crime Complaint Center, PSA I-091015-PSA, Internet of Things poses opportunities for cyber crime, September 10, 2015. https://www.ic3.gov/PSA/2015/PSA150910.pdf
- CISA, Project Upskill, Module 5. https://www.cisa.gov/audiences/high-risk-communities/projectupskill/module5
