Smart Devices, Silent Botnets: How Your TV, Camera and Vacuum Became Hackers' New Playground
A lawyer in Minnesota was cleaning his kitchen when his robot vacuum started shouting racial slurs at him. In Los Angeles, another unit chased a family dog across the living room while broadcasting abuse through its speaker. In Australia, a television reporter sat in a park across the street from a stranger's apartment, opened an app, and watched a man make coffee through the camera embedded in his own vacuum cleaner. None of these people had done anything wrong. Their machines had simply been listening — or rather, someone else had been listening through them.
These aren't isolated pranks. They're symptoms of a much larger shift that security researchers have been documenting with increasing alarm through 2025 and into 2026: the ordinary gadgets filling up modern homes — televisions, doorbell cameras, speakers, thermostats, vacuum cleaners — have quietly become one of the most exploited categories of technology on the planet. And unlike a hacked laptop, which usually announces itself through a crash, a pop-up, or a furious antivirus alert, a hacked smart device tends to keep working exactly as intended. The vacuum still cleans. The camera still streams. The router still routes traffic. Nothing looks broken, because nothing is — the device is just quietly doing something else at the same time.
A population explosion nobody secured
The scale of what's connected is hard to hold in your head. By the end of 2025, roughly 21 billion IoT devices were online worldwide, according to IoT Analytics, and that number is projected to reach 39 billion by 2030. Security vendors Bitdefender and Netgear logged 13.6 billion attacks against consumer IoT devices between January and October 2025 alone, and found that the average connected household absorbs close to 30 attack attempts a day — before its owners have poured their morning coffee. SonicWall separately reported a 124% year-over-year jump in IoT malware attacks, with more than 17 million of those aimed specifically at internet-connected cameras.
What makes this population so attractive to attackers isn't sophistication — it's the opposite. Most successful IoT compromises don't require a zero-day exploit or nation-state tradecraft. They exploit the same handful of problems that manufacturers have tolerated for years: default admin passwords nobody changes, remote-access features left switched on by default, and firmware that goes years without a security patch. Automated scanning tools index these open, poorly protected devices by the millions, turning what used to be a targeted intrusion into something closer to industrial harvesting.
When the infection ships from the factory
The most unsettling development of the past two years didn't involve hacking in any traditional sense at all. In 2025, Google, along with security firms Human Security and Trend Micro, disclosed BadBox 2.0 — malware pre-installed on more than 10 million Android-based smart TVs, streaming boxes, digital projectors, in-car infotainment systems and digital picture frames before they ever left the factory. Owners did nothing wrong. There was no phishing email to fall for, no suspicious link, no vulnerability to patch after the fact, because the compromise happened upstream of the purchase entirely. The devices arrived enrolled in a botnet straight out of the box, later repurposed for residential proxy abuse, click fraud and credential-stuffing attacks against other services.
The implication is bigger than any single botnet. For years, "buy from a reputable brand" was reasonable security advice. BadBox 2.0 demonstrated that a manufacturer's own supply chain can become the delivery mechanism for malware, which means the assurance that a device came from a known retailer or big-name manufacturer no longer guarantees very much at all.
The megabotnets breaking DDoS records
While some devices arrive compromised, most still get recruited the old-fashioned way: through unpatched routers, cameras and DVRs sitting exposed on the open internet. That recruitment has scaled into something genuinely new. The Aisuru botnet — built largely from home routers, CCTV cameras and DVRs — launched a distributed denial-of-service attack that peaked at 29.7 terabits per second and roughly 14.1 billion packets per second in late 2025, a record that Cloudflare had to mitigate directly and that shattered the previous ceiling within months of it being set. Microsoft Azure separately absorbed a related flood peaking at 15.72 Tbps. By early 2026, Aisuru and its Android-focused successor, Kimwolf, had compromised more than three million devices between them.
In March 2026, a joint operation by the US, Germany and Canada took down the command-and-control infrastructure behind four such botnets — Aisuru, Kimwolf, JackSkid and a fourth network — which had collectively infected over three million devices and were capable of the DDoS capacity described above. It was a genuine win, and also a limited one: the takedown disabled the command channels, not the underlying devices. Millions of routers, cameras and DVRs are still sitting online today, running the same outdated firmware and the same default credentials that got them infected in the first place, waiting for the next botnet operator to come along and claim them.
The most intimate case: what happens when the vacuum turns on you
If botnets are the abstract, industrial-scale version of the IoT problem, robot vacuums make it personal. These machines increasingly ship with cameras, microphones, lidar mapping and permanent cloud connectivity — features sold as conveniences for remote monitoring or pet-checking, which double as a built-in surveillance kit for anyone who can get into the device.
At DEF CON 32 in 2024, researchers Dennis Giese and Braelynn Luedtke demonstrated a chain of vulnerabilities in Ecovacs Deebot vacuums and lawn robots that let them access a device's camera and microphone without triggering any warning light, gain root access to the underlying operating system, and connect via Bluetooth from up to roughly 450 feet away during a narrow authentication window. The PIN meant to protect the video feed turned out to be verified on the app side rather than the device side, making it straightforward to bypass. Separately, a flaw in the DJI Romo vacuum allowed one researcher's custom app to receive live video, audio and mapping data from roughly 7,000 other people's units across at least two dozen countries — not because he tried to hack anyone, but because the backend simply responded to requests that should never have reached him. DJI pushed emergency patches within days. In 2025, the US Cybersecurity and Infrastructure Security Agency issued its own advisory over a separate flaw involving weak default credentials on a vacuum's docking-station Wi-Fi link, which could have let an attacker push malicious firmware disguised as a legitimate update.
None of this means every robot vacuum is compromised, or that manufacturers are ignoring the problem — Ecovacs and DJI both shipped fixes once the flaws became public. But it illustrates something structural: a device engineered to map the layout of someone's home, equipped with a camera and a microphone, and connected permanently to the internet, is a fundamentally different risk than a smart lightbulb. When it fails, it doesn't just fail — it can watch.
Regulation is finally catching up, slowly
Governments have noticed. The European Union's Cyber Resilience Act begins enforcing mandatory vulnerability reporting on September 11, 2026, requiring manufacturers selling connected devices into the EU to notify regulators within 24 hours of an actively exploited flaw, with fines of up to €15 million or 2.5% of global turnover for non-compliance. Full obligations, including mandatory secure-by-design requirements, land in December 2027. In the United States, the FCC's Cyber Trust Mark — a voluntary labeling scheme for consumer IoT security, modeled on NIST guidance — has been running since 2025, though federal procurement rules starting in January 2027 will effectively make it mandatory for vendors selling to government agencies. Neither measure fixes the roughly 21 billion devices already deployed, but both push manufacturers toward building the next generation of hardware to a higher baseline — much as GDPR reshaped privacy practices well beyond Europe's borders once companies decided it was easier to build one global standard than several regional ones.
What actually reduces the risk at home
None of this requires becoming a network administrator, but it does require treating the smart-home category with the same seriousness as a laptop or a phone. The single highest-impact step is changing every device's default password, since automated scanners specifically hunt for factory credentials at internet scale. The second is network segmentation: putting cameras, TVs, speakers and vacuums on a separate guest network or VLAN so that a compromised device can't reach the computer where banking and email live. Disabling remote-access and cloud-streaming features that aren't actually in use closes off doors that most owners never knew were open. And because unpatched firmware remains the most commonly exploited vector across every report on the subject, enabling automatic updates — or setting a monthly reminder to check for them manually on devices that don't support it — closes the gap that most attacks are built to exploit in the first place.
The uncomfortable truth is that the convenience driving smart-home adoption and the security debt piling up behind it are the same phenomenon. Every device that got easier to set up, cheaper to manufacture and more capable of streaming a live feed to a phone became, by the same measure, easier to compromise, cheaper to recruit into somebody else's botnet, and more capable of watching the people who bought it. That trade-off isn't going away. The only real choice left is how many of those doors a household decides to leave unlocked.