As told by Lukas Apynis, senior cybersecurity engineer at Baltimax and ESET specialist, some people hesitate to use robot vacuum cleaners because they have heard that the data collected by these devices allegedly ends up in unreliable hands, according to a Baltimax press release.
Read more What kind of meat to choose if you want to quickly prepare a grilled dinner?
However, according to the expert, such a statement is overly simplified.
“Although some robots do collect home maps, usage statistics, technical data, and models with cameras can also process images, data storage depends on the specific manufacturer, chosen region, cloud infrastructure, privacy settings, and device model,” says the IT expert. “This is not a reason to reject smart technologies, but before purchasing, it is worth researching the manufacturer’s data policy and ensuring that unnecessary functions can be disabled.”
Smart devices – as vulnerable as computers
According to the cybersecurity expert, people still mistakenly believe that only computers or phones can pose a threat. From a cybersecurity perspective, any smart device connected to the internet can become a target for criminals.
“The most common myth is that a device without a keyboard or screen cannot be dangerous. Moreover, many think that cybercriminals must first choose a specific victim, but in reality, a large portion of attacks happen automatically – hackers’ systems constantly search for vulnerable devices on the internet,” says L. Apynis, emphasizing that a modern robot vacuum is essentially a small computer on wheels. “It has internet connectivity, an app, various sensors, and some models even have cameras. Therefore, the same cybersecurity principles apply to it as to a computer.”
A robot vacuum taken over by cybercriminals can be used to monitor the environment, collect data, disturb owners, or even serve as an intermediary to access other devices connected to the home network.
“Sometimes this is done by individual hackers out of curiosity, but insecure Internet of Things devices can also be included in botnets controlled by organized criminals,” explains cybersecurity expert L. Apynis. “So the threat is real, although cases of robot vacuum takeovers are not yet as common as email or social media account thefts.”
How are robot vacuums hacked?
According to L. Apynis, one of the most common reasons cybercriminals manage to take control of smart devices, including robot vacuums, is reused passwords. If the same password was leaked on another website and is used for the robot vacuum’s account, criminals can exploit it to try to access the device.
“There have also been other cases where devices had insufficiently protected Bluetooth connections, insecure authentication, easily guessable security keys, or software vulnerabilities. These are already manufacturer design and security flaws that an ordinary user cannot fix themselves,” says the cybersecurity expert.
According to L. Apynis, a home map alone is usually not very valuable to cybercriminals, but the situation changes when this information is combined with other data – a person’s name, address, time at home, camera footage, or other leaked data. In such cases, a much more detailed picture of a person’s daily life can be formed, understanding when no one is home, how many people live there, or even where certain items are kept.
“In the worst case, cybercriminals can take control of the robot, access its camera, or use the device as a gateway to the home network. Often the biggest problem is not the robot itself, but that the attacker already has access to your account, data stored in the cloud, or has found a weak spot in the home network,” says L. Apynis.
Although cases of robot vacuum takeovers are not yet common, real incidents have been recorded worldwide. In 2024, cybercriminals in the USA took control of some Ecovacs Deebot X2 robots and broadcast offensive messages through the built-in speakers. In Australia, security researchers together with journalists demonstrated that exploiting security flaws could allow a vulnerable robot to photograph people inside homes.
In Lithuania, widely publicized cases of robot vacuum takeovers have not yet been recorded, but the National Cybersecurity Center (NKSC) has identified serious vulnerabilities in other smart devices, such as video cameras.
When choosing and using a robot vacuum, it is worth remembering:
- Choose not only based on suction power or battery life – find out how many years the manufacturer will provide software and security updates.
- The more the device sees, hears, and knows about your home, the more responsibly you should choose its manufacturer.
- If the device can operate without the internet, consider the possibility of not connecting it to the internet at all.
- Use a unique password, regularly install software updates, and enable two-factor authentication if the manufacturer offers this option.
- Smart devices should serve humans, not humans blindly trust them.
5 steps to protect your robot vacuum
- Use a unique password and, if the manufacturer provides the option, enable two-factor authentication (2FA/MFA).
- Regularly update the robot’s software and control app.
- Connect the robot to a separate Wi-Fi network dedicated to guests or smart devices so it is not on the same network as work computers or personal files.
- Disable unused functions, such as remote video monitoring, microphone, or other unnecessary accesses.
- When selling or disposing of the robot, remember to unlink the account, delete saved home maps, and restore factory settings.