In a disturbing series of events, Chinese-made Ecovacs Deebot X2 robot vacuums in multiple US cities were hacked, resulting in attackers not only physically controlling these devices but also yelling obscenities through their onboard speakers. Victims recall a stranger accessing the device's live camera feed and remote control feature via the Ecovacs app. Minnesota attorney Daniel Swenson recounts his family's shocking experience with the hacked device, its speaker blaring racist epithets at them.
Horrifyingly, another early incident involved a remote-controlled Deebot X2 chasing a pet dog around its Los Angeles home, with abusive remarks emanating from its speakers. Later, an El Paso resident was subjected to racial slurs from his device until he managed to unplug it. The exact number of hacked Ecovacs devices remains unknown.
Uncomfortably, security researchers had warned Ecovacs six months prior about significant security flaws in its devices and the app controlling them, including a detrimental Bluetooth connector flaw granting complete device access from over 100 meters away. Other issues included a faulty PIN code system protecting the device's video feed and the ability to disable the warning sound meant to play when the robot's camera is being observed. As a response to these heightened incidences, Ecovacs stated it would issue a security upgrade for its X2 series in November.
- CyberBeat
CyberBeat is a grassroots initiative from a team of producers and subject matter experts, driven out of frustration at the lack of media coverage, responding to an urgent need to provide a clear, concise, informative and educational approach to the growing fields of Cybersecurity and Digital Privacy.
If you have a story of interest, a comment, a concern or if you'd just like to say Hi, please contact us
We couldn't do this without the support of our sponsors and contributors.