Become an A&B portal user and receive giveaways!
Become an A&B portal user and receive giveaways!
maximize

Smart home: convenience or threat? What manufacturers don't tell you

Magdalena Milert
08 of March '26
w skrócie
  • Smart home devices collect large amounts of data about users' daily lives and how they use their homes.
  • Home networks with IoT devices are frequent targets of cyber attacks and hacking attempts.
  • Data leaks can reveal information about users and their activities, which later ends up on the black market.
  • Particularly sensitive is the data of children using toys that use artificial intelligence.
  • For more interesting information, visit the home page of the AiB portal

Smart devices are increasingly finding their way into homes. Automatic lighting, controlling the heating from a phone or home monitoring cameras have become part of everyday life. With the growing popularity of smart home technology, however, there are increasing questions about data security and user privacy.

Solutions referred to as smart homes are increasingly appearing in apartments and homes. These are internet-connected devices that can be controlled from a phone or automatic, scheduled operating scenarios. This category includes vacuum cleaners, lighting, thermostats, cameras, door locks, voice-controlled speakers, televisions or kitchen appliances, among others. Their popularity is primarily due to convenience. Who among us has never gone back to check that the door is locked and the iron is off? These devices allow you to remotely check and turn on many appliances, such as the heating before you return home, or set the lights to respond to the presence of household members.

At the same time, such a system means that there are many devices constantly connected to the network in the house. The average household already has more than a dozen IoT devices, i.e. appliances that communicate over the Internet. Each of them generates data on how the home is used and the daily habits of the occupants. However, the more such equipment, the more data collected and the more opportunities for hacking - the average home with such devices experiences an average of about 29 cyberattack attempts per day! These attacks mainly involve automatic network scanning for weak security or default passwords.

for you or for yourself

Much of the threat stems from the fact that smart home devices collect huge amounts of information. Televisions, cameras, speakers or thermostats record data about what's going on in the home. They can record information about the programs they watch, when someone enters the home, how often they use the devices or what questions they ask the voice assistant. This data goes to device manufacturers and is sold to companies that work with them. On this basis, elaborate user profiles are created, which can either be used to personalize advertisements or sold further to other entities.

The security of the systems themselves is also a problem. In 2025, a case of data leakage from Mars Hydro devices was revealed. The unsecured database contained some 2.7 billion records, including users' email addresses, account names, device information and records of their activity. The database was publicly accessible due to a cloud misconfiguration. Such data could be used for identity theft, fraud or to take control of devices in the home.

Another threat comes from the fact that many devices depend on the manufacturer's external servers. If the server stops working or the company ends support for a particular model, the device can suddenly lose functionality. Some operations do not take place directly on the device located at home, but on company-owned computers located in data centers. When a user opens an app on the phone and tries to turn on a light, check a camera image or open a door lock, the command first goes to the manufacturer's server. Only from there is it transmitted to a device in the home. If the server stops working or the company ends support for a particular model, the device can suddenly lose functionality. This happens, for example, during a failure of the Internet infrastructure or when the manufacturer decides to shut down a legacy cloud service. In such cases, the application can no longer connect to the device, even though the equipment is physically still at home and operational. In such situations, even basic system components stop working. If a company changes its strategy, ends support for older devices, or simply shuts down the servers that support a particular system, one can lose access to the equipment that is still in his or her home.

Black market for stolen data

A huge problem is also, of course, the use of seized data. There are now entire sites where stolen databases are traded. One example was the LeakBase platform, which for several years was used to sell seized information about users and companies. The service had more than 142,000 users and thousands of entries containing data from various leaks. It was shut down only after an international police operation.

On such platforms, data is usually sold or shared as large bundles of information. These can include email addresses, passwords, login data for online accounts, device data, and sometimes detailed records of user activity. They are bought by those engaged in online fraud, phishing or attempts to take over accounts on various services. Even seemingly harmless data can be used to create more complex attacks. Criminals combine information from various leaks, building accurate profiles of users. This allows them to impersonate well-known institutions or technology companies and send messages that look plausible. In the case of smart home devices, such information can also facilitate attempts to gain access to the home network or take control of connected equipment.

For children

A special category of smart devices are toys that use artificial intelligence and an Internet connection. These can be plush mascots, educational robots or interactive speakers designed for children. Many of them allow the child to talk to the toy, ask questions or talk about their experiences.

Such products collect highly sensitive information. In one high-profile case, it was discovered that the system of a company producing an AI talking toy was virtually unsecured. Such data is particularly sensitive because children often treat an interactive toy as their confidant of secrets, their closest friend. The conversations may include information about daily life, interests or emotions. In the wrong hands, such data can be used to manipulate the child or to try to make contact with him in the real world.

Many toys use external artificial intelligence models to generate responses. While manufacturers claim to use safeguards and restrictions, this means that children's data ends up in further systems and services beyond the toy itself.

In recent years, however, a number of cases have emerged showing that declared data protection policies do not always work in practice. One of the most famous examples was the CloudPets toy data leak in 2017. The plush mascots allowed voice messages to be sent between a child and family members. However, it turned out that the company's database was publicly accessible due to a lack of adequate security. Data of more than 820,000 user accounts and more than 2.2 million voice recordings sent between children and their families were disclosed. The data was extremely easy to access, and the company did not respond to reports of the problem for a long time.

View this post on Instagram

A post shared by WIRED (@wired)

The latest examples already involve AI-based toys. In 2026, more than 50,000 records of children's conversations with Bondu - a plush dinosaur with artificial intelligence functionality - were leaked. The toy allows children to have conversations with an LLM-based system that answers questions and responds to statements just like chatbots. It turned out, however, that the online panel intended for parents was poorly secured - anyone with a regular Google account could access records of conversations the children had with the toy. Among the disclosures were not only the conversation transcripts themselves, but also personal information such as children's names, birth dates and information about family members. Once logged in, it was possible to see the transcripts of the children's conversations with the toy.

forethought won't hurt

Smart home technologies bring convenience to the home, but at the same time create extensive data collection and new attack surfaces for cybercriminals. Devices constantly connected to the Internet can become a source of data leaks, a tool for monitoring users, or an element of larger network attacks. That's why it makes sense to pay more attention to the security of your systems. It's a good idea to keep in mind a few basic rules that can reduce the risk of data loss or equipment takeover:

  • First and foremost, regularly change passwords for accounts associated with smart home devices and avoid using the same login credentials on different services. It's also a good idea to use long and hard-to-guess passwords, and use password managers to help store login information securely.
  • It's also a good idea to enable two-factor authentication, if the manufacturer offers it. This will ensure that even if your password is taken, access to your account will require additional confirmation, such as a code sent to your phone.
  • It is also important to regularly update device software. Manufacturers publish security patches that fix detected bugs and vulnerabilities. Failure to update makes devices an easier target for cybercriminals.
  • Users should also watch out for online fraud attempts. Leaked data is often used in phishing attacks. Fake messages can look like communications from device manufacturers or service providers, so it's always a good idea to check the message sender and avoid clicking on suspicious links.
  • It's also a good idea to limit the amount of data shared with devices and apps. In privacy settings, you can often disable some of the functions that collect information about you, or limit the scope of permissions granted.

As the number of devices connected to the Internet grows, so does the number of potential threats. Many smart home incidents are due to errors in system security, improper configuration of cloud services, or lack of adequate data protection standards. Therefore, the need for stricter design rules for such technologies and greater control over how user data is processed is increasingly being emphasized.

Ultimately, a smart home can be a convenient and useful solution, but it requires informed use of technology. Manufacturers and users alike need to pay more attention to security issues to mitigate the risks associated with the increasingly pervasive presence of networked devices.

Magdalena Milert

The vote has already been cast

INSPIRATIONS