Robot vacuums across the country were hacked in the space of several days, according to reporting by ABC News. This allowed the attackers to not only control the robovacs, but use their speakers to hurl racial slurs and abusive comments at anyone nearby.
All of the affected robots were of the same make and model, the Chinese-made Ecovacs Deebot X2s. This particular robovac has developed a reputation for being easy to hack, thanks to a critical security flaw. ABC News, for instance, was able to get full control over one of the robots, including the camera.
One victim of this week’s hacks was a Minnesota lawyer named Daniel Swenson. He told ABC that he was watching TV when the robot started making weird noises, like “a broken-up radio signal or something.” Through the app, Swenson could tell that a stranger was accessing the live camera feed and the remote control feature.
He reset the password and rebooted the vacuum, but that’s when the weirdness really started. It immediately started moving again of its own accord and the speakers began emitting a human voice. This voice was yelling racist obscenities right in front of Swenson’s son.
“I got the impression it was a kid, maybe a teenager,” said Swenson. “Maybe they were just jumping from device to device messing with families.” Ultimately, he said it could have been worse, such as if the vacuum silently spied on his family for days on end.
Swenson’s device was hacked on May 24. That same day another Deebot X2s in Los Angeles began chasing around a dog. This vacuum’s speakers also shouted abusive comments. Five days later, a similar incident happened in El Paso. It remains unclear how many of the company’s devices have been hacked in total.
At the root of this issue is a security flaw that allows bad faith actors to bypass the required four-digit security PIN in order to gain control of the vacuum. This issue originally came to light in December 2023. The Bluetooth connector also has a flaw that allows for complete access from up to 300 feet away. However, the attacks occurred throughout the country, so the Bluetooth vulnerability is an unlikely culprit.
According to Gizmodo, the company has developed a patch to eliminate the aforementioned security flaw that’ll roll out sometime in November. We reached out to Ecovacs to get a confirmation on this.
Trending Products
LG 24MP60G-B 24″ Full HD (1920 x 1080) IPS Monitor with AMD FreeSync and 1ms MBR Response Time, and 3-Side Virtually Borderless Design – Black
LG UltraGear QHD 27-Inch Gaming Monitor 27GL83A-B – IPS 1ms (GtG), with HDR 10 Compatibility, NVIDIA G-SYNC, and AMD FreeSync, 144Hz, Black
Acer Nitro 27″ WQHD 2560 x 1440 PC Gaming IPS Monitor | AMD FreeSync Premium Up to 180Hz Refresh 0.5ms DCI-P3 95% 1 Display Port 1.2 & 2 HDMI 2.0 XV271U M3bmiiprx,Black
Logitech MK345 Wireless Keyboard and Mouse Combo with Palm Rest, 2.4 GHz USB Receiver, Compatible with PC, Laptop, Black
Motorola MG7550 – Modem with Built in WiFi | Approved for Comcast Xfinity, Cox | For Plans Up to 300 Mbps | DOCSIS 3.0 + AC1900 WiFi Router | Power Boost Enabled
HP 230 Wireless Mouse and Keyboard Combo – 2.4GHz Wireless Connection – Long Battery Life – Durable & Low-Noise Design – Windows & Mac OS – Adjustable 1600 DPI – Numeric Keypad (18H24AA#ABA)
ASUS TUF Gaming GT502 ATX Full Tower PC Case, Tempered Glass, Tool-free Side Panel, Modular Design, ARGB Hub, 2- way Graphic Card Mounting Orientation Compatible, 360mm and 280mm Radiator compatible
Lenovo 15.6″ FHD Laptop, Intel Pentium N6000 Quad-core Processor, 16GB Memory, 1TB SSD Storage, Ethernet Port, HDMI, USB-C, WiFi & Bluetooth, Windows 11 Home, WOWPC USB Bundle
Thermaltake View 200 TG ARGB Motherboard Sync ATX Tempered Glass Mid Tower Computer Case with 3x120mm Front ARGB Fan, CA-1X3-00M1WN-00
