Between January and October 2025 alone, security researchers at Bitdefender and Netgear logged 13.6 billion attacks aimed at consumer IoT devices — an average of 29 attempted intrusions on every connected home, every single day, nearly three times the rate seen in 2024. Smart doorbells and security cameras sit at the top of the target list, because a compromised camera doesn't just leak data — it lets a stranger watch your front door, your driveway, sometimes your living room, in real time.
The unsettling part is that most people never find out their camera was accessed. Consumer cameras don't push an alert every time a new session logs in unless you've specifically turned that setting on. This guide walks through the 9 concrete warning signs that something is wrong, explains exactly how attackers get in (it's almost never a sophisticated exploit), and gives you a step-by-step checklist to lock the device down in about 15 minutes — no technical background required, just knowing which menu to open.
One sign alone isn't proof — two or more is a red flag
Cameras glitch, batteries degrade, and Wi-Fi hiccups happen for innocent reasons all the time. Don't panic over a single odd moment. But if you notice two or more of the signs below happening around the same time, treat it as a compromise and work through the lockdown checklist immediately.
Why Doorbells and Cameras Are the #1 IoT Hacking Target
Video doorbells and indoor/outdoor cameras are uniquely attractive to attackers for three reasons: they're always connected to the internet, they capture something valuable (live video and audio of your home), and — critically — most people set them up once and never touch the security settings again. Unlike a laptop, nobody thinks to check a doorbell for updates.
According to reporting from security researchers tracking this pattern through early 2026, criminals have started using compromised smart doorbells, locks, and garage-door openers not just to spy, but to scout homes before physical break-ins — checking whether anyone is home, when routines happen, and where valuables might be. Separately, there's a growing pattern of "sextortion"-style attacks: intruders who gain access to indoor cameras threaten to release recorded footage unless the homeowner pays a ransom. Neither of these requires advanced hacking skill — both usually start with the same weak link.
| Entry Point | How Common | How It's Exploited |
|---|---|---|
| Default or reused password | Most common by far | Credential-stuffing bots try leaked email/password pairs from other breaches, or the factory default listed in the manual |
| Outdated firmware | Very common | Known vulnerabilities in old firmware versions remain exploitable indefinitely if never patched |
| Phishing for app credentials | Common | Fake "your camera needs verification" emails trick owners into entering their login on a spoofed page |
| Unsecured router / exposed ports | Less common but severe | UPnP or manual port-forwarding exposes the camera's admin interface directly to the internet |
Not sure if your home network is safe?
Our certified bilingual tech remotes in, audits every connected device on your network, and locks it down — same day, from $119.99. No fix, no fee.
9 Warning Signs Your Smart Doorbell or Camera Is Compromised
The status/activity light behaves oddly
Most doorbells and cameras have a small LED that indicates recording or active-connection status. If it's lit when you haven't opened the app, blinks in an unfamiliar pattern, or is completely dark when it should be active, someone else may be initiating sessions. Some intruders disable the light through admin settings specifically to hide activity — if the light physically can't be turned off in settings but is dark anyway, that's a stronger signal.
A pan-tilt-zoom camera moves on its own
If you own an indoor PTZ camera and it swivels, tilts, or zooms without you or anyone in your household controlling it through the app, this is one of the clearest indicators of unauthorized access — someone with valid login credentials is actively steering it.
You hear unfamiliar voices or sounds through the speaker
Many doorbells and cameras have two-way audio. If a voice you don't recognize speaks through the device, plays music, or makes noise when no one in your home is using the app, someone else has active control of the audio channel. Change the password and enable 2FA immediately — do not wait.
Unrecognized devices or sessions in "account activity"
Open the companion app and look for a section usually called Devices, Sessions, Connected Apps, or Login Activity under account/security settings. Compare the list of phones, tablets, and browsers against what your household actually owns. Any unfamiliar model name, unfamiliar city/IP location, or login timestamp when everyone was asleep is a red flag.
Battery drains far faster than it used to
An attacker actively streaming or reviewing footage keeps the camera's radio and processor working harder than normal idle operation. If a battery-powered doorbell that used to last 2-3 months suddenly needs recharging every 2-3 weeks with no change in your own usage or weather conditions, unauthorized streaming is one possible cause (a failing battery is the more common one — check both).
The device runs warm or Wi-Fi data usage spikes when idle
Check your router's device traffic/bandwidth monitor (most modern routers show per-device usage under something like "Attached Devices" or "Traffic Monitor"). A camera that's idle — no one home, no motion — but still shows continuous high upload data is likely streaming to somewhere other than your own app session.
You receive password-reset or 2FA codes you didn't request
An unexpected "Your verification code is..." text or "Reset your password" email tied to your camera account is a direct sign someone is actively trying to take over — or already has — the account. Never enter a code you didn't request, and change the password from the official app immediately, not from a link in the email/SMS.
Motion alerts stop arriving, or arrive with a delay
Some attackers disable notification settings after gaining access so the real owner doesn't get alerted to activity they're now also watching. If motion alerts that were reliable for months suddenly go silent — with no setting changes on your end — check the notification settings and connected-devices list right away.
Recorded clips appear that you didn't trigger, or clips are missing
Review your event/clip history. Clips timestamped during hours no one was near the door, or gaps where clips should exist but don't (an intruder covering their tracks by deleting footage of themselves), both warrant an immediate security review.
The Full Lockdown Checklist: Securing a Doorbell or Camera in 15 Minutes
Change the password to a unique 12+ character passphrase
Open the companion app > Account > Security/Password. Never reuse a password from another site — credential-stuffing bots specifically try passwords leaked from unrelated breaches against camera brands. A passphrase like four random unrelated words is both strong and easy to type on a phone.
Turn on two-factor authentication (2FA)
In Account > Security, enable 2FA/MFA — usually a 6-digit code sent by SMS or generated by an authenticator app. This single step blocks the overwhelming majority of credential-stuffing takeovers, because a stolen password alone is no longer enough to log in.
Install the latest firmware
Check Device Settings > Firmware/Software Update inside the app. Manufacturers patch real vulnerabilities in these updates — a doorbell that was secure when installed two years ago can become exploitable the moment a new flaw is discovered and disclosed, until it's patched. Turn on automatic updates if the option exists.
Review and revoke unrecognized sessions and shared users
In the same Devices/Sessions list you checked for warning signs, sign out any session you don't recognize and remove any "shared user" or "family member" access you didn't explicitly grant — including a previous tenant, contractor, or old partner who may still have standing access from before you owned the account.
Move the device to a guest or dedicated IoT Wi-Fi network
Log in to your router's admin panel (typically 192.168.1.1 or 192.168.0.1 in a browser) and create a Guest Network or IoT Network with client isolation enabled. Connect the camera to that network instead of your main one. If the camera is ever compromised, the attacker is contained there and cannot reach your laptops, phones, or file storage on the main network.
Disable UPnP and remote port forwarding for the device
In your router settings, check for UPnP (Universal Plug and Play) and turn it off — it allows devices to open ports to the internet automatically without your knowledge, which is one of the ways camera admin interfaces end up directly exposed. If you manually forwarded a port for remote camera access in the past, remove that rule; the manufacturer's cloud app already provides secure remote access without it.
Buying a used or secondhand camera? Do this first
Before you ever mount a secondhand doorbell or camera, perform a full factory reset (usually a physical button held 10-20 seconds) and create a brand-new account — never keep the previous owner's account linked, since they may retain access even after you take physical possession. Also confirm the specific model still receives firmware updates; discontinued models that no longer get security patches carry risk regardless of how strong your password is.
Choosing App Permissions and Sharing Settings Wisely
Most camera apps let you grant "guest" or "family" access to other people — useful for a partner or babysitter, but each additional account is another possible entry point if that person's own email or phone is compromised. Review shared access periodically (every 6 months is a reasonable habit) and remove anyone who no longer needs it: a former dog-sitter, an ex-roommate, a contractor who only needed access during a renovation.
Also check what the camera's mobile app permission requests on your phone — location access, contacts, microphone beyond the camera's own audio. Legitimate camera apps rarely need contacts or SMS permissions; if an app requests far more than its function requires, that's worth researching before granting it.
Renters vs Homeowners: Who's Responsible for What
If you rent, a doorbell or camera that came pre-installed by a landlord or a previous tenant deserves extra scrutiny — you have no way of knowing whether the account was ever properly transferred, whether old shared users were removed, or when the firmware was last updated. Where possible, ask your landlord directly whether the device account was reset for you; if they can't confirm it, treat the device the same as a secondhand purchase and request a full factory reset with a new account created solely in your name before relying on it for security. If you're the one moving out, the reverse responsibility applies: remove your account and personal footage before handing the property back, and don't leave a device linked to your personal cloud account for the next occupant.
Homeowners installing a new system have more control from day one, which makes the lockdown checklist above easier to apply thoroughly during initial setup rather than retrofitting it onto an account that's already been active for months or years.
How IT Cares Approaches a Smart Home Camera Audit
When we're called in for a full smart home network audit, camera and doorbell review follows a consistent pattern: we start at the router (since it's the foundation everything else depends on), then work outward to each connected camera — checking firmware version against the manufacturer's latest release, reviewing every active session and shared user against what the household actually recognizes, confirming 2FA is enabled wherever the platform supports it, and testing whether the device sits on an isolated network segment or shares the same broadcast domain as laptops and phones. We also check for leftover port-forwarding rules from previous setups, which is a surprisingly common finding on systems that have changed hands or been configured by a previous installer without documentation.
Two-Factor Authentication: SMS vs Authenticator App
Not all 2FA is implemented the same way, and it's worth understanding the tradeoff when your camera app offers a choice. SMS-based 2FA sends a one-time code by text message — simple to set up, works on any phone, but is vulnerable to SIM-swapping attacks, where an attacker convinces your mobile carrier to transfer your phone number to a SIM card they control, intercepting the code. This is a real but relatively rare attack that typically targets specific high-value individuals rather than random camera owners. Authenticator app-based 2FA (Google Authenticator, Authy, or similar) generates codes locally on your device without going through your carrier at all, making it immune to SIM-swapping. If your camera app offers both options, the authenticator app method is the stronger choice — but SMS-based 2FA is still dramatically better than no 2FA at all, so don't skip it while waiting for a "perfect" setup.
What Manufacturers Are Doing About This Industry-Wide
The camera and smart home industry has made real, measurable progress on this problem over the past several years, even as attack volume has grown. Many manufacturers now force a unique password (or force a password change from a unique per-device default, rather than one shared default across an entire product line) during initial setup. Some brands have adopted mandatory 2FA for any account with remote viewing enabled. Trade groups and some regulators have pushed baseline IoT security standards requiring unique default credentials, coordinated vulnerability disclosure programs, and minimum support periods for firmware updates. None of this replaces the responsibility that falls on the device owner — a manufacturer-side improvement only helps if the specific model you own has actually received it — but it does mean a camera bought new today from a major manufacturer generally ships in a meaningfully better security posture than one bought five or six years ago.
How These Attacks Actually Unfold, Step by Step
Understanding the actual mechanics of a typical camera takeover makes the fixes above feel less abstract. Here's the sequence most real-world cases follow:
Step 1 — Credential harvesting. The attacker doesn't target your specific camera; they run automated tools against massive lists of email/password combinations leaked from unrelated data breaches over the years (a service, a forum, a retailer — none of which need to be related to your camera brand). If you've ever reused a password, one of those leaked combinations may match your camera account.
Step 2 — Automated login attempts. Bots try thousands of leaked username/password pairs per hour against camera manufacturer login endpoints. This is called credential stuffing, and it doesn't require any skill from the attacker — it's a purchased or freely available tool doing the work. Accounts without 2FA and with a reused password are the ones that succeed.
Step 3 — Silent access. Once logged in, the attacker typically doesn't announce themselves. They browse recorded clips, watch the live feed, and note patterns — when the home is empty, where entrances are, whether there's a security system. Most consumer camera apps do not push a notification to the legitimate owner when a new session starts unless that specific alert is enabled.
Step 4 — Monetization or exploitation. From here, documented patterns diverge: some attackers sell verified "working" camera credentials in bulk on dark web marketplaces; some use the access directly for extortion, threatening to release recorded footage; others — per the pattern researchers flagged in early 2026 — use the access purely for reconnaissance ahead of a physical break-in, then move on without ever being detected by the homeowner.
Every single step in this chain is broken by the fixes in the checklist above. A unique password stops Step 1 from mattering. Two-factor authentication stops Step 2 even if Step 1 succeeds. Session/login notifications catch Step 3 immediately. There is no point in this chain that isn't defeated by the basic hygiene most people simply never set up.
What to Look For When Buying a Secure Smart Doorbell or Camera
If you're shopping for a new doorbell or camera, security-relevant features are just as important as resolution or field of view. Here's what to check before buying:
| Feature to Check | Why It Matters |
|---|---|
| Two-factor authentication support | Blocks the vast majority of credential-stuffing takeovers even if the password leaks |
| Regular firmware update history | Check the manufacturer's support page for updates within the last 6-12 months — this shows active security maintenance |
| End-to-end or at-rest encryption for stored clips | Protects recorded footage even if the cloud storage backend itself were ever breached |
| Local storage option (microSD or local hub) | Reduces reliance on a third-party cloud provider and can work without any internet connection for local-only viewing |
| Clear privacy policy on data retention/sharing | Tells you how long footage is kept and whether it's ever shared with law enforcement or third parties by default |
| Login/session activity log visible in-app | Lets you actually check for unauthorized access, rather than being blind to it |
Avoid unbranded, extremely low-cost cameras sold with no clear manufacturer support page or update history — these disproportionately ship with weak default security and rarely, if ever, receive patches for vulnerabilities discovered after launch.
Cloud Storage vs Local Storage: Which Is More Private?
Cloud storage (footage uploaded automatically to the manufacturer's servers) offers convenience — access from anywhere, automatic backup if the physical device is stolen or destroyed — but it also means your footage exists on a third party's infrastructure, governed by their security practices and privacy policy, not just your own. Local storage (microSD card in the camera, or a local hub/NVR on your own network) keeps footage physically in your home, with no third-party server ever holding a copy, at the cost of losing that footage if the physical device is stolen, destroyed, or the storage medium fails.
Many modern cameras support both simultaneously — local storage as the primary copy, with optional cloud backup for redundancy. If privacy is your top priority, look specifically for cameras that support local-only operation without requiring a cloud account at all; not every brand offers this.
Common Mistakes That Undermine Even Good Security Habits
A few practical mistakes we see repeatedly during home network audits, even in households that thought they'd done everything right:
- Writing the new password down somewhere visible — a sticky note near a home office desk, or a note saved in an unencrypted phone notes app that syncs to a cloud service using the same reused password pattern.
- Forgetting to update the mobile app itself — app updates sometimes include their own security fixes separate from the camera's firmware; an outdated app can have its own vulnerabilities regardless of how current the camera's firmware is.
- Granting "family" access too liberally — every shared account is a second password that needs the same hygiene as your own; a weak password on a shared account undermines a strong one on the primary account.
- Assuming a doorbell camera is "set and forget" — unlike a computer, most people never revisit a doorbell's settings after initial installation, meaning a security gap present at setup can persist for years unnoticed.
Doorbell-Specific vs Indoor Camera Considerations
Front-door video doorbells and indoor cameras share the bulk of the security guidance in this article, but each carries a slightly different risk profile worth naming directly. A compromised doorbell mainly exposes activity at your entrance — who visits, package deliveries, daily routine timing — information that's valuable primarily for burglary reconnaissance. A compromised indoor camera, especially one with two-way audio placed in a living space or bedroom, exposes far more personal activity and carries the added risk of live audio/video access to private moments, which is the scenario behind the extortion-style attacks referenced earlier in this guide. If you're deciding where to allocate the most careful setup attention — reviewing sessions most frequently, being strictest about 2FA — indoor cameras generally warrant the higher priority given the depth of what they can expose if compromised.
Quick Reference: The 15-Minute Checklist in One Place
- Change the account password to a unique 12+ character passphrase
- Enable two-factor authentication, preferring an authenticator app over SMS where available
- Install the latest firmware from the app's device settings
- Review and remove any unrecognized sessions or shared users
- Move the device to a guest/IoT Wi-Fi network with client isolation
- Disable UPnP and any manual port-forwarding rules on the router
- Factory reset and re-register under a new account for any secondhand device
None of these steps require technical expertise beyond following the specific menu paths in your device's app — the entire process typically takes under 15 minutes once you know where to look, and it closes off every entry point described in the attack chain earlier in this guide.
What To Do If You Confirm a Breach
If you've worked through the checklist above and confirmed unauthorized access — an unrecognized session that was actively live, footage you didn't record, or a password reset you can prove wasn't you — take these additional steps: change the password on any other account that shared that same password (this is why unique passwords per site matter), check whether your router itself shows signs of tampering (see our router and smart home hacked warning signs guide), and consider filing a report with local police if you believe footage was used to plan a break-in or was shared/leaked, since that crosses from a privacy issue into a criminal one.
Want a professional to check your whole smart home setup?
IT Cares audits routers, cameras, doorbells, and every connected device in your home — closes exposed ports, sets up network segmentation, and confirms firmware is current. Most audits completed same-day, remote or on-site across Canada.
Frequently Asked Questions
How can I tell if my smart doorbell or camera has been hacked?
Look for the status light behaving oddly, self-moving pan-tilt cameras, unfamiliar voices through the speaker, unrecognized sessions in the app, faster-than-normal battery drain, unusual network activity when idle, or password-reset emails you didn't request. Any single sign can be innocent — two or more together are a strong indicator.
What is the single most common way smart cameras get hacked?
Reused or never-changed default passwords. Attackers run automated credential-stuffing tools against leaked email/password lists, or simply try the manufacturer's factory default, which is often published in the manual and catalogued on public default-password databases.
Can someone watch my camera feed without me knowing?
Yes — most consumer cameras don't alert the owner when a new session starts unless you specifically enable login notifications. Reviewing "active sessions" in your camera app regularly matters as much as password strength.
Should I put my smart doorbell or camera on a separate Wi-Fi network?
Yes, this is one of the highest-impact steps available. A guest or dedicated IoT network with client isolation means that even if a camera is compromised, the attacker cannot pivot to your laptops, phones, or file storage on the main network.
Is it safe to buy a used or secondhand smart doorbell camera?
Only after a full factory reset and a brand-new account — never keep the previous owner's account linked. Also confirm the model still receives firmware updates; discontinued models without security patches remain a risk regardless of password strength.
Should I choose cloud storage or local storage for my camera?
Cloud storage is convenient and backs up automatically, but your footage lives on a third party's servers. Local storage (microSD or a local hub) keeps footage physically in your home at the cost of losing it if the device is stolen or destroyed. Many cameras support both — look for a local-storage option if privacy is the priority.
What should I look for when buying a new smart doorbell or camera?
Prioritize 2FA support, a visible history of regular firmware updates, encrypted clip storage, an in-app session activity log, and a clear data-retention privacy policy. Avoid unbranded, very low-cost cameras with no visible support page or update history.

Comments (3)
Checked my doorbell app's "connected devices" list after reading this and found a login from a city I've never been to. Changed the password, turned on 2FA, and removed the session immediately. Genuinely unsettling how easy it was to check once I knew where to look — thank you for this.
Our indoor camera kept rotating at 2-3am and we assumed it was a software glitch for months. Turns out it was a shared account left over from the previous homeowner who never got removed. Full factory reset and new account fixed it instantly.
Put all our cameras on the guest network like this guide suggests. Took about 10 minutes total on the router. Peace of mind knowing that even if one camera gets compromised it can't touch my work laptop on the main network.
Leave a Comment