Software Engineer Accidentally Gains Access to Thousands of Robot Vacuum Cleaners
A software engineer’s attempt to connect a PlayStation controller to his robot vacuum cleaner inadvertently opened a security vulnerability, granting him access to data from approximately 7,000 other devices. The incident, initially reported by Norwegian media and subsequently gaining international attention, highlights the growing concerns surrounding the security of Internet of Things (IoT) devices and the potential for unintended consequences when tinkering with connected technology. The incident underscores the importance of robust security measures in the rapidly expanding world of smart home devices.
Sammy Azdoufal, the engineer at the center of the incident, explained that he was curious about how he could customize his DJI Roborock robot vacuum. He began by examining the communication between the vacuum’s app and the device itself, hoping to map the controls. “They have an app associated with the vacuum,” Azdoufal told Agence France-Presse (AFP). “So I tried to figure out what the app sends to the robot when I move it around.” After successfully linking the PlayStation controller, he intended to program the vacuum to emit a crying sound when its battery was low. Yet, his exploration quickly took an unexpected turn.
While attempting to determine the vacuum’s battery status, Azdoufal discovered he was receiving data from thousands of other devices. “You can get a full map of all the rooms, you can access the cameras and microphones,” he explained to AFP, adding that he could likewise estimate the location of the devices. This unintentional access raised immediate privacy and security concerns, prompting Azdoufal to accept action.
Security Vulnerability and DJI’s Response
Azdoufal, who previously worked in cybersecurity, proactively covered the camera on his own robot vacuum as a precaution. He initially contacted DJI, the manufacturer of the Roborock vacuum, but received a delayed response. He then reached out to technology news website The Verge, providing them with the serial number of a Roborock vacuum they had recently reviewed. According to The Verge, Azdoufal was able to generate a detailed map of the journalist’s home and confirm the vacuum was in operation.
However, Azdoufal was unable to control the journalist’s vacuum or access its camera or microphone feed – reportedly given that DJI had restricted access after learning about the vulnerability. This suggests that the company took swift action to mitigate the potential security breach once it was alerted to the issue.
DJI acknowledged the flaw in a statement to AFP, stating they discovered a vulnerability in the app following internal investigations in late January and immediately implemented corrective measures. Two updates released in February resolved the problem, according to the company. “DJI has high standards for data security and privacy and has established processes to identify and address potential vulnerabilities,” the statement read. The company’s response highlights the ongoing challenge of securing IoT devices against unauthorized access and potential misuse.
The Roborock series, considered DJI’s flagship line of robot vacuums, can cost around 23,000 Norwegian kroner (approximately $2,100 USD as of March 3, 2026), according to the original reporting. Azdoufal purchased the vacuum in December and began experimenting with it in January.
The Broader Implications for IoT Security
This incident serves as a stark reminder of the potential security risks associated with the proliferation of IoT devices in our homes. Robot vacuums, smart speakers, security cameras, and other connected devices collect vast amounts of data about our daily lives, making them attractive targets for hackers. The ease with which Azdoufal gained access to thousands of devices underscores the necessitate for manufacturers to prioritize security throughout the entire product lifecycle, from design and development to deployment and ongoing maintenance.
The vulnerability exploited by Azdoufal stemmed from a lack of proper authentication and authorization mechanisms within the DJI Roborock app. Without adequate security measures, it’s possible for unauthorized individuals to gain access to sensitive data, control devices remotely, and even compromise the privacy of users. This incident also raises questions about the responsibility of manufacturers to proactively identify and address security vulnerabilities before they are exploited.
Experts in cybersecurity emphasize the importance of several key security practices for IoT devices. These include strong passwords, regular software updates, network segmentation, and the use of encryption to protect data in transit and at rest. Users should also be aware of the privacy implications of connected devices and carefully review the privacy policies of manufacturers before purchasing and using them.
The incident with the DJI Roborock vacuum is not an isolated case. Numerous other vulnerabilities have been discovered in IoT devices in recent years, highlighting the systemic challenges of securing this rapidly evolving technology landscape. In 2023, a researcher discovered a vulnerability in smart baby monitors that allowed unauthorized access to live video feeds. Similarly, in 2024, a security flaw in a popular smart doorbell was exploited to gain access to home networks. These examples demonstrate the pervasive nature of IoT security risks and the need for a comprehensive approach to address them.
The increasing sophistication of cyberattacks and the growing number of connected devices are creating a perfect storm for security breaches. As IoT devices become more integrated into our lives, it’s crucial that manufacturers, researchers, and users work together to ensure that these devices are secure and protect our privacy.
What Happens Next?
DJI has stated that it continues to monitor its systems for vulnerabilities and is committed to improving the security of its products. The company is likely to conduct further investigations into the incident and implement additional security measures to prevent similar breaches in the future. Users of DJI Roborock vacuums are advised to ensure their devices are running the latest firmware updates and to follow best practices for IoT security. The company has not announced any specific plans for compensating affected users, but they may offer security audits or other measures to address concerns.
This incident is likely to spur further discussion about the need for stronger regulations and standards for IoT security. Several governments around the world are considering legislation to require manufacturers to implement minimum security standards for connected devices. The European Union, for example, has adopted the Cyber Resilience Act, which aims to improve the cybersecurity of products with digital elements. Such regulations could help to raise the bar for IoT security and protect consumers from potential harm.
The case of Sammy Azdoufal and the hacked robot vacuums serves as a cautionary tale about the importance of security in the age of the Internet of Things. It’s a reminder that even seemingly innocuous devices can pose a security risk and that vigilance is essential to protect our privacy and security in an increasingly connected world.
What are your thoughts on the security of smart home devices? Share your comments below, and please share this article with your network to raise awareness about the importance of IoT security.
Worth a look