Are Robot Vacuums a Privacy Risk? An Honest Evidence Review

Researched from manufacturer documentation, primary sources and owner reports. Spykee World does not hands-on test products, and takes no affiliate commission. How we work.

Yes, and the risk is specific enough to date. Images from development Roombas leaked in 2020 through the gig workers paid to label them. In 2024 researchers took over Ecovacs robots over Bluetooth from 140 metres away, and reused passwords let strangers drive real families’ Deebots. A camera free model, a unique password and current firmware close most of it.

The honest answer sits between two bad ones. One says the thing charging in your hallway is a camera on wheels feeding a stranger. The other says nothing has ever actually happened. Both are wrong, and you do not have to guess, because the record is short: a handful of dated incidents, three published privacy policies, one peer reviewed lab attack, and one manufacturer’s bankruptcy filing. We take no money from any vacuum brand and there are no affiliate links here.

What has actually gone wrong, and when?

Six years of this story fit in one table. These are the incidents we could put a date and a named source on. Everything after is detail underneath them.

Date What happened Documented by What it means for a buyer
Fall 2020, published Dec 2022 Gig workers labeling training data for development Roomba J7 units posted images from testers’ homes to closed social media groups MIT Technology Review, which obtained 15 screenshots Pre-release hardware, consenting testers. A contract failure, not a hack
Dec 2023 Researchers disclose at 37C3 that the Ecovacs live video PIN was checked by the phone app, not the robot or the server Dennis Giese and Braelynn Luedtke, on stage A PIN the app checks by itself stops nobody talking to the robot directly
Jan 29, 2024 Amazon and iRobot terminate the $1.7 billion acquisition. Amazon pays a $94 million fee, iRobot cuts about 31% of staff Fortune, on iRobot’s own announcement The EU objection was competition on Amazon’s store, not your floor plan
May 2024 Deebot X2 units in Minnesota, Los Angeles and El Paso are taken over within days and used to shout racist abuse through their speakers ABC News (Australia) The way in was reused passwords, not a break in at Ecovacs
Aug 2024 DEF CON 32 talk documents Bluetooth remote code execution on Ecovacs robots via a static encryption key shared across devices Giese and braelynn, in their own slides One key shared across a product line stops being secret once somebody reads the firmware
Oct 2024 ABC and Giese take over a consenting owner’s Deebot X2 over Bluetooth from up to 140 metres away and watch its live camera ABC News (Australia) The vendor’s “physical access required” line did not survive the demonstration
Nov 2024 Ecovacs ships an over the air firmware update for the X2 PIN bypass, having improved it once in August Ecovacs, in its statement to ABC Firmware updates are the whole defense against this class of flaw
Dec 14, 2025 iRobot files for Chapter 11. Nasdaq moves to delist and trading is suspended Dec 22 iRobot’s own SEC Form 8-K The brand rated best at patching is the brand in bankruptcy court

Two absences matter as much as the entries. No source in this review documents images from a retail robot, the kind you buy in a store, reaching the internet. ABC could not establish how many Deebots were taken over in total, so any figure quoted for that is a guess. And nothing we read supports the claim repeated hardest of all, that these companies sell your floor plan to advertisers.

Did a Roomba really photograph someone on the toilet?

Close view of the front bumper of a charcoal grey robot vacuum, showing a small square matte black camera module with a tiny dark lens and an amber indicator set into the lower bumper edge.
Postage stamp sized, matte black, ankle high. If you are checking a robot for a camera, this is the thing to look for, and it is not on top.

Yes. MIT Technology Review published the investigation in December 2022 after obtaining 15 screenshots of private photos “which had been posted to closed social media groups.” No person took them. They came from “development versions of iRobot’s Roomba J7 series robot vacuum” and went to Scale AI, which “contracts workers around the world to label audio, photo, and video data used to train artificial intelligence.” Ecovacs, of all companies, describes the fallout accurately on its own privacy blog: “pictures of a female sitting on a toilet, captured by a robotic vacuum cleaner, circulated around the Internet.”

The details cut both ways. iRobot said these were “special development robots with hardware and software modifications that are not and never were present on iRobot consumer products for purchase,” used by testers who had signed consent agreements, and that the images were “shared in violation of a written non-disclosure agreement” by an annotation vendor the company then dropped. That is a supply chain failure, not a product defect. If you own a store bought Roomba, nothing here says your floors went online.

The scale is what stays with you. iRobot has said it shared over 2 million images with Scale AI plus an unknown quantity with other platforms, and every frame came from inside a house. Dennis Giese, whose research runs through the rest of this article, told MIT Technology Review why this category is not a doorbell: these machines have “powerful hardware, powerful sensors” and “can drive around in your home… and you have no way to control that.”

Reddit argued about the word consent rather than the contract. “I could be wrong, but no one willingly wants to be monitored. Tech related ‘consent’ is usually meaningless” took the top comment on r/privacy at 346 points, while a quieter reply noted the photos came from opted in beta testers, not customers. Both hold. The testers agreed to something. Almost nobody agrees to the labeling pipeline behind it, because almost nobody knows it is there.

How did strangers end up driving other people’s vacuums?

Two column flat diagram comparing a Bluetooth attack path that needs no account against a credential stuffing path that starts with a password leaked from another site.
Two different doors, constantly written up as one. A firmware update closes the left one. Only a password you use nowhere else closes the right one.

Two separate failures in the same year, and conflating them is the standard mistake here. The flaws were found by Giese, a Germany based independent researcher, and Braelynn Luedtke of Leviathan Security Group, whose talk credits read simply braelynn. ABC News in Australia replicated and publicised the work; it did not discover it.

The first door is the robot. At 37C3 in December 2023 the pair showed the PIN protecting live video was verified only by the app, never by the robot or the server, which ABC’s write up called an “honour system.” At DEF CON 32 in August 2024 they went further, and their slide deck gives the mechanism in two flat lines: the payload was “encrypted with static AES key such as ‘12345678ecovacs'” and “Input validation is… insufficient.” A key shared across a product line is not a key. It is a formality anyone with a firmware dump can read.

That October, ABC and Giese ran it live on a volunteer’s Deebot X2. Giese “could do it entirely over Bluetooth, from up to 140 metres away,” and drove the robot and its camera from another continent. Ecovacs had said users “do not need to worry excessively,” and that the flaw required “specialised hacking tools and physical access to the device.” The reporter’s rebuttal is one sentence: “All it had taken was my $300 smartphone, and I hadn’t even laid eyes on Sean’s robot until after hacking into it.”

The second door needed no vulnerability at all. In May 2024, Deebot X2 units in Minnesota, Los Angeles and El Paso were hijacked within days of each other and used to scream racist abuse at the families who owned them. We are not reprinting the language. One owner’s robot worked the same floor as the family bathroom, and his reaction was about the camera rather than the noise: “Our youngest kids take showers in there,” he said. “I just thought of it catching my kids or even me, you know, not dressed.”

Ecovacs found no evidence its own systems were breached. What its investigation found, per the statement it gave ABC, was “a credential stuffing event” with login attempts running “by a factor of 90:1” over the normal daily volume. Somebody fed passwords stolen from an unrelated site into the Ecovacs login. Reuse one and you hand over the key. The company said the PIN bypass was improved in August 2024, corrected by firmware in November, and that “Only the X2 Series has this vulnerability.” Giese called the first fix insufficient, and Cyber Daily ran the statement in full.

One footnote for any product page you read. That hacked robot carried TÜV Rheinland certification. A former certification tester at TÜV SÜD, Lim Yong Zhi, told ABC that testing in this category does not require testers to attempt in depth or professional attacks. The badge describes paperwork, not whether anyone competent tried to break in.

What do iRobot, Roborock and Ecovacs say they collect?

All three publish the answer, and the language beats any summary of it, including ours.

Company Its own words What that does and does not promise
iRobot Images “will not be viewable by us unless and until you opt in both to image collection and to sharing each image with iRobot.” Separately: “Unless your device is enrolled in the iRobot Select program, your device will NOT automatically transmit this information to iRobot.” A double opt in on photographs, the strongest camera language of the three. It sits beside a separate category the policy calls device environment data: “floorplan and room names, existence and type of objects, floor type, other iRobot devices”
Roborock “When obstacles are detected, the photo is saved on the robot in an encrypted format rather than as a standard image file… The cloud acts only as a temporary communication channel and does not store the image.” A design claim about where images live and for how long. A promise about handling, not something a buyer can audit from outside the device
Ecovacs “DEEBOT robot vacuums counter hackers accessing cameras by encrypting all data gathered by the device (including videos) with the AES-128 (128-bit Advanced Encryption Standard).” Encryption is only as good as key handling, and the flaw researchers used was a static AES key shared across robots plus a PIN the app checked by itself

Roborock goes furthest on where processing happens, the most concrete privacy claim in this review: its voice model is “fully integrated into the robot, enabling offline voice control even without Wi-Fi. All voice data is processed on-device,” and for pet recognition, “All AI computations are performed on-device, with no data sent to the cloud or shared with third parties.” If that holds, the microphone question mostly answers itself.

All three share one limit. A privacy policy says what a company intends to do with data it holds. It says nothing about whether somebody else can reach the device, which is what went wrong in 2024. Ecovacs published its encryption claim before the DEF CON talk, and the claim was technically true.

Does iRobot’s bankruptcy change the math?

Two column flat comparison card setting three common assumptions about the Amazon deal and iRobot's collapse against what the regulatory filings and ratings actually say.
Three beliefs worth correcting before you shop. The third is the awkward finding in this whole review.

Start with the correction, because it is nearly universal. Regulators did not move against the Amazon deal over home surveillance. When the $1.7 billion acquisition collapsed on January 29, 2024, EU competition chief Margrethe Vestager framed it as shelf space: the investigation “preliminarily showed that the acquisition of iRobot would have enabled Amazon to foreclose iRobot’s rivals by restricting or degrading access to the Amazon Stores.”

What followed was worse than a lost deal. The Robot Report tracked the slide through iRobot’s filings: 105 more layoffs in late 2024, “reducing its global workforce by nearly 50% from the start of that year,” and by November 24, 2025 a debt to contract manufacturer Picea of $161.5 million, “$90.9 million of which was past due.” iRobot’s Form 8-K closes it out: Nasdaq “determined to delist the Company’s common stock” after the Chapter 11 filing of December 14, 2025, trading suspended December 22. Where the case lands is not settled in anything we read as of August 10, 2026, and we are not inventing an outcome. Roombas did not stop working on December 14.

Here is the uncomfortable part. Consumer Reports’ lab testing found that “of the companies we test, only iRobot earns an Excellent rating in data security,” earned on patching and on engagement “with the security research community.” No brand earned a top rating for data privacy specifically. CR’s Justin Brookman set the bar plainly: “These companies need to make sure the cameras in robotic vacs have reasonable security protections to ensure that attackers can’t access them.”

So the best security record in the category belongs to the company in bankruptcy court, and a networked camera is only as safe as the team still shipping patches for it. That is a going concern question and no spec sheet answers it. If you want a machine that watches the house on purpose, that is a different product with a different threat model, covered in our guide to home security robots.

Does a camera free vacuum fix it?

Flat vector diagram showing three robot vacuum sensor layouts side by side: mapping turret with no camera, turret plus a front bumper camera, and a flat top shell with a front bumper camera.
The raised disc on top is the mapping sensor, not a lens. Its presence tells you nothing about whether the robot has a camera, so check the spec sheet.

Mostly, and the people who care most converged on it years ago. The same question keeps reappearing on r/privacy in almost the same words, from “Does anybody know a vacuum robot like Roomba but where all the data stays private” in July 2023 to “what is Most advanced ‘No camera/mic’ robot vacuum July 2026?” this July. The answer barely moves. “Buy one that uses a LiDAR sensor to navigate, so no camera at all” took the top reply on the 2025 version of the thread at 75 points, and Consumer Reports lands in the same place: “A few robotics don’t have WiFi connectivity, so there are no privacy or security concerns there.”

Two caveats keep it from being clean. No camera is not the same as unlistenable: a peer reviewed 2020 paper, LidarPhone, turned a vacuum’s mapping laser into a crude microphone and reported “approximately 91% and 90% average accuracies of digit and music classifications” from a prototype built on a Xiaomi Roborock. Controlled lab conditions, and nothing here documents anyone doing it to a real household. File it against the word immune, not against buying the thing.

Local control is also arriving slower than the marketing implies. Matter 1.4 added robot vacuums with an emphasis on “direct LAN communication (via Ethernet, Wi-Fi, or Thread), reducing reliance on cloud servers,” but per Vacuum Wars the rollout keeps slipping, Narwal having moved support on its Flow from late 2025 “to sometime in 2026.” Start and stop over your own network is useful. Mapping, object recognition and scheduling still generally take the long way through a vendor’s servers.

What actually lowers your risk?

Three rung flat vector ladder of robot vacuum privacy measures, from app settings and a unique password, through firmware updates and network isolation, to replacing the vendor firmware with local only software.
Take the rungs in order and stop where the cost stops being worth it. Rung one takes five minutes and closes the attack that actually reached families in 2024.

Start in the app tonight, because the cheapest fix is the one that mattered most in practice. Give the account a password you use nowhere else, since credential stuffing rather than a clever exploit is what put strangers inside those Deebots. Then switch off what you do not use. iRobot’s policy names both controls: “Through the settings in your app, you may choose to not transmit map data to us; you may also choose to send images of obstacles if the device has image collection sharing, to help improve our services.” It also documents the blunt option, disconnecting the robot from Wi-Fi and Bluetooth entirely. You lose scheduling, app control and remote start. You keep a vacuum that cleans.

Next rung, the network. Install firmware when it appears; the Ecovacs hole was closed over the air in November 2024, and a robot that never updates keeps every flaw it shipped with. Past that, a vacuum is another client on your WiFi, and the local network behaviour we work through in how WiFi security cameras work applies here too. Reddit regulars do the obvious thing, blocking the robot’s outbound internet access at the router or parking it on a segment with no route out. One r/privacy commenter runs a flashed Roborock “on a WiFi subnet that has no outgoing internet access for extra paranoya,” typo and all.

The top rung is a subculture, not a setting. Valetudo is open source firmware that replaces the vendor cloud with local only control, and its maintainer’s stated reason reads like a reply to the 2022 leak: “what was ‘just’ your floor plan a few years ago might now be a picture of you sitting on your toilet ending up in an S3 bucket and, soon after, on the internet.” It surfaced unprompted in eight of the twenty Reddit threads we pulled. We are describing it, not walking you through it, because flashing a robot voids whatever support you had and hands you the maintenance. Its own community is not uniformly charmed either; a newcomer on r/homeautomation in February 2025 called the people running the project “arrogant & condescending,” and the moderator answered in the thread rather than deleting it.

Our position, plainly. Buy the model without a camera if the feature list allows it, give it a password you use nowhere else, install firmware when it shows up, then stop thinking about it. If you want the camera because obstacle avoidance genuinely works better with one, that is a real trade and you can make it with your eyes open. What you should not do is treat an encryption claim on a product page as proof of anything. Ecovacs published one, and the key was sitting in the firmware. If cameras in the house are the wider worry, our guide to finding hidden cameras in a room beats a vacuum spec sheet, and the rest of our evidence reviews live in the Security Tech section.

Sources