Pair and Bond
Endings

Baby Monitors Raise Data Security and Privacy Concerns

Parents rely on baby monitors to keep an eye on their children, but these devices also collect sensitive data and pose security risks.

Endings: Networking, network, game characters, lines, connections, interfaces.

Parents around the world rely on baby monitors to keep an eye on their children, but these devices also collect sensitive data and pose security risks.

Baby monitors allow parents to keep an eye on their babies without having to be in the same room. The first model was the Zenith Radio Nurse, released on sale in 1938. More recent products have many advanced features, including contactless breathing and vital signs monitoring, AI-powered sleep analytics, cry and sound analysis, and environmental monitoring.

However, these new levels of functionality depend on ever more sensors, more cloud processing, and more data being collected on children. Parents now have to weigh up the privacy of the data these devices collect, as well as the security risks they bring into the home.

In May 2026, a security researcher in France named Sammy Azdoufal decided to probe some of the weaknesses behind budget smart cameras. Azdoufal discovered that he could pull up other people’s live and recorded footage without needing to guess a password or do anything that really counts as “hacking”. His findings, reported by CyberNews, traced back to a shared system used behind the scenes by more than 300 different camera brands sold on retailers such as Amazon.

He estimated that more than one million devices were affected, many of them baby monitors in bedrooms.

Shared Vulnerabilities

What most parents don’t realise is that the brand on the box is rarely the company that built the camera or wrote its software. Many monitors, even from well known sellers, come out of a small number of factories. They get sold under dozens of different names, so one weakness underneath can affect them all.

The cybersecurity operations company Rapid7 published some of the first well known research into these cameras years ago, and a 2026 academic study found the same pattern repeating in newer devices and their apps.

Regulators have started responding. Updated in 2022, new cybersecurity rules under the EU’s Radio Equipment Directive have applied to any internet-connected wireless device sold in the EU. These new rules require manufacturers to protect users’ data, stop devices being hijacked and guard against fraud.

Some manufacturers are taking steps to improve security. For example, the baby monitor manufacturer Owlet announced in late 2025 that its newest model was the first baby monitor awarded the SGS Cybersecurity mark. This mark requires manufacturers to include encryption, a unique password, and a channel for researchers to report flaws.

The certification gives parents something concrete to look for.

Privacy and Long-term Protection

The UK has rules covering both sides of this. The Product Security and Telecommunications Infrastructure Act, in force since 2024, bans default passwords and forces manufacturers to say how long they’ll support a device.

On the data side, the UK goes further than most countries through the Information Commissioner’s Office Children’s Code, which applies to any connected device likely to be used by children. The code requires the highest privacy settings by default, and gives parents a genuine right to see, or delete, what’s been collected, backed by fines of up to 4% of global turnover.

Most parents just don’t know to ask.

Device TypeNumber of Devices Affected
Baby MonitorsOver 1 million
Budget Smart CamerasOver 300 different camera brands

The bigger issue isn’t something one password can fix. The underlying issues in the industry mean new vulnerabilities will keep appearing, so the safest path is staying informed and choosing devices with transparent security and support policies.

Related coverage

More from Endings