Skip to main content

9 Signs Your Smart Home Device May Have Been Hacked — and What to Do Next

Media 9 Signs That Your Smart Home Device Has Been Hacked

 

Smart cameras, doorbells, speakers, televisions, thermostats and even appliances are now connected to home networks.

That is convenient.

It also means devices that once performed one simple job now contain:

  • software
  • network connections
  • cloud accounts
  • microphones
  • cameras
  • stored credentials
  • mobile apps

Like any internet-connected technology, they can potentially be compromised.

But there is an important distinction:

A smart device behaving strangely does not automatically mean a hacker is controlling it.

Software bugs, poor Wi-Fi, cloud-service outages and hardware faults can produce many of the same symptoms.

The right question is therefore not:

“Is this weird?”

It is:

“Is there evidence of unauthorised access or unexplained changes?”

Here are nine signs that deserve investigation.

1. Settings Change Without You Changing Them

One of the stronger warning signs is an unexplained configuration change.

For example:

  • thermostat schedule changes
  • camera recording settings change
  • smart lock permissions change
  • microphone/privacy setting changes
  • device name changes
  • remote access becomes enabled
  • new automation appears

First check whether:

  • another authorised family member changed it
  • an app update reset the configuration
  • an automation caused it

If nobody can explain the change, investigate the account controlling the device.

Repeated unexplained configuration changes are considerably more suspicious than one light bulb flickering.

2. You Receive Account or Security Notifications You Did Not Trigger

Pay particular attention to messages such as:

New device signed in

Password changed

New user added

Two-step verification changed

Remote access enabled

Camera sharing invitation accepted

when you did not perform the action.

That is direct evidence that somebody may have accessed the account rather than merely a malfunctioning device.

Do not click links in an unexpected security email.

Open the manufacturer's official app or website yourself and review:

  • recent activity
  • signed-in devices
  • authorised users
  • account settings

If the activity is not yours, secure the account immediately.

3. An Unknown Person or Account Has Access

Many smart-home platforms allow devices to be shared with:

  • partners
  • family
  • guests
  • installers
  • previous occupants

Periodically review who has access.

You may discover:

  • an old guest account
  • former housemate
  • installer
  • unknown email address
  • account you no longer recognise

This is particularly important for:

  • cameras
  • doorbells
  • smart locks
  • garage-door systems
  • alarms

Remove access that is no longer required.

Use the same principle businesses use for IT accounts:

access should disappear when the legitimate need disappears.

4. A Camera Moves or Activates Unexpectedly

For a motorised security camera, unexplained movement can be concerning.

Likewise, investigate if:

  • camera activates unexpectedly
  • recording begins at unusual times
  • privacy mode switches off
  • camera angle changes
  • status light behaves unexpectedly

But check the ordinary explanations first.

Many cameras include:

  • motion tracking
  • scheduled patrol
  • person detection
  • automatic calibration

that can move the camera without human involvement.

The suspicious scenario is not simply:

“The camera moved.”

It is:

“The camera moved in a way that its configured features cannot explain, and account activity also looks wrong.”

5. You Hear Unexpected Audio From a Speaker, Camera or Intercom

A smart speaker suddenly speaking is not necessarily evidence of compromise.

Possible legitimate causes include:

  • accidental voice activation
  • scheduled announcement
  • automation
  • another authorised household member

But investigate if you hear:

  • unknown voices through a camera
  • unexpected two-way audio
  • unfamiliar announcements
  • repeated activity nobody in the household triggered

For devices with:

  • microphones
  • cameras
  • intercom functionality

unexpected two-way communication deserves particularly prompt attention.

6. Your Router Shows Devices You Don't Recognise

Log into your router or Wi-Fi management application and review connected devices.

You may find names such as:

Unknown

or obscure manufacturer names.

Do not immediately assume those are hackers.

Smart devices frequently identify themselves poorly.

An unfamiliar entry could be:

  • television
  • smartwatch
  • smart bulb
  • printer
  • phone using a private MAC address

Work through the list systematically.

Compare:

  • MAC address
  • manufacturer
  • connection time
  • Wi-Fi band
  • device information

If a device genuinely cannot be accounted for, remove/block it and change the Wi-Fi credentials if necessary.

7. The Device Is Sending Unexplained Amounts of Data

Smart devices often communicate with cloud services, so some network traffic is expected.

A camera will naturally upload far more information than a smart plug.

What deserves attention is a significant unexplained change from the device's normal behaviour.

For example:

smart plug normally sends tiny amounts of traffic

then suddenly begins continuously transferring large quantities of data.

Or:

camera sends traffic while recording is supposedly disabled.

Routers with traffic-monitoring functionality can help identify unusually active devices.

But data usage by itself is not proof of compromise.

Firmware downloads, cloud backups and software updates can create temporary spikes too.

8. Your Password Suddenly Stops Working

If credentials you know are correct suddenly fail, investigate.

Possible innocent explanations include:

  • service outage
  • app problem
  • password-expiry mechanism
  • account lockout

But an attacker who gained account access might:

  • change the password
  • replace recovery details
  • add another authorised user
  • change MFA

Use the provider's official account-recovery mechanism.

Then review:

  • recent sign-ins
  • recovery email
  • telephone number
  • MFA methods
  • shared users

If the password was reused elsewhere, change those accounts too.

9. Security Features or Updates Have Been Changed

Another useful warning sign is unexplained interference with security configuration.

Examples include:

  • automatic updates switched off
  • remote administration enabled
  • device no longer updating
  • security notifications disabled
  • unfamiliar admin account added

But be careful with one common misconception:

a failed firmware update does not automatically mean an attacker is preventing it.

It may simply be:

  • old hardware
  • vendor problem
  • failed internet connection
  • unsupported device

The NCSC recommends keeping smart devices updated because manufacturers use firmware updates to fix vulnerabilities. It also recommends avoiding devices that are already unsupported or close to the end of their support period.

What Is Stronger Evidence of a Hack?

Some indicators are far more persuasive than others.

Weak evidence

  • device crashes
  • Wi-Fi drops
  • light flickers
  • app runs slowly
  • firmware update fails

These commonly have innocent explanations.

More concerning

  • settings change repeatedly
  • strange network behaviour
  • device behaves differently from its configuration

Strong evidence

  • unknown successful account login
  • password or MFA changed
  • unknown authorised user
  • recordings accessed unexpectedly
  • remote-control activity you cannot explain
  • security notification confirming a change you did not make

Treat evidence, not fear, as the basis for your response.

What Should You Do if You Suspect Compromise?

Do not start randomly resetting every device immediately.

Work methodically.

1. Secure the controlling account

From a trusted computer or phone:

  • change the account password
  • use a unique password
  • enable two-step verification
  • sign out other sessions where supported
  • remove unknown users/devices

The NCSC recommends strong unique passwords and enabling 2-step verification where the smart-device service supports it.

2. Disconnect a Seriously Suspect Device

If a:

  • camera
  • lock
  • alarm
  • baby monitor

appears to be actively controlled by somebody else, disconnecting it from the network can prevent continued remote access while you investigate.

For a Wi-Fi device, that may mean temporarily:

  • turning it off
  • disconnecting its network access
  • blocking it through the router

Think carefully before disconnecting safety-critical equipment.

3. Check the Manufacturer's Security Guidance

Look at the manufacturer's official support page.

Check for:

  • security advisories
  • firmware releases
  • account-compromise instructions
  • factory-reset procedure
  • support-life information

The NCSC specifically recommends following the manufacturer's instructions if you believe somebody has taken control of a smart device.

4. Update the Device

Once you have regained control:

  • install current firmware
  • update the companion app
  • enable automatic updates where supported

Firmware updates often close vulnerabilities discovered after the device was sold.

An unsupported device that no longer receives security updates deserves particular scrutiny.

5. Factory Reset Where Appropriate

If you genuinely believe a device itself has been compromised, use the manufacturer's official reset procedure.

Then configure it as a new device rather than simply restoring every old setting without review.

Afterwards:

  • create a new password
  • update firmware
  • enable MFA/2SV
  • review privacy settings
  • disable unnecessary remote access

The NCSC advises resetting a smart device according to manufacturer guidance when somebody may have taken control of it.

6. Secure the Wi-Fi Network

If the attacker may have gained network access, review the router too.

Use:

  • WPA2 or preferably WPA3 where supported
  • strong Wi-Fi password
  • current router firmware
  • changed router administrator credentials

Remove unknown connected devices.

Do not reuse the same password for:

router administration

and:

Wi-Fi access.

Put Smart Devices on Their Own Network

Where your router supports it, one useful security improvement is isolating smart devices from computers containing sensitive information.

You might use:

  • IoT network
  • guest network
  • separate VLAN

depending on your equipment and technical ability.

Then a compromised smart plug or television has fewer opportunities to communicate with:

  • laptops
  • desktops
  • NAS devices

on the main network.

This does not make vulnerable devices safe.

It reduces the potential impact if one is compromised.

Disable Remote Access if You Don't Use It

Ask yourself:

Do I genuinely need to control this device from outside the house?

For some products the answer is yes.

A smart doorbell is designed around remote notifications.

But perhaps an:

  • appliance
  • light
  • smart plug

does not require internet-based remote control.

The NCSC explicitly recommends disabling remote access when it is not needed.

Choose Devices That Will Still Receive Updates

One of the biggest smart-home security problems is longevity.

A conventional light switch can operate for decades.

A smart switch may depend on:

  • cloud provider
  • mobile app
  • firmware updates
  • security support

The NCSC recommends checking how long a manufacturer promises to support a device before buying it and treating the support date almost like a security use-by date.

That is particularly important for:

  • cameras
  • smart locks
  • alarms
  • routers

because compromise has more serious consequences.

UK Smart Devices Now Have Minimum Security Requirements

Smart-device security has changed substantially since many older versions of this article were written.

The UK's Product Security and Telecommunications Infrastructure regime came into force on 29 April 2024.

It imposes baseline security requirements on relevant consumer connectable products sold in the UK.

Among the important principles are protections around:

  • default passwords
  • vulnerability reporting
  • transparency over security-update support

That is an improvement.

But regulation does not make every connected device impossible to hack.

Consumers still need to:

  • install updates
  • secure their accounts
  • enable MFA
  • remove obsolete devices

Don't Keep Unsupported Devices Connected Forever

If a manufacturer says:

Security updates ended in 2023

that should influence whether the device remains on your network in 2026.

You do not necessarily need to replace a harmless old smart bulb immediately.

But I would be much less comfortable continuing to rely on unsupported:

  • cameras
  • locks
  • routers
  • alarms
  • baby monitors

that expose sensitive functionality or information.

A Smart Home Security Checklist

For every important connected device:

  1. Use a unique account password.
  2. Enable 2SV/MFA where available.
  3. Keep firmware and apps updated.
  4. Enable automatic updates where possible.
  5. Review users who can access the device.
  6. Disable remote access if unnecessary.
  7. Check the manufacturer's support end date.
  8. Keep the router updated and securely configured.
  9. Consider separating IoT devices from your main computers.
  10. Remove or replace unsupported equipment.

These measures are far more effective than constantly watching a smart bulb for suspicious flickering.

How Hamilton Group Can Help

Smart-home security often overlaps with the same technologies businesses depend on:

  • Wi-Fi
  • routers
  • passwords
  • network segmentation
  • firmware
  • cyber-security controls

Hamilton Group can help investigate unusual network behaviour and improve the security of connected environments, particularly where home-working equipment and business systems share the same network.

We can assist with:

  • Wi-Fi and router security
  • network configuration
  • IoT segmentation
  • cyber-security reviews
  • suspicious network activity
  • device-security advice
  • home-working security

The key question is not simply:

“Did my smart device behave strangely?”

It is:

“Is there evidence that somebody accessed the account, changed the configuration or gained control without authorisation?”

Visit hgmssp.com or call 0330 043 0069.

SEO Meta Description

 

SEO Keywords

 

Drupal-ready blog summary

 

I would replace the current article with this version. The major improvement is moving away from sensational signs such as “your light flickered, therefore hackers” and creating an evidence-based hierarchy. The rewrite also brings the article up to date with the UK’s current smart-device security regime and NCSC advice around support lifetimes, unique passwords, 2SV, automatic updates and disabling unnecessary remote access.