9 Signs Your Smart Home Device May Have Been Hacked — and What to Do Next
Smart cameras, doorbells, speakers, televisions, thermostats and even appliances are now connected to home networks.
That is convenient.
It also means devices that once performed one simple job now contain:
- software
- network connections
- cloud accounts
- microphones
- cameras
- stored credentials
- mobile apps
Like any internet-connected technology, they can potentially be compromised.
But there is an important distinction:
A smart device behaving strangely does not automatically mean a hacker is controlling it.
Software bugs, poor Wi-Fi, cloud-service outages and hardware faults can produce many of the same symptoms.
The right question is therefore not:
“Is this weird?”
It is:
“Is there evidence of unauthorised access or unexplained changes?”
Here are nine signs that deserve investigation.
1. Settings Change Without You Changing Them
One of the stronger warning signs is an unexplained configuration change.
For example:
- thermostat schedule changes
- camera recording settings change
- smart lock permissions change
- microphone/privacy setting changes
- device name changes
- remote access becomes enabled
- new automation appears
First check whether:
- another authorised family member changed it
- an app update reset the configuration
- an automation caused it
If nobody can explain the change, investigate the account controlling the device.
Repeated unexplained configuration changes are considerably more suspicious than one light bulb flickering.
2. You Receive Account or Security Notifications You Did Not Trigger
Pay particular attention to messages such as:
New device signed in
Password changed
New user added
Two-step verification changed
Remote access enabled
Camera sharing invitation accepted
when you did not perform the action.
That is direct evidence that somebody may have accessed the account rather than merely a malfunctioning device.
Do not click links in an unexpected security email.
Open the manufacturer's official app or website yourself and review:
- recent activity
- signed-in devices
- authorised users
- account settings
If the activity is not yours, secure the account immediately.
3. An Unknown Person or Account Has Access
Many smart-home platforms allow devices to be shared with:
- partners
- family
- guests
- installers
- previous occupants
Periodically review who has access.
You may discover:
- an old guest account
- former housemate
- installer
- unknown email address
- account you no longer recognise
This is particularly important for:
- cameras
- doorbells
- smart locks
- garage-door systems
- alarms
Remove access that is no longer required.
Use the same principle businesses use for IT accounts:
access should disappear when the legitimate need disappears.
4. A Camera Moves or Activates Unexpectedly
For a motorised security camera, unexplained movement can be concerning.
Likewise, investigate if:
- camera activates unexpectedly
- recording begins at unusual times
- privacy mode switches off
- camera angle changes
- status light behaves unexpectedly
But check the ordinary explanations first.
Many cameras include:
- motion tracking
- scheduled patrol
- person detection
- automatic calibration
that can move the camera without human involvement.
The suspicious scenario is not simply:
“The camera moved.”
It is:
“The camera moved in a way that its configured features cannot explain, and account activity also looks wrong.”
5. You Hear Unexpected Audio From a Speaker, Camera or Intercom
A smart speaker suddenly speaking is not necessarily evidence of compromise.
Possible legitimate causes include:
- accidental voice activation
- scheduled announcement
- automation
- another authorised household member
But investigate if you hear:
- unknown voices through a camera
- unexpected two-way audio
- unfamiliar announcements
- repeated activity nobody in the household triggered
For devices with:
- microphones
- cameras
- intercom functionality
unexpected two-way communication deserves particularly prompt attention.
6. Your Router Shows Devices You Don't Recognise
Log into your router or Wi-Fi management application and review connected devices.
You may find names such as:
Unknown
or obscure manufacturer names.
Do not immediately assume those are hackers.
Smart devices frequently identify themselves poorly.
An unfamiliar entry could be:
- television
- smartwatch
- smart bulb
- printer
- phone using a private MAC address
Work through the list systematically.
Compare:
- MAC address
- manufacturer
- connection time
- Wi-Fi band
- device information
If a device genuinely cannot be accounted for, remove/block it and change the Wi-Fi credentials if necessary.
7. The Device Is Sending Unexplained Amounts of Data
Smart devices often communicate with cloud services, so some network traffic is expected.
A camera will naturally upload far more information than a smart plug.
What deserves attention is a significant unexplained change from the device's normal behaviour.
For example:
smart plug normally sends tiny amounts of traffic
then suddenly begins continuously transferring large quantities of data.
Or:
camera sends traffic while recording is supposedly disabled.
Routers with traffic-monitoring functionality can help identify unusually active devices.
But data usage by itself is not proof of compromise.
Firmware downloads, cloud backups and software updates can create temporary spikes too.
8. Your Password Suddenly Stops Working
If credentials you know are correct suddenly fail, investigate.
Possible innocent explanations include:
- service outage
- app problem
- password-expiry mechanism
- account lockout
But an attacker who gained account access might:
- change the password
- replace recovery details
- add another authorised user
- change MFA
Use the provider's official account-recovery mechanism.
Then review:
- recent sign-ins
- recovery email
- telephone number
- MFA methods
- shared users
If the password was reused elsewhere, change those accounts too.
9. Security Features or Updates Have Been Changed
Another useful warning sign is unexplained interference with security configuration.
Examples include:
- automatic updates switched off
- remote administration enabled
- device no longer updating
- security notifications disabled
- unfamiliar admin account added
But be careful with one common misconception:
a failed firmware update does not automatically mean an attacker is preventing it.
It may simply be:
- old hardware
- vendor problem
- failed internet connection
- unsupported device
The NCSC recommends keeping smart devices updated because manufacturers use firmware updates to fix vulnerabilities. It also recommends avoiding devices that are already unsupported or close to the end of their support period.
What Is Stronger Evidence of a Hack?
Some indicators are far more persuasive than others.
Weak evidence
- device crashes
- Wi-Fi drops
- light flickers
- app runs slowly
- firmware update fails
These commonly have innocent explanations.
More concerning
- settings change repeatedly
- strange network behaviour
- device behaves differently from its configuration
Strong evidence
- unknown successful account login
- password or MFA changed
- unknown authorised user
- recordings accessed unexpectedly
- remote-control activity you cannot explain
- security notification confirming a change you did not make
Treat evidence, not fear, as the basis for your response.
What Should You Do if You Suspect Compromise?
Do not start randomly resetting every device immediately.
Work methodically.
1. Secure the controlling account
From a trusted computer or phone:
- change the account password
- use a unique password
- enable two-step verification
- sign out other sessions where supported
- remove unknown users/devices
The NCSC recommends strong unique passwords and enabling 2-step verification where the smart-device service supports it.
2. Disconnect a Seriously Suspect Device
If a:
- camera
- lock
- alarm
- baby monitor
appears to be actively controlled by somebody else, disconnecting it from the network can prevent continued remote access while you investigate.
For a Wi-Fi device, that may mean temporarily:
- turning it off
- disconnecting its network access
- blocking it through the router
Think carefully before disconnecting safety-critical equipment.
3. Check the Manufacturer's Security Guidance
Look at the manufacturer's official support page.
Check for:
- security advisories
- firmware releases
- account-compromise instructions
- factory-reset procedure
- support-life information
The NCSC specifically recommends following the manufacturer's instructions if you believe somebody has taken control of a smart device.
4. Update the Device
Once you have regained control:
- install current firmware
- update the companion app
- enable automatic updates where supported
Firmware updates often close vulnerabilities discovered after the device was sold.
An unsupported device that no longer receives security updates deserves particular scrutiny.
5. Factory Reset Where Appropriate
If you genuinely believe a device itself has been compromised, use the manufacturer's official reset procedure.
Then configure it as a new device rather than simply restoring every old setting without review.
Afterwards:
- create a new password
- update firmware
- enable MFA/2SV
- review privacy settings
- disable unnecessary remote access
The NCSC advises resetting a smart device according to manufacturer guidance when somebody may have taken control of it.
6. Secure the Wi-Fi Network
If the attacker may have gained network access, review the router too.
Use:
- WPA2 or preferably WPA3 where supported
- strong Wi-Fi password
- current router firmware
- changed router administrator credentials
Remove unknown connected devices.
Do not reuse the same password for:
router administration
and:
Wi-Fi access.
Put Smart Devices on Their Own Network
Where your router supports it, one useful security improvement is isolating smart devices from computers containing sensitive information.
You might use:
- IoT network
- guest network
- separate VLAN
depending on your equipment and technical ability.
Then a compromised smart plug or television has fewer opportunities to communicate with:
- laptops
- desktops
- NAS devices
on the main network.
This does not make vulnerable devices safe.
It reduces the potential impact if one is compromised.
Disable Remote Access if You Don't Use It
Ask yourself:
Do I genuinely need to control this device from outside the house?
For some products the answer is yes.
A smart doorbell is designed around remote notifications.
But perhaps an:
- appliance
- light
- smart plug
does not require internet-based remote control.
The NCSC explicitly recommends disabling remote access when it is not needed.
Choose Devices That Will Still Receive Updates
One of the biggest smart-home security problems is longevity.
A conventional light switch can operate for decades.
A smart switch may depend on:
- cloud provider
- mobile app
- firmware updates
- security support
The NCSC recommends checking how long a manufacturer promises to support a device before buying it and treating the support date almost like a security use-by date.
That is particularly important for:
- cameras
- smart locks
- alarms
- routers
because compromise has more serious consequences.
UK Smart Devices Now Have Minimum Security Requirements
Smart-device security has changed substantially since many older versions of this article were written.
The UK's Product Security and Telecommunications Infrastructure regime came into force on 29 April 2024.
It imposes baseline security requirements on relevant consumer connectable products sold in the UK.
Among the important principles are protections around:
- default passwords
- vulnerability reporting
- transparency over security-update support
That is an improvement.
But regulation does not make every connected device impossible to hack.
Consumers still need to:
- install updates
- secure their accounts
- enable MFA
- remove obsolete devices
Don't Keep Unsupported Devices Connected Forever
If a manufacturer says:
Security updates ended in 2023
that should influence whether the device remains on your network in 2026.
You do not necessarily need to replace a harmless old smart bulb immediately.
But I would be much less comfortable continuing to rely on unsupported:
- cameras
- locks
- routers
- alarms
- baby monitors
that expose sensitive functionality or information.
A Smart Home Security Checklist
For every important connected device:
- Use a unique account password.
- Enable 2SV/MFA where available.
- Keep firmware and apps updated.
- Enable automatic updates where possible.
- Review users who can access the device.
- Disable remote access if unnecessary.
- Check the manufacturer's support end date.
- Keep the router updated and securely configured.
- Consider separating IoT devices from your main computers.
- Remove or replace unsupported equipment.
These measures are far more effective than constantly watching a smart bulb for suspicious flickering.
How Hamilton Group Can Help
Smart-home security often overlaps with the same technologies businesses depend on:
- Wi-Fi
- routers
- passwords
- network segmentation
- firmware
- cyber-security controls
Hamilton Group can help investigate unusual network behaviour and improve the security of connected environments, particularly where home-working equipment and business systems share the same network.
We can assist with:
- Wi-Fi and router security
- network configuration
- IoT segmentation
- cyber-security reviews
- suspicious network activity
- device-security advice
- home-working security
The key question is not simply:
“Did my smart device behave strangely?”
It is:
“Is there evidence that somebody accessed the account, changed the configuration or gained control without authorisation?”
Visit hgmssp.com or call 0330 043 0069.
SEO Meta Description
SEO Keywords
Drupal-ready blog summary
I would replace the current article with this version. The major improvement is moving away from sensational signs such as “your light flickered, therefore hackers” and creating an evidence-based hierarchy. The rewrite also brings the article up to date with the UK’s current smart-device security regime and NCSC advice around support lifetimes, unique passwords, 2SV, automatic updates and disabling unnecessary remote access.