ring doorbell camera

Ring Faces Intense Scrutiny After Reports That Thousands of Users’ Information Was Leaked Online

The security camera company owned by Amazon says that there was not a breach of its servers and blame the issue on lax cybersecurity practices by users.

Although Ring, the security company owned by Amazon, has been blaming recent reports of hacking on lax cybersecurity practices by customers, as news outlets and security researchers discover lists of leaked usernames and passwords online.

Last week, BuzzFeed News was alerted to the compromising of 3,672 Ring camera accounts, which exposed log-in emails, passwords, time zones and the names that customers gave to their cameras, including location information like “bedroom” or “front door.” In addition, TechCrunch reported that a security researcher discovered a list of 1,562 unique email addresses and passwords on the dark web.

If hackers successfully breached Ring accounts, as at least some people have achieved, they can gain access to live camera footage associated with an account as well as payment information and Ring speakers installed in the home.

Researchers told BuzzFeed that the formatting of the leaked list appears to be from a company database, not from credential stuffing, a practice that involves uses special software to rapidly enter previously compromised emails and passwords to get access to an account. For example, a hacker could use a list of emails and passwords from the Capitol One breach and check them to see if customers used the same information for their Ring account.

Read More: Ring Doorbells Had Security Bug That Exposed Wi-Fi Passwords To Hackers

“One could argue that the person maybe got these through credential stuffing,” Cooper Quintin, a security researcher with the Electronic Frontier Foundation, told BuzzFeed. “But if that was the case, why did that person go through and add the information about names of camera and time zones?”

In response to the BuzzFeed report, a Ring spokesperson said that the data was not compromised as part of a breach to its systems.

“Our security team has investigated these incidents and we have no evidence of an unauthorized intrusion or compromise of Ring’s systems or network,” the spokesperson said. “It is not uncommon for bad actors to harvest data from other company's data breaches and create lists like this so that other bad actors can attempt to gain access to other services.”

Although Ring says it has notified affected users, many told TechCrunch and BuzzFeed that they were not contacted by the company.

In a blog post published on Dec. 8, Ring appeared to blame the account takeovers on customers’ lack of cybersecurity protections, including not using two-factor authentication to guard their accounts and using the same emails and passwords over and over again.

“Out of an abundance of caution, we encourage Ring customers to change their passwords and enable two-factor authentication,” the blog post reads.

VICE noted that Ring does not currently require users to implement two-factor, a step that could protect all users from similar attacks. “Time and time again we’ve seen that people using mass-market consumer devices aren’t going to know or implement robust security measures at all times,” the outlet wrote

Researchers also said that internet-connected devices, often called IoT devices, have been historically vulnerable to hacking via an insecure network. The Ring cameras are an extension of that problem, made more disturbing by the fact that the accounts contain sensitive information about a person’s home and lifestyle that could lead to someone burglarizing their home.

“This illustrates that when you bring an internet connected camera in to your home, you’re also potentially bringing anyone on the internet into your home,” Quintin said.

Ring has already faced scrutiny this year for its more than 600 partnerships with law enforcement departments across the U.S., which allows police to request videos from users for use in criminal investigations.

Featured

  • Survey: 54% of Organizations Cite Technical Debt as Top Hurdle to Identity System Modernization

    Modernizing identity systems is proving difficult for organizations due to two key challenges: decades of accumulated Identity and Access Management (IAM) technical debt and the complexity of managing access across multiple identity providers (IDPs). These findings come from the new Strata Identity-commissioned report, State of Multi-Cloud Identity: Insights and Trends for 2025. The report, based on survey data from the Cloud Security Alliance (CSA), highlights trends and challenges in securing cloud environments. The CSA is the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

  • Study: Only 35 Percent of Companies Include Cybersecurity Teams When Implementing AI

    Only 35 percent of cybersecurity professionals or teams are involved in the development of policy governing the use of AI technology in their enterprise, and nearly half (45 percent) report no involvement in the development, onboarding, or implementation of AI solutions, according to the recently released 2024 State of Cybersecurity survey report from ISACA, a global professional association advancing trust in technology. Read Now

  • New Report Series Highlights E-Commerce Threats, Fraud Against Retailers

    Trustwave, a cybersecurity and managed security services provider, recently released a series of reports detailing the threats facing the retail sector, marking the second year of its ongoing research into these critical security issues. Read Now

  • Stay Secure in 2024: Updated Cybersecurity Tips for the Office and at Home

    Cyber criminals get more inventive every year. Cybersecurity threats continue to evolve and are a moving target for business owners in 2024. Companies large and small need to employ cybersecurity best practices throughout their organization. That includes security integrators, manufacturers, and end users. Read Now

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3