Are Ring Cameras Safe From Hackers? What the FTC Case Actually Found
Affiliate Disclosure: This article contains affiliate links. If you buy through these links, we may earn a commission at no extra cost to you. Our editorial opinions are our own and are not influenced by affiliate relationships. Read our full disclosure policy →
Contents
Quick Answer
Ring cameras are not meaningfully easier to break into than any other connected camera — but the accounts in front of them have been, and that is a different problem with a different fix. The FTC’s 2023 complaint describes credential stuffing and brute force attacks in 2017 and 2018, no multifactor authentication until 2019, and roughly 55,000 US customers whose accounts were reached as a result. Almost none of that involved defeating the camera itself. If you use a password on your camera account that you have used anywhere else, that is your risk, and turning on two-step verification plus a unique password closes most of it in about five minutes.
What the FTC Actually Found
In May 2023 the Federal Trade Commission announced a proposed order against Ring. It is worth reading what the complaint says rather than the headlines it produced, because the two are not the same story. The FTC’s allegation was not that Ring’s cameras contained a flaw an attacker could exploit. It was that Ring failed to implement standard protections against two well-known threats — credential stuffing and brute force attacks — despite warnings from its own employees, outside security researchers and press coverage.
The specifics matter. The FTC states that Ring experienced multiple credential-stuffing attacks in 2017 and 2018 and did not implement common protections such as multifactor authentication until 2019, and that its implementation then was sloppy enough to blunt the benefit. The consequence, in the complaint’s own framing, was that attackers continued to reach stored videos, live streams and account profiles belonging to approximately 55,000 US customers, and in some cases used the cameras’ two-way audio to speak to the people inside. The proposed order required Ring to pay 5.8 million dollars in consumer refunds and to build a privacy and security program including multifactor authentication for both employee and customer accounts.
The attack path the FTC describes starts with a password leaked somewhere else entirely, not with a flaw in the camera.Almost None of It Was a Break-In at Ring
Credential stuffing is worth understanding properly, because the name makes it sound more exotic than it is. An unrelated website is breached — a forum, a retailer, anything — and its email and password pairs end up circulating. Software then replays those exact pairs against other services in bulk. Nothing is being cracked. If you used the same password on a camera account that you used on the breached site, one of those attempts simply logs in, and from the service’s point of view it looks like you arriving.
This is precisely why the fix is not on the camera. NIST’s authentication guidelines require that when a password is set or changed, it be compared against a list of values known to be commonly used, expected or compromised — explicitly including passwords obtained from previous breach corpuses. The same document requires rate limiting: controls that cap consecutive failed authentication attempts so an attacker cannot simply keep trying. Those two controls, plus a second factor, are what stands between a leaked password and a stranger watching your living room.
Two Different Failures, Two Different Fixes
What the FTC described
- Passwords reused from breaches elsewhere
- No second factor on customer accounts until 2019
- Weak limits on repeated login attempts
- Attackers reaching live view and two-way audio
What actually closes it
- A password used on this account and nowhere else
- Two-step verification turned on for every user
- Rate limiting, which is the provider’s job, not yours
- Removing shared users and old devices you no longer recognize
The Other Half of the Case Was Not Hackers At All
The part of the story that gets less attention is the internal one, and for some readers it is the more uncomfortable half. The FTC’s case also covered Ring’s own handling of customer video. The Electronic Frontier Foundation’s summary of the complaint records that in 2017 one Ring employee viewed thousands of video recordings belonging to female users, including cameras pointed at bathrooms and bedrooms, over a period of months, and that the company did not take adequate steps to notify customers or obtain consent for extensive human review of their recordings until January 2018.
That is not a hacking problem and no password change fixes it. It is a governance problem, and it is the reason the order obliges Ring to delete data products derived from unlawfully reviewed videos and to put novel safeguards around human review of footage. If your concern about cameras is who at the company can see the recordings rather than who outside it can, that concern is legitimate, it was substantiated, and the honest answer is that local storage — footage that never leaves your house — is the only architecture that removes the question entirely. Our guide to subscription-free systems covers the brands built that way.
What Changed After the Order
Enough that the 2019-era criticism should not be applied to a camera bought today without qualification. Ring now asks for a verification code at sign-in, and supports delivering it by text message, an authenticator app, WhatsApp or a push approval, so the code is not locked to a single channel. The order also compels ongoing obligations rather than a one-time fix: a standing privacy and security program, multifactor authentication on employee as well as customer accounts, and deletion of the models and algorithms derived from the improperly reviewed footage.
| The concern | Where it stood in the complaint | Where it stands now |
|---|
| Second factor on your account | Not implemented until 2019, after two years of credential-stuffing attacks | A verification code at sign-in, deliverable by text, authenticator app, WhatsApp or push approval |
| Employee access to your video | One employee viewed thousands of recordings in 2017; no adequate consent process until January 2018 | Order requires safeguards on human review and deletion of derived data products |
| Repeated login attempts | Standard protections were not in place | A provider-side control; NIST requires capping consecutive failed attempts |
| Money and enforcement | Proposed order requiring 5.8 million dollars in consumer refunds | A binding program rather than a promise, subject to the order |
None of that makes a camera account safe by itself. It moves the weakest link back to where it usually sits: the password you chose and whether anything else is sharing it.
Where Your Actual Risk Sits Today
Rank the realistic threats and the list is short, and mostly boring. A password reused from a site that was later breached is far and away the most likely way somebody else ends up looking at your camera. Second is a shared user you added once and forgot — an ex-housemate, a contractor, a dog walker — whose own account security you have no visibility into at all. Third, and much further down, is somebody physically taking the camera, which is a storage question rather than a security-software one.
What is not realistically on that list, on the evidence of the FTC complaint, is an attacker defeating the camera’s encryption or exploiting the device itself. The complaint describes account compromise throughout. That distinction should change what you spend your effort on.
The Numbers From the Complaint
2017-18
years of credential-stuffing attacks before MFA
2019
the year multifactor authentication arrived
~55,000
US customers whose accounts were reached
5.8M
dollars in consumer refunds under the order
All four figures are taken from the FTC’s own press release announcing the proposed order.
Six Things That Genuinely Reduce the Risk
In Order of How Much They Actually Help
1
Use a password nowhere else
This one step removes the entire attack path in the FTC complaint. A password manager makes it practical; remembering it does not.
2
Turn on two-step verification
Ring supports codes by text, authenticator app, WhatsApp or push approval. An authenticator app is the sturdiest of those.
3
Audit shared users
Every shared user is another account that can reach your video, secured by somebody else’s habits. Remove the ones you no longer need.
4
Check the device list
Sign out sessions and devices you do not recognize. A password change means little if an old session stays valid.
5
Decide where footage lives
Cloud storage is convenient and creates an off-site copy; local storage means nobody at any company can review it. Pick deliberately.
6
Point cameras at entrances, not interiors
The most invasive part of the FTC case involved cameras aimed at bedrooms and bathrooms. Placement is a privacy control, not just a coverage one.
The last point is worth more than it sounds. A camera watching a front door produces footage that is useful to you and uninteresting to anyone else; a camera watching a living room produces the footage that made the FTC’s complaint so damaging. Our room-by-room placement walkthrough treats that as a design decision rather than an afterthought. If you are still choosing hardware, the Ring camera lineup guide covers which model suits which position, and the Ring Protect breakdown explains exactly what you lose without a plan.
The Gap Most People Never Close: Shared Users and Old Accounts
Two-step verification protects the account it is turned on for. It does not protect an account somebody else controls, and shared users have real access — live view among it. If a shared user reuses passwords, your camera inherits their habits, and no setting on your side changes that.
The same applies to hardware you no longer use. A camera you gave away, sold or replaced can remain attached to an account long after you have stopped thinking about it, which is exactly why a factory reset before a device changes hands is worth doing properly rather than assuming a new owner’s setup wipes it — our Ring doorbell reset guide covers the procedure per model. And if the worry is not the account at all but the camera itself being taken off the wall, the answer is architectural: cameras that keep footage somewhere other than the camera, including models that do not depend on your Wi-Fi at all.
What to Actually Do
Do one thing today: change your camera account to a password you have never used anywhere else, and turn on two-step verification with an authenticator app rather than text messages. That single action closes the exact attack path the FTC’s complaint describes, and it takes about five minutes. Everything else on this page is a refinement of it.
Then decide which of two different worries is actually yours, because they lead to opposite purchases. If the worry is a stranger reaching your account, the fix is authentication hygiene and the brand barely matters — every cloud camera shares this exposure. If the worry is who inside a company can review your footage, no password fixes it and you should buy a system that stores video locally instead, accepting that you lose the off-site copy in exchange. Read the Ring Alarm breakdown if you are extending beyond cameras. What would change our advice is a fresh enforcement action or a documented device-level vulnerability — neither of which the current record shows.
SafeBode does not yet run an in-house product testing program. This guide is built from manufacturer specifications, official support documentation, current retail listings and verified buyer feedback rather than hands-on testing, and we say so plainly rather than implying testing we have not done.
Frequently Asked Questions
Have Ring cameras actually been hacked?
Accounts have been compromised; the cameras themselves were not defeated. The FTC’s complaint describes credential stuffing and brute force attacks against accounts, which succeed because a password was reused elsewhere, not because something in the camera was broken.
Does two-step verification really stop this?
It stops the specific attack in the complaint, which relies on a correct password alone being enough. Once a second factor is required, a leaked password on its own no longer opens the account. An authenticator app is sturdier than text messages, because a phone number can be transferred away from you.
Is my Ring camera safe if I use a strong password?
Strong is less important than unique. A long password that you also use on a forum which is later breached is exposed anyway. A moderately complex password used on exactly one account is safer than a very complex one you have reused.
Can someone talk through my camera?
That is documented in the FTC’s complaint as something attackers did after reaching accounts, using the two-way audio feature. It is an account compromise consequence, not a separate flaw, so the same fix applies.
Are Ring employees watching my videos?
The FTC case concerned historical practice and led to an order requiring safeguards around human review of footage and deletion of data derived from videos that were reviewed improperly. If you want the question removed rather than governed, a system that stores video locally is the only architecture that does it.
Should I stop using cloud cameras entirely?
Not necessarily, but you should choose knowingly. Cloud storage gives you an off-site copy that survives the camera being stolen, at the cost of your footage existing on somebody else’s infrastructure. Local storage reverses both. Neither is universally correct.
What about shared users on my account?
They are the most commonly overlooked exposure. A shared user has real access, secured by their own password habits rather than yours. Review the list periodically and remove anyone who no longer needs it, the same way you would take back a spare key.
Do I need to worry about someone stealing the camera itself?
It is a real risk but a different one, and no account setting addresses it. The fix is where footage is stored: a camera that writes only to a card in its own housing loses the evidence along with the hardware, while one that streams to a hub indoors or to the cloud does not.
Sources
Show sources (4)