• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CybersecurityRobotics

One man accidentally gained access to thousands of robot vacuums, exposing the AI cyber nightmare risk facing millions of Americans

Nick Lichtenberg
By
Nick Lichtenberg
Nick Lichtenberg
Business Editor
Down Arrow Button Icon
Nick Lichtenberg
By
Nick Lichtenberg
Nick Lichtenberg
Business Editor
Down Arrow Button Icon
February 25, 2026, 12:36 PM ET
robot
Who, or what, is controlling your vacuum robot?Getty Images

When software engineer Sammy Azdoufal sat down to steer his new DJI Romo robot vacuum with a PlayStation 5 video game controller, he didn’t expect to accidentally commandeer a global surveillance network. Using an AI coding assistant to reverse-engineer how the vacuum communicated with DJI’s remote servers, Azdoufal extracted a security token meant to prove he owned his specific device. Instead, as reported by Popular Science, the backend servers treated him as the owner of nearly 7,000 robot vacuums operating across 24 countries.

Recommended Video

With a few keystrokes, Azdoufal discovered he could tap into live camera feeds, activate microphones, and even compile 2D floor plans of strangers’ private homes. While he responsibly reported the security bug (to The Verge) rather than exploiting it, this staggering vulnerability highlights a terrifying reality: The rapid, unchecked integration of automated systems is creating a massive and unprecedented security gap.

Millions of Americans are increasingly welcoming these internet-connected devices into their most intimate spaces. Roughly 54 million U.S. households had at least one smart home device installed as of 2020, per Parks Associates. Furthermore, companies like Tesla, Figure, and 1X are racing to introduce sophisticated, humanoid autonomous robots capable of living in homes and performing complex chores.

The surveillance capabilities of smart devices became a national talking point earlier this year, when a Google Nest device apparently stored footage on the cloud of the alleged kidnapping of Nancy Guthrie, mother of Today show host Savannah Guthrie. That was followed shortly afterward by an Amazon Super Bowl ad for its Ring product, meant to be a charming rescue of a lost dug but actually revealing that networked cameras capable of spying on Americans are everywhere. The backlash seemingly prompted Amazon to discontinue its partnership with a police surveillance firm. Once you add autonomous AI agents into this mix, you have what cyber giant Thales describes as a budding nightmare scenario.

The nightmare scenario around the corner

According to the recently released Thales 2026 Data Threat Report, a stunning 70% of organizations now explicitly cite AI as their top data security risk. And just like the DJI vacuums relying on remote cloud servers, enterprises are eagerly embedding AI into their daily workflows, granting automated systems broad access to sprawling enterprise data.

The core issue is a shocking lack of visibility and foundational data control. The Thales report reveals only 34% of organizations actually know where all their sensitive data resides. And because AI systems continuously ingest and act upon information across vast cloud environments, it is incredibly difficult to enforce “least-privilege access,” or the practice of granting only the minimum necessary access rights. If a machine’s credentials—such as tokens or API keys—are compromised, the resulting data exposure can be devastating.

In fact, credential theft is currently the leading attack technique against cloud management infrastructure, cited by 67% of organizations that have suffered cloud attacks. Imagine the 7,000 robotic vacuum cleaners, but a whole community’s Nest or Ring devices, being controlled by an AI agent instead.

Rodney Brooks, the cofounder of iRobot, creator of the Roomba vacuum creator said Elon Musk’s vision of a future powered by humanoid robots was “pure fantasy thinking,” because they’re just too clumsy.

“Today’s humanoid robots will not learn how to be dexterous despite the hundreds of millions, or perhaps many billions of dollars, being donated by VCs and major tech companies to pay for their training,” Brooks wrote in a blog post. It’s unclear if that thinking extends to a human or AI agent controlling that robot remotely.

“Insider risk is no longer just about people. It is also about automated systems that have been trusted too quickly,” warned Sebastien Cano, senior vice president of cybersecurity products at Thales. When basic security measures like identity governance and access policies are weak, Cano notes “AI can amplify those weaknesses across corporate environments far faster than any human ever could.”

Making matters worse, the very tools used to build software are lowering the barrier to entry for exploiting these systems. AI-powered coding tools—like the one Azdoufal used to easily reverse-engineer the DJI servers—make it significantly easier for individuals with less technical knowledge to uncover and exploit software flaws. Despite these escalating automated threats, only 30% of companies surveyed currently have a dedicated AI security budget, relying instead on traditional perimeter defenses built for human users.

As Eric Hanselman, chief analyst at S&P Global’s 451 Research, pointed out, a fundamental paradigm shift is urgently required.

“As AI becomes deeply embedded into enterprise operations, continuous data visibility and protection are no longer optional,” Hanselman stated.

Without a radical rethinking of identity and encryption protocols, society is essentially leaving the front door wide open for the proverbial next software engineer with a video-game controller.

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
Nick Lichtenberg
By Nick LichtenbergBusiness Editor
LinkedIn icon

Nick Lichtenberg is business editor and was formerly Fortune's executive editor of global news.

See full bioRight Arrow Button Icon

Latest in Cybersecurity

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Cybersecurity

robot
CybersecurityRobotics
One man accidentally gained access to thousands of robot vacuums, exposing the AI cyber nightmare risk facing millions of Americans
By Nick LichtenbergFebruary 25, 2026
2 hours ago
Jenkins stands a podium in front of San Francisco City Hall
LawCrime
Former San Francisco homeless charity CEO stole $1.2 million in public funds and spent it on luxury vehicles and Louis Vuitton, authorities say
By The Associated PressFebruary 25, 2026
3 hours ago
cyber
Cybersecuritycyber
Nearly two-thirds of companies have lost track of their data just as they’re letting AI in through the front door to wander around
By Nick LichtenbergFebruary 25, 2026
6 hours ago
gen z
AIChatbots
We studied chatbots and language and saw a huge problem: They mean 80% when they say ‘likely’ but humans hear 65%
By Mayank Kejriwal and The ConversationFebruary 25, 2026
13 hours ago
Young girl uses AI virtual assistant to do schoolwork.Concept of Artificial Intelligence and Futuristic technology
AIEducation
‘Students can’t reason’: Teachers warn AI is fueling a crisis in kids’ ability to think
By Eva RoytburgFebruary 24, 2026
1 day ago
Photo of Peter Thiel
CybersecuritySocial Media
Discord distances itself from Peter Thiel–backed verification software after its code was found on a U.S. government server
By Catherina GioinoFebruary 24, 2026
2 days ago

Most Popular

placeholder alt text
Economy
Goldman Sachs says U.S. consumers are stuck with higher prices even after Supreme Court ruling opens door to $180 billion in tariff refunds
By Sasha RogelbergFebruary 23, 2026
2 days ago
placeholder alt text
Economy
Scott Bessent has ’got a feeling’ that $175 billion raised under the IEEPA is lost to the American people for good
By Eleanor PringleFebruary 23, 2026
2 days ago
placeholder alt text
Cybersecurity
Discord distances itself from Peter Thiel–backed verification software after its code was found on a U.S. government server
By Catherina GioinoFebruary 24, 2026
2 days ago
placeholder alt text
Economy
In less than a year, Trump erased 12 years of solvency for the trust fund that pays for Medicare Part A
By Nick LichtenbergFebruary 23, 2026
2 days ago
placeholder alt text
Personal Finance
Trump announces 401(k)s for all: ‘We will match your contribution with up to $1,000 each year’
By Amanda Gerut and Nick LichtenbergFebruary 24, 2026
16 hours ago
placeholder alt text
Economy
The record gap between corporate profits and worker pay has an ‘undercurrent of betrayal,’ top economist warns 
By Jason MaFebruary 23, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.