Smart home cameras promise homeowners a direct view of their front porch, driveway or nursery from anywhere in the world. That promise depends entirely on the company behind the lens keeping video feeds locked down, and federal regulators have shown a pattern of finding that promise broken.
In August 2024, the Federal Trade Commission took action against security camera firm Verkada, a company that sells cameras primarily to businesses and institutions. The agency’s complaint alleged that Verkada failed to secure the video footage and other personal data it collected, leaving systems vulnerable to unauthorized access. The FTC also found the company violated the CAN-SPAM Act, the federal law governing commercial email. Verkada settled the case, agreeing to a $2.95 million payment along with new security requirements the company must follow going forward.
Verkada is not the only camera maker regulators have gone after. The FTC’s own Ring refunds page lays out a separate case involving the popular doorbell and indoor camera brand. The agency found that Ring employees and contractors had access to customers’ private video recordings that went far beyond what their jobs required, and that the company’s lax security practices allowed outside parties to gain unauthorized access to some camera feeds as well. That finding led to consumer refunds distributed through the FTC.
Together, the two cases point to the same underlying weakness. Cameras marketed as tools for keeping a home safe can become a liability when the manufacturer does not secure the data behind them. Homeowners rarely get advance notice when that happens, and they often only learn about a problem once regulators publish a case file or a refund program opens.
There are steps homeowners can take on their end regardless of which brand of camera sits above their front door. Turning on two-factor authentication for the camera’s app account adds a second checkpoint beyond a password, so a stolen or guessed password alone cannot open a live feed. Keeping the camera’s firmware updated matters just as much, since manufacturers routinely patch security holes that would otherwise stay open indefinitely. Reusing a password from another account is one of the more common ways outside parties gain entry, so a unique password for the camera app closes off that path. Homeowners should also periodically check which third-party apps, family members or shared accounts still have access to their camera feed and remove any that no longer need it.
None of these steps guarantee a camera maker will handle data responsibly on the back end. What they do is limit how much damage a company’s own security lapse can do once it happens, which is exactly the gap both the Verkada and Ring cases exposed.

Leave a Reply