Ring LLC, the home security camera company owned by Amazon, agreed to pay $5.8 million in consumer redress to resolve findings that it had failed to implement adequate access controls preventing its own employees and contractors from accessing customers' private home video footage without authorization, and had failed to implement basic security measures including multi-factor authentication that would have prevented credential-stuffing attacks from allowing outside actors to take over customers' Ring cameras — in some cases using hijacked cameras to harass, stalk, and make racist and obscene statements to people inside customers' homes.DOCUMENTED
Ring markets its cameras specifically on the premise that they give homeowners security and awareness — the ability to see what is happening at their home when they are away, and the confidence that their private spaces are monitored only by them or those they choose to share access with. The combination of employee privacy violations and the security failures that enabled outside attackers to access those same feeds directly contradicted Ring's core product promise and created the opposite of security for affected customers.DOCUMENTED
- Ring employees and contractors accessed customers' private home and bedroom camera footage for personal viewing without authorization
- One employee reviewed thousands of video clips belonging to female customers over a multi-month period without any business justification
- Ring did not implement multi-factor authentication for customer accounts, enabling credential-stuffing attacks that gave attackers access to live camera feeds
- Compromised cameras were used by outside attackers to harass and communicate with customers — including children — through the two-way audio feature
- $5.8 million in consumer redress and a comprehensive consent order requiring specific security and privacy program measures
The Employee Access Problem
Ring's internal access control systems did not adequately restrict employee and contractor access to customer video footage. Employees whose job functions did not require access to customers' private video were able to view that footage using internal tools that should have been limited to personnel with legitimate operational needs — such as customer support staff assisting with specific reported issues. Without role-based access controls limiting video access to personnel with a documented need, the system functioned as an unrestricted window into customers' private lives for anyone at Ring who chose to look.DOCUMENTED
Investigators found specific documented instances of employees accessing customer footage for personal reasons — in the most egregious case, an employee who worked in Ring's Ukraine operations center reviewed thousands of video clips belonging to female customers who had cameras in their bedrooms or other private spaces, without any business purpose for the access. The access was not detected by Ring's internal monitoring systems for months, indicating that the anomalous access pattern — large volumes of footage accessed without associated customer service interactions — was not being flagged for review.DOCUMENTED
The Credential-Stuffing Vulnerability
Ring did not require or offer multi-factor authentication for customer accounts during the period covered by the investigation — a basic security measure that prevents attackers who obtain a user's username and password from accessing the account without also possessing a second authentication factor. Credential-stuffing attacks — in which attackers use large lists of username and password combinations obtained from other data breaches to attempt access at multiple services — are highly effective against accounts that rely solely on passwords, because many users reuse passwords across services.REVIEWED
The absence of multi-factor authentication meant that attackers who obtained Ring account credentials through credential-stuffing or other means had immediate, unrestricted access to the customer's live camera feeds and historical footage. In documented cases, this access was used for harassment — attackers spoke through Ring cameras' two-way audio features to customers, in some cases directing racial slurs and sexual comments at adults and children in the home. The attacks were deeply distressing to the families affected and were entirely preventable with widely available authentication technology that Ring had not implemented.DOCUMENTED
Families who bought Ring cameras to feel safer in their homes found that their bedrooms and living rooms were accessible not only to Ring's own employees but to outside attackers — who spoke to their children through the camera's speaker using language no one in the home should have heard.
Home Camera Privacy and Security Expectations
Home security cameras are a particularly sensitive category of consumer device because they are frequently placed in intimate spaces — bedrooms, nurseries, children's rooms — where the expectation of privacy is strongest. When customers place cameras in their homes, they reasonably expect that access to the resulting footage is limited to themselves and those they explicitly authorize. A security company that sells cameras specifically on the premise of giving homeowners control over their security bears a heightened obligation to ensure that both its own employees and outside actors are prevented from accessing footage the homeowner did not intend to share.REVIEWED
The consent order requires Ring to implement role-based access controls limiting employee access to customer footage to personnel with documented business needs, to require multi-factor authentication for all customer accounts, to implement anomaly detection for unusual patterns of employee access to customer data, and to delete customer footage that is no longer needed for the service's operation rather than retaining it indefinitely. The $5.8 million in consumer redress was directed to victims of the camera compromises — customers whose accounts were accessed by outside attackers during the credential-stuffing attack period.DOCUMENTED
Securing Your Home Security Cameras
Consumers who use Ring or other internet-connected home security cameras should take several immediate steps to secure their accounts and devices. Enable two-factor authentication if the camera app offers it — this prevents credential-stuffing attacks from succeeding even when an attacker has obtained the account password from another source. Use a unique, strong password for the camera app account that is not reused from any other service. Regularly review which devices and third-party apps are connected to the camera account and remove any that are not actively needed. Consider where cameras are placed — cameras should generally not be placed in rooms where people have a reasonable expectation of complete privacy, like bedrooms or bathrooms, because those placements create the greatest potential harm if the camera is compromised either by company insiders or outside attackers. Review the camera manufacturer's privacy policy to understand who at the company can access the video footage and under what conditions.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.