Is a baby monitor app safe? Hacking, the cloud, and what "no account" really means

Baby monitors do get hacked, but almost never the way the movies show it. In the documented cases somebody logged in with a reused password, a maker's cloud mixed up accounts, or a camera sat on the internet with its factory password. Here is what happened, what a local-only app changes, and what is still up to you.

Updated
In short
  • Most real incidents went through a cloud account or the maker's servers, not your Wi-Fi: 55,000 Ring accounts opened with reused passwords (2017–2018), 13,000 Wyze users shown strangers' thumbnails after a server mix-up (February 2024), Eufy admitting in January 2023 that its web streams weren't encrypted.
  • The rest were cameras left on the internet with a factory password. The Mirai botnet took over some 380,000 devices in 2016 with a list of just 62 default logins.
  • A "local only" app removes the account and the servers, so there is nothing for a stranger to log in to. Your router password, camera firmware and phone lock are still yours to handle.
  • Mamoon has no cloud and no account; video stays on your home Wi-Fi and cry detection runs on the phone. Away from home it uses Tailscale, an end-to-end encrypted VPN. Dormi, Cloud Baby Monitor and Baby Monitor 3G work locally too.
  • Seven steps cover nearly everything: router password and WPA2/WPA3, camera updates, no default passwords, 2FA on cloud accounts, UPnP off, care with guest networks, and an old phone that is updated, signed out and locked.

Have baby monitors and home cameras really been hacked?

Yes. What is striking is how ordinary the methods were: somebody logged in, or a company's own systems got it wrong. Incidents checked on September 29, 2026:

WhenWhoWhat happenedHow
2016Mirai botnetSome 380,000 cameras, DVRs and routers taken over for attacks62 common factory logins tried on devices reachable from the internet
2017–2018 (FTC order May 2023)Ring (Amazon)About 55,000 US accounts opened by strangers. Separately, an employee viewed thousands of women's videos for monthsCredential stuffing with passwords leaked elsewhere; the FTC says Ring offered no multi-factor authentication until 2019
May 2019 – Feb 2020iBaby M6SAny camera's stored alert clips, plus owners' emails and locations, could be fetched from the maker's cloudCloud keys baked into the camera and an ID bug; fixed in March 2020 after Bitdefender published
Nov 2022 – Jan 2023Eufy (Anker)"Local storage" cameras uploaded thumbnails to the cloud; web streams opened unencrypted in a media player. Anker admitted it and moved to encrypted WebRTCVendor design and marketing, not a break-in
Sept 8, 2023WyzeAbout 2,300 web-viewer users could see 10 other people's cameras for about 40 minutesA wrong caching setting during a server deployment
Feb 16, 2024WyzeAbout 13,000 users received thumbnails from strangers' cameras; 1,504 tapped them. No live videoAfter an AWS outage, a caching library mixed up device and user IDs

Each company fixed its problem; none of this means their current products are unsafe. The pattern is the point: the weak spot was almost always the account, the maker's servers, or a device open to the internet.

How does a baby monitor actually get hacked?

Six doors, roughly in order of how often they were used:

What does "local only, no account" change, and what doesn't it?

A local-only app sends video from the camera to your phone over your own Wi-Fi and stops there. With no account, there is nothing to credential-stuff. With no servers holding your video, an outage can't show your nursery to a stranger and an employee can't browse it. That closes the first two doors, the ones behind the biggest cases.

The other doors are in your house: the router, the camera's firmware, the phone you watch on. "Local" puts them in your hands, which is the point.

The trade-off: a cloud app gives you video at work with no setup, because the maker's servers do the connecting. A local app asks you to set up a VPN for that. Both are reasonable; just know which one you are choosing.

How Mamoon handles it

There is no Mamoon account and no Mamoon cloud. Video goes from the baby phone or camera to the parent phone over your home Wi-Fi and works with the internet down. Cry detection runs on the phone itself, so no audio leaves it. There are no recordings or cloud clips to leak; the morning overview stays on your phone.

Away from home, Mamoon uses Tailscale, a free VPN built on WireGuard. Tailscale documents that traffic is end-to-end encrypted between your devices and that its relay servers only handle already-encrypted packets: the private keys never leave your phones, so a relay can't read the video. You install it on both phones, or on a home server for a Wi-Fi camera.

Mamoon is not the only app that works this way. Dormi (Android only) advertises encrypted streaming with no ads and no tracking. Cloud Baby Monitor uses only your home Wi-Fi by default and needs no internet unless you turn on its Unlimited Range. Baby Monitor 3G requires no account and encrypts the connection; it works over Wi-Fi or cellular. Bibino says plainly that communication goes through its servers and Premium recordings are kept there for 21 days, which is what gives it range with no setup. They draw the line in different places.

Is it safe to use an old phone as a baby monitor?

In one way an old phone is safer than a Wi-Fi camera: no port on your router, no maker cloud of its own. The risks are the phone's. One too old for security updates has known, published holes; one still signed in to your email and photos is a trove for whoever picks it up. Update it as far as it goes, remove accounts it doesn't need, set a screen lock. Setup is in the old phone guide.

The checklist

  1. Lock down the router. Set Wi-Fi encryption to WPA2 or WPA3 and change both passwords: the Wi-Fi password and the router's admin login. The FTC's home Wi-Fi guide puts these first.
  2. Update the camera's firmware. Turn on automatic updates if offered, as the UK's NCSC advises. Since April 2024, UK law requires makers to publish how long they will provide updates; read that number before you buy.
  3. Change every default password. The camera's, the router's, and the Camera Account on a Tapo. Mirai's whole toolkit was a list of 62 factory logins.
  4. Turn on two-factor authentication on any cloud account you keep: the camera maker's, your Apple or Google account, your email. Reused passwords opened 55,000 Ring accounts.
  5. Turn off UPnP and port forwarding on the router unless you know exactly why you need them; CISA and the NCSC both say so. To reach a camera from outside, use a VPN such as Tailscale instead of an open port.
  6. Think before using a guest network. A guest or "IoT" network keeps the camera away from your laptops, but many guest networks isolate devices from each other, so a local-only app on your phone may not see the camera. Put both on the same network, or turn client isolation off for that one.
  7. Prepare the old phone. Install every update it can still get, remove accounts it doesn't need, set a PIN or fingerprint, and keep it on a charger away from the crib. If it ever leaves the house, erase it first.

When a cloud monitor is the better choice

Frequently asked questions

Can a Wi-Fi baby monitor be hacked?

It can, and the documented ways are mundane: a reused password on the maker's account, a bug on the maker's servers, or a camera reachable from the internet with a factory password. Unique passwords, two-factor authentication, updates and no open ports cover nearly every real case.

Does Mamoon send anything to a server?

No account, no cloud, no recordings. Video and sound go over your home Wi-Fi from the camera to your phone, and cry detection runs on the phone. The website's own data handling is in the privacy notice.

Does a Tapo camera still talk to TP-Link if I watch it in Mamoon?

Yes, unless you block it. TP-Link states that first setup, remote viewing, sharing and clock sync use its cloud, and that live viewing works locally once the camera is set up. Mamoon reads the video straight from the camera over your Wi-Fi; the camera's own cloud connection is separate and yours to allow or block on the router.

Is Tailscale safe for watching the baby from outside?

Tailscale is a WireGuard VPN. Its documentation says traffic is end-to-end encrypted between your devices and its relays can't decrypt it because the keys never leave your phones. Your Tailscale login is an account, though, so protect it with two-factor authentication.

Sources

  1. FTC press release, May 31, 2023: Ring, 55,000 hacked accounts, MFA only from 2019, employee video access (all sources opened September 29, 2026)
  2. Engadget: Wyze incident of February 16, 2024, 13,000 users, 1,504 taps, caching library and CBS News with Wyze's statement
  3. Wyze forum: Web View service advisory, September 8, 2023 (2,300 users, 10 affected, caching setting)
  4. TidBITS, December 2, 2022: Eufy cameras uploading thumbnails to the cloud and gHacks, February 1, 2023: Anker admits streams weren't end-to-end encrypted
  5. Bitdefender Labs, February 26, 2020: iBaby M6S vulnerabilities, fixed March 2020
  6. CISA alert, October 14, 2016: Mirai, 62 default logins, 380,000 devices; change defaults, disable UPnP, update
  7. FTC: How to secure your home Wi-Fi network (WPA2/WPA3, two passwords, UPnP, guest network)
  8. UK NCSC: Smart security cameras and baby monitors, using them safely (default password, automatic updates, UPnP and port forwarding) and NCSC: Smart devices in the home (2-step verification)
  9. UK government: PSTI product security regime, in force April 29, 2024 (no universal default passwords, published update period)
  10. TP-Link community (moderator answer): what Tapo cameras do with and without the internet and TP-Link FAQ: RTSP and ONVIF on the local network
  11. Tailscale: encryption (WireGuard, end-to-end) and Tailscale: DERP relays can't decrypt traffic
  12. Dormi: encrypted streaming, no ads, no tracking
  13. Cloud Baby Monitor: home Wi-Fi by default, no internet required, Unlimited Range over the internet
  14. Baby Monitor 3G on the App Store: Wi-Fi or cellular, encrypted connection, no account required
  15. Bibino FAQ: communication through its servers, Premium recordings kept 21 days
  16. Apple: before you sell or give away an iPhone and Google: set a screen lock on Android

Spotted a mistake or an outdated figure? Write to [email protected].

A video baby monitor you already own

Mamoon turns an old phone or a Wi-Fi camera into a baby monitor. It recognizes a cry by itself, wakes you even with the nursery sound muted, and the picture never leaves your Wi-Fi.

Want to know when Mamoon is out?

30 days free, then $3.99 a month or $24.99 a year · coming soon to Google Play and the App Store · How Mamoon works