The signs a smart home device has been interfered with
Smart home hardware is unusually bad at telling you when something is wrong. There is no alert, no scan result, often not even a log you can read. What there is instead is a handful of behaviours that do not quite make sense, and one page in your router that lists everything currently connected. This is how these devices actually get reached, what the early signs look like, and what monitoring is realistic in a house rather than a data centre.
The facts behind the checks
- CISA: put smart home and IoT devices on the guest network ‘if internet access is the only thing they require’ — this prevents device discovery onto the main network.
- CISA: default router credentials ‘may be publicly available’; the router password should be long, random and unique.
- CISA on firmware: ‘Routine updates will protect you against known vulnerabilities.’
- CISA: ‘Disable Wi-Fi Protected Setup (WPS)’ — it increases the chance of unauthorised network access.
- Report device intrusion and spyware to the FBI at IC3.gov; report a cyber incident to CISA at cisa.gov/report or 1-844-729-2472.
How these devices get reached
Three routes account for most of it. The first is the account rather than the device: someone gets into the app account that controls the camera, usually with a password reused from a service that was breached. Nothing is compromised on your network at all — they simply log in.
The second is the device’s own software. A known flaw in firmware that was never updated, on a device sitting on the same network as everything else. CISA’s point about routine updates protecting against known vulnerabilities applies as much to a doorbell as to a laptop, but doorbells rarely nag you.
The third is the network itself: default router credentials that were never changed and, as CISA notes, may be publicly available; or Wi-Fi Protected Setup left enabled, which CISA says increases the likelihood of unauthorised access.
What gives it away
- A device that appears on your router’s connected-clients list and does not match anything you own.
- A camera or speaker whose activity light comes on when nobody is using it, or which reports viewing sessions you did not start.
- Settings that revert or change on their own: a camera’s motion zones redrawn, a smart lock’s access schedule altered, a device renamed.
- Notifications about a login to the controlling app from a location or device you do not recognise, or a password reset email you did not request.
- Router settings you did not touch — remote management switched on, a different DNS server, an unfamiliar administrator account.
- A device that has stopped responding to its own app while apparently still being online, which occasionally indicates someone else has taken control of it.
If it has already happened
- Start with the account, not the device. Change the password on the controlling app to something long and unique, enable the strongest second factor it offers, and sign out all other sessions.
- Check the account’s recovery settings — email address, phone number, any additional users or shared access that has been granted.
- Disconnect the suspect device from Wi-Fi, then factory-reset it and set it up again from scratch rather than trying to repair the existing configuration.
- Update the device’s firmware as part of the rebuild, and turn on automatic updates if the manufacturer offers them.
- Change your router’s administrator password and your Wi-Fi passwords, confirm remote management is off, disable WPS, and check the connected-devices list once everything is back on.
- If the device was on your main network, move it to the guest network as part of putting it back, per CISA’s instruction.
Where to report it
Device intrusion, spyware and stalkerware are reportable to the FBI’s Internet Crime Complaint Center at IC3.gov. CISA takes cyber incident reports at cisa.gov/report, at Central@cisa.dhs.gov, or on 1-844-729-2472.
If the compromise led to fraud, add a report at ReportFraud.ftc.gov. If it led to identity theft, IdentityTheft.gov produces a personalised recovery plan and pre-filled letters to send to businesses and credit bureaus.
Reporting a smart doorbell feels disproportionate. It is not: these reports are how the pattern across many households becomes visible.
The monitoring that is realistic at home
You are not going to run intrusion detection in a hallway cupboard, and you do not need to. Three habits cover most of the ground.
Look at the router’s list of connected devices every few months and make sure you can name everything on it. This is the single most informative page in a home network, and almost nobody opens it.
Read the notifications the apps already send you. Login alerts, new-device alerts and shared-access changes are the closest thing to a security log these products offer, and they are usually switched on by default and then ignored.
Keep the separation in place so that a device you cannot monitor cannot see the devices that matter. CISA’s guest-network instruction is a monitoring strategy as much as a preventive one: it means an unfamiliar device on the main network is genuinely unexpected, rather than one of thirty things you half-recognise.
Sources: CISA Project Upskill, Module 5 · FTC — how to secure your home Wi-Fi network · FBI Internet Crime Complaint Center · CISA — report a cyber incident · FTC IdentityTheft.gov
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.