New York Attorney General Secures $450,000 Settlement Over eufy Home Security Camera Security Concerns
Time 2 Minute Read

New York Attorney General Letitia James announced a $450,000 settlement with three companies distributing eufy home security video cameras—Fantasia Trading LLC, Power Mobile Life LLC and Smart Innovation LLC—following an investigation into the security of their Internet-enabled video products. The settlement follows findings that, in some cases, video streams from eufy cameras were transmitted without end-to-end encryption and active video feeds could be accessed without authentication by individuals with the corresponding URL.

The Office of the Attorney General (OAG) initiated the investigation after a November 2022 disclosure by a security researcher raised concerns about the accuracy of eufy’s marketing claims regarding its security and encryption measures. The researcher’s findings suggested that eufy’s Internet-connected security cameras, video doorbells and smart locks did not fully encrypt video data in transit, despite company assurances that consumer footage would remain private and secure.

The OAG’s investigation confirmed that, in certain circumstances:

  • video data was not protected by end-to-end encryption, leaving portions of the transmission unencrypted;
  • active video streams could be accessed without authentication if an individual had the correct URL;
  • some URLs could be determined without directly obtaining them from a user, increasing the risk of unauthorized access; and
  • the companies had not implemented sufficient security testing procedures, leading to undetected vulnerabilities.

Under the terms of the settlement, the companies must implement enhanced security measures including:

  • developing and maintaining a comprehensive information security program to protect consumer data;
  • implementing secure software development practices, including third-party security testing;
  • maintaining a vulnerability management program with regular penetration testing; and
  • enhancing encryption protocols for video storage and transmission.

This resolution highlights the importance of robust security measures for Internet-connected devices that store and transmit sensitive consumer data. Companies offering such products must ensure that their security practices align with industry standards and that their marketing claims accurately reflect their security capabilities.

You May Also Be Interested In

Time 5 Minute Read

A recent summary judgment order is a reminder that, in insurance coverage disputes, straightforward arguments can still win the day. In a coverage action arising from dozens of underlying personal injury suits, the court adopted a clear, text-based approach to the duty to defend—and ordered the insurer to provide a defense.

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page