Skip to content
MonitorUltra

Is your baby monitor hacked? How to tell, and how to check

· · 8 min

If you are reading this at 2am because the camera moved on its own, start with the checks in the middle of this article. They take about fifteen minutes and they will usually settle the question one way or the other.

Most of the time there is a dull explanation. Cameras have auto-tracking modes, apps have sessions you forgot were open, and partners check the nursery without mentioning it. But the failure mode is real, it has a small number of specific causes, and every one of them is something you can look at yourself tonight.

The short answer

The reliable signs of a compromised baby monitor are a camera that pans or tilts when nobody in the household is using the app, sound coming out of the camera's speaker that nobody in the house sent, settings you did not change, and unfamiliar devices or logins in the vendor's app. To check, review the account's active sessions and shared users, then check your router for port forwarding rules. Almost every real case starts with a reused password.

The signs that actually mean something

The camera moves when nobody is using the app. A motorised camera that pans or tilts while every phone in the house is idle is the single strongest indicator, because moving it requires an active control session. Confirm nobody else in the household is in the app first, then treat it seriously.

A voice, music, or noise from the camera's speaker. Two-way talk is a control feature. If the speaker produces anything you did not send, someone has an audio channel to your child's room.

Settings that changed on their own. The camera's name, its Wi-Fi network, motion zones, recording schedule, or notifications being switched off. Attackers turn off alerts because alerts are how people notice.

Sessions or devices you cannot account for. Most vendor apps list active sessions, logged-in devices, or shared users. An entry you do not recognise is direct evidence.

Emails you did not trigger. Password reset requests, new sign-in notifications, or a confirmation that the account's email address was changed. Attackers change the email so you cannot recover the account.

Being signed out for no reason. Sometimes a sign of a password change you did not make.

The signs that usually mean something else

Being honest about this matters, because the internet is full of pages that treat every oddity as an intrusion.

  • A status LED behaving unexpectedly. Many cameras let the LED be disabled in software, and many blink for firmware updates or network drops. On its own it proves nothing.
  • The camera panning slowly across the room. Auto-tracking and scheduled patrol modes do exactly this. Check whether the model has one and whether it is on.
  • Static, buzzing, or another baby crying. On analogue monitors this is almost always interference or a neighbour's monitor on the same frequency, which is a real privacy problem but a different one.
  • The monitor dropping off the network. Weak Wi-Fi, a congested channel, or a router that reboots overnight. Very common, rarely sinister.
  • The camera restarting itself. Scheduled firmware updates.

How to check, in order

1. Your account, first

Open the vendor's app and find the account or security section. Look for active sessions, logged-in devices, or login history, and check every entry against devices you own. Revoke anything unfamiliar.

Then check the account's email address is still yours, and that the phone number attached to it is still yours.

2. Shared users

Look for a family, guests, or shared access list. Cameras often accumulate these: grandparents, a former childminder, an ex-partner. Remove everyone who does not currently need access. Sharing granted years ago outlives the reason it was granted.

3. Your email account

Search your inbox, and the deleted items, for messages from the vendor. Password resets, new-device sign-ins, and address change confirmations you never saw are the trail. If your email account itself has been compromised, every other check is moot, so secure that first.

Then check whether your email address appears in known data breaches. If it does and you reused that password on the camera account, you have a plausible route without needing any other evidence.

4. Your router

Sign in to your router's admin page and look for two things.

Connected devices. Work through the list. Unknown entries are worth investigating, though modern phones use randomised MAC addresses and cheap smart plugs have inscrutable names, so a device you cannot place is not proof of anything by itself.

Port forwarding and UPnP. This is the more useful check. A port forwarding rule pointing at the camera means that camera is reachable directly from the internet by anyone who finds the address, and there are public search engines that index exactly these devices. If you did not create the rule yourself, UPnP probably created it on the camera's request. Delete the rule. Turn UPnP off unless something you rely on breaks without it.

5. Firmware

Check the camera's firmware version against the vendor's current release. Old firmware is what turns a published vulnerability into your problem. If the vendor has stopped publishing updates for your model, that is worth knowing regardless of what tonight's check finds.

If you find something, do this in this order

The order matters, because doing it the other way round lets the attacker straight back in.

  1. Change the account password, to something unique that is not used anywhere else. Use a password manager. Reusing a password is what makes the account the easy way in.
  2. Turn on two-factor authentication if the vendor supports it. If it does not, note that as a point against the vendor.
  3. Revoke every session and remove every shared user, including ones you recognise. You can re-add the people who still need access afterwards.
  4. Factory reset the camera. This clears any local configuration an attacker may have set, including a changed device password.
  5. Update the firmware before you put it back into service.
  6. Set it up again with the new account password and a device password that is not the one printed on the label.
  7. Change your Wi-Fi password if the camera had a port forwarding rule pointing at it. The camera holds your Wi-Fi credentials, so a compromised camera means a compromised network key.

If you would rather not go through this again, the piece on what actually makes a baby monitor secure covers what to look for before you buy the next one.

Why default passwords keep coming up

Two routes exist into a monitor, and they are not equally difficult.

The first is the account. Credentials leaked from unrelated services are tried automatically, in bulk, against every login form worth attacking. This requires no skill and no proximity, and it works whenever someone has reused a password. It is the cheap route, which is why it is the common one.

The second is the device itself, reachable from the internet through a forwarded port or an exposed management interface, still running the admin password printed on its own label. Cameras that were shipped with a fixed default and never prompted the owner to change it are the classic case.

Neither route involves anyone breaking encryption. Both are solved by a unique password and by not exposing the device directly to the internet.

The part you cannot fix afterwards

Changing a password stops future access. It does nothing about footage that has already been uploaded.

A monitor that stores clips on a vendor's server has a much larger exposed surface than one that stores nothing. That footage is reachable by your account, by the vendor's staff and systems, by whatever subprocessors the vendor uses, and by anyone who compromises any of those. It persists for as long as the vendor's retention policy says, and their retention policy can change without you noticing. A breach at the vendor two years from now can expose recordings made tonight.

This is the argument for asking a different question before you buy: not how well the footage is protected, but whether it is kept at all. I have written that argument out in full in a baby monitor that records nothing, and the related case for keeping the analysis on the device is in on-device AI versus cloud AI.

Analogue monitors are a separate problem

Old analogue monitors, the 49 MHz and 900 MHz ones, cannot be hacked over the internet because they are not on it. They broadcast unencrypted radio in the clear, which anyone nearby with a compatible receiver can pick up. There is no password to change and no firmware to update. The exposure is limited to radio range, but within that range it is total.

DECT monitors encrypt the link and are a reasonable choice if you want a monitor with no internet connection at all.

Where MonitorUltra sits in this

MonitorUltra runs on two Apple devices you already own, pairs by scanning a QR code on the baby unit, and streams encrypted in transit through a LiveKit relay so the parent unit can be anywhere. It does not record. There is no clip history and nothing stored on a server, so there is no archive that a future breach could expose.

That removes one category of risk. It does not remove the others, and the checks above still apply to any account you hold. Use a unique password, and remove people from family sharing when they no longer need access.

Frequently asked questions

Can someone hack a baby monitor that has no internet connection? Not remotely. Analogue monitors can be received by anyone within radio range because they broadcast unencrypted. DECT monitors encrypt the link and require physical proximity to attack.

Does a moving camera definitely mean I have been hacked? No. Auto-tracking and patrol modes move the camera on their own, and another person in the household may be in the app. Rule both out before anything else.

Will a factory reset fix a compromised camera? It clears local configuration, but on its own it is not enough. If the attacker has your account credentials they can simply add the camera again. Change the account password first, revoke sessions, then reset.

Should I report it? If you have evidence of unauthorised access, report it to the vendor, and to your national cybercrime reporting body if someone spoke through the camera. Keep screenshots of the session log before you revoke anything, because revoking clears the evidence.

How do I know whether my camera is exposed to the internet? Check your router for port forwarding rules pointing at it, and check whether UPnP is enabled. Those two settings are what make a camera on your home network reachable from outside it.