A family in the US state of California said they got the scare of a lifetime this past weekend when their smart security cameras began falsely warning of three North Korean intercontinental ballistic missiles headed to the cities of Los Angeles and Chicago, and the state of Ohio. Thankfully, the missile warning was a hoax. Less comforting was the fact that the family’s Nest security cameras had been hacked.
According to a Mercury News report, Laura Lyons and her family were minding their own business on Sunday when they heard a loud noise like an Amber Alert from their living room in Orinda, California. It took a moment for Lyons and her husband to figure out that the alert was coming from their Nest camera, while their eight-year-old son crawled underneath a rug in terror.
“It warned that the United States had retaliated against Pyongyang and that people in the affected areas had three hours to evacuate,” Lyons told the Mercury News. “It sounded completely legit, and it was loud and got our attention right off the bat...It was five minutes of sheer terror and another 30 minutes of trying to figure out what was going on.”
The Lyons family then made several panicked phone calls to emergency services and Nest, and scanned news channels to find that no such attack occurred. While on the phone with Nest, Lyons said she was angered to discover they were the likely victims of a third-party hack and said the company had failed to contact them about a data breach.
This is far from the first time we’ve heard about hacked Nest devices. In December, a family in the US state of Texas was terrified to hear the voice of a hacker via their Nest camera threatening to kidnap their baby. The previous month, a man in the state of Arizona claimed a benevolent hacker notified him through his Nest Cam IQ that his private information had been compromised. One thing these stories have in common is Nest’s customer service recommendation to affected users: Change your passwords and enable two-factor authentication.
The incidents form a compelling argument for better smart home security practices, such as changing logins from factory defaults, but they also sow distrust in smart devices as a whole, which broadly seem all too easily exploitable by good and bad actors alike.
Gizmodo has reached out to Nest for comment about its security practices, as well as for further clarification on its notification policy regarding data breaches. We’ll be sure to update if we hear back. [Mercury News]
Featured image: Nest