Eufy sold millions of cameras on a single promise: your footage stays home, period. The Verge proved it was uploading face thumbnails to Amazon's cloud without telling anyone. Then they found something worse — anyone could watch your live camera feed through a simple web URL with zero authentication. No password needed. Just your camera's serial number in the link. Anker denied it, then went silent for weeks, then finally admitted it was true. Eufy promised "military-grade encryption" on every product page. In reality, anyone with VLC media player and your camera's serial number could watch your living room in real time. No password. No encryption. Just a plain URL streaming unprotected video of your home to anyone who asked for it.
What they claim: Eufy marketed cameras with the tagline "Nobody but you has access to your data" and "Everything is stored locally" — promising footage never leaves the device.
What we found: The Verge proved in November 2022 that Eufy cameras were uploading facial recognition thumbnails to AWS cloud servers without user consent. Worse, camera feeds could be accessed remotely via a URL with no authentication — anyone with the link could watch live footage. The URLs used a predictable pattern based on device serial numbers.
What they claim: Eufy's privacy policy and marketing stated facial recognition was processed "on-device" using an embedded AI chip, with no cloud component.
What we found: Security researcher Paul Moore discovered Eufy was uploading facial recognition thumbnails to AWS cloud servers, tagged with user-identifiable information. These images persisted on AWS even after being "deleted" from the Eufy app. The researcher demonstrated this by monitoring network traffic from a Eufy Doorbell Dual.
What they claim: Eufy marketed cameras with the tagline "Nobody but you has access to your data" and "Everything is stored locally" — promising footage never leaves the device.
What we found: The Verge proved in November 2022 that Eufy cameras were uploading facial recognition thumbnails to AWS cloud servers without user consent. Worse, camera feeds could be accessed remotely via a URL with no authentication — anyone with the link could watch live footage. The URLs used a predictable pattern based on device serial numbers.
What they claim: Eufy's privacy policy and marketing stated facial recognition was processed "on-device" using an embedded AI chip, with no cloud component.
What we found: Security researcher Paul Moore discovered Eufy was uploading facial recognition thumbnails to AWS cloud servers, tagged with user-identifiable information. These images persisted on AWS even after being "deleted" from the Eufy app. The researcher demonstrated this by monitoring network traffic from a Eufy Doorbell Dual.
What they claim: Eufy claimed all footage was "end-to-end encrypted" with "military-grade encryption" and only accessible to the device owner.
What we found: Security researcher Paul Moore and The Verge demonstrated that Eufy camera streams could be accessed via VLC media player using an unencrypted URL. No authentication token, no encryption in transit. The stream URLs followed a predictable pattern, meaning any camera could potentially be accessed if its serial number was known.
What they claim: After initial reports, Anker's head of communications told The Verge: "I can confirm that it is not possible to start a stream and watch live footage using a third-party player such as VLC."
What we found: The Verge's own journalists reproduced the exact attack Anker denied was possible, watching live Eufy camera feeds through VLC. After weeks of silence and denials, Anker's CEO finally admitted in a statement that the company had made mistakes and that streams were not end-to-end encrypted by default, contradicting years of marketing claims.
What they claim: Eufy markets itself as the privacy-first alternative to Ring and Nest, with prominent "No Monthly Fee" and "Local Storage" messaging designed to attract privacy-conscious consumers.
What we found: Mozilla's *Privacy Not Included* project awarded Eufy cameras a "Privacy Not Included" warning label, citing the cloud upload scandal, unencrypted streams, and Anker's pattern of deception. The report noted that Eufy's entire brand was built on a privacy promise that was systematically violated.
What they claim: Eufy markets itself as the privacy-first alternative to Ring and Nest, with prominent "No Monthly Fee" and "Local Storage" messaging designed to attract privacy-conscious consumers.
What we found: Mozilla's *Privacy Not Included* project awarded Eufy cameras a "Privacy Not Included" warning label, citing the cloud upload scandal, unencrypted streams, and Anker's pattern of deception. The report noted that Eufy's entire brand was built on a privacy promise that was systematically violated.
What they claim: Eufy claimed all footage was "end-to-end encrypted" with "military-grade encryption" and only accessible to the device owner.
What we found: Security researcher Paul Moore and The Verge demonstrated that Eufy camera streams could be accessed via VLC media player using an unencrypted URL. No authentication token, no encryption in transit. The stream URLs followed a predictable pattern, meaning any camera could potentially be accessed if its serial number was known.
What they claim: After initial reports, Anker's head of communications told The Verge: "I can confirm that it is not possible to start a stream and watch live footage using a third-party player such as VLC."
What we found: The Verge's own journalists reproduced the exact attack Anker denied was possible, watching live Eufy camera feeds through VLC. After weeks of silence and denials, Anker's CEO finally admitted in a statement that the company had made mistakes and that streams were not end-to-end encrypted by default, contradicting years of marketing claims.
What they claim: Eufy's privacy commitment stated users have "complete control" over who can access their footage, with data accessible only through the Eufy app with authenticated accounts.
What we found: The Eufy web portal (my.eufylife.com) was found to have logged users into other people's accounts, showing strangers' camera feeds, personal information, and home addresses. Users reported seeing live feeds from other people's cameras and being able to pan/tilt/zoom cameras in strangers' homes.
What they claim: Eufy's privacy commitment stated users have "complete control" over who can access their footage, with data accessible only through the Eufy app with authenticated accounts.
What we found: The Eufy web portal (my.eufylife.com) was found to have logged users into other people's accounts, showing strangers' camera feeds, personal information, and home addresses. Users reported seeing live feeds from other people's cameras and being able to pan/tilt/zoom cameras in strangers' homes.