← Smart Home
F

Eufy Security Cameras

Fail
Anker · 🇨🇳 China · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Eufy Security
Manufacturer: Anker

⚠️ The bottom line

Eufy sold millions of cameras on a single promise: your footage stays home, period. The Verge proved it was uploading face thumbnails to Amazon's cloud without telling anyone. Then they found something worse — anyone could watch your live camera feed through a simple web URL with zero authentication. No password needed. Just your camera's serial number in the link. Anker denied it, then went silent for weeks, then finally admitted it was true. Eufy promised "military-grade encryption" on every product page. In reality, anyone with VLC media player and your camera's serial number could watch your living room in real time. No password. No encryption. Just a plain URL streaming unprotected video of your home to anyone who asked for it.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
🇺🇸 United States (data storage)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
B
Parent company: Anker (Eufy)
Uploaded footage to cloud despite "local only" claims
1 structural risks · 8 products →
Spying
4/4 EXTREME
Is someone spying on me?
Data Sharing
0/4 N/A
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
12Contradictions
10Critical
2High
0Medium
13Sources
Findings by concern
Spying 4/4 EXTREME 4 findings
⚠️ criticalmarketing vs observed
Eufy sold millions of cameras on a single promise: your footage stays home, period. The Verge proved it was uploading face thumbnails to Amazon's cloud without telling anyone. Then they found something worse — anyone could watch your live camera feed through a simple web URL with zero authentication. No password needed. Just your camera's serial number in the link. Anker denied it, then went silent for weeks, then finally admitted it was true.

What they claim: Eufy marketed cameras with the tagline "Nobody but you has access to your data" and "Everything is stored locally" — promising footage never leaves the device.

What we found: The Verge proved in November 2022 that Eufy cameras were uploading facial recognition thumbnails to AWS cloud servers without user consent. Worse, camera feeds could be accessed remotely via a URL with no authentication — anyone with the link could watch live footage. The URLs used a predictable pattern based on device serial numbers.

⚠️ criticalpolicy vs observed
Eufy said facial recognition happens entirely on a chip inside your camera — nothing leaves your house. A security researcher caught it red-handed uploading tagged photos of faces to Amazon's cloud. Even after you deleted them in the app, the face images stayed on Amazon's servers. Your face, labeled with your name, sitting on a cloud server Eufy swore didn't exist.

What they claim: Eufy's privacy policy and marketing stated facial recognition was processed "on-device" using an embedded AI chip, with no cloud component.

What we found: Security researcher Paul Moore discovered Eufy was uploading facial recognition thumbnails to AWS cloud servers, tagged with user-identifiable information. These images persisted on AWS even after being "deleted" from the Eufy app. The researcher demonstrated this by monitoring network traffic from a Eufy Doorbell Dual.

⚠️ criticalmarketing vs observed
Eufy sold millions of cameras on a single promise: your footage stays home, period. The Verge proved it was uploading face thumbnails to Amazon's cloud without telling anyone. Then they found something worse — anyone could watch your live camera feed through a simple web URL with zero authentication. No password needed. Just your camera's serial number in the link. Anker denied it, then went silent for weeks, then finally admitted it was true.

What they claim: Eufy marketed cameras with the tagline "Nobody but you has access to your data" and "Everything is stored locally" — promising footage never leaves the device.

What we found: The Verge proved in November 2022 that Eufy cameras were uploading facial recognition thumbnails to AWS cloud servers without user consent. Worse, camera feeds could be accessed remotely via a URL with no authentication — anyone with the link could watch live footage. The URLs used a predictable pattern based on device serial numbers.

⚠️ criticalpolicy vs observed
Eufy said facial recognition happens entirely on a chip inside your camera — nothing leaves your house. A security researcher caught it red-handed uploading tagged photos of faces to Amazon's cloud. Even after you deleted them in the app, the face images stayed on Amazon's servers. Your face, labeled with your name, sitting on a cloud server Eufy swore didn't exist.

What they claim: Eufy's privacy policy and marketing stated facial recognition was processed "on-device" using an embedded AI chip, with no cloud component.

What we found: Security researcher Paul Moore discovered Eufy was uploading facial recognition thumbnails to AWS cloud servers, tagged with user-identifiable information. These images persisted on AWS even after being "deleted" from the Eufy app. The researcher demonstrated this by monitoring network traffic from a Eufy Doorbell Dual.

Security 4/4 EXTREME 6 findings
⚠️ criticalmarketing vs observed
Eufy promised "military-grade encryption" on every product page. In reality, anyone with VLC media player and your camera's serial number could watch your living room in real time. No password. No encryption. Just a plain URL streaming unprotected video of your home to anyone who asked for it.

What they claim: Eufy claimed all footage was "end-to-end encrypted" with "military-grade encryption" and only accessible to the device owner.

What we found: Security researcher Paul Moore and The Verge demonstrated that Eufy camera streams could be accessed via VLC media player using an unencrypted URL. No authentication token, no encryption in transit. The stream URLs followed a predictable pattern, meaning any camera could potentially be accessed if its serial number was known.

⚠️ criticalmarketing vs observed
When caught, Anker's PR team looked The Verge straight in the eye and said "it is not possible" to watch feeds via VLC. The Verge was literally watching a feed via VLC at that moment. Anker denied it for weeks. Finally, months later, the CEO admitted the whole thing — years of "end-to-end encrypted" marketing was false. They quietly updated their website to remove the claim.

What they claim: After initial reports, Anker's head of communications told The Verge: "I can confirm that it is not possible to start a stream and watch live footage using a third-party player such as VLC."

What we found: The Verge's own journalists reproduced the exact attack Anker denied was possible, watching live Eufy camera feeds through VLC. After weeks of silence and denials, Anker's CEO finally admitted in a statement that the company had made mistakes and that streams were not end-to-end encrypted by default, contradicting years of marketing claims.

⚠️ criticalmarketing vs observed
Eufy's entire sales pitch was "we're the private one." Mozilla investigated and slapped them with a Privacy Not Included warning — their harshest label. The brand built entirely on the promise of privacy turned out to be less private than the competitors it was trying to replace. People bought Eufy specifically because they didn't trust Ring. They got the same cloud uploads with none of the honesty.

What they claim: Eufy markets itself as the privacy-first alternative to Ring and Nest, with prominent "No Monthly Fee" and "Local Storage" messaging designed to attract privacy-conscious consumers.

What we found: Mozilla's *Privacy Not Included* project awarded Eufy cameras a "Privacy Not Included" warning label, citing the cloud upload scandal, unencrypted streams, and Anker's pattern of deception. The report noted that Eufy's entire brand was built on a privacy promise that was systematically violated.

⚠️ criticalmarketing vs observed
Eufy's entire sales pitch was "we're the private one." Mozilla investigated and slapped them with a Privacy Not Included warning — their harshest label. The brand built entirely on the promise of privacy turned out to be less private than the competitors it was trying to replace. People bought Eufy specifically because they didn't trust Ring. They got the same cloud uploads with none of the honesty.

What they claim: Eufy markets itself as the privacy-first alternative to Ring and Nest, with prominent "No Monthly Fee" and "Local Storage" messaging designed to attract privacy-conscious consumers.

What we found: Mozilla's *Privacy Not Included* project awarded Eufy cameras a "Privacy Not Included" warning label, citing the cloud upload scandal, unencrypted streams, and Anker's pattern of deception. The report noted that Eufy's entire brand was built on a privacy promise that was systematically violated.

⚡ highmarketing vs observed
Eufy promised "military-grade encryption" on every product page. In reality, anyone with VLC media player and your camera's serial number could watch your living room in real time. No password. No encryption. Just a plain URL streaming unprotected video of your home to anyone who asked for it.

What they claim: Eufy claimed all footage was "end-to-end encrypted" with "military-grade encryption" and only accessible to the device owner.

What we found: Security researcher Paul Moore and The Verge demonstrated that Eufy camera streams could be accessed via VLC media player using an unencrypted URL. No authentication token, no encryption in transit. The stream URLs followed a predictable pattern, meaning any camera could potentially be accessed if its serial number was known.

⚡ highmarketing vs observed
When caught, Anker's PR team looked The Verge straight in the eye and said "it is not possible" to watch feeds via VLC. The Verge was literally watching a feed via VLC at that moment. Anker denied it for weeks. Finally, months later, the CEO admitted the whole thing — years of "end-to-end encrypted" marketing was false. They quietly updated their website to remove the claim.

What they claim: After initial reports, Anker's head of communications told The Verge: "I can confirm that it is not possible to start a stream and watch live footage using a third-party player such as VLC."

What we found: The Verge's own journalists reproduced the exact attack Anker denied was possible, watching live Eufy camera feeds through VLC. After weeks of silence and denials, Anker's CEO finally admitted in a statement that the company had made mistakes and that streams were not end-to-end encrypted by default, contradicting years of marketing claims.

Honesty 4/4 EXTREME 2 findings
⚠️ criticalpolicy vs observed
On May 17, 2023, Eufy users logged into their accounts and found themselves watching strangers' cameras. They could pan, tilt, and zoom cameras inside other people's homes. They could see names, addresses, and saved clips. Eufy blamed a "software bug during a server upgrade." The company that promised nobody else could ever see your footage accidentally gave random strangers full control of your cameras.

What they claim: Eufy's privacy commitment stated users have "complete control" over who can access their footage, with data accessible only through the Eufy app with authenticated accounts.

What we found: The Eufy web portal (my.eufylife.com) was found to have logged users into other people's accounts, showing strangers' camera feeds, personal information, and home addresses. Users reported seeing live feeds from other people's cameras and being able to pan/tilt/zoom cameras in strangers' homes.

⚠️ criticalpolicy vs observed
On May 17, 2023, Eufy users logged into their accounts and found themselves watching strangers' cameras. They could pan, tilt, and zoom cameras inside other people's homes. They could see names, addresses, and saved clips. Eufy blamed a "software bug during a server upgrade." The company that promised nobody else could ever see your footage accidentally gave random strangers full control of your cameras.

What they claim: Eufy's privacy commitment stated users have "complete control" over who can access their footage, with data accessible only through the Eufy app with authenticated accounts.

What we found: The Eufy web portal (my.eufylife.com) was found to have logged users into other people's accounts, showing strangers' camera feeds, personal information, and home addresses. Users reported seeing live feeds from other people's cameras and being able to pan/tilt/zoom cameras in strangers' homes.

Sources