Miljan Zivkovic

For parents, keeping children safe is not only instinctive but a priority. We
babyproof the house, we check the car seat twice, we wake up in the middle of the
night at the smallest sound.

As technology has evolved, it also offered a promise to help parents watch over our kids even when we are not in the same room as them.

Throughout the different stages of kids’ lives, parents now rely on different technology to help keep kids safe. This tech now includes trackers, location-sharing apps and parental control apps. But at the earliest stages of our kids’ lives, we rely on baby monitors.

Monitors allow parents to keep an eye on babies without having to be in the same room. The first model was the Zenith Radio Nurse, released on sale in 1938.

More recent products have many advanced features, including contactless breathing and vital signs monitoring, AI-powered sleep analytics, cry and sound analysis, and environmental monitoring. However, these new levels of functionality depend on ever more sensors, more cloud processing, and more data being collected on children.

Parents now have to weigh up the privacy of the data these devices collect, as well
as the security risks they bring into the home. In May 2026, a security researcher in France named Sammy Azdoufal decided to probe some of the weaknesses behind budget smart cameras.

Azdoufal discovered that he could pull up other people’s live and recorded footage without needing to guess a password or do anything that really counts as “hacking”. His findings, reported by CyberNews, traced back to a shared system used behind the scenes by more than 300 different camera brands sold on retailers such as Amazon.

He estimated that more than one million devices were affected, many of them baby monitors in bedrooms.

Shared vulnerabilities

What most parents don’t realise is that the brand on the box is rarely the company
that built the camera or wrote its software. Many monitors, even from well known
sellers, come out of a small number of factories. They get sold under dozens of
different names, so one weakness underneath can affect them all.

The cybersecurity operations company Rapid7 published some of the first well known research into these cameras years ago, and a 2026 academic study found the same pattern repeating in newer devices and their apps.

Baby monitor
Parents may not realise they have a right to see data collected from devices.
Rodica Vasiliev

Regulators have started responding. Updated in 2022, new cybersecurity rules under the EU’s Radio Equipment Directive have applied to any internet-connected wireless device sold in the EU. These new rules require manufacturers to protect users’ data, stop devices being hijacked and guard against fraud.

Some manufacturers are taking steps to improve security. For example, the baby monitor manufacturer Owlet announced in late 2025 that its newest model was the first baby monitor awarded the SGS Cybersecurity mark. This mark requires manufacturers to include encryption, a unique passwords and a channel for researchers to report flaws. The certification gives parents something concrete to look for.

Security is only half of it. Even a monitor that’s never hacked can still raise data privacy issues. Many collect more than video. They gather information on feeding times, as well as sleep and growth data, and share it with third parties for analytics or advertising under vague “partner” clauses.

Sleep pattern data from a baby monitor isn’t classed as medical information under GDPR, so companies can use it for analytics or advertising unless parents opt out.
This data often isn’t as anonymous as companies claim once combined with other details.

Cry detection and sleep analysis add to this, since both usually mean sending audio
and video to the cloud, where it may also help train a company’s algorithms.

Because these features depend on cloud processing rather than staying on the
device, the data often leaves the home network, increasing both privacy and security exposure.

Privacy and long-term protection

The UK has rules covering both sides of this. The Product Security and Telecommunications Infrastructure Act, in force since 2024, bans default passwords and forces manufacturers to say how long they’ll support a device.

On the data side, the UK goes further than most countries through the Information Commissioner’s Office Children’s Code, which applies to any connected device likely to be used by children.

The code requires the highest privacy settings by default, and gives parents a genuine right to see, or delete, what’s been collected, backed by fines of up to 4% of global turnover. Most parents just don’t know to ask.

None of this means every camera monitor is dangerous, or that the reassurance they
offer isn’t real. But the trade-off keeps showing up in the research. Internet-connected monitors carry more risk than simple closed ones that talk directly between two devices in your home.

Treat the password like a banking one, keep the app updated, and check how long the manufacturer will support it. The bigger issue isn’t something one password can fix. The underlying issues in the industry mean new vulnerabilities will keep appearing, so the safest path is staying informed and choosing devices with transparent security and support policies.

The Conversation

Erika Sanchez-Velazquez does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

Leave a Reply

Your email address will not be published. Required fields are marked *