Wyze says ~13,000 customers could briefly see others' camera feeds, after a similar issue in 2023; Wyze blames glitches in rebooting systems after an AWS outage
https://www.theverge.com/... The security issue is being blamed on “a third-party caching library,” but the company acknowledges that it let customers down @cassidy@mastodon.blaede.family : Wyze shows customer cameras to the wrong users—again. Imagine if you used these cameras inside, in private, intimate spaces like a bedroom or as a baby cam. This is the third time in three years they've had a similar issue; I don't think I would *ever* trust Wyze for cameras or anything security related. … @avoidthehack@infosec.exchange : Wyze says camera breach let 13,000 customers briefly see into other people's homes — Initially, the company reported it “only” affected 14 users. Attempts to blame web host provider AWS and then blames a “third-party caching client library.” Ummm... taking bets on a misconfigured S3 bucket here. … X: Rob Leathern / @robleathern : Looks like @WyzeCam had a privacy/security issue where folks had temp access to other people's cameras. This is very bad + the description leads me to more questions...We can now confirm that as cameras were coming back online, about 13,000 Wyze users received thumbnails from cameras that were not their own and 1,504 users tapped on them... Paul Moore / @paul_reviews : The Verge really, REALLY go to town on firms who breach privacy. Huge respect @StarFire2258 and yet another disappointing effort by @WyzeCam - this should not be possible under any circumstances if #encryption is used properly. Another one to avoid. Phil Kelly / @phil_kelly_nyc : This is wild. Tech security and assurance (including with zk and other cryptography) will continue to be one of the most important areas of innovation for years. Ross Henderson-McKillop / @rsmck : I actually like these little cameras. I've got a few of them. None of them run Wyze's own firmware and I'd never use their app. IMHO all IP CCTV should be on prem to a server/NVR whatever that *you* control. Not a cloud service. Dave Zatz / @davezatz : Cool, cool. Massive outage followed by massive privacy lapse. Although, at this point, no one paying attention should be surprised. Caroline Haskins / @car0linehaskins : Wyze, a popular home security camera brand, is disclosing that 13,000 of its users “received thumbnails from cameras that were not their own” on the morning of Friday February 16 [image] Tom Warren / @tomwarren : Wyze cameras let some owners see into a stranger's home — again. Stunning that this has happened again 😬 https://www.theverge.com/... Jennifer Pattison Tuohy / @jp2e : Wyze's no-good, very-bad weekend continues to get worse ... The company says a breach identified on Friday let 13,000 customers briefly see into other people's homes https://www.theverge.com/... via @Verge Matt Johansen / @mattjay : If you have a Wyze WiFi camera I'd unplug it. Hearing reports of folks opening their app and seeing other people's camera feeds. Dan Wroclawski / @danwroc : Wyze is tanking its own reputation. Can't believe this has happened AGAIN. 🤦♂️ Michael Hulet / @mhuletdev : Truly, I beg you all, please understand that all these internet-connected cameras everywhere make you less safe, not more Peter Skaronis / @peter_skaronis : Wyze first with the same default password for all cameras. Now you can see other people's cameras without trying. Dmitry Kulshitsky / @dkulshitsky : @mattjay Wyze Roulette Brian Fagioli / @brianfagioli : @Techmeme @NexusBen I just put one of their cameras outside my house, and to be honest, this doesn't bother me — only because it's an outside camera. If I had one of their cameras inside my house, however, I'd probably be replacing it. Forums: Hacker News : Wyze security incident update r/wyzecam : I was watched by someone — I'm shocked. I'm a 23 year old girl and I was getting ready for work during the outage. r/wyzecam : Update on Investigation of 2/16/24 Security Issue r/wyzecam : Update on Security Event r/technology : Wyze says camera breach let 13,000 customers briefly see into other people's homes Msmash / Slashdot : Wyze Says Camera Breach Let 13,000 Customers Briefly See Into Other People's Homes
Context & Ripple Effects
Wyze’s latest disclosure follows a similar camera-feed mix-up reported in 2023, making recurrence—not merely the size of this event—the central issue for a product used in private spaces.
The company’s security record also includes previously disclosed remote-access flaws and a 2019 server leak affecting customer account and device data. The new incident ties privacy exposure to recovery behavior after a cloud-service disruption and to a third-party caching component.
First-order effects
- About 13,000 Wyze customers received thumbnails or feeds from other users’ cameras; Wyze says 1,504 users tapped those thumbnails.
- Wyze’s system-restart and cache-isolation controls face immediate scrutiny after the company linked the exposure to glitches during recovery from an AWS outage and a third-party caching library.
Second-order effects
- A repeated feed-visibility failure raises the trust cost for Wyze users deciding where to deploy cameras, especially in sensitive indoor settings, and gives rival camera providers a clearer reliability and privacy distinction to emphasize.
- The incident highlights that an upstream outage can become a tenant-isolation problem in downstream applications, increasing pressure on cloud-dependent device vendors to test restart and cache behavior—not just steady-state operation.
Third-order effects
- If similar failures continue, smart-home camera security will be judged increasingly on whether services preserve strict user-to-user data boundaries during degraded operation and recovery, rather than on device security alone.
- The case points to a broader accountability challenge in connected services: vendors remain responsible for customer exposure even when the triggering conditions involve cloud outages and third-party software components.
The trend: Connected-camera providers are being pushed to treat privacy isolation during cloud failures and recovery as a core product-resilience requirement.