Thousands of Amazon Ring User Credentials Exposed in Major Data Leak

A massive data leak exposes the login credentials and sensitive camera data of over 3,600 Ring camera owners, putting their homes and privacy at severe risk. Ring denies a system breach and blames the exposure on credential harvesting from other companies.

A significant data leak exposes the login credentials and personal information of 3,672 Amazon Ring camera owners. The compromised data includes log-in emails, passwords, time zones, and camera names that often reveal specific locations like "bedroom" or "front door." This sensitive information poses a severe risk to affected users, as malicious actors potentially gain access to live camera feeds, home addresses, phone numbers, and partial payment details.

New Zealand security researcher Nick Shepherd discovers this exposed data on an anonymous text storage site and immediately contacts Ring customer support, but a representative states they are unable to assist. Buzzfeed News verifies the leak by contacting four affected individuals, none of whom receive a notification from Ring about the exposure. Additionally, none of these compromised users have two-factor authentication enabled on their accounts at the time of the leak.

Ring denies experiencing an unauthorized intrusion into its own systems and claims that bad actors simply harvest credentials from previous data breaches at other companies. This incident raises substantial privacy concerns given that over 700 US police departments hold contracts with Ring. These agreements allow law enforcement to request resident camera footage without a warrant and provide police with free cameras in exchange for promoting Ring's neighborhood watch app.

Read More at the original source →