DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Secures $450,000 from Companies Selling Home Security Cameras that Failed to Secure Private Videos

Posted on January 28, 2025December 27, 2025 by Dissent

NYS Attorney General has been the most active state attorney general in terms of going after entities that don’t secure data properly.  The following is from her latest press release:

NEW YORK – New York Attorney General Letitia James secured $450,000 from three companies that distribute eufy home security video cameras for failing to secure consumers’ private home security videos. The companies, Fantasia Trading LLC, Power Mobile Life LLC, and Smart Innovation, LLC distribute a line of video cameras, video doorbells, and video smart locks under the eufy brand. An investigation by the Office of the Attorney General (OAG) found that video streams from the cameras were not always securely encrypted and could be accessible to anyone with the relevant link without authentication. The settlement requires these companies to take steps to ensure stronger protections for customers’ data and pay $450,000 in penalties and costs.

[…]

In November 2022, a security researcher publicly disclosed tests indicating that marketing claims about the eufy products’ security and “end-to-end encryption” of data might not be accurate. The OAG opened an investigation focused on a line of eufy-branded internet-enabled video cameras, video doorbells, and video locks distributed by Fantasia Trading, Power Mobile Life, and Smart Innovation. The marketing for these home security products assured consumers that their data would be kept private and secure.

The OAG’s investigation revealed that, in certain situations, video sent over the internet from eufy home security products was not protected by end-to-end encryption, and that at least a portion of the connection did not use any type of encryption at all. The investigation also uncovered that an active video stream could be accessed by anyone with the relevant URL, without authentication, and that it may have been possible to deduce the URL without obtaining it from a user. The companies had not previously identified these security vulnerabilities because they did not have the necessary processes in place to test their safeguards or to identify risks to the security and privacy of consumers’ video.

As a result of this settlement, Fantasia Trading, Power Mobile Life LLC, and Smart Innovation will pay $450,000 in penalties and costs and take steps to ensure the eufy home security products they sell better protect consumers’ private videos. The agreement requires that the companies regularly substantiate that the developer of the eufy home security products:

  • Maintains a comprehensive information security program designed to protect the security, confidentiality, and integrity of consumer information;
  • Uses secure software development processes, including the use of third-party tools for testing software for security vulnerabilities;
  • Maintains a vulnerability management program that includes regular penetration testing and vulnerability testing; and
  • Implements appropriate encryption processes, including the encryption of video in storage and in transit.

 

Related: Anker Tries To Bullshit The Verge About Security Problems In Its Eufy ‘Smart’ Camera

 


Related:

  • Attorney General James Secures $450,000 from US Radiology Specialists for failing to protect patient data
  • Attorney General James Reaches Agreement with Marymount Manhattan College to Invest $3.5 Million to Protect Students’ Online Data
  • Update on the Clark & Anderson, P.A. breach
  • Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches
  • Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches
Category: Business SectorExposureLegislationOf NoteU.S.

Post navigation

← KuCoin Agrees to $297 Million Settlement Over Regulatory Breach
Ransomware attack kept ENGlobal out of some systems for 6 weeks →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life
  • Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.