Thousands of Ring users exposed as company's PR nightmare continues

Ring Indoor Cam
(Image credit: Ring)

Ring has suffered a data leak that exposed the personal information of more than 3,600 users, according to BuzzFeed News -- or did it? The security-camera maker denies its systems were breached.

Despite the public-relations nightmare that a recent string of reported "hacks" has birthed, I believe the Amazon-owned company is telling the truth. Here's why.

When I heard a bad actor hacked an 8-year-old's indoor Ring cam and claimed to be Santa Claus, I dug into the coverage of similar cases nationwide. 

The common denominator among all the attacks was not that a malicious entity got into Ring's trove of personal data. It's that the "hackers" gained entry to Ring online accounts through the front door -- by using the legitimate users' previously compromised, reused passwords. 

The kind of data BuzzFeed News says was exposed in the data leak, such room names and payment information along with email address, passwords and time zones, could have come from a breach of Ring's systems. 

But it also could have been "scraped" from Ring accounts that had already been accessed through compromised credentials. 

The fact that the number of affected accounts is in the low thousands rather than in the hundreds of thousands indicates that Ring accounts were likely not breached en masse.

As for how Ring-cam assailants got into those accounts, there are a number of ways to carry out such an attack. Most are alarmingly simple. 

There's software circulating the internet, for example, that shuffles through username-and-password combinations compromised in previous data breaches until it finds a correct match.  

A lucky guess could do the trick, too. That's why it's imperative to create a password that's long, strong and unique. We also recommended enabling two-factor authentication (2FA) both on Ring cameras and  when any other company offers it.

But do I think Ring has taken enough steps to assure users their accounts are kept safe? Absolutely not. 

As The Verge pointed out, Ring hasn't taken the kind of measures Google has to notify users when an account has been logged into from an unknown device or IP address. And although Ring offers 2FA, it didn't start stressing the importance of this account-protecting feature to users until last week. 

Still, the Ring cameras involved in these incidents are internet-enabled devices some have decided to adopt in their most sacred spaces. While indoor security cameras certainly provide practical purpose, it'd be an error on the user's part to give it the same password they use for Facebook.

When it comes to our smart home security tips, none is more key than devising unique passwords for your accounts -- especially for ones linked to video and audio devices in your home.

Kate Kozuch

Kate Kozuch is the managing editor of social and video at Tom’s Guide. She writes about smartwatches, TVs, audio devices, and some cooking appliances, too. Kate appears on Fox News to talk tech trends and runs the Tom's Guide TikTok account, which you should be following if you don't already. When she’s not filming tech videos, you can find her taking up a new sport, mastering the NYT Crossword or channeling her inner celebrity chef.

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know