Affiliate Disclosure: Some links on this page are affiliate links. As an Amazon Associate, we earn from qualifying purchases — at no extra cost to you. We do not buy, install, or physically handle the cameras we cover; our rankings come from aggregated owner reviews, ratings and expert consensus. Commissions never change our verdicts. We're reader-supported: commissions fund hosting, research and updates, so if a guide helped, buying through our links keeps it going. How we rank · full disclosure.
Short answer: to protect a wifi camera from hackers, give its account a password you use nowhere else, turn on two-step verification, keep the firmware current, tighten your router, and limit who you share the feed with. A leading cause of camera takeovers is a reused password, which the FTC alleged in its Ring case; default passwords, outdated firmware and exposed services are the other common routes. That means the fixes are cheap, mostly free, and within reach of any owner on a Saturday morning.
This hub is about the human side of the problem: who can see your footage, how an account gets taken over, and what to do if it happens. We do not sell or install cameras, and nothing here comes from hands-on testing. It draws on Federal Trade Commission and CISA guidance, vendor support pages, and the public record of the FTC’s action against Ring. See how we rank and our affiliate disclosure for how the site works.

In Plain English
A home camera is really two things: a lens in your house, and an online account that lets you watch it from anywhere. The lens is rarely the weak point. The account is.
Think of it like a front door with a very good lock and a spare key hidden under a plant pot that everyone in the neighborhood already knows about. If you use the same password on your camera app that you used for a shopping site that later got breached, the spare key is out. Thieves run leaked passwords through lots of sites automatically, and a camera account is one of the places they try.
So the plan is simple. Make the password unique. Add the second sign-in step so a stolen password is not enough. Keep the camera and router up to date. Be picky about who you share the live view with. And know what to do in the first ten minutes if something looks wrong. None of it needs technical skill, and none of it needs a new purchase.
How a Camera Actually Gets Exposed
Four routes cover nearly everything that goes wrong for a home owner. The first is credential stuffing: attackers take usernames and passwords stolen from unrelated breaches and try them against camera services. The FTC’s complaint against Ring describes exactly this, saying the company failed to put standard protections in place and that bad actors used the two-way talk feature to harass and threaten people. The second is a default or weak password on the camera or the router it hangs off. CISA’s home-network guidance says to change default log-in passwords and usernames because the defaults are readily available online.
The third is outdated firmware, which leaves known bugs open. The fourth is self-inflicted exposure: leaving Wi-Fi Protected Setup, Universal Plug and Play or remote management switched on at the router, which CISA advises turning off. There is also a fifth route you cannot fix yourself, which is a mistake or misuse on the vendor’s side of the cloud. The best response to that one is to share less, store less and choose vendors that disclose and fix problems. Our can security cameras be hacked page covers the documented incidents in detail, so this hub concentrates on what you do about them.
Lock the Account First
Do this before anything else, because it closes the route attackers use most. Set a long password that exists only for the camera app, ideally generated and stored in a password manager. Then turn on two-step verification. CISA’s guidance is to enable multifactor authentication on every account that offers it, because even if a criminal has your password, they cannot get in without completing the second step.
Ring shows what a good menu looks like. Its support pages say two-step verification sends a six-digit code when you sign in, with choices of text message, authenticator app, WhatsApp or approving a push notification on another signed-in device, and you can generate backup codes from the Control Center. If your camera app offers an authenticator app, that is a sensible choice because it does not depend on your phone number. Save the backup codes somewhere safe before you need them, and remember that an authenticator app is tied to the phone it was set up on, so plan for a phone upgrade.
Finally, check which email address the account is registered to. If that mailbox uses a weak or reused password, an attacker can simply reset the camera password from it. Fix the email account first if you are unsure.
Tighten the Router the Camera Lives On
Your router is the front gate for every device in the house, so a few minutes here protects the cameras as well. The FTC’s Wi-Fi guidance is to encrypt the network with WPA3 Personal or WPA2 Personal, to change both the Wi-Fi password and the router’s admin password, and to keep the router’s software up to date. CISA adds the switches to turn off: WPS, UPnP and remote management, plus a note to watch for unfamiliar devices on the network.
The FTC’s advice on IP cameras goes one step further and suggests considering a separate network for cameras, so that if another gadget is compromised it cannot reach them. The easy version is your router’s guest network. Before moving a camera, check that its app still finds it, since some cameras expect to share a network with your phone during setup. If a change knocks a camera offline, our camera keeps going offline guide lists the usual causes.
One more rule from experience of how these setups fail: avoid opening a port on your router to reach a camera from outside. Opening a port makes the camera reachable from the public internet, where scanning services that index internet-connected devices can find it. Most camera apps offer a cloud or app connection that does not require this, so check yours first.
Keep Firmware and the App Current
Vendors fix security holes through firmware and app updates, so an unpatched camera keeps its known problems. The FTC recommends checking the manufacturer’s website for camera software updates or enrolling in update notifications for both the camera and the viewing app. In practice: switch on automatic firmware updates wherever the app offers them, and put a reminder in your calendar twice a year to check the ones that cannot update themselves.
The same logic applies to your phone and the camera app on it. Install the app only from the official app store, keep the operating system updated, and be suspicious of a login page you reached from an email or text. The FTC also advises checking that a camera’s login page starts with https, so credentials travel encrypted.
Decide Who Can See the Footage
Shared access is a quiet source of exposure, because people stay on the list long after they need to be. Ring lets the account owner share devices as shared users, with three permission levels: Limited, which allows live view, event history and notifications; Standard, which adds mode controls and video sharing; and Advanced, which adds downloading recordings, changing device settings and managing users. Access is granted per device, and removing someone from a location takes them off every device there.
Whatever brand you own, the habit is the same. Give people the least access that does the job, review the list when your household changes, and remove old contractors, ex-partners and former house sitters. The FTC also suggests choosing cameras with granular permission controls, such as limiting who can view and when, or switching remote access off entirely.
Then think about the vendor’s side. The FTC’s Ring order is a useful reminder: the agency alleged that a Ring employee viewed thousands of recordings from female users, including in bathrooms and bedrooms, over several months without being detected. The stipulated order the FTC filed with the court in May 2023 requires a privacy and security program, multi-factor authentication for customers and employees, and deletion of certain older customer videos. That is one company’s case, not a verdict on the whole market. But it explains why some owners prefer recording locally, and why the indoor camera decision deserves its own thought.
Cameras Inside the Home Deserve Extra Care
An outdoor camera watches a porch. An indoor camera watches your life. The privacy stakes are higher indoors, so the rules of thumb are stricter. Keep cameras out of bathrooms, bedrooms and changing areas. Tell guests and household members where cameras are. Consider disabling remote viewing, or unplugging the camera, when everyone is home, as the FTC suggests being careful about remote access for private spaces. If you stay in a rental or hotel, the reverse question matters: how to check for hidden cameras and what the law says covers that.
A camera you cannot get comfortable with is a camera worth moving. A lens aimed at a hallway or the front door tells you what you need to know about visitors, without watching someone eat breakfast.
Buying With Privacy in Mind
You can shortlist privacy before you look at price. The FTC advises looking for cameras with built-in encryption of account information, live streams and stored video, and for permission controls fine enough to designate administrators and limit remote access. Add three questions of your own. Does the app offer two-step verification? Does the maker publish firmware updates and a way to report vulnerabilities? Can the camera record locally to a card or box, so that you can choose whether footage ever touches the cloud?
Be wary of brand-less cameras with no update history. And be equally wary of any product page that promises the camera is unhackable. Nothing connected to the internet is, and the honest claim is a company that patches quickly and explains what happened.
If You Think It Has Been Compromised
Act in this order. If you may want a record later, take quick screenshots of the account activity first. Then change the account password from a device you trust, then turn on two-step verification if it was off. Sign out every other session and device. Review the shared-user list and remove anyone you do not recognize. Check the camera’s settings for anything altered, update its firmware, and change the router’s admin password if it is still the default. If the same password was used elsewhere, change it there too, starting with your email. Our page on how to tell if a camera is hacked lists the warning signs, from a camera moving on its own to alerts about unfamiliar sign-ins.
If someone spoke to you or a family member through the camera, or you found footage was viewed by a stranger, note the date and time and keep the screenshots you took of the account activity. You may want them if you decide to contact the manufacturer or report it. That is general information rather than legal advice, so speak with a lawyer or local law enforcement about anything that feels like a crime.
A Ten-Minute Checklist
- Set a unique, long password on the camera account and store it in a password manager.
- Turn on two-step verification and save the backup codes.
- Check that the account’s email address has its own strong password and two-step verification.
- Switch on automatic firmware updates, or set a calendar reminder to check twice a year.
- Set the router to WPA3 or WPA2, change the Wi-Fi and admin passwords, and turn off WPS, UPnP and remote management.
- Move cameras to a guest network if the app still works there.
- Review shared users and delete anyone who no longer needs access.
- Turn off remote viewing or unplug indoor cameras when they are not needed.
Going Deeper: Why the Second Step Matters, and Where It Falls Short
Passwords fail in a predictable way. People reuse them, and when one site is breached, the leaked list gets tried everywhere. Multi-factor authentication changes the math because it asks for something beyond what a leaked list contains. NIST describes it as a combination of two or more factors, such as something you know, something you have and something you are, and says it strengthens accounts because attackers who compromise a password still cannot pass the additional check.
Not all second steps are equal, though. NIST points out that traditional methods such as one-time PINs and text-message codes remain vulnerable to phishing, where a fake login page tricks you into typing the code. It names FIDO authenticators, which can be hardware keys or built into phones and laptops, as the most secure widely available option. CISA likewise describes phishing-resistant multifactor authentication as the next level up. Most home camera apps do not offer FIDO keys yet, so for most owners the practical advice is to take the best second step on offer and to build one habit: never share a verification code, and treat an unexpected one as a sign your password is out.
The Ring case shows why layers matter. The FTC said credential stuffing hit the company multiple times in 2017 and 2018, that about 55,000 US customers experienced unauthorized access, and that the company only added multi-factor authentication in 2019. The agency’s proposed order included a $5.8 million payment for consumer refunds. Everything the FTC required, from a security program to customer multi-factor authentication, is something you can copy at home on a smaller scale. The account is protected by a unique password and a second step. The network is protected by an updated, hardened router. The footage is protected by limiting who can see it, and by choosing where it is stored.
The strongest single message from these sources is that privacy is mostly maintenance. Once you have done the ten-minute list, put a reminder in your calendar for every six months. Check for updates, prune the shared-user list, and confirm the router still has the settings you chose. A camera that watches the house is worth a few minutes of watching over in return.
Sources & References
- FTC Says Ring Employees Illegally Surveilled Customers, Failed to Stop Hackers from Taking Control of Users' Cameras — Federal Trade Commission
- Using IP Cameras Safely — Federal Trade Commission Consumer Advice
- How to Secure Your Home Wi-Fi Network — Federal Trade Commission Consumer Advice
- Home Network Security — Cybersecurity and Infrastructure Security Agency (CISA)
- Turn on MFA — Cybersecurity and Infrastructure Security Agency (CISA)
- Multi-Factor Authentication — National Institute of Standards and Technology (NIST)
- Using an Authenticator App to Sign In to Ring — Ring
- Adding and Managing Shared and Guest Users — Ring