DJI Cloud Authorization Bug Exposes Data From Nearly 7,000 Robot Vacuums
S2 · 11 Feb 2026 · DJI · Multiple countries
Record
| Company | DJI |
| Industry | Drones / eVTOL |
| Type(s) | cyber |
| Date | 11 Feb 2026 (day precision) |
| Time of day | not documented |
| Location | Multiple countries |
| Severity | (minor injury or single-unit damage) |
| Scale | ~7,000 devices across 24 countries |
| Confidence | medium |
| Verified flag | Yes - independently re-checked against the cited source |
Summary
A software engineer reverse-engineering his own DJI robot vacuum discovered that cloud credentials also granted access to camera feeds, microphone audio, home maps, and status data for roughly 7,000 other DJI robot vacuums across 24 countries.
Primary source
Publisher: Popular Science · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| 11 Feb 2026 | DJI Cloud Authorization Bug Exposes Data From Nearly 7,000 Robot Vacuums | Popular Science | Popular Science |
DJI other incidents timeline
Drones / eVTOL context
cyber context
DJI industry position
Related incidents
Other DJI entries
- 03 Aug 2026 - FCC public notice would retroactively revoke sales authorization for DJI Air 3S, Mini 5 Pro, Avata 360 over LiDAR classification
- 07 Mar 2026 - DJI Pays $30K Bug Bounty After Researcher Hacks 7,000 Robot Vacuums
- 22 Dec 2025 - FCC adds DJI to Covered List, bars new drone models from US market
- 02 Aug 2025 - Kent Police DJI Matrice 30T crashes into child, severe hand injury
- ~Mar 2018 - Check Point Research discloses DJI account/data vulnerability
- 02 Aug 2017 - US Army orders fleet-wide ban on DJI drones over cyber vulnerabilities
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs