RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskDJI › 11 Feb 2026

DJI Cloud Authorization Bug Exposes Data From Nearly 7,000 Robot Vacuums

S2 · 11 Feb 2026 · DJI · Multiple countries

Record

CompanyDJI
IndustryDrones / eVTOL
Type(s)cyber
Date11 Feb 2026 (day precision)
Time of daynot documented
LocationMultiple countries
Severity (minor injury or single-unit damage)
Scale~7,000 devices across 24 countries
Confidencemedium
Verified flagYes - independently re-checked against the cited source

Summary

A software engineer reverse-engineering his own DJI robot vacuum discovered that cloud credentials also granted access to camera feeds, microphone audio, home maps, and status data for roughly 7,000 other DJI robot vacuums across 24 countries.

Primary source

Popular Science

Publisher: Popular Science · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
11 Feb 2026 DJI Cloud Authorization Bug Exposes Data From Nearly 7,000 Robot Vacuums Popular Science Popular Science

DJI other incidents timeline

Drones / eVTOL context

cyber context

DJI industry position

Related incidents

Other DJI entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs