by Adrianna Nine at ExtremeTech
A court filing submitted Wednesday by the Federal Trade Commission reveals that a former Amazon employee abused their Ring footage access to spy on users. The employee sought footage from cameras placed in bedrooms and bathrooms, impacting at least 81 female users and even fellow Ring unit employees.
The filing is part of a $5.8 million civil lawsuit alleging that Amazon (Ring’s parent company) committed privacy violations by “failing to restrict employees’ and contractors’ access to its customers’ videos.” According to the original complaint, a single employee spent several months in 2017 watching thousands of video recordings without the users’ consent. Most of these recordings occurred in “intimate spaces” in the home.
A colleague eventually took notice of the employee’s inappropriate behavior and reported it to her supervisor. The supervisor reportedly “discounted the report, telling the female employee that it is ‘normal’ for an engineer to view so many accounts.” It took the supervisor realizing that the offending employee was “only viewing videos of ‘pretty girls’” to escalate the report, which eventually resulted in the offending employee’s termination. Shortly after, Amazon realized it had no way to determine how many employees had abused private Ring footage.
The complaint also states Amazon failed to implement security measures that would have mitigated known user safety risks. Employees and third-party security researchers continuously warned of brute force and “credential stuffing” attacks that allowed bad actors to access users’ accounts, but Ring refused to act. In 2017 and 2018, Ring experienced several waves of credential-stuffing attacks. There were even multiple incidents in which hackers used Ring devices’ two-way audio capabilities to harass and threaten users, reportedly going so far as to sexually proposition users and their children. Still, it took until 2019 for Ring to introduce multi-factor authentication and other security checks.
The FTC has demanded that Ring…