FTC Sending $5.6 Million in Refunds to Ring Customers Over Security Failures

Share This Post

The Federal Trade Commission (FTC) this week announced that it is sending out a total of more than $5.6 million in refunds to customers of the Amazon-owned home security camera company Ring as the result of a 2023 settlement.

In May 2023, the FTC announced a complaint against Ring for failing to implement security protections to ensure customer privacy and allowing hackers and employees to access user devices and accounts.

Ring’s failure, the FTC said, allowed hackers to access customer videos and account profiles, and in some cases to completely take over devices and threaten and harass customers, including elderly people and children.

According to the agency, hackers exploited security vulnerabilities to access the videos, video streams, and account profiles of at least 55,000 Ring customers in the US.

According to the complaint, Ring also failed to restrict employee access to customer videos, which allowed at least one employee to surveil female customers in bathrooms or bedrooms.

Furthermore, the FTC noted that until 2018 Ring had failed to notify its customers or obtain their consent for performing reviews of their videos for various purposes, including training AI algorithms.

“Ring deceived its customers by failing to restrict employees’ and contractors’ access to its customers’ videos, using its customer videos to train algorithms without consent, and failing to implement security safeguards. These practices led to egregious violations of users’ privacy,” the FTC said this week.

The commission announced that it is sending over 117,000 PayPal payments to individuals who owned certain Ring devices, including indoor cameras, and that these payments should be redeemed within 30 days.

Advertisement. Scroll to continue reading.

In May last year, the FTC also said that Amazon had agreed to pay $25 million as part of a separate settlement regarding accusations that it kept children’s voice recordings captured by Alexa smart speakers instead of deleting them.

Related: Tech Support Firms Agree to $26M FTC Settlement Over Fake Services

Related: FTC Accuses Avast of Selling Customer Browsing Data to Advertisers

Related: FTC Orders Blackbaud to Address Poor Security Practices

Related: Ring Will No Longer Allow Police to Request Doorbell Camera Footage From Users

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.

Article

BFU – Seeing is Believing

Oh no, the device is in BFU. This is the common reaction; a device needs extracting, and you find it in a BFU state. Often, there’s an assumption that a BFU extraction will only acquire basic information, but that isn’t always the case.