RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / DJI / 2026-02-11

DJI Cloud Authorization Bug Exposes Data From Nearly 7,000 Robot Vacuums

S2 · 02/11
2026 · DJI · Multiple countries

Record

CompanyDJI
Categorydrones evtol
Typecyber
Date02/11
2026
Time of daynot documented
LocationMultiple countries
SeverityS2 (minor injury or single-unit damage)
Scale~7,000 devices across 24 countries
Confidencemedium
VerificationYes - adversarially checked against the cited source
SourcePopular Science

What happened

A software engineer reverse-engineering his own DJI robot vacuum discovered that cloud credentials also granted access to camera feeds, microphone audio, home maps, and status data for roughly 7,000 other DJI robot vacuums across 24 countries.

DJI record context

Entries by year and severity

232017 S3: 11172018 S2: 11182025 S3: 22252026 S2: 12026 S3: 2326
S1S2S3S4S5

By incident type

By severity

DJI vs drones evtol alternatives

drones evtol context

drones evtol: entries by year

482016 S5: 11162017 S3: 11172018 S2: 11182019 S2: 22019 S3: 13192022 S2: 22022 S3: 12022 S4: 14222023 S2: 12023 S4: 12232024 S2: 12024 S3: 34242025 S3: 52025 S4: 12025 S5: 28252026 S2: 22026 S3: 42026 S4: 1726
S1S2S3S4S5

drones evtol: failure modes

drones evtol: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in drones evtol

SevDateCompanyEvent
S32026-03-07DJIDJI Pays $30K Bug Bounty After Researcher Hacks 7,000 Robot Vacuums
S22018-03DJICheck Point Research discloses DJI account/data vulnerability

Other DJI entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs