11,000 Robotic Mowers Hijacked: The IoT Default Password Problem Is Still Not Fixed

A researcher remotely took control of 11,000 internet-connected robotic mowers sold in 30+ countries using a single shared admin password. The maker is China-based. The backdoor is still there.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Autonomous robotic lawn mower operating outdoors, representing the IoT security vulnerability in Yarbo devices that allowed remote hijacking by an ethical hacker.

Autonomous robotic lawn mower operating outdoors, representing the IoT security vulnerability in Yarbo devices that allowed remote hijacking by an ethical hacker.

A security researcher based in Germany remotely took control of a robotic lawn mower operating outside a family home in upstate New York. He did it from 6,000 miles away, using a single shared administrator password that was built into the device by the manufacturer and never intended to be changed.

The mower belongs to Yarbo. The problem affected more than 11,000 of its devices deployed across more than 30 countries.

What the researcher found

Andreas Makris, an ethical hacker, disclosed the vulnerability on 8 May 2026, revealing that Yarbo's internet-connected robotic mowers shared a single default administrative credential across the entire product fleet. Exploiting it gave him access to owner email addresses, home WiFi passwords, and precise GPS coordinates for every affected device.

He built a live map plotting the location of more than 11,000 units. He then demonstrated remote takeover for The Verge, steering a mower already operating on a residential property. The robot's camera moved with each command. There was nothing technically preventing him from driving it anywhere on the property or using its sensors to observe the occupants.

Makris also identified multiple Yarbo units operating in close proximity to critical infrastructure, including near a major power plant.

Because Yarbo's robots effectively function as internet-connected Linux computers, the implications extend beyond physical control. A malicious actor could, in principle, spin up the mower's cutting blades, probe connected home networks, or enlist the devices into a botnet for use in wider attacks.

The researcher noted that the flaw could not simply be resolved by end users changing their own passwords. Firmware updates on affected devices were reportedly restoring them to the same default credentials.

The China connection

Yarbo presents publicly as a New York-based robotics company, with US headquarters listed in Ronkonkoma, New York. In practice, it is a trading name for Hanyang Tech, a company headquartered in Shenzhen, China.

This distinction matters in the current GCC regulatory environment. Across the Gulf, procurement frameworks for smart city infrastructure and internet-connected devices are increasingly requiring clear disclosure of hardware origin, particularly where devices have persistent remote access capabilities enabled by the manufacturer. The UAE's Telecommunications and Digital Government Regulatory Authority and Saudi Arabia's National Cybersecurity Authority both publish guidance on IoT device security requirements. The Yarbo case is a clear example of why those frameworks exist.

The company's response

Yarbo co-founder Kenneth Kohlmann issued a public statement acknowledging that the technical findings were accurate and apologising for the security failures. The company stated it had temporarily disabled the remote diagnostic tunnels identified by the researcher, reset root passwords, restricted unauthenticated access points, and begun replacing its shared credential system with device-level independent credentials.

Yarbo also pledged to introduce an allowlist-based remote diagnostic model with user authorisation and audit logging, and said it would launch a formal vulnerability disclosure channel and explore a bug bounty programme.

Makris and The Verge's Sean Hollister remain unconvinced. Their central concern is that Yarbo stopped short of removing manufacturer remote access entirely. The company retains what amounts to a persistent internal backdoor, promising tighter controls and audit logging rather than eliminating the access pathway itself.

"It controversially retains an internal backdoor," Hollister wrote in a follow-up report published Friday.

Why this matters for enterprise and GCC security teams

The Yarbo case is not an isolated incident. It is one example of a structural problem that affects a large portion of the consumer IoT and commercial robotics market: internet-connected devices shipped with shared default credentials and manufacturer-retained remote access capabilities that end users cannot remove.

For enterprise security teams managing smart building systems, facility automation, or campus environments across the Gulf region, the risk profile of this class of device is significant. Procurement teams in the GCC are increasingly evaluating Chinese-manufactured hardware against national security and data sovereignty requirements. The Yarbo disclosure adds concrete evidence to that risk calculus.

The proximity of compromised devices to critical infrastructure identified in this research also touches on a broader concern that MENA security practitioners have raised through GCC cybersecurity policy forums: the convergence of OT and IoT attack surfaces as smart city infrastructure scales across the region.

Three immediate actions for security and procurement teams

First, audit any internet-connected device deployed on your network or facility for manufacturer-retained remote access capabilities. If the vendor cannot confirm that remote diagnostic access requires explicit per-session user authorisation, treat the device as a potential persistent access point.

Second, review procurement criteria for IoT and robotic devices to include disclosure of hardware origin, credential management architecture, and firmware update processes. Devices that restore default credentials on firmware update represent a systemic risk, not a configuration issue.

Third, apply network segmentation to any internet-connected operational device. If a device cannot be fully isolated from internal networks, it should not be deployed in proximity to sensitive systems or critical infrastructure.

The managed detection and response frameworks being adopted across GCC enterprises increasingly include IoT device monitoring as a mandatory component. The Yarbo disclosure is a timely reminder of why.


Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

GCC IoT and OT securitysmart city cyber riskChina hardware supply chainMENA critical infrastructureIoT device vulnerability 2026enterprise IoT procurement securitydefault credential exploitsautonomous device security