Skip to content
Defici
← Defici NewsTech News

Half the Devices in a Modern Office Still Have the Password They Shipped With

By Defici Editorial · 30 Aug 2026

AI-generated · Defici Editorial

The number of connected devices in an ordinary home or small office has quietly multiplied - security cameras, printers, network storage, smart plugs, doorbells, thermostats, all sorts of gadgets that connect to the internet. Almost all of them arrive with a default password set at the factory: something simple, often the same across every single unit of that model, and frequently documented publicly in a manual anyone can find. The default exists so the device can be set up out of the box, and the manufacturer assumes the owner will change it. Very often the owner does not, because the device works perfectly well with the password it came with, and nothing forces the change.

An unchanged default password is a serious weakness precisely because it is not a secret at all. It is not something an intruder has to guess or crack; for a given model it can simply be looked up, and it is the same key that fits every unshipped, unchanged unit of that device in the world. There are automated tools that do nothing but scan the internet for connected devices and try the well-known factory passwords against them, and a device left on its default is, to such a tool, an open door found by turning a handle rather than picking a lock. The device does not need to be important or interesting; it only needs to be reachable and still using the credentials it was born with.

The consequences are not abstract. A camera or a baby monitor left on its default can be watched by strangers. A printer or a piece of network storage can be a way into the wider network it sits on, a foothold from which other, more valuable systems become reachable. And connected devices are frequently hijacked not for what they hold but for what they can do - quietly conscripted, in enormous numbers, into being used for other attacks, all without the owner noticing any change in how the device behaves day to day. The device keeps working exactly as before, which is why the compromise stays invisible until it causes harm elsewhere.

The remedy is almost embarrassingly simple and applies to every connected device that has a password: change the default to something unique the moment you set it up. It takes a minute or two per device, usually through the device's own app or settings page, and it converts an openly known key into one nobody can look up. It is worth doing a quick mental inventory of the connected things already installed - the ones that were set up long ago and forgotten - and checking whether any are still on the credentials they arrived with. Where a device also offers updates, keeping it current matters too, but changing the factory password is the single highest-value step, because a default left in place is not a lock that might be picked - it is a lock whose key was published, and left under the mat.

This article was generated by Defici's AI editorial system.

ShareXWhatsAppLinkedIn

Get Defici News in your inbox