Skip to main content

Internet-connected hot tubs can be hacked and controlled remotely

Lars Plougmann/Flickr

Hot tubs are supposed to be a great way to relax, but that’s a little harder to do when you aren’t in control of them. Thousands of hot tubs running a system made by Balboa Water Group have exploits that can be hacked to allow malicious actors to remotely control them, according to a recent report from the BBC.

The issue, discovered by security researchers at the U.K.-based security firm Pen Test Partners, stems from lapses in a mobile app that enables hot tub owners to control their tubs from their phone. Attackers could theoretically gather information found on public resources to find homes with the vulnerable hot tubs and target them. The malicious actors could use third-party databases to find the GPS location data of a given tub and hijack it. There is no authentication that would prevent the attackers from getting into the system.

Recommended Videos

Once the attackers have picked their target, they can assume control of the tub remotely. That means they can make the temperature hotter or colder, take over the pumps and jets, and change the lights. The entire attack can be carried out over a smartphone or laptop.

Please enable Javascript to view this content

According to the BBC, Balboa Water Group was caught off guard by the report and said it was “surprised” to learn of the vulnerability. The mobile app that gives users the ability to remotely control their hot tub has been available for about five years and users have never reported any issues or hacking attempts, according to the company.

Balboa Water Group is in the process of addressing the security flaw and plans to have it patched up by the end of February — which is a long time to leave a known flaw unpatched and available to exploit. The company is working with its customers to set up individual usernames and passwords so they can secure their apps. It previously opted not to have users set up personal accounts because it wanted to simplify the activation process. While that might have made things more convenient, the decision also exposed users to having their personal time in the hot tub interrupted by hackers.

AJ Dellinger
AJ Dellinger is a freelance reporter from Madison, Wisconsin with an affinity for all things tech. He has been published by…
Narwal debuts innovative robot vacuum with new mop-cleaning functionality at CES 2025
Narwal Flow

Narwal is responsible for some of our favorite robot vacuums, including the premium Narwal Freo Z Ultra, which features a modern aesthetic and ultra-quiet operation. The company’s track record of innovation continued at CES 2025 with the reveal of the Narwal Flow -- an upcoming robot vacuum built with a powerful new mopping system.

The Narwal Flow employs a new type of mopping system (dubbed the FlowWash Mopping System) that actively cleans its rolling mopping plate as it's cleaning your floors. This ensures you won’t be tracking dirty mops across the ground and should result in a better overall cleaning experience. The robot is equipped with both a clean and dirty water tank, allowing it to extract dirty water from the mop while simultaneously rewetting it. This allows the mop to remain in excellent condition without needing to head back to the docking station for self-cleaning.

Read more
Beatbot reveals futuristic AquaSense 2 Series pool cleaners at CES 2025
Beatbot AquaSense 2

The original AquaSense Series was wildly popular when it hit the market in early 2024, and at CES 2025, Beatbot officially revealed its successor, the AquaSense 2 Series. Consisting of three robotic pool cleaners and starting at $1,500, Series 2 models are designed to automate all aspects of pool cleaning. The high-end AquaSense 2 Ultra even incorporates AI technology into the mix, promising a superior clean.

AquaSense 2 is the most affordable of the trio at $1,499, yet the three-in-one pool cleaner is still pretty well-rounded. It can clean floors, walls, and the waterline, and can run for up to four hours before needing a recharge. Toss in obstacle detection, four unique cleaning modes, and an array of 16 sensors, and it’s well-suited for most pools.

Read more
Nanoleaf reveals three smart lights, plus a spooky LED face mask at CES 2025
A person holding the Nanoleaf Light Therapy Face Mask

Nanoleaf revealed a bunch of new products at CES 2025. Along with the usual lineup of smart lights, it also debuted an LED Light Therapy Face Mask, marking the brand’s first foray into the wellness industry. Like most light therapy masks, the one from Nanoleaf looks a bit terrifying. But since it’s an advanced Food and Drug Administration (FDA) Level 2 certified skincare device, it’ll likely become a popular choice among shoppers.

The Nanoleaf LED Light Therapy Face Mask is now available for preorder and costs $150. That makes it much more affordable than other devices, which can climb over $500. Despite the low price, it’s packed with useful features. This includes clinically proven red and Near Infrared Light (NIR) treatments to reduce fine lines, acne, and uneven skin tone, as well as stimulate collagen production.

Read more