- The timeline: from a viral hack to a company response in 24 hours
- Anatomy of vulnerabilities: what went wrong in the IoT architecture
- Winners and losers: who comes out diminished from this affair
- The view of a Milanese agency: the IoT risk in Italian SMEs
- Next moves: what an SME should do after this case
- The work in progress: what Yarbo hasn't solved yet
- Implications for those communicating tech products: the role of content
A security researcher demonstrated they could remotely control thousands of Yarbo robotic lawnmowers. The exposed flaws included GPS coordinates, Wi-Fi passwords, and users' email addresses. Yarbo responded with a detailed statement, confirming the vulnerabilities and announcing immediate corrective measures.
However, the case isn't just about a robotics manufacturer. In fact, it's a wake-up call for any SME that integrates IoT devices into its operational processes or products. The attack surface expands every time a connected device enters a company without an adequate security architecture. Therefore, IoT risk management is no longer an issue reserved for large corporations.
We at SHM Studio let's analyze the incident history, the responsibilities that emerged, and the practical implications for Italian companies that want to adopt connected technologies consciously. In summary: the security of a digital product begins in the design phase, not in crisis management.
The timeline: from a viral hack to a company response in 24 hours
On May 7, 2026, an article published on The Verge shook the international tech community. A security researcher demonstrated they could remotely hijack a Yarbo robotic lawnmower. The device, equipped with rotating blades, moved towards the journalist on site. The incident had an immediate impact.
Beyond the physical aspect, the vulnerability was deeper. Thousands of Yarbo devices were exposed: GPS coordinates, Wi-Fi passwords, user email addresses were accessible to anyone with basic technical skills. This was not a sophisticated attack. On the contrary, the flaws were structural and widespread.
The next day, Yarbo published a response of about 1,200 words. The company confirmed the researcher's findings, publicly apologized, and provided a detailed action plan. Furthermore, it announced that it had already temporarily disabled remote access to the affected devices.
Anatomy of vulnerabilities: what went wrong in the IoT architecture
To understand the seriousness of the case, it's helpful to analyze the technical structure involved. Yarbo robots communicate with a mobile app and a cloud backend. The authentication between the device and the server had significant gaps. Consequently, an external attacker could intercept communications and take control of the device.
The Wi-Fi credentials stored in the device were accessible in plain text. This is a fundamental design flaw. In fact, end-to-end encryption of sensitive data is considered a minimum standard in any responsible IoT architecture. According to NIST guidelines for IoT security, credential protection is among the fundamental requirements for connected devices.
Remote session management was also problematic. The absence of robust identity verification mechanisms allowed third parties to impersonate the device owner. Therefore, the problem was not a single bug. It was a systemic approach to security that lacked solid foundations.
Winners and losers: who comes out diminished from this affair
Yarbo emerges from this episode with a damaged reputation, despite the quick response. The transparency shown is commendable. However, the damage has already been done: thousands of users had sensitive data exposed for an indefinite period. Trust in the brand will take time to rebuild.
The security researcher, on the other hand, demonstrated the value of responsible disclosure . Its methodology has led to a concrete improvement in product security. This approach is exactly what organizations like OWASP promote for the IoT sector.
The ones who lose out in a less visible way are SMEs that adopt IoT devices without assessing their security profile. Often, these companies do not have a dedicated IT team. As a result, they implicitly rely on the manufacturer's security. When this fails, the consequences can be severe: data theft, unauthorized access to company networks, legal liabilities.
The view of a Milanese agency: the IoT risk in Italian SMEs
We at SHM Studio we work daily with Italian SMEs that are digitizing their processes. We observe a clear trend: the adoption of connected devices is accelerating, but the security culture is not growing at the same speed.
The Yarbo case is not an exception. According to an analysis by McKinsey on the IoT market , the security of connected devices remains one of the main concerns for companies adopting these technologies. However, risk assessment is often postponed compared to implementation.
For an Italian SME, a compromised IoT device can mean access to the internal company network. Therefore, it's not just about the device itself. It's about the entire digital infrastructure that the device can reach once connected.
Next moves: what an SME should do after this case
Yarbo's response offers a useful model, even for companies that don't produce hardware. First and foremost, transparency in the event of an incident is essential. Communicating promptly with users reduces reputational damage in the long run.
For SMEs adopting IoT devices, there are some concrete actions to consider. In particular:
- Inventory of connected devices: map every IoT device present in the company, including those for operational use such as scanners, printers, and sensors.
- Network segmentation: isolate IoT devices on a separate VLAN. This way, even if a device is compromised, access to the main network remains limited.
- Supplier assessment: before purchasing a connected device, check the firmware update policy and the manufacturer's security history.
- Regular updates: many IoT vulnerabilities are corrected through patches. However, automatic updates are not always enabled by default.
In addition to this, it is useful to integrate IoT security into the overall digital strategy. An digital marketing strategy solid, for example, assumes that the collected data is protected. Brand credibility also depends on the security of the systems that manage customer information.
The work in progress: what Yarbo hasn't solved yet
Yarbo's response was quick and detailed. However, some issues remain open. The announced intervention plan requires time to be fully implemented. In the meantime, users who have already shared sensitive data with the device cannot recover that privacy.
Furthermore, it's unclear how Yarbo will handle devices already sold that won't receive updates. This is a common problem in the IoT ecosystem: manufacturers tend to focus resources on newer models. As a result, older devices remain vulnerable even after flaws have been identified.
For tech SMEs developing connected products, this aspect is critical. Product lifecycle management must include a clear security support policy. Without it, legal and reputational risk grows over time. A professional web presence and a SEO Strategy effective strategy is not enough if the underlying product has structural vulnerabilities.
Implications for those communicating tech products: the role of content
There's an often overlooked aspect in these cases: product communication. When a vulnerability emerges, the quality of the communication response largely determines public perception. Yarbo chose transparency. This choice partially mitigated the damage.
For Italian SMEs that market tech products, the copywriting strategy must include crisis scenarios. Similarly, the communication on LinkedIn and the google ads campaigns must be consistent with the values of transparency that the brand wants to convey.
Finally, the overall digital presence — from the website to campaigns — must reflect a responsible approach to technology. B2B customers are increasingly attentive to these signals. Therefore, product security and brand communication are not separate areas. They are two sides of the same corporate reputation.
To learn more about how to structure a digital strategy that integrates security and communication, you can contact the SHM Studio team or explore the insights available in the Blog . We at SHM Studio support Italian SMEs in building a solid, aware digital presence focused on customer trust.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.