In May 2026, the Yarbo case shook the connected robotics industry. A security researcher demonstrated how thousands of robotic lawnmowers — produced by the Chinese company Yarbo — could be easily hijacked. The exposed data included GPS coordinates, Wi-Fi passwords, email addresses, and much more. Yarbo responded with a detailed 1,200-word statement, confirming the vulnerabilities and announcing a corrective plan.
However, the case goes beyond a single product. In fact, it represents a wake-up call for any SME using networked connected IoT devices — from industrial machinery to video surveillance systems, to logistics sensors. The attack surface grows with every device added, often without adequate security policies. Consequently, the operational implications for Italian companies are concrete and urgent.
We at SHM Studio we monitor these dynamics to help SMEs understand the digital risks associated with technological transformation. In this analysis, we retrace the case history, identify the real winners and losers, and offer a strategic perspective geared towards medium-sized businesses.
The timeline: from a runaway lawnmower to a global reputation crisis
On May 7, 2026, The Verge published a detailed investigation on how a security researcher managed to remotely take control of a Yarbo robot lawnmower. The device — equipped with rotating blades — was directed against its owner. The incident immediately attracted global media attention.
The next day, Yarbo released a public response of about 1,200 words. The company confirmed the vulnerabilities reported by the researcher. Additionally, it offered a formal apology and outlined a structured action plan to fix the identified issues. As a first immediate measure, Yarbo temporarily disabled remote access to its devices.
In parallel, the cybersecurity community began to map the scope of the problem. Thousands of Yarbo devices were exposed. Therefore, the data at risk included real-time GPS coordinates, Wi-Fi credentials, registered user email addresses, and other personal information.
Anatomy of the vulnerability: why it was so easy to exploit
The flaws found in the Yarbo system were not sophisticated. On the contrary, they were basic architectural errors. Access to the remote control API did not require robust authentication. Thus, anyone with basic technical knowledge could intercept and replicate control calls.
Furthermore, sensitive user data was transmitted in clear text or with insufficient encryption. Specifically, Wi-Fi passwords stored on the device were recoverable without special privileges. This type of error is classified among the most critical vulnerabilities according to standards OWASP IoT Top 10 .
The Yarbo case is not isolated. According to recent research by Gartner , over 60% of consumer and semi-professional IoT devices have at least one unpatched critical vulnerability. Consequently, the problem affects a much broader ecosystem than the single brand involved.
Winners and losers: who emerges strengthened from this affair
Yarbo's response was timely and detailed. This represents a positive element in crisis management. However, the brand's reputation has suffered significant damage, which will be difficult to recover in the short term in the European and North American markets.
The direct losers are evident: Yarbo as a brand, the retailers who had bet on the product, and more broadly the entire category of connected garden robots. In fact, consumer confidence in these devices will inevitably slow down in the coming weeks.
The unexpected winners are instead the vendors of IoT security solutions and specialized consultants in cybersecurity for OT/IoT environments. Similarly, manufacturers who had already invested in security certifications such as IEC 62443 or the NIST framework for IoT emerge strengthened. In summary, those who had done their homework can now differentiate themselves with credibility.
A third, less obvious group of winners is independent security researchers. The Yarbo case demonstrates the concrete value of responsible disclosure and strengthens the legitimacy of bug bounty as an industrial practice.
Reading SHM Studio: the risk isn't in the robot, it's in the model
We at SHM Studio we work daily with Italian SMEs undergoing digitalization. We observe a recurring pattern: companies invest in connected devices — smart machinery, IP cameras, warehouse sensors — without building a parallel security governance.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.