Hacker Exploits Security Flaws in Yarbo Robot Lawnmowers, Demonstrates Physical and Privacy Risks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Security researcher Andreas Makris remotely hacked Yarbo robot lawnmowers, demonstrating their severe vulnerabilities. He controlled the robots from Germany, nearly running over a Verge editor in the US, and accessed sensitive data. The incident highlights risks of physical harm and privacy breaches due to poor AI security design.[AI generated]

Why's our monitor labelling this an incident or hazard?

The robot lawn mowers are AI systems as they autonomously navigate and perform complex tasks like mowing, using onboard computing and sensors. The event involves the use and malfunction (security vulnerabilities) of these AI systems, which have directly led to harms: physical danger to a person (the researcher lying in the mower's path), privacy violations (unauthorized access to cameras, GPS, Wi-Fi credentials), and potential broader harms (botnet formation, network intrusion). The article documents actual exploitation and demonstration of these harms, not just potential risks. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Robots, sensors, and IT hardwareConsumer products

Affected stakeholders
ConsumersGeneral public

Harm types
Physical (injury)Human or fundamental rights

Severity
AI incident

AI system task:
Recognition/object detectionGoal-driven organisation


Articles about this incident or hazard

Thumbnail Image

A hacker ran me over with a robot lawn mower

2026-05-07
The Verge
Why's our monitor labelling this an incident or hazard?
The robot lawn mowers are AI systems as they autonomously navigate and perform complex tasks like mowing, using onboard computing and sensors. The event involves the use and malfunction (security vulnerabilities) of these AI systems, which have directly led to harms: physical danger to a person (the researcher lying in the mower's path), privacy violations (unauthorized access to cameras, GPS, Wi-Fi credentials), and potential broader harms (botnet formation, network intrusion). The article documents actual exploitation and demonstration of these harms, not just potential risks. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Attack Of The Killer Lawnmowers: Security Flaw Let Hackers Control These Landscaping Robots - SlashGear

2026-05-07
SlashGear
Why's our monitor labelling this an incident or hazard?
The robotic lawnmower is an AI system with autonomous navigation and internet connectivity. The security flaw allows unauthorized control, which directly leads to potential harms including physical injury, privacy breaches, and illegal network activity. The hacker's ability to control the fleet and access sensitive data shows the AI system's malfunction has directly led to significant harm or risk thereof. This meets the criteria for an AI Incident rather than a hazard because the vulnerability is actively exploitable and the harms are concrete and immediate risks, not just plausible future harms.
Thumbnail Image

Hacker Takes Over Robot Lawnmower, Runs Over Innocent Man

2026-05-08
Futurism
Why's our monitor labelling this an incident or hazard?
The robot lawnmower qualifies as an AI system because it is an autonomous robot performing complex tasks such as navigation and operation of blades. The hacker's ability to take control and manipulate the robot demonstrates a malfunction or misuse of the AI system. The event directly reveals a risk of physical injury (harm to a person) and privacy breaches (harm to property and personal data). While no injury happened, the demonstrated exploit shows a credible and immediate risk of harm, making this an AI Incident rather than just a hazard. The company's initial denial and slow response further emphasize the seriousness of the issue.
Thumbnail Image

Hacker Takes Over Robot Lawnmower, Runs Over Innocent Man (Futurism article, 5/8, based on a 5/7 Verge srticle)

2026-05-09
Democratic Underground
Why's our monitor labelling this an incident or hazard?
The robot lawnmower qualifies as an AI system due to its autonomous navigation and multifunctional capabilities. The hacking event is a misuse of the AI system, leading directly to physical harm to a person, which is a clear harm to health. The presence of hardcoded passwords and backdoors shows a failure in the system's security design, contributing to the incident. Therefore, this event is classified as an AI Incident because the AI system's malfunction and malicious use directly caused harm.