iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift
Home ›› Technology ›› Cybersecurity ›› Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Security firm Include Security documents how Bright Data's residential proxy network uses consent-based SDKs embedded in consumer apps, including smart TVs, to route AI training data scraping traffic through home internet connections. The research highlights the unique advantages of connected TVs over mobile phones for this purpose, including always-on power, high-speed WiFi, and minimal user oversight.

iG
iGEN Editorial
June 14, 2026
Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Enterprise technology leaders concerned about data privacy and cybersecurity should be aware of a growing practice: the use of residential internet-of-things devices, particularly smart TVs, as proxy nodes for AI training data scraping. According to security research firm Include Security, the company Bright Data operates what it markets as the world's largest residential proxy network, with over 400 million home IP addresses sourced via a software development kit (SDK) embedded in consumer apps. With user consent, these apps turn phones and smart TVs into exit nodes that paying customers use to scrape web data for AI models.

Why Residential Proxies Matter for AI

AI companies depend on web-scraped content for pre-training, retrieval, agent grounding, and search, Include Security explains. But modern web defenses—including Cloudflare, DataDome, and HUMAN—throttle or block requests from known cloud IP addresses. The workaround is residential proxies: a scraping job routed through a Comcast or T-Mobile subscriber's connection appears to come from a paying residential customer. Krebs reported in October 2025 that "a glut of proxies from Aisuru and other sources is fueling large-scale data harvesting efforts tied to various AI projects." Academic measurement going back to 2019 shows these networks are overwhelmingly misused. The FBI issued a formal advisory earlier this year.

Most press has focused on illegal residential-proxy supply—botnets (Aisuru, Kimwolf), trojanized apps (HUMAN Security’s PROXYLIB disclosure), pre-infected IoT hardware (Google/Mandiant’s IPIDEA takedown). Bright Data, however, operates on the legal supply side with a consent-based model, and Include Security found it has received far less scrutiny.

Bright Data's Consent SDK

Bright Data advertises "150M+ IPs" sourced via its consent SDK embedded in partner apps. The SDK, with user agreement, turns devices into exit nodes for its network. Include Security documents that some partner publishers, such as PlayWorks, disclose the Bright Data relationship in their privacy policies. However, the researchers argue that privacy-policy disclosure is the wrong control surface for a TV, since scrolling through a legal document via TV remote arrow keys is cumbersome, and the in-app consent dialog does not convey that a paying Bright Data customer will route scraping traffic through the user's home internet.

Why Connected TV Is the Ultimate Proxy

Include Security compared smart TVs (connected TVs, or CTVs) to mobile phones as proxy nodes and found TVs superior in every relevant dimension:

Factor Mobile phone Smart TV / CTV
Power Battery most of the day Always plugged in
Network WiFi + cellular Always WiFi, high-speed
Uptime Intermittent 24/7 in standby
Bandwidth ceiling Low (cellular caps) Effectively unlimited
User attention Actively used Often unattended
Consent UI Text on a phone screen Text navigated via TV remote arrow keys
Corporate/family oversight Higher (MDM, mobile EDR) Virtually none

A TV never hits 1% battery, jumps between WiFi networks, or gets locked when the user is asleep, making it a near-perfect residential proxy.

A Representative Case: Petflix on Roku

Include Security highlights Petflix, a Roku app documented by The Verge, as a representative case. Its opt-in screen reads: "To enjoy Petflix for free with fewer ads, you are allowing Brig..." (the source text cuts off). The researchers note that the consent flow does not adequately inform users that their home internet connection will be used for third-party scraping traffic.

Implications for Enterprise Cybersecurity

For enterprise technology buyers, the use of consumer IoT devices—including smart TVs in corporate lobbies, break rooms, or home offices of remote workers—as proxy nodes introduces a new vector for data exfiltration and network contamination. While Bright Data's SDK is consent-based and arguably legal, the lack of transparency in consent UI and the difficulty of auditing device behavior make it challenging for organizations to enforce data security policies. The FBI advisory and academic research showing widespread misuse of such networks underscore the risk. Organizations should consider whether any IoT devices with internet connectivity on their networks could be running similar SDKs, and review their acceptable-use policies for consumer devices in corporate environments.


Sources: Hacker News – Best

Keep Reading

Recommended Stories

Indian Government Considers Cybersecurity Framework for IoT Devices Beyond CCTV Cameras Technology

Indian Government Considers Cybersecurity Framework for IoT Devices Beyond CCTV Cameras

The Indian government is exploring a broader cybersecurity framework for Internet of Things (IoT) devices, extending beyond CCTV cameras to include smart meters, home automation, and industrial sensors. The initiative aims to reduce vulnerabilities in connected products through mandatory security certification and supply chain transparency.

July 13, 2026
New Research Reveals LLM Agents Often Choose Over-Privileged Tools, Posing Security Risks Technology

New Research Reveals LLM Agents Often Choose Over-Privileged Tools, Posing Security Risks

A new study introduces ToolPrivBench to evaluate over-privileged tool selection in LLM agents. The research finds that agents commonly choose higher-privilege tools even when lower-privilege alternatives are sufficient, and that safety alignment does not prevent this. A privilege-aware post-training defense is proposed to reduce unnecessary high-privilege tool use.

June 20, 2026
Neuro-Inspired Vision-Language Models Show Resilience to Membership Inference Privacy Leakage Technology

Neuro-Inspired Vision-Language Models Show Resilience to Membership Inference Privacy Leakage

A new study explores whether neuro-inspired multi-modal vision-language models (VLMs) are resilient to membership inference privacy attacks. Using topological regularization, the authors found that NEURO VLMs reduce MIA success by up to 24% without sacrificing model utility, offering a promising path for secure AI deployment.

June 17, 2026
SAMark Watermarking Breaks Paraphrase Robustness Barrier for AI-Generated Text Technology

SAMark Watermarking Breaks Paraphrase Robustness Barrier for AI-Generated Text

Researchers propose SAMark, a self-anchored text watermarking framework that achieves up to 90.2% true positive rate under paragraph-level paraphrasing attacks, outperforming the strongest prior baseline by more than 30% on average. The method breaks the robustness-quality trade-off by using multi-channel hyperbolic scoring and diversity-aware filtering.

June 17, 2026