iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Why UK data sovereignty is the next competitive advantage for digital industries Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed El Nino May Weaken India's Monsoon, Threaten Rice and Maize Output, FAO Warns Nigel Farage Warns UK Social Media Ban 'Unlikely to Work' Due to VPNs YouTube Premium at $16 Includes YouTube Music: Subscription Swap Analysis for Heavy Users New Lara Croft voice actor calls role 'the pinnacle' for gaming actresses ahead of 2027 Tomb Raider games
Home ›› Technology ›› Cybersecurity ›› Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Security firm Include Security documents how Bright Data's residential proxy network uses consent-based SDKs embedded in consumer apps, including smart TVs, to route AI training data scraping traffic through home internet connections. The research highlights the unique advantages of connected TVs over mobile phones for this purpose, including always-on power, high-speed WiFi, and minimal user oversight.

iG
iGEN Editorial
June 14, 2026
Smart TVs Become Nodes in AI Scraping Networks, Security Research Reveals

Enterprise technology leaders concerned about data privacy and cybersecurity should be aware of a growing practice: the use of residential internet-of-things devices, particularly smart TVs, as proxy nodes for AI training data scraping. According to security research firm Include Security, the company Bright Data operates what it markets as the world's largest residential proxy network, with over 400 million home IP addresses sourced via a software development kit (SDK) embedded in consumer apps. With user consent, these apps turn phones and smart TVs into exit nodes that paying customers use to scrape web data for AI models.

Why Residential Proxies Matter for AI

AI companies depend on web-scraped content for pre-training, retrieval, agent grounding, and search, Include Security explains. But modern web defenses—including Cloudflare, DataDome, and HUMAN—throttle or block requests from known cloud IP addresses. The workaround is residential proxies: a scraping job routed through a Comcast or T-Mobile subscriber's connection appears to come from a paying residential customer. Krebs reported in October 2025 that "a glut of proxies from Aisuru and other sources is fueling large-scale data harvesting efforts tied to various AI projects." Academic measurement going back to 2019 shows these networks are overwhelmingly misused. The FBI issued a formal advisory earlier this year.

Most press has focused on illegal residential-proxy supply—botnets (Aisuru, Kimwolf), trojanized apps (HUMAN Security’s PROXYLIB disclosure), pre-infected IoT hardware (Google/Mandiant’s IPIDEA takedown). Bright Data, however, operates on the legal supply side with a consent-based model, and Include Security found it has received far less scrutiny.

Bright Data's Consent SDK

Bright Data advertises "150M+ IPs" sourced via its consent SDK embedded in partner apps. The SDK, with user agreement, turns devices into exit nodes for its network. Include Security documents that some partner publishers, such as PlayWorks, disclose the Bright Data relationship in their privacy policies. However, the researchers argue that privacy-policy disclosure is the wrong control surface for a TV, since scrolling through a legal document via TV remote arrow keys is cumbersome, and the in-app consent dialog does not convey that a paying Bright Data customer will route scraping traffic through the user's home internet.

Why Connected TV Is the Ultimate Proxy

Include Security compared smart TVs (connected TVs, or CTVs) to mobile phones as proxy nodes and found TVs superior in every relevant dimension:

Factor Mobile phone Smart TV / CTV
Power Battery most of the day Always plugged in
Network WiFi + cellular Always WiFi, high-speed
Uptime Intermittent 24/7 in standby
Bandwidth ceiling Low (cellular caps) Effectively unlimited
User attention Actively used Often unattended
Consent UI Text on a phone screen Text navigated via TV remote arrow keys
Corporate/family oversight Higher (MDM, mobile EDR) Virtually none

A TV never hits 1% battery, jumps between WiFi networks, or gets locked when the user is asleep, making it a near-perfect residential proxy.

A Representative Case: Petflix on Roku

Include Security highlights Petflix, a Roku app documented by The Verge, as a representative case. Its opt-in screen reads: "To enjoy Petflix for free with fewer ads, you are allowing Brig..." (the source text cuts off). The researchers note that the consent flow does not adequately inform users that their home internet connection will be used for third-party scraping traffic.

Implications for Enterprise Cybersecurity

For enterprise technology buyers, the use of consumer IoT devices—including smart TVs in corporate lobbies, break rooms, or home offices of remote workers—as proxy nodes introduces a new vector for data exfiltration and network contamination. While Bright Data's SDK is consent-based and arguably legal, the lack of transparency in consent UI and the difficulty of auditing device behavior make it challenging for organizations to enforce data security policies. The FBI advisory and academic research showing widespread misuse of such networks underscore the risk. Organizations should consider whether any IoT devices with internet connectivity on their networks could be running similar SDKs, and review their acceptable-use policies for consumer devices in corporate environments.


Sources: Hacker News – Best

Keep Reading

Recommended Stories

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Technology

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Troy Hunt loaded the 1,000th breach into Have I Been Pwned, highlighting that disclosure lag times are worsening despite GDPR and CCPA. Examples include Carnival's 43-day delay and Zara's 45-day silence after ShinyHunters attacks, leaving victims uninformed for weeks.

June 14, 2026
Yale Linus Smart Lock L2 Lite: An Affordable, No-Subscription Smart Lock for UK Renters Technology

Yale Linus Smart Lock L2 Lite: An Affordable, No-Subscription Smart Lock for UK Renters

The Yale Linus Smart Lock L2 Lite, reviewed by TechRadar, is an affordable smart lock priced at £129.98 that mounts over existing cylinders without drilling. It supports Matter over Thread for compatibility with Apple Home, Google Home, Alexa, and SmartThings, and operates without a subscription fee. Key features include digital keys, PIN codes, Auto-Unlock, and KeySense, though it lacks built-in Wi-Fi and Apple Home Key support.

June 14, 2026
Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives Technology

Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives

Samsung MAX VPN ceased operations on June 15, 2026, affecting over 50 million users. The app remains as a dead shell unless uninstalled. Users are advised to switch to third-party VPNs for continued protection.

June 15, 2026
Adaptive Security Enlists Conan O'Brien for 15-Part Cybersecurity Training Series Targeting AI Fraud Technology

Adaptive Security Enlists Conan O'Brien for 15-Part Cybersecurity Training Series Targeting AI Fraud

New York-based cybersecurity firm Adaptive Security has partnered with talk show host Conan O'Brien to produce a 15-part training series addressing AI-enabled threats such as phishing, deepfakes, and voice cloning. The series, available to enterprise customers, aims to improve employee engagement and awareness of sophisticated cyber attacks.

June 15, 2026