Independent publication · not affiliated with any camera maker · written for camera owners

Guide 4 of 4 · Real or imitation

The Maker’s Own App, Address and Messages, and the Imitations

Every popular camera brand attracts imitators: look-alike pages, telephone numbers in ads and pop-ups, and emails claiming that a camera has been hacked. The genuine article has a few traits that do not change, and the imitations repeat a small number of patterns.

Reviewed 2 October 2026 · About 9 minutes

The app, as the stores list it

Each maker publishes one main app for its cameras, free to obtain from the Apple App Store and Google Play, with paid plans sold inside it. A store page names the publisher beneath the app’s title, and that line is the quickest test of a listing: the publisher of a maker’s own app is the maker, or the company that owns it.

Main camera apps as the U.S. stores list them
MakerApp titlePublisher shown
ArloArlo Secure: Home SecurityArlo Technologies, Inc.
BlinkBlink Home MonitorImmedia Semiconductor, an Amazon company
RingRing - Always HomeRing.com, the Amazon-owned Ring business
WyzeWyze - Make Your Home SmarterWyze Labs, Inc.
eufyAnker eufy, formerly eufy SecurityPower Mobile Life LLC, part of the Anker group

Imitation listings tend to give themselves away in the title or the publisher line: titles that wrap words such as guide, manual or for around a brand name, publisher names belonging to an individual or an unrelated company, and descriptions promising to connect, unlock or rescue a camera. Store titles change from time to time; the publisher line changes far less often.

Reading a web address

A web address is read from the right of its first section, not the left. In the stretch between https:// and the first single slash, the name immediately before the ending, such as .com, identifies who controls the page. Everything to its left is a subdivision chosen by that owner, and anyone can put a brand name there.

https://account.ring.com/

Controlled by ring.com. The word on the left is a subdivision of Ring’s own domain.

https://ring.com.cam-portal.example/account

Controlled by cam-portal.example. The brand name on the left is decoration chosen by that owner.

https://www.blinkforhome.com/

Blink’s own domain is blinkforhome.com: a maker’s domain is not always the brand name alone.

The makers profiled here use these main domains: arlo.com, blinkforhome.com, ring.com, wyze.com and eufy.com, with subdivisions of each for accounts and documentation. A maker’s domain is printed in its quick-start leaflet and on its packaging, which makes those a firmer source than a search result.

Look-alike addresses follow a handful of shapes, shown here on the reserved .example ending so that none of them leads anywhere:

  • Brand on the left, owner on the rightarlo.camera-pages.example belongs to camera-pages.example, whatever the first word says.
  • Extra words joined by hyphenswyze-cam-connect.example borrows the brand and adds words that sound like a service.
  • A near-miss spellingrinq-home.example swaps a single letter in the hope that the eye will not catch it.
  • The brand on another endingeufy.example uses the right name on an ending the maker does not use.

Messages a maker does send

Genuine maker messages arrive inside the app as notifications, and by email from the maker’s own domain. They cover a predictable set of subjects: motion and doorbell events, sign-ins from a new phone, password changes, plan renewals and receipts, firmware news and product recalls. A sign-in alert describes the device and the approximate place of the sign-in and refers back to the app’s security settings.

What genuine messages leave out is just as consistent. They do not ask for the account password or a verification code to be sent back, they do not demand payment to restore a camera, and they do not request remote control of a computer.

Any message can be checked without touching the links or numbers inside it, by opening the maker’s app directly and looking for the same information there. A genuine sign-in alert or renewal notice is mirrored in the app; an imitation is not.

Five patterns aimed at camera owners

Scams aimed at camera owners are not sophisticated, but they arrive at moments of mild confusion, often while a new camera is being added, and they borrow the maker’s name. Five patterns account for most of them.

The ad with a telephone number

Search ads and look-alike pages present a number as the maker’s service line. Whoever answers offers to finish pairing, restore a camera or secure an account, then asks for remote control of a computer, card details or both. Cameras are added in the maker’s phone app, so the offer has no legitimate purpose.

The pop-up about a compromised camera

A browser pop-up, sometimes with sound, announces that a camera or a network has been compromised and shows a number. A web browser cannot see the state of a home camera at all; only the maker’s app can. The pop-up is an ad or a malicious page, and closing the browser tab ends it.

The email that claims to have recorded the reader

Mass emails claim that the sender has taken over a camera, often a computer’s webcam, and recorded something embarrassing, then demand cryptocurrency. Some quote an old password from a public data breach to seem credible. The FBI and the FTC describe these messages as extortion attempts; the senders hold no recording.

The caller who offers to secure the cameras

An unexpected call claims that the household’s cameras have been hacked or are broadcasting publicly, and offers protection for a fee. Makers do not make such calls, and the account’s sign-in history and shared users are visible in the maker’s app.

The look-alike sign-in page

A link in a text message or email leads to a page dressed in a maker’s colors that asks for the account email, the password and the code from a two-step verification message. Whoever runs the page uses all three at once on the real site. Read as described above, the page’s address gives it away.

How makers protect an account

Camera accounts are a common target because many people reuse passwords that have leaked from other services. Makers counter this with two-step verification, which sends a one-time code to a phone or an email address at each new sign-in, so that a leaked password alone is not enough. Ring has required it on every account since 2020; the other makers profiled here offer it, in some cases switched on by default, and each describes its arrangement in the app’s account security settings.

Two further features matter. Shared-user or guest access lets other members of a household use the cameras with accounts of their own, so the owner’s password is never passed around and each person can be removed separately. A list of signed-in devices, offered by several makers, shows which phones are signed in to the account, which is where an unwanted sign-in would appear.

Codes from two-step verification messages are meant to be typed into the maker’s own app or website and nowhere else. A request to read such a code aloud, or to forward it, is the clearest sign of an attempt to take over the account.

When something has already happened

People who have given a caller remote control of a computer, a password or payment details are in a common position, and the U.S. Federal Trade Commission’s consumer guidance addresses it directly. It covers running up-to-date security software on the computer the caller reached; changing passwords that may have been exposed, starting with email and the camera account; contacting the bank or card company, through the number printed on the card, about any charges; and reporting the scam to the FTC.

Camera accounts carry checks of their own: the maker’s app shows which devices are signed in and who has shared access, and lets the owner remove any that should not be there. Outside the United States, national fraud-reporting services play the role the FTC plays.