> ## Content Index
> Fetch the complete content index at: https://www.humanoidthreats.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOActive
- URL: https://www.humanoidthreats.com/directory/ioactive/
- Published: 2026-10-04T10:14:04.000Z
- Updated: 2026-10-04T11:14:49.000Z
- Description: Security research and testing firm with one of the longest track records in robot hacking research, dating back to 2017.
- Author: Theo Marchetti
- Tags: Directory, #dir-robot

Category

Robot security research and testing

Website

[www.ioactive.com](https://www.ioactive.com/?ref=humanoidthreats.com)

Last verified

October 4, 2026

## What is IOActive?

IOActive is a security research and services firm known for hardware and embedded security testing. It has published robot security research since 2017.

## Key capabilities

- Security assessments and penetration testing of devices and embedded systems.
- Published robot security research, including "Hacking Robots Before Skynet" (2017), which reported nearly 50 vulnerabilities across robotic platforms.
- Demonstrated ransomware on SoftBank's NAO and Pepper robots in 2018.
- Contributed to the Robot Vulnerability Scoring System (RVSS).

## Why it matters for humanoid robot security

IOActive's 2026 follow-up research, done with Alias Robotics, found 38 vulnerabilities in three consumer robots, including missing authentication, hardcoded credentials and unsigned firmware. It concluded that the same classes of weakness have persisted since 2017\. Teams deploying humanoids can use firms like this for independent testing before rollout.

## Where it fits in a humanoid robot security program

IOActive works as an outside tester rather than a product you install. For humanoid robots, that means penetration testing of the hardware, firmware, wireless interfaces and companion apps before launch or before a large purchase. Teams typically bring in a firm like IOActive when they need an independent view of a robot's security, for example to satisfy a customer or regulator.

## Who it is for

- Humanoid and service robot manufacturers preparing a product launch
- Enterprises evaluating a robot fleet purchase
- Security teams that need independent robot testing or monitoring

## Questions to ask IOActive

- Which humanoid or service robot platforms have you tested or protected so far?
- Do you cover wireless setup, cloud links and the robot's AI assistant, not just the network?
- Can findings be shared with the robot vendor under coordinated disclosure?
- What does ongoing monitoring look like after deployment?

## Similar listings

- [Alias Robotics](https://www.humanoidthreats.com/directory/alias-robotics/): Robot security specialist

## Related on Humanoid Threats

- [Can humanoid robots be hacked?](https://www.humanoidthreats.com/can-humanoid-robots-be-hacked/)
- [Browse the full Humanoid Robot Security Directory](https://www.humanoidthreats.com/directory/)

## Sources

- [IOActive: From Skynet to AI Agents (2026)](https://www.ioactive.com/from-skynet-to-ai-agents-the-state-of-robot-security-nine-years-later/?ref=humanoidthreats.com)

*This listing is editorial and free; inclusion is not an endorsement. Work at IOActive?* [*Claim or update this listing*](mailto:info@humanoidthreats.com?subject=Update%20listing%3A%20ioactive)*.*

Get the weekly Humanoid Threats Brief → [Subscribe](#/portal/signup)