216 Million LG Smart TVs Caught Recording Audio With the Screen Off — Security article on gikiewicz.com

In a video published on their YouTube channel, Gamers Nexus called it “216 million spy TVs.” The investigation, conducted with three independent security researchers, claims that LG’s latest smart televisions keep recording audio from the built-in microphone even when the screen is turned off — and that software flaws could additionally let attackers listen in on private conversations. The story spread fast. Very fast.

TL;DR: An investigation by Gamers Nexus with three independent security researchers found that up to 216 million LG smart TVs worldwide record audio even with the screen off, buffer it offline until connectivity returns, and sweep local home networks to map connected devices. Security flaws could additionally let attackers listen in on private conversations. European commentators argue the practices may violate GDPR, with fines reaching 4% of global turnover.

What Did the Investigation Into LG Smart TVs Actually Reveal?

The short answer: far more than passive viewing-history tracking. The investigation, a collaboration between Gamers Nexus and Level1Techs, uncovered that LG smart televisions are actively sweeping local networks to identify and map secondary devices, while simultaneously logging audio from the built-in microphone even in standby mode. The TV is not a passive participant in the living room. It is an active sensor platform.

For years, the standard privacy complaint about smart TVs centered on ACR — Automatic Content Recognition — a technology capable of “detecting” what content a household is watching and reporting it back for advertising purposes. According to Xataka’s coverage, we assumed that knowing what we watch was the whole problem. With LG, that turns out to be only the beginning. The gap between expectation and reality is wide.

The researchers went beyond surface-level observation. They instrumented the TV’s network traffic, examined its firmware behavior, and tested what the device does across different power states. Their findings, covered by Malwarebytes, include both intentional telemetry — the network mapping and microphone activity — and unintentional security vulnerabilities that could be exploited by third parties. That combination is what makes this case unusual. It is not only a story about aggressive data collection built into the product, but also about flaws that expose owners to external attackers. Privacy policy and security posture failed at the same time.

Could this have stayed hidden indefinitely? Possibly. Without traffic instrumentation and power-state testing, a dark screen in standby gives no visible indication of what the hardware is doing. The researchers had to deliberately measure behavior the device never discloses to its owner. That asymmetry — the manufacturer knows everything, the buyer knows nothing — is the thread connecting every finding in the report.

How Many LG TVs Are Affected and Who Found the Problem?

Up to 216 million devices worldwide, according to the investigation’s estimate, which Gamers Nexus promoted directly on Bluesky alongside their video report. The figure covers LG’s smart TV installed base, making this one of the largest potential surveillance footprints ever documented in consumer hardware. For comparison, most data-breach disclosures involve populations far smaller than this.

The technical work came from three independent security researchers, with Gamers Nexus and Level1Techs coordinating publication and verification. That structure matters. Findings reproduced by multiple independent parties are harder to dismiss as a one-off misconfiguration or an outlier firmware version. The multi-party approach also meant the testing covered different device configurations and network setups rather than a single lab scenario.

Coverage spread quickly across outlets in several languages. Malwarebytes summarized the security implications for its readership. Xataka covered the Spanish-language angle. Pravda Polska and Headtopics reported the findings for Polish and international audiences respectively, while smaller outlets like Peq42 and the java366 blog amplified the story further. The story crossed language barriers within days. That does not happen with marginal claims.

LG has not, in the sources available, published a detailed rebuttal of the specific technical findings. The company’s public posture in the coverage so far has not addressed the standby-mode microphone behavior or the network sweeping directly. Silence at this scale tends to invite exactly what European commentators are now openly discussing: legal action.

What Is ACR and Why Does It Matter Here?

ACR stands for Automatic Content Recognition, a technology embedded in most modern smart TVs that continuously monitors what appears on the screen. According to the investigation by Gamers Nexus, working with three independent security researchers, LG’s implementation goes far beyond cataloging viewing habits. The TVs were caught sweeping local networks to identify and map secondary devices connected to the same home network. That is a different league entirely.

On LG sets, ACR technology is capable of detecting what content is playing, as Xataka explains in its coverage of the findings. Smart TVs have monitored viewing for years, and most consumers accepted that trade-off long ago. What changes the calculus here is audio capture. The investigation showed that LG TVs record sound from the built-in microphone even in standby mode, when the screen is off and the owner assumes the device is idle. The assumption was wrong.

Pravda Polska’s report adds a detail that makes this worse. If the internet connection is disabled, the TV stores the recorded data locally and transmits it to LG’s servers once connectivity is restored. In other words, cutting the network cable does not erase anything. The data waits. It persists on the device until it can leave the device. This behavior was clearly engineered deliberately; buffering with deferred upload is not an accident of sloppy code.

Why does ACR matter in this context? Because it is the legal and technical foundation LG uses to justify continuous monitoring of the panel. Once a device is always watching and always listening, the line between content recognition and surveillance becomes blurry. Very blurry. ACR was sold to consumers as a way to get better recommendations. The investigation reframes it as the entry point for something much broader: whole-home device mapping and ambient audio collection, running around the clock, regardless of whether anyone is actively watching television.

Which Security Flaws Could Let Attackers Listen In?

Testing documented by Malwarebytes found that while LG smart TVs track viewing and scan home networks, separate security flaws could let attackers record conversations — even in standby mode. That is the core of the technical problem. The spying is not limited to LG itself; the platform’s weaknesses potentially open the door to third parties. Two distinct threat actors, one device.

The Gamers Nexus investigation, as summarized by Peq42, focused on LG’s latest smart TVs and identified vulnerabilities alongside the data collection practices. Headtopics reports that the TVs actively sweep local networks to identify and map secondary devices while simultaneously logging data. A device that maps your network is effectively drawing a blueprint of your home infrastructure. Routers, consoles, cameras, laptops — all inventoried.

Consider what an attacker could do with this combination:

  • Map every device on a home network through the TV’s active scanning
  • Use microphone access to record conversations in standby mode
  • Rely on stored audio being uploaded once the connection returns
  • Potentially pivot from the TV to other unsecured devices on the same network
  • Exploit the fact that most users never update TV firmware
  • Target a device that runs 24/7 and sits in the living room
  • Avoid suspicion, since a dark screen looks inactive
  • Combine network maps with audio to profile occupants over time

Malwarebytes’ testing is explicit: the flaws could allow an attacker to listen in, not just LG. This elevates the story from a privacy complaint to a security incident. A television that maps networks while appearing asleep is a persistent foothold inside the home. Few households treat the TV as part of their attack surface; it has no antivirus, no monitoring, and no one rebooting it with security in mind.

The standby-mode aspect deserves emphasis. Most people mentally power down a TV when the screen goes dark. If the microphone remains live and the network stack keeps running scans, then the most trusted screen in the house doubles as an always-on listening post — one that law enforcement and consumers alike would never think to check. The attack surface is psychological as much as technical.

European commentators believe the answer is yes. Gamers Nexus itself stated that “LG should be sued in EU for breaking GDPR laws,” a sentiment echoed widely across coverage of the investigation. The java366 blog post called the situation “huge” and urged continued exposure of the company’s practices. Under GDPR, recording audio in a private home without clear, informed, freely given consent is very difficult to defend. The home is precisely the context the regulation protects most strongly.

The scale amplifies the legal exposure. Roughly 216 million LG televisions worldwide are affected, according to the figure highlighted by Gamers Nexus on Bluesky. GDPR fines scale with the number of affected data subjects and the severity of the violation. With a potential footprint that large, the maximum penalty tier — up to 4% of global annual turnover — becomes a realistic starting point for regulators. For a company of LG’s size, that figure reaches into billions of dollars.

There is also the consent question. Consumers bought televisions, not microphones that record while the screen is off. If consent was buried in terms of service or tied to basic device functionality, GDPR’s requirements for explicit, granular consent were likely not met. Polish and Spanish coverage of the investigation framed the findings in exactly these terms. Consent obtained through a wall of legal text does not qualify as freely given under the regulation — a point EU authorities have made repeatedly in prior enforcement actions against technology companies.

No lawsuit has been confirmed yet in the sources available. But the groundwork — technical evidence, an affected population, and public pressure — is clearly in place. Regulators in the EU have acted on smaller scandals. Data protection authorities across member states have opened proceedings over far less intrusive behavior, and the investigation has now been documented in enough languages that a complaint landing on a regulator’s desk seems less a question of if than when. Public campaigns like this one have historically shaped enforcement priorities.

How Can You Limit What Your LG TV Collects?

The most reliable step is the bluntest one: disconnect the television from the network entirely. But sources add an uncomfortable caveat. Pravda Polska reports that when the connection is off, the TV stores recorded audio and sends it to the server after connectivity is restored. Pulling the plug on Wi-Fi delays transmission; it does not guarantee deletion. Only cutting power at the outlet stops the behavior dead.

Practical measures based on the documented behavior:

  • Disable ACR and advertising options in the TV’s settings menus
  • Revoke microphone permissions wherever the interface allows it
  • Deny the TV network access, or place it on an isolated VLAN
  • Block the TV’s outbound traffic at the router level
  • Cut power at the outlet when the set is not in use
  • Avoid connecting external cameras to the same network segment
  • Regularly check for and install firmware updates
  • Consider an external streaming box with the TV’s smart features disabled

The network scanning finding deserves special attention. Since the TVs map secondary devices, isolating the television on its own network segment limits what it can inventory. Anything you keep off that segment — security cameras, laptops, smart speakers — stays off the map the TV builds. Segmentation turns an unlimited scanning scope into a very small one.

The table below ranks the options by effectiveness:

MeasureEffortEffectivenessCaveat
Cut power at outletLowTotal while offResets convenience features
Isolated VLANMediumHighRequires router config
Router-level blockingMediumHighFirmware updates may change endpoints
Disable ACR in settingsLowModerateDoesn’t stop microphone logging
Revoke mic permissionsLowModerateDepends on firmware honoring the toggle
External streaming boxMediumModerateTV smart features must be disabled

None of these is perfect. But layered together, they shrink the attack surface from “whole home, always on” to something a household can actually reason about.

Frequently Asked Questions

Do LG smart TVs record audio when the screen is off?

Yes. The investigation found that LG TVs keep recording audio from the built-in microphone even in standby mode, with the screen off. According to Gamers Nexus’s Bluesky post, up to 216 million devices worldwide are potentially affected. The behavior continues in a state most owners interpret as powered down.

Does disconnecting the TV from Wi-Fi stop the data collection?

Not entirely. Pravda Polska reports that when the internet connection is disabled, the TV stores the recorded data locally and transmits it to LG’s servers once connectivity is restored. Disconnecting delays transmission; it does not delete the buffer. Cutting power at the outlet is the only measure the sources describe as fully stopping the device.

Could someone other than LG listen in through the TV?

Possibly. Malwarebytes’ coverage states that security flaws identified in testing could let attackers record conversations, even in standby mode — separate from LG’s own data collection. The TVs also sweep local networks to map secondary devices, giving an attacker a blueprint of the home network. Third-party exploitation is a documented risk, not just a theoretical one.

Is LG facing a lawsuit over GDPR violations?

None is confirmed in the available sources. However, Gamers Nexus stated publicly that “LG should be sued in EU for breaking GDPR laws,” and coverage across European outlets framed the findings as likely violations. With roughly 216 million affected devices, the maximum GDPR penalty tier of up to 4% of global annual turnover is in play.

Summary

The Gamers Nexus investigation reframes the smart TV from a convenience device into an always-on sensor platform. The key takeaways:

  • Up to 216 million LG smart TVs may record audio in standby mode, with the screen off
  • Disconnecting the network does not delete captured audio — it buffers locally and uploads later
  • The TVs actively sweep home networks, mapping every connected device
  • Separate security flaws could let third-party attackers listen to private conversations
  • European commentators argue the practices may breach GDPR, with fines up to 4% of global turnover

If you own an affected set, audit its settings today. Disable ACR, revoke microphone access, and isolate the device on your network. Then share the investigation — public pressure is, so far, the only force moving this story forward.