Kohler's new smart toilet product, the Dekoda, has come under scrutiny after security researchers and engineers revealed that its camera system does not provide true end-to-end encryption as advertised. While the company claims that user data is protected with end-to-end encryption and stored securely, technical analysis and direct communication with Kohler confirmed that the data is decrypted and processed on Kohler's own systems, meaning the company itself can access sensitive footage and health data. This revelation has raised significant privacy concerns, especially given the intimate nature of the data being collected and the misleading use of security terminology in marketing materials.
The controversy has sparked public backlash and renewed debate about the privacy implications of internet-connected health devices, particularly those that collect highly sensitive personal information. Experts warn that the presence of cameras in such devices, combined with ambiguous or misleading claims about encryption, could expose users to privacy violations and potential misuse of their data. The incident highlights the need for greater transparency and accuracy in how companies describe their security practices, as well as the importance of robust privacy protections for emerging health technologies.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
A security researcher determined that Dekoda does not provide true end-to-end encryption because Kohler can decrypt and access user data once it reaches the company's servers. The finding raised concerns that sensitive health-related camera data is accessible to the company contrary to typical expectations for E2EE.
Kohler introduced the Dekoda device, a smart toilet attachment that uses optical sensors and machine learning to analyze toilet bowl contents and provide health insights. The product was marketed with privacy claims including end-to-end encryption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.