Here's a fun thread on IoT security gone wrong:
https://twitter.com/rombulow/status/990684463007907840?s=19
In a nutshell: It seems that if you use GET requests (ie, what looks like a regular website URL) to make an IoT device do something, there is a good chance your browser will pre-load it when you least expect it (ie, your garage door opens, oops!), or a search engine might hit it and set it off.
Cheers,
-Nico