Reminds me of a few years ago, when I accidentally exposed my Domoticz install to the internet without authentication. I've had missed something in my Nginx config with X-Forwarded-For headers. After about a week or something apparently a foreign visitor came by my install and decided to have some good fun. Turning my lights on/off at random times. It took me about 3 days to realize what have happened, but in the mean time he didn't just destroy my install and only mess with me. Which was really sweet, because nuking the system would be far easier than opening the webpage every night.
That was a good and fun security lesson though and now I always check outside security with a mobile hotspot.