Home / Software & Gaming / Security / VTech admits to toy hack that affected 6.4 million children

VTech admits to toy hack that affected 6.4 million children

Hong Kong based toy-company, VTech, has admitted that the details of more than six million children and their parents were revealed in a recent hack of its Innotab child-friendly tablet. The hack revealed not only names and addresses, but often photos that the children had taken, as well as messages sent between users through the various applications on the device.

“Regretfully our database was not as secure as it should have been,” VTech's updated FAQ page reads. On the 14th November its “Learning Lodge,” App store was broken into it said, giving a hacker access to the customer database and Kid Connect servers. This led to other sites and services bring affected, including Lumibeauxreves.com, VSmilelink.com, Sleepybearlullabytime.com and many other international VTech owned entities.

It assured concerned parents that it had now taken appropriate steps to secure its databases and various services moving forward and that none of its other online systems have been affected by this breach. It also promised that no financial details were copied away, but suggested that updating user passwords on all services wouldn't be a bad idea.

Fortunately in this case, the hacker that exposed this vulnerability was not a nefarious one. In a chat with Motherboard they revealed that they were “sickened,” that it was so easy to access such sensitive details, especially the personal images of children. “VTech should have the book thrown at them,” they said.

innotabmax

Source: VTech

In total they were able to access more than 190GB of photos and audio logs. In many cases, those can then be traced back to usernames and account details, which makes the security breach even more worrisome for those affected or using child-friendly, heavily connected devices.

“I can get a random Kid Connect account, look through the dump, link them to their circle of friends, and the parent who registered at Learning Lodge,” the hacker said. “I have the personal information of the parent and the profile pictures, emails, passwords, nicknames…of everyone in their Kid Connect contacts list.”

That's the most egregious part of this whole thing. Not that VTech was hacked – because often times it can be a case that if someone wants to hack your service, they will find a way eventually – but that the data was stored in a manner where it could all be linked together. The lack of encryption and how easy it was to piece together details from different services to paint a pretty full picture of a family.

This hack occurred around the same time that security researchers warned of the dangers of high-tech toys, pointing the finger at Mattel and its Hello Barbie toy for not taking security more seriously.

Discuss on our Facebook page, HERE.

KitGuru Says: Companies really need to start hiring on security consultants. Encryption should be mandatory for this sort of stuff and cast iron protections in place. It shouldn't even be close this easy. 

 

Become a Patron!

Check Also

Marvel Rivals has a major security issue enabling Remote Code Execution

A Remote Code Execution exploit has been discovered in Marvel Rivals, allowing hackers to remotely spread malware through the game.

4 comments

  1. But David Cameron said encryption is a tool for terrorists! At his next speech he should applaud VTech for thinking of the children!

  2. But David Cameron said encryption is a tool for terrorists! At his next speech he should applaud VTech for thinking of the children!

  3. .❝my neighbor’s mother is making $98 HOURLY on the internet❞….A few days ago new McLaren F1 subsequent after earning 18,512$,,,this was my previous month’s paycheck ,and-a little over, $17k Last month ..3-5 h/r of work a day ..with extra open doors & weekly paychecks.. it’s realy the easiest work I have ever Do.. I Joined This 7 months ago and now making over $87, p/h..Learn More right Here….
    lv..
    ➤➤
    ➤➤➤ http://GlobalSuperEmploymentVacanciesReportJobs/GetPaid/$97hourly… ❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦

  4. .❝my neighbor’s mother is making $98 HOURLY on the internet❞….A few days ago new McLaren F1 subsequent after earning 18,512$,,,this was my previous month’s paycheck ,and-a little over, $17k Last month ..3-5 h/r of work a day ..with extra open doors & weekly paychecks.. it’s realy the easiest work I have ever Do.. I Joined This 7 months ago and now making over $87, p/h..Learn More right Here….
    lv..
    ➤➤
    ➤➤➤ http://GlobalSuperEmploymentVacanciesReportJobs/GetPaid/$97hourly… ❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦.❦

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!