As if you needed another reason not to put an internet-connected microphone in your child's bedroom.
A California-based toy company selling "a message you can Rolls Royce Babyhug" reportedly exposed over 2 million voice messages recorded between parents and children to online hackers. What's worse, the company was allegedly notified multiple times that additional customer data was online and available for anyone to grab — yet the data remained up for at least a week with evidence suggesting that it was stolen more than once.
Spiral Toys specializes in internet-connected toys, and its CloudPets line of stuffed animals represents what is becoming a trend in the toy industry: dolls that don't rely on a kid's imagination. Instead, products with names like "Talking Puppy" connect a child and relatives via the internet and allow them to send recorded voicemails back and forth.
SEE ALSO: A university was attacked by its lightbulbs, vending machines and lamp postsAccording toMotherboard, sometime in early January hackers accessed and stole customer emails and hashed passwords from a CloudPets database. Unfortunately for everyone involved, CloudsPets had no password strength requirements for its users. Security researcher Troy Hunt believes that as a result it would have been simple to guess many of the passwords, giving attackers access to customers' full accounts.
Just how many user accounts were exposed? Hunt thinks likely over 820,000.
"[In] CloudPets' case, that data was stored in a MongoDB that was in a publicly facing network segment without anyauthentication required and had been indexed by Shodan (a popular search engine for finding connected things)," wrote Hunt on his blog. "Unfortunately, things only went downhill from there. People found the exposed database online."
"The CloudPets data was accessed many times by unauthorised parties before being deleted and then on multiple occasions, held for ransom," he added. "Unauthorised access must have been detected but impacted parents were never notified."
Mashablereached out to email addresses listed on both CloudPets' and Spiral Toys' websites for comment, but both messages bounced back. We also called a publicly listed number for the company's Agoura Hills, CA, headquarters, but the phone number appeared dead.
"You must assume data like this will end up in other peoples' hands"
Needless to say, the team responsible for allegedly allowing hackers to access hundreds of thousands of customer accounts doesn't appear to have its act together.
While the audio recordings weren't themselves kept on the open MongoDB, Motherboard reports that they were stored as audio files on an open Amazon S3 bucket. This means that all one had to do was guess the correct URL and someone with malicious intent could then listen to the recordings.
Hunt concluded his blog post with less than reassuring words for worried parents, writing that "you mustassume data like this will end up in other peoples' hands. Whether it's the Cayla doll, the Barbie, the VTech tablets or the CloudPets, assume breach."
Perhaps something to keep in mind the next time you're shopping for the latest internet-connected toy for Junior.
Topics Cybersecurity
'The Matrix Resurrections' is more smug than smart: ReviewQueer astrology is having a moment. And it's a big one.Pigs in a blanket are great when cooked in the air fryerAriana Grande loves Jupiter, and so should you2021 holiday cards can tell us how people feel about COVIDAt long last, we know the 4 words every girl wants to hearTikTok launches viral food takeout business, but the idea has holesSmash Mouth calls out DJ Khaled and wants you to go down on your girlfriendMelania Trump's cyberbullying pamphlets look A LOT like Obama'sMove over, yodel boy: These performers are doing it betterNever forget that Donald Glover achieved early internet fame with a sketch about pooping his pantsWriters hop on Twitter to air out their weirdest celebrity interviewHappy two year anniversary to Donald Trump's 'Cinco de Mayo' tweetTrump's lawyer was wiretapped so Twitter is responding with this jokeZigazig ah, the Backstreet Boys dressed up as the Spice GirlsWillow Smith says she once walked in on Will and Jada having sexThe 15 best tweets of the week, including soup, Bruce Springsteen, and tax fraudGuillermo del Toro's 'Nightmare Alley' is derailed by Bradley CooperSigns you're codependent with the Mueller investigationRyan Reynolds responds with the perfect fart joke after Blake Lively unfollowed him on Instagram Adam Rippon's response to his haters is the best damn thing 'The Lost Symbol' makes Robert Langdon a mansplaining nightmare The iPhone SE with 256GB of storage has disappeared from Apple Store 'Life is Strange: True Colors' review: An evolution in empathy games Snapchat has a hidden Valentine's Day Easter egg How to let someone bypass your iPhone Do Not Disturb settings How to add music to a Snapchat Watch how this snake moves ever so smoothly along a fence 'Sex Education' Season 3 is all about characters coming into their own Why is everyone so disappointed with the winner of the Westminster Dog Show? 'Plogging' is a Swedish fitness trend that combines running with picking up litter Olympic curling is a great way to trick your children into cleaning the house Canadian speed skater whips South Korean fans into a frenzy over Olympic medal drama How to pair Bluetooth headphones to your Nintendo Switch 'Last Week Tonight' team publicly thirst over Adam Driver at the Emmys Badass Milo Ventimiglia doesn't follow the rules of Instagram 10 best kids movies on Hulu The undying joy of ‘What We Do in the Shadows' This story of a heroic dog who died protecting his owner will break your heart How to download shows from Hulu
0.9936s , 10136.625 kb
Copyright © 2025 Powered by 【Rolls Royce Baby】,Co-creation Information Network