As if you needed another reason not to put an internet-connected microphone in your child's bedroom.
A California-based toy company selling "a message you can Dead Againhug" reportedly exposed over 2 million voice messages recorded between parents and children to online hackers. What's worse, the company was allegedly notified multiple times that additional customer data was online and available for anyone to grab — yet the data remained up for at least a week with evidence suggesting that it was stolen more than once.
Spiral Toys specializes in internet-connected toys, and its CloudPets line of stuffed animals represents what is becoming a trend in the toy industry: dolls that don't rely on a kid's imagination. Instead, products with names like "Talking Puppy" connect a child and relatives via the internet and allow them to send recorded voicemails back and forth.
SEE ALSO: A university was attacked by its lightbulbs, vending machines and lamp postsAccording toMotherboard, sometime in early January hackers accessed and stole customer emails and hashed passwords from a CloudPets database. Unfortunately for everyone involved, CloudsPets had no password strength requirements for its users. Security researcher Troy Hunt believes that as a result it would have been simple to guess many of the passwords, giving attackers access to customers' full accounts.
Just how many user accounts were exposed? Hunt thinks likely over 820,000.
"[In] CloudPets' case, that data was stored in a MongoDB that was in a publicly facing network segment without anyauthentication required and had been indexed by Shodan (a popular search engine for finding connected things)," wrote Hunt on his blog. "Unfortunately, things only went downhill from there. People found the exposed database online."
"The CloudPets data was accessed many times by unauthorised parties before being deleted and then on multiple occasions, held for ransom," he added. "Unauthorised access must have been detected but impacted parents were never notified."
Mashablereached out to email addresses listed on both CloudPets' and Spiral Toys' websites for comment, but both messages bounced back. We also called a publicly listed number for the company's Agoura Hills, CA, headquarters, but the phone number appeared dead.
"You must assume data like this will end up in other peoples' hands"
Needless to say, the team responsible for allegedly allowing hackers to access hundreds of thousands of customer accounts doesn't appear to have its act together.
While the audio recordings weren't themselves kept on the open MongoDB, Motherboard reports that they were stored as audio files on an open Amazon S3 bucket. This means that all one had to do was guess the correct URL and someone with malicious intent could then listen to the recordings.
Hunt concluded his blog post with less than reassuring words for worried parents, writing that "you mustassume data like this will end up in other peoples' hands. Whether it's the Cayla doll, the Barbie, the VTech tablets or the CloudPets, assume breach."
Perhaps something to keep in mind the next time you're shopping for the latest internet-connected toy for Junior.
Topics Cybersecurity
Will Ferrell had time to canvas for the midterms. What's your excuse?Grown man Elon Musk puts out a call for ... 'ur dankest memes'Most streamed movies this week (July 2) are rather strange'Gold diggin' dog scams McDonald's customers pretending to be a stray, owner saysYes, there are 100 million rogue black holes wandering our galaxyCreepy anglerfish jack9 of the best celebrity trollsThe best apps and sites for travelersRelatable man sets fire to home while attempting to kill spiders with a blowtorchNFT marketplace OpenSea user email addresses leak after data breachNFT marketplace OpenSea user email addresses leak after data breachThe 10 types of trolls you'll spot in the wild15 dog toys that your pooch (probably) can't destroyTwitter shames Trump for doing the absolute least in the wake of explosive devicesDrowning baby kangaroo saved thanks to quick, heroic police actionYes, there are 100 million rogue black holes wandering our galaxyKendrick Lamar, Olivia Rodrigo, and artists blast Roe v Wade decision at GlastonburyCheck out this beautiful sky penis the Marines drew over CaliforniaSome good news: Doughnut the 289 accounts advocating for reproductive justice and health conversations Twitter mocks Donald Trump for 'unpresidented' spelling mistake Xbox at E3 2019: Game Pass PC subscribers won't need Xbox Live Gold Black Lives Matter website hit with more than 100 DDoS attacks this year Google Calendar scam adds malicious links to your schedule Adult toy store employees fight off armed robber by throwing dildos at him Google Calendar service restored after 3 Samsung Galaxy Fit is now available in the U.S. for $99 Steven Spielberg's 'West Side Story': Here's the first photo Student VR game is the hidden gem of E3 2019 The ballsy realism of HBO's Euphoria is worth the risk: Review Neil Gaiman explains why 'Good Omens' is so worryingly relevant today 'Big Little Lies' episode 2 recap: It's ironically about telling the truth Google promises $1 billion to fight housing crisis Weed lovers will find this Reddit gift exchange mixup hilarious Many health and wellness apps haven't done research to back up claims 12 smartphone camera bumps, ranked 'Men in Black: International' is a waste of its leads: Review Little girl sends BBC anxious letter about Big Ben, gets the perfect reply People are sharing their 'best' dad jokes on Twitter for Father's Day Samsung asks QLED TV owners to run a virus scan
2.4079s , 10131.5625 kb
Copyright © 2025 Powered by 【Dead Again】,Defense Information Network