As if you needed another reason not to put an internet-connected microphone in your child's bedroom.
A California-based toy company selling "a message you can adult sex videoshug" reportedly exposed over 2 million voice messages recorded between parents and children to online hackers. What's worse, the company was allegedly notified multiple times that additional customer data was online and available for anyone to grab — yet the data remained up for at least a week with evidence suggesting that it was stolen more than once.
Spiral Toys specializes in internet-connected toys, and its CloudPets line of stuffed animals represents what is becoming a trend in the toy industry: dolls that don't rely on a kid's imagination. Instead, products with names like "Talking Puppy" connect a child and relatives via the internet and allow them to send recorded voicemails back and forth.
SEE ALSO: A university was attacked by its lightbulbs, vending machines and lamp postsAccording toMotherboard, sometime in early January hackers accessed and stole customer emails and hashed passwords from a CloudPets database. Unfortunately for everyone involved, CloudsPets had no password strength requirements for its users. Security researcher Troy Hunt believes that as a result it would have been simple to guess many of the passwords, giving attackers access to customers' full accounts.
Just how many user accounts were exposed? Hunt thinks likely over 820,000.
"[In] CloudPets' case, that data was stored in a MongoDB that was in a publicly facing network segment without anyauthentication required and had been indexed by Shodan (a popular search engine for finding connected things)," wrote Hunt on his blog. "Unfortunately, things only went downhill from there. People found the exposed database online."
"The CloudPets data was accessed many times by unauthorised parties before being deleted and then on multiple occasions, held for ransom," he added. "Unauthorised access must have been detected but impacted parents were never notified."
Mashablereached out to email addresses listed on both CloudPets' and Spiral Toys' websites for comment, but both messages bounced back. We also called a publicly listed number for the company's Agoura Hills, CA, headquarters, but the phone number appeared dead.
"You must assume data like this will end up in other peoples' hands"
Needless to say, the team responsible for allegedly allowing hackers to access hundreds of thousands of customer accounts doesn't appear to have its act together.
While the audio recordings weren't themselves kept on the open MongoDB, Motherboard reports that they were stored as audio files on an open Amazon S3 bucket. This means that all one had to do was guess the correct URL and someone with malicious intent could then listen to the recordings.
Hunt concluded his blog post with less than reassuring words for worried parents, writing that "you mustassume data like this will end up in other peoples' hands. Whether it's the Cayla doll, the Barbie, the VTech tablets or the CloudPets, assume breach."
Perhaps something to keep in mind the next time you're shopping for the latest internet-connected toy for Junior.
Topics Cybersecurity
This store is getting trolled hard over its Christmas adGuess which gender is more likely to be verified on Twitter? We'll wait.Snapchat inks deal with Foursquare for more precise geofiltersGlobal warming record crumbles due in part to freak Arctic warmthJimmy Fallon loves 'Gilmore Girls' and names his top four charactersApple had to buy many of its old products for its pricey design bookMeet the female Instagram artists reclaiming the memeFacebook might not detect fake news, but this Chrome extension willBET salutes President Obama with beautiful 'Love and Happiness' concertRichard Branson is bringing us the next supersonic passenger aircraftEdward Snowden rethinks that tweet about voting third partyRichard Branson is bringing us the next supersonic passenger aircraftGoogle's new PhotoScan app is an incredibly easy way to digitize old, printed photosThis surreal image of Saturn is not a paintingPeople are wasting their good tortillas on supermoon memesYour guide to prepping for 'Fantastic Beasts and Where to Find Them''Sing' for your Thanksgiving dessert: AMC is screening the musical for freeHTC's esports boss doesn't think VR is ready for pro gamingTinder launches new transSombra has arrived in 'Overwatch' Covid vaccine side effects show your immune system works, say doctors Recapping Dante: Canto 7, or Hell by the Numbers by Alexander Aciman Instagram adds templates to 'easily create' Reels Google Meet is testing AI Conversing with Brodsky, and Other News by Sadie Stein In the Darkroom with W. Eugene Smith Let the Memory Live Again, and Other News by Sadie Stein Netflix removes its $10 'Basic' plan in the US It Was Too Strong: An Interview with Todd Hido Gimme Shelter by Sadie Stein Prince Harry joins the U.S. work force to...fight misinformation? What We Talk About When We Talk About Ill What We’re Doing by Sadie Stein Fourth Wall by Sadie Stein Google Pixel owners report rampant app crashing Teeth Marks: Three Early Poems by Albert Cossery by Anna Della Subin The pandemic offered a unique chance for many people to come out as queer Is WhatsApp down? Here's what we know. The Gatorade Gx Sweat Patch was weird, neat, and ultimately kind of pointless Nail Art by Sadie Stein
1.2245s , 8611.828125 kb
Copyright © 2025 Powered by 【adult sex videos】,Pursuit Information Network