• Home
  • Contact Us !
  • Privacy Policy
Snipblog
  • Home
  • News
  • Mobile
  • Internet News
  • Social Media
  • Real Estate
  • Gadgets
  • Education
  • Technology
  • Finance
  • Car 2K17-2K18
No Result
View All Result
  • Home
  • News
  • Mobile
  • Internet News
  • Social Media
  • Real Estate
  • Gadgets
  • Education
  • Technology
  • Finance
  • Car 2K17-2K18
No Result
View All Result
Snipblog
No Result
View All Result
Home Internet News

Massive Hack Attack on Educational Toy Company Exposes Parents, Kids

onkar by onkar
December 15, 2015
in Internet News, News
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Massive Hack Attack on Educational Toy Company Exposes Parents, KidsThe award-winning Hong Kong-based maker of electronic learning toys for kids on Friday announced that its Learning Lodge database was breached in a hack attack on Nov. 14.

Learning Lodge lets customers download apps, learning games, e-books, and other educational content to VTech products.

The news first surfaced on Motherboard, which last week reported that the personal information of nearly 5 million adults and more than 200,000 children was exposed. The victims are primarily parents in several countries, including the United States.

Photos and chat logs were stolen from VTech’s Kid Connect service, which lets adults use smartphones to chat with kids using a VTech tablet, Motherboard reported Monday.

VTech initially played down the news, basically saying that on Nov. 14, an unauthorized access of customer data from its Learning Lodge website had taken place.

The company later admitted that it first learned about the breach last Tuesday, via a Canadian journalist’s email asking about the incident.

That triggered an internal investigation, which turned up “irregular activity” on its Learning Lodge website.

The news surfaced after the hacker responsible for the intrusion informed Motherboard of the breach and provided files containing the stolen data. The hacker claimed to have shared the data only with Motherboard.

Weak Protection

The hacker used an SQL injection to gain root access to VTech’s servers.

The data stolen includes names; email, street and IP addresses; passwords; secret questions and answers for password retrieval; customers’ download histories; and the names, genders and birthdates of children who used VTech’s apps.

The compromised data does not include Social Security numbers, driver’s license numbers, or credit card information and data, VTech pointed out.

The company has notified all victims and is securing its systems, it said in a Monday update on the breach.

The Learning Lodge passwords were protected with the MD5 algorithm, which is widely acknowledged to be weak, security expert Troy Hunt, who maintains the Have I Been Pwned? website, told Motherboard.

Further, the secret questions were stored in plain text. Security practices at VTech reportedly were inadequate on several levels. SSL Web encryption wasn’t used, and data was transmitted unprotected. Further, VTech’s websites leaked extensive data from their databases and APIs.

The Threat Level

The danger is that most people use the same emails and passwords for many of their online accounts, said Péter Gyōngyōsi, product manager at Balabit.

“In this world, losing the key to one account is losing the key to the kingdom,” he told TechNewsWorld.

VTech “is discounting the sensitive nature of the stolen data and vastly underestimates the value of a home mailing address, child’s name, date of birth or an email address,” remarked Jeff Hill, channel marketing manager atStealthbits.

A credit card number “is less valuable” than that type of personal data, because it easily can be canceled, and anomalous purchases readily identified, he told TechNewsWorld.

The stolen data can be used to “develop targeted phishing attacks that can ultimately yield access to any number of personal accounts — credit card statements, banking accounts, 401K plans [and] healthcare accounts,” Hill said.

Risk to Children

VTech has been “colossally irresponsible,” said Beth Marcus, CEO of Playrific. “What would [it] consider personally identifying information? Shoe size — or a geolocated recent photo of a child?”

Kids are at greatest risk from people they know, or who appear to know them, she told TechNewsWorld, and they “don’t need additional information floating around to improve the ability of miscreants’ odds of successful impersonation.”

VTech needs to “decouple all information that identifies kids or anything about them from credential information everywhere in [its] system where it might be at rest,” Marcus advised.

The FCC attorneys working on COPPA “get [this], and are trying to shape rules to limit those risks without destroying opportunities for kids,” she added.

However, compliance with COPPA “may not take into account the inevitable breach scenario, after which it’s too late,” pointed out Mark Bower, global director of product management at HP Enterprise Data Security.

The KidSAFE program, designed to let vendors meet the requirements of COPPA, “requires only basic protections,” and doesn’t go far enough against modern attack vectors, he told TechNewsWorld.

COPPA and KidSAFE perhaps should be revised and enhanced, he suggested.

“This fight is worth fighting,” Marcus remarked. “There’s too much at stake. Imagine saying ‘really sorry we disclosed all that stuff about you when you were 10 — have a nice life.'”

[“source-technewsworld”]

Tags: Educational Toy CompanyExposes ParentsKidsMassive Hack Attack
Previous Post

New US Asteroid Mining Law Could Violate International Space Treaty

Next Post

Gadget Ogling: Zippy 3D Printing, Custom-Molded Earphones, and Fast-Food Buttons

onkar

onkar

Next Post
Gadget Ogling: Zippy 3D Printing, Custom-Molded Earphones, and Fast-Food Buttons

Gadget Ogling: Zippy 3D Printing, Custom-Molded Earphones, and Fast-Food Buttons

  • Trending
  • Comments
  • Latest
The 3 Main Types of Scaffolding and What They are used for

The 3 Main Types of Scaffolding and What They are used for

December 18, 2016
Microsoft’s OneNote Can Now Help With Your Maths Homework

Microsoft’s OneNote Can Now Help With Your Maths Homework

September 3, 2016
A Brief History of Mayo Stands and Other Tools and Equipment

A Brief History of Mayo Stands and Other Tools and Equipment

October 25, 2016
Modest Fashion 2023: A Comprehensive Guide

Modest Fashion 2023: A Comprehensive Guide

May 26, 2023
Asus ZenFone 2 Variant With 4GB RAM, 16GB Inbuilt Storage Launched

Asus ZenFone 2 Variant With 4GB RAM, 16GB Inbuilt Storage Launched

0
Optical Fibre Laid in 68,000 Village Panchayats: Telecom Minister

Optical Fibre Laid in 68,000 Village Panchayats: Telecom Minister

0
iPhone 6s Sports 1.8GHz Dual-Core Apple A9 SoC in Certification Listing

iPhone 6s Sports 1.8GHz Dual-Core Apple A9 SoC in Certification Listing

0
Microsoft Targeting SMBs in Punjab, Haryana for Cloud Services

Microsoft Targeting SMBs in Punjab, Haryana for Cloud Services

0
7 benefits of mobile apps for businesses

7 benefits of mobile apps for businesses

May 5, 2025

Announcing the general availability of Llama 4 MaaS on Vertex AI

May 2, 2025
Benefits of a Home Loan: Save Money on Taxes While Realizing Your Dream of Owning Your Own Home

Benefits of a Home Loan: Save Money on Taxes While Realizing Your Dream of Owning Your Own Home

April 16, 2025
The oceans of Earth once turned green, and they might turn back

The oceans of Earth once turned green, and they might turn back

April 11, 2025

Recent News

7 benefits of mobile apps for businesses

7 benefits of mobile apps for businesses

May 5, 2025

Announcing the general availability of Llama 4 MaaS on Vertex AI

May 2, 2025
Benefits of a Home Loan: Save Money on Taxes While Realizing Your Dream of Owning Your Own Home

Benefits of a Home Loan: Save Money on Taxes While Realizing Your Dream of Owning Your Own Home

April 16, 2025
The oceans of Earth once turned green, and they might turn back

The oceans of Earth once turned green, and they might turn back

April 11, 2025
  • Home
  • Contact Us !
  • Privacy & Policy

No Result
View All Result
  • Home
  • News
  • Mobile
  • Internet News
  • Social Media
  • Real Estate
  • Gadgets
  • Education
  • Technology
  • Finance
  • Car 2K17-2K18