Don’t do SECURITY. Do business SECURELY.

VTech breach exposes data of millions of parents and children

A hack of toymaker VTech's online services exposed around 4.8 million parent accounts and 6.3 million children's profiles, including photos and chat logs.

Hong Kong-based toymaker VTech suffered a breach of its online learning and app platforms. The breach was first reported by Motherboard in late November 2015. VTech later confirmed that around 4.8 million parent accounts and 6.3 million children’s profiles had been affected worldwide.

What happened

  • A hacker got into VTech’s Learning Lodge app store and its Kid Connect messaging databases and contacted Motherboard. VTech said it had not known about the access until the journalist told it.
  • Exposed data included parents’ names, email addresses, and home addresses, along with children’s names, genders, and birth dates. The hacker also obtained children’s photos and chat logs.
  • Most of the people affected were in the US, France, the UK, and Germany.
  • In January 2018 VTech agreed to pay US$650,000 to settle US Federal Trade Commission allegations that it breached children’s privacy law and had wrongly claimed the data was encrypted.

Why it mattered

This was one of the largest known breaches of children’s data. It raised concerns about the security of connected toys, and it later led to action by the US regulator.

Lessons for organisations

Organisations that collect children’s data should keep only what they need, delete it when it is no longer required, and make sure their privacy notices match the security measures they actually have in place.

Sources: Motherboard, FTC

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights