Hong Kong-based toymaker VTech suffered a breach of its online learning and app platforms. The breach was first reported by Motherboard in late November 2015. VTech later confirmed that around 4.8 million parent accounts and 6.3 million children’s profiles had been affected worldwide.
What happened
- A hacker got into VTech’s Learning Lodge app store and its Kid Connect messaging databases and contacted Motherboard. VTech said it had not known about the access until the journalist told it.
- Exposed data included parents’ names, email addresses, and home addresses, along with children’s names, genders, and birth dates. The hacker also obtained children’s photos and chat logs.
- Most of the people affected were in the US, France, the UK, and Germany.
- In January 2018 VTech agreed to pay US$650,000 to settle US Federal Trade Commission allegations that it breached children’s privacy law and had wrongly claimed the data was encrypted.
Why it mattered
This was one of the largest known breaches of children’s data. It raised concerns about the security of connected toys, and it later led to action by the US regulator.
Lessons for organisations
Organisations that collect children’s data should keep only what they need, delete it when it is no longer required, and make sure their privacy notices match the security measures they actually have in place.
Sources: Motherboard, FTC
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.