Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a22d5b82aceca594

Jump to content

2017 CloudPets data breach

From Wikipedia, the free encyclopedia
(Redirected from CloudPets)
CloudPets data breach
DateFebruary 2017
TypeCyberattack, Data breach
ThemeRansomware, insecure database
OutcomeOver 820,000 user records and 2.2 million voice recordings leaked

CloudPets were a line of Internet-connected soft toys manufactured by now defunct Spiral Toys that was the subject of numerous security vulnerabilities in February 2017.[1][2] The plush teddy bear-style toys used Bluetooth to connect to a parent's smartphone to allow distant family members to send voice messages to the toy, and allow children to send voice messages back.[3]

Security researchers demonstrated that the toy itself was insecure and could be trivially accessed via Bluetooth. The personal records of over 820,000 owners of the toy[4] were stored in an insecure MongoDB database. Attackers also replaced the database with a ransom demand pointing to a Bitcoin address.[5] Data retrieved from the CloudPets database was sent to the Australian security researcher Troy Hunt who included it in Have I Been Pwned?, a database of users whose data has been compromised. The database of user records also contained links pointing to over 2.2 million audio files hosted on Amazon Web Services containing the voice messages sent to and from the toys.[4][6] Hunt stated that the database hack was "ridiculously easy".[7]

Following disclosure of security vulnerabilities, CloudPets started enforcing stronger password requirements on users of the service—they had previously not enforced any password complexity requirements and their documentation had suggested short, weak passwords.[3] Numerous journalists and security researchers including Hunt noted that the company was non-responsive to disclosures from security researchers and enquiries from journalists.[4]

See also

[edit]

References

[edit]
  1. Mathews, Lee. "The Latest Privacy Nightmare For Parents: Data Leaks From Smart Toys". Forbes. Retrieved 2017-08-06.
  2. Kan, Michael. "Smart teddy bears involved in a contentious data breach". Network World. Archived from the original on March 1, 2017. Retrieved 2017-08-06.
  3. 1 2 Hern, Alex (2017-02-28). "CloudPets stuffed toys leak details of half a million users". The Guardian. ISSN 0261-3077. Retrieved 2017-08-06.
  4. 1 2 3 Larson, Selena (2017-02-27). "Stuffed toys leak millions of voice recordings from kids and parents". CNNMoney. Archived from the original on February 28, 2017. Retrieved 2017-08-06.
  5. "Children's messages in CloudPets data breach". BBC News. 2017-02-28. Retrieved 2017-08-06.
  6. "CloudPets' data breach underlines need for secure cloud apps". ComputerWeekly. Retrieved 2017-08-06.
  7. Cooper, Luke (2017-02-28). "Millions Of Private Messages Between Parents And Kids Hacked In Cloud Pets Security Breach". Huffington Post. Retrieved 2017-08-06.