Data breach at HK toy maker VTech highlights broader problems


  • TECH
  • Monday, 30 Nov 2015

Hack episode: The stolen data included information about customers who download children's games, books and other educational content,

HONG KONG: The theft of toy maker VTech Holdings Ltd's database highlights a growing problem with basic cybersecurity measures at small, non-financial companies that handle electronic customer data, industry watchers said.

The hacked data at VTech included information about customers who download children's games, books and other educational content, the Hong Kong-based toy maker said. The breach also included information relating to children.

As more devices are connected to the Internet and as companies increasingly collect personal information about their customers, such attacks are expected to increase.

"Smaller companies might be targeted less often, but the implications ... can be just as serious," said Bryce Boland, Asia Pacific chief technology officer of cyber security firm FireEye. "As larger companies implement stronger security measures, smaller companies become relatively easy targets for cybercrime."

VTech has a market value of HK$21.9bil (RM11.9 bil). Tech giant Apple Inc has a market capitalisation of US$657bil (RM2.7tril).

In VTech's case, information that should have been obscured and unrecoverable if the database were breached - such as passwords and secret answers - either wasn't obscured at all or was done so improperly, said Larry Salibra, founder and chief executive of crowd-sourced bug-testing platform, Pay4Bugs.

Salibra said these types of security measures were basic best practices that don't require a lot of money. "This seems to be a trend. Hardware manufacturers really don't value software skills - I would imagine because they don't see any immediate positive impact to their bottom line," Salibra said.

"Software talent is an easy place to be cheap with minimal consequences until something like this happens."

VTech said in a statement that about five million customer accounts and related children's' profiles worldwide were affected. It did not break out how many profiles belonged to parents and how many to children. News site Motherboard reported that data belonging to some 4.8 million parents and more than 200,000 children was taken.

The site said it had spoken to a hacker who claimed to be behind the attack, who said he planned to do "nothing" with the data. Motherboard's report could not be independently confirmed.

VTech said the breached database included names, email addresses, passwords, secret questions and answers for password retrieval, IP addresses, mailing addresses, download histories and children's names, genders and birth dates.

The company, which sells children's tablets, electronic learning toys and baby monitors, said the targeted database did not include credit card information, ID card numbers, Social Security numbers or drivers licence numbers.

Vtech said it has taken steps to prevent further attacks but did not provide details. It said it has emailed every account holder.

Vtech's stock has fallen 22% this year. Shares and trade in other VTech securities were suspended on morning. — Reuters

Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

AI spending worries cast gloom over Alphabet, Microsoft
Electric cars and digital connectivity dominate at Beijing auto show
Most global tech leaders see their companies unprepared for AI
India plans curbs on suspect bank accounts to fight cyber fraud, sources say
Tech companies plug into India's smaller cities for talent
Tencent pushes wider adoption of AI-powered smart mobility system from a vehicle’s cockpit to the factory floor
Artificial intelligence offers an opportunity to improve EV batteries
Apple still leads high-end smartphone sales in China, but Huawei and Honor are catching up
Brave China ‘cancer warrior’ dies two days after 25th birthday, final wish to find brother a girlfriend left unfulfilled, leaves netizens devastated
Meta shares plunge as prolonged AI spending plans unnerve investors

Others Also Read