VTech Holdings Limited, the Hong Kong maker of baby monitors and electronic toys, announced that its customer database was hacked two weeks ago.
The company says an unauthorized party accessed VTech customer data housed in its Learning Lodge app store database on November 14, 2015. Learning Lodge gives its customers the ability to download apps, learning games, e-books and other educational content to their VTech products.
Upon discovering the unauthorized access, VTech claims it immediately conducted a thorough investigation, which involved a comprehensive check of the affected site and implementation of measures to defend against any further attacks. The company says its customer database contains general user profile information including names; email addresses; encrypted passwords; secret questions and answers for password retrieval; IP addresses; mailing addresses; and download histories.
In the company's statement on the incident, it says: "It is important to note that our customer database does not contain any credit card information and VTech does not process nor store any customer credit card data on the Learning Lodge website. To complete the payment or check-out process of any downloads made on the Learning Lodge website, our customers are directed to a secure, third party payment gateway. In addition, our customer database does not contain any personal identification data (such as ID card numbers, Social Security numbers or driving license numbers)."
This is where the company's reaction is a bit obtuse. The company is hoping to make good waves in public sentiment by stating that no payment information or personal I.D. data was present in the heist. While that technically may be true, a brute force hacker or semi-intelligent cracker could use the combination of customer mailing addresses, answers to secret questions, and IP addresses to correlate lots of information that render a credit card or I.D. unneeded.
For example, an attacker can correlate on the information to readily-available credit information sold on the Dark Web, and then apply for new credit cards with the address, name, and secret answer data.
Hong Kong's common law has a data privacy ordinance as well as dozens of past cases that could put the company in jeopardy. The Hong Kong government takes data privacy very seriously, and VTech should face fines and possible other civil or criminal penalties for failing to secure customer data.
Most importantly, this highlights the failings for many Internet of Things companies on the security front. Companies concentrate on developing usable devices that connect to the Internet, but secure methods of information transmission or information storage are forgotten or ignored. Especially in Hong Kong, which lacks a large community of technologists, these failings are all too common.
VTech Data Breach Highlights IoT Failings
VTech Holdings Limited, the Hong Kong maker of baby monitors and electronic toys, announced that its customer database was hacked two weeks ago.
The company says an unauthorized party accessed VTech customer data housed in its Learning Lodge app store database on November 14, 2015. Learning Lodge gives its customers the ability to download apps, learning games, e-books and other educational content to their VTech products.
Upon discovering the unauthorized access, VTech claims it immediately conducted a thorough investigation, which involved a comprehensive check of the affected site and implementation of measures to defend against any further attacks. The company says its customer database contains general user profile information including names; email addresses; encrypted passwords; secret questions and answers for password retrieval; IP addresses; mailing addresses; and download histories.
In the company's statement on the incident, it says: "It is important to note that our customer database does not contain any credit card information and VTech does not process nor store any customer credit card data on the Learning Lodge website. To complete the payment or check-out process of any downloads made on the Learning Lodge website, our customers are directed to a secure, third party payment gateway. In addition, our customer database does not contain any personal identification data (such as ID card numbers, Social Security numbers or driving license numbers)."
This is where the company's reaction is a bit obtuse. The company is hoping to make good waves in public sentiment by stating that no payment information or personal I.D. data was present in the heist. While that technically may be true, a brute force hacker or semi-intelligent cracker could use the combination of customer mailing addresses, answers to secret questions, and IP addresses to correlate lots of information that render a credit card or I.D. unneeded.
For example, an attacker can correlate on the information to readily-available credit information sold on the Dark Web, and then apply for new credit cards with the address, name, and secret answer data.
Hong Kong's common law has a data privacy ordinance as well as dozens of past cases that could put the company in jeopardy. The Hong Kong government takes data privacy very seriously, and VTech should face fines and possible other civil or criminal penalties for failing to secure customer data.
Most importantly, this highlights the failings for many Internet of Things companies on the security front. Companies concentrate on developing usable devices that connect to the Internet, but secure methods of information transmission or information storage are forgotten or ignored. Especially in Hong Kong, which lacks a large community of technologists, these failings are all too common.
Other China Tech Buzz:
GLOBAL MARKETS-Wall St extends gains on slowing but strong US labor market
China has to stabilize its housing market and address risks to its economy if it wants to avoid 'Japanification', JPMorgan says
China is now using advanced 3D-printing tech in its warplanes
Syniverse, which routes billions of texts annually for AT&T, T-Mobile, Verizon, China Mobile, and others, says in May it found it was hacked starting in 2016 (Lorenzo Franceschi-Bicchierai/VICE)
Montana close to becoming first U.S. state to completely ban TikTok
China Accuses NSA's TAO Unit of Hacking its Military Research University – Channel969
TheVoiceOfJoyce If the World is dependent on the US & China not slowing down, give China relief from Trump era tariffs. Free up the Global supply chain. In America pass the entire Infrastructure & Families Act. Give kids an opportunity to learn and adults the ability to retrain. We’ll create an economic boom. Somehow entrepreneurs will be able to fill in the gaps of production. The new Variant, it’s too soon to know it’s impact on society. Wait for the scientific verdict! Clear economic conditions are up to us! We can be proactive. It takes work!
GGRAsia Galaxy Macau gaming area probed for smoking breach- govt
Trump Admin Walks Back Tariff Exemption On Electronics
Latest China Tech News
China’s Top Court Issues First AI Judicial Guidelines, Targeting Deepfakes and Copyright Disputes
New Chinese Commercial Space Hub Is a One-Stop Military Command Center in Disguise
Sanctions Be Damned: Huawei’s $2,800 Tri-Fold Flex Signals a Nightmare Realized for Apple and Washington
Shielding China's $424 Billion Microchip Lifeline with Controlled Supply Chain
AI² Robotics Debuts AlphaBot O1 at International SME Fair, Winning Top Honors
China Accelerates E-Commerce Push Through AI Cross-Border Shifts and Regional Subsidies
Shenzhen and Changsha Forge Divergent Quantum Paths: Commercial Crossovers vs. Precision Measurement
China Standardizes Low-Altitude Infrastructure as Wuhu Air Show Drives Drone Exports and All-in-One Kits
China’s National AI Fund Backs Video Generator Kling at $18 Billion Valuation as Cities Accelerate Infrastructure
Chinese Robotics Pioneers Pivot to Embodied AI as First-Half Revenues Surge