<!-- mobian-agent-page publisher="time" canonical="https://time.com/4130704/vtech-hack-childrens-toys/" -->

---
description: A cyberattack targeting Hong Kong-based children&#x27;s toy manufacturer VTech has left millions of accounts compromised.
title: Everything to Know About a Massive Hack Targeting Children&#x27;s Toys
image: https://static.time.com/v3/assets/bltea6093859af6183b/bltde9b4e688a7f4b2a/69887336bc6cfc452f3da989/gettyimages-155048435.jpg?branch=production&amp;width=3840&amp;quality=75&amp;auto=webp&amp;crop=16:9
---

![](https://static.time.com/v3/assets/bltea6093859af6183b/bltde9b4e688a7f4b2a/69887336bc6cfc452f3da989/gettyimages-155048435.jpg?branch=production&width=3840&quality=75&auto=webp&crop=16:9)

* [Business](/section/business/)  
## Business  

Update your preferences in [Account Settings](/account/preferences/)  
Close
* [Tech](/tag/time-section-tech/)  
## Tech  

Update your preferences in [Account Settings](/account/preferences/)  
Close

# Everything to Know About a Massive Hack Targeting Children's Toys

<!-- video src="https://cdn.jwplayer.com/manifests/kCXAmgKD.m3u8" -->
## Video: Tech Time: Is Face Scanning the Future of Security?

[Watch (HLS stream): Tech Time: Is Face Scanning the Future of Security?](https://cdn.jwplayer.com/manifests/kCXAmgKD.m3u8) (1:53)

![Tech Time: Is Face Scanning the Future of Security?](https://cdn.jwplayer.com/v2/media/kCXAmgKD/poster.jpg?width=720)

_Published 2015-08-24. Using Biometrics, some companies are making it so that you never have to remember a password again. But is it really the most secure method? TIME Tech Editor Alex Fitzpatrick weighs in._


![Lisa Eadicicco](https://static.time.com/v3/assets/bltea6093859af6183b/blta24f1d2424cdf115/69889434cd1bba5a48700c86/lisa-eadicicco1.jpg?branch=production&width=3840&quality=75&auto=webp&crop=1:1)

by 

[Lisa Eadicicco](/author/lisa-eadicicco/)


![Lisa Eadicicco](https://static.time.com/v3/assets/bltea6093859af6183b/blta24f1d2424cdf115/69889434cd1bba5a48700c86/lisa-eadicicco1.jpg?branch=production&width=96&quality=75&auto=webp)

## Lisa Eadicicco


Update your preferences in [Account Settings](/account/preferences/)

Close

Dec 1, 2015 4:55 PM CUT

![Dream Toys 2012 - Launch Photocall](https://static.time.com/v3/assets/bltea6093859af6183b/bltde9b4e688a7f4b2a/69887336bc6cfc452f3da989/gettyimages-155048435.jpg?branch=production&width=3840&quality=75&auto=webp&crop=3:2)

The VTech InnoTab 2, Oct. 31, 2012

The VTech InnoTab 2, Oct. 31, 2012Gareth Cattermole—Getty Images

![Lisa Eadicicco](https://static.time.com/v3/assets/bltea6093859af6183b/blta24f1d2424cdf115/69889434cd1bba5a48700c86/lisa-eadicicco1.jpg?branch=production&width=3840&quality=75&auto=webp&crop=1:1)

by 

[Lisa Eadicicco](/author/lisa-eadicicco/)


![Lisa Eadicicco](https://static.time.com/v3/assets/bltea6093859af6183b/blta24f1d2424cdf115/69889434cd1bba5a48700c86/lisa-eadicicco1.jpg?branch=production&width=96&quality=75&auto=webp)

## Lisa Eadicicco


Update your preferences in [Account Settings](/account/preferences/)

Close

Dec 1, 2015 4:55 PM CUT

A cyberattack targeting Hong Kong-based children’s toy manufacturer VTech has left millions of accounts compromised, putting the data of parents and children alike at risk. The breach took place on Nov. 14; VTech discovered it 10 days later.

What should you know about the VTech hack? Find out more below:

**How many people have been affected and how?**

On Nov. 30, [VTech confirmed](http://www.vtech.com/en/press%5Frelease/2015/data-breach-on-vtech-learning-lodge-update/ "undefined") that about five million customer accounts and children’s profiles associated with those accounts have been compromised. The hacker, or hackers, was able to access data housed in VTech’s Learning Lodge app store, according to the company. The exposed data includes parents’ names, email addresses, passwords, secret questions and answers used to verify account information, IP addresses, mailing addresses, and download history. Information about children, such as names, genders, and birth dates, have also been taken.

Customers in the United States, France, the United Kingdom, Germany, Canada, Spain, Belgium, the Netherlands, the Republic of Ireland, Latin America, Australia, Denmark, Luxembourg, and New Zealand have been impacted by the breach, [according to VTech](https://www.vtech.com/en/media/faq-about-data-breach-on-vtech-learning-lodge/ "undefined").

Motherboard [reports](http://motherboard.vice.com/read/hacker-obtained-childrens-headshots-and-chatlogs-from-toymaker-vtech "undefined") that photos of children and their parents were also vulnerable. A hacker told the technology news site he or she was able to download nearly 200GB worth of photos from VTech’s Kid Connect Platform, a feature that lets children and parents exchange messages over the company’s products. Audio clips of children speaking have also reportedly been found on the server. VTech hasn’t confirmed this since the investigation is still ongoing, but did say that photos and audio clips stored in its database are encrypted while chat logs are not.

**What about credit card numbers?**

The database that was breached doesn’t store credit card data, social security numbers or drivers license numbers. VTech says payments are not processed on the Learning Lodge website, but rather via a secure third-party payment gateway.

**How did the hacker(s) get in?**

VTech’s servers were breached using a technique known as SQL injection, according to [Motherboard](http://motherboard.vice.com/read/one-of-the-largest-hacks-yet-exposes-data-on-hundreds-of-thousands-of-kids "undefined"). This is an attack in which malicious code is injected into forms found on websites, where users typically enter personal data.

The stolen account passwords were [hashed](https://msdn.microsoft.com/en-us/library/aa545602%28v=cs.70%29.aspx "undefined"), a method of hiding the characters in a password by transforming that passcode into a different string of characters. These passwords, however, were hashed using a specific algorithm known as MD5, which [has been said to be easy to crack](http://arstechnica.com/security/2013/03/how-i-became-a-password-cracker/ "undefined").

Troy Hunt, the security researcher who verified the attack as part of Motherboard’s investigation, also made [some worrisome observations](http://www.troyhunt.com/2015/11/when-children-are-breached-inside.html "undefined") about the state of VTech’s web security in general. According to Hunt, VTech doesn’t use SSL, which creates a secure connection between a website and a visitor’s browser. SSL is a commonly used security feature used across the Internet.


**Why is this hack different from others?**

The VTech hack follows several other high-profile cybersecurity incidents we’ve seen over the past year, including hacks against Sony and adult hookup site Ashley Madison. But the VTech hack is particularly unsettling for two reasons: It involves the personal data of children, and it’s unclear why VTech was storing this data in the first place. VTech writes that it uses personal information to identify its customers and track their downloads.

When asked for comment and confirmation regarding the details above, VTech pointed TIME to [this FAQ document. ](https://www.vtech.com/en/media/faq-about-data-breach-on-vtech-learning-lodge/ "undefined")

```json
[{"@context":"https://schema.org","@type":"NewsArticle","@id":"https://time.com/4130704/vtech-hack-childrens-toys/","mainEntityOfPage":{"@type":"WebPage","@id":"https://time.com/4130704/vtech-hack-childrens-toys/"},"headline":"Everything to Know About a Massive Hack Targeting Children's Toys","datePublished":"2015-12-01T16:55:48.000Z","dateModified":"2026-04-13T08:07:02.046Z","description":"Hackers can apparently access photos of parents and children","url":"https://time.com/4130704/vtech-hack-childrens-toys/","keywords":["Tech","Security"],"thumbnailUrl":"https://static.time.com/v3/assets/bltea6093859af6183b/bltde9b4e688a7f4b2a/69887336bc6cfc452f3da989/gettyimages-155048435.jpg?branch=production&width=1200&quality=75&auto=webp&crop=1200:675&height=675","author":[{"@type":"Person","name":"Lisa Eadicicco","jobTitle":null,"url":"https://time.com/author/lisa-eadicicco/"}],"articleSection":"Business","image":[{"@type":"ImageObject","url":"https://static.time.com/v3/assets/bltea6093859af6183b/bltde9b4e688a7f4b2a/69887336bc6cfc452f3da989/gettyimages-155048435.jpg?branch=production&width=1200&quality=75&auto=webp&crop=1200:675&height=675","width":1200,"height":675,"headline":"Dream Toys 2012 - Launch Photocall","caption":"Dream Toys 2012 - Launch Photocall","creditText":"Gareth Cattermole—Getty Images","representativeOfPage":true}],"publisher":{"@type":"Organization","name":"Time","url":"https://time.com/","logo":{"@type":"ImageObject","url":"https://time.com/images/logo.png","width":528,"height":156},"foundingDate":"March 3, 1923","sameAs":["https://www.facebook.com/time","https://www.instagram.com/time/?hl=en","https://twitter.com/time","https://www.pinterest.com/timemagazine"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/section/business/","name":"Business"}},{"@type":"ListItem","position":2,"item":{"@id":"/tag/time-section-tech/","name":"Tech"}},{"@type":"ListItem","position":3,"item":{"@id":"https://time.com/4130704/vtech-hack-childrens-toys/","name":"Everything to Know About a Massive Hack Targeting Children's Toys"}}]},{"@context":"https://schema.org","@type":"VideoObject","name":"Tech Time: Is Face Scanning the Future of Security?","description":"Using Biometrics, some companies are making it so that you never have to remember a password again. But is it really the most secure method? TIME Tech Editor Alex Fitzpatrick weighs in.","thumbnailUrl":"https://cdn.jwplayer.com/v2/media/kCXAmgKD/poster.jpg?width=720","uploadDate":"2015-08-24T13:07:53.000Z","contentUrl":"https://cdn.jwplayer.com/manifests/kCXAmgKD.m3u8","embedUrl":"https://time.com/4130704/vtech-hack-childrens-toys/","duration":"PT1M53S","potentialAction":{"@type":"SeekToAction","target":"https://time.com/4130704/vtech-hack-childrens-toys/?jw_start={seek_to_second_number}","startOffset-input":"required name=seek_to_second_number"}}]
```
