Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - IoT Connected Toys Data Breach
News & Analysis

IoT Connected Toys Data Breach

ISBuzz TeamBy ISBuzz TeamMarch 1, 2017Updated:March 2, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Internet of Things (IoT) car from being hijacked
Print
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that Spiral Toys, parent company of the popular CloudPets line of internet-connected toys, was hacked, exposing personal messages and information, Cybersecurity experts from FireMon, Imperva, InfoArmor and Lieberman Software commented below.

Paul Calatayud, Chief Technology Officer at FireMon:

paul-calatayud“I like to call IoT the IoMT as in the Internet of Malicious Things, and news of the teddy bear leak hits on two main issues. One, the growing use of open source databases, and two, putting devices on the internet.

MongoDB is becoming a common technology for use in e-commerce due to its flexibility and price (free). Like most things that are free there are hidden costs in the form of no security confirmations or common security models. This results in what I call security regression, where best practices quickly become forgotten in the rush to slap an application on the internet. Combine this with devices that are exposed to the internet and you have a combination for a hackers paradise.

Consumers need to be aware that it takes a lot of energy and investments to properly secure their information. If you have a sense the company may not be up to the task, you may want to think twice about what information you are sharing with them.”

Ben Herzberg, Security Research Group Manager at Imperva: 

 Ben Herzberg“Let’s start with the good: using a slow-to-crack algorithm (bCrypt) was a good choice, and probably prevented additional damage.

With the great increase of IoT devices, from teddy bears like the ones connecting with CloudPets to medical devices monitoring patients to connected refrigirators, our race for innovation brings a lot of cool stuff to life in a very short time, and this will continue in the next years, as there is a potential to revolutionize the way we’re living.

However, we’ve seen a lot of security glitches from these IoT companies, and they need to understand that information security is not just a ‘good-to-have.’ We’ve seen hundreds of thousands of such devices used in Denial of Service (DoS) attacks, taking down huge organizations. We’re seeing those devices being used in other malicious activities like probing websites for vulnerabilities and attempting to take over accounts.

In conclusion – every company that’s selling devices that connect to the internet must know that in that moment they become a target, and will probably not have a lot of grace time before they start getting attacked.”

Byron Rashed, Vice President of Global Marketing, Advanced Threat Intelligence at InfoArmor:

Byron Rashed“Why so many password (credentials) breaches? The answer is simple – convenience. With all forms of security, convenience suffers. Whether it be using various forms of two-factor authentication or multi-factor authentication, users need to manage and remember passwords. Best practice would dictate a different and unique password for each application. Just think how many applications the average person uses in one day – email, social media sites, banking, shopping, etc. Not only is it daunting, but it’s inconvenient; however, it has become a necessity in today’s digital age.

Companies are faced with the dilemma between ease of use and the overall customer experience versus security of accounts. Investing in technologies such as encryption and multi-factor authentication add to the cost of doing business while degrading the customer experience. Many companies do not fully assess the risk of convenience versus security.

SHA-1 and MD5 hashes can easily be cracked by automated tools on black market sites on the Dark Web were cyber criminals can get clear text passwords. Professional cyber gangs are very organized and members have areas of specialty from network infiltration to data exfiltration to monetization. Many of these organizations bring in millions of dollars in income, and some are shielded with non-extradition to the victim country.

Like every new and emerging (mainly consumer-based) technology, security is a afterthought or not planned out correctly. The IoT will bring many challenges to both companies and consumers as vulnerabilities become apparent in successful IoT attacks.”

Philip Lieberman, President & CEO at Lieberman Software:

Philip Lieberman“The legal description for this breach is gross negligence with little to no thought given to the security of the data or application.

Then again, for most IoT sales the vendor is not monetizing the data, only the device itself (a single point in time purchase for minimal margin).  The business model for IoT provides little to no incentive for security and off-shore vendors have a shield of no legal recourse for US consumers.

With any single point in time purchase of a connected device, my advice is to assume it is already compromised, every credential you enter is compromised, and there will be no improvement.  With that assumption, expectations of complete disclosure should be expected for the time being. I still have my old fashioned thermostat ready to go in case the Internet connected one loses its mind and my control.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}