vtech

VTech data breach exposed personal data of 200,000 children

Written by Joseph Nordqvist

Published: 06:42, November 28, 2015

The personal data of over 200,000 children was exposed after VTech, which sells electronic learning products, had its app store database, Learning Lodge, hacked.

The hackers gained access to sensitive information such as email addresses, passwords, and home addresses of 4,833,678 consumers who have bought products sold by VTech. In addition, information on the birthdays, first names, and genders of over 200,000 children was exposed.

VTech said that the hacked database stored information on customers from the US, UK, Ireland, Canada, France, Spain, Germany, Belgium, Denmark, the Netherlands, Luxembourg, Australia, New Zealand, Hong King, China, and Latin America.

In an email to customers, the company said: “Upon discovering the unauthorised access we immediately conducted a thorough investigation, which involved a comprehensive check of the affected site and implementation of measures to defend against further attacks.”

The company said it was “important to note that our customer database does not contain any credit card or banking information” nor social security numbers.”

Security expert, Troy Hunt, said he was extremely concerned by the breach.

“When it’s hundreds of thousands of children including their names, genders and birthdates, that’s off the charts,” he wrote.

“When it includes their parents as well – along with their home address – and you can link the two and emphatically say ‘Here is 9 year old Mary, I know where she lives and I have other personally identifiable information about her parents (including their password and security question)’, I start to run out of superlatives to even describe how bad that is.”



Troy Hunt analyzed the data and found that VTech doesn’t even use SSL web encryption and data such as passwords are completely unprotected.

“Taking security seriously is something you need to do before a data breach, not something you say afterwards to placate people,” he added.

According to Motherboard, the hacker, who requested anonymity, said that they were able to access VTech’s database using a technique known as SQL injection. “It was pretty easy to dump, so someone with darker motives could easily get it,” the hacker said in an encrypted chat.

Joseph Nordqvist Avatar

Other News

IQE revenue rises 43% as AI demand boosts semiconductor materials

Sep 7, 2026

German industrial production falls as car output drops sharply

Sep 7, 2026

Eurozone growth picks up, but employment barely rises

Sep 7, 2026

Why businesses replace equipment that still works

Sep 7, 2026

What happens to a product after a customer returns it?

Sep 7, 2026

Factories weigh the cost of recycled water against supply risks

Sep 7, 2026

Why invoice fraud remains a business risk as payments go digital

Sep 7, 2026

EV battery recyclers face a long wait for used packs

Sep 6, 2026

France moves business invoicing beyond the emailed PDF

Sep 6, 2026

The financing gap that can stop an export order before it ships

Sep 6, 2026

Singapore sets a benchmark for liquid-cooled AI data centers

Sep 6, 2026

Non-food sales lead a 0.6% decline in eurozone retail trade

Sep 6, 2026

Texas repair law expands access to electronics parts and tools

Sep 6, 2026

Thailand’s high-income push puts smaller firms and regional cities in focus

Sep 6, 2026

Canada’s trade surplus shrinks as exports to the US fall

Sep 5, 2026

El Niño strengthens into 2027, raising risks for food prices, power and trade

Sep 5, 2026

Nvidia agrees to buy Hugging Face for $12.93 billion, pledges to keep platform open

Sep 5, 2026

Global food prices rise as sugar leads August increases

Sep 5, 2026

A weaker currency can lift overseas profits without reviving factories at home

Sep 5, 2026

AI shortcuts may weaken managers’ judgment, researchers warn

Sep 4, 2026