vtech

VTech data breach exposed personal data of 200,000 children

Written by Joseph Nordqvist

Published: 06:42, November 28, 2015

The personal data of over 200,000 children was exposed after VTech, which sells electronic learning products, had its app store database, Learning Lodge, hacked.

The hackers gained access to sensitive information such as email addresses, passwords, and home addresses of 4,833,678 consumers who have bought products sold by VTech. In addition, information on the birthdays, first names, and genders of over 200,000 children was exposed.

VTech said that the hacked database stored information on customers from the US, UK, Ireland, Canada, France, Spain, Germany, Belgium, Denmark, the Netherlands, Luxembourg, Australia, New Zealand, Hong King, China, and Latin America.

In an email to customers, the company said: “Upon discovering the unauthorised access we immediately conducted a thorough investigation, which involved a comprehensive check of the affected site and implementation of measures to defend against further attacks.”

The company said it was “important to note that our customer database does not contain any credit card or banking information” nor social security numbers.”

Security expert, Troy Hunt, said he was extremely concerned by the breach.

“When it’s hundreds of thousands of children including their names, genders and birthdates, that’s off the charts,” he wrote.

“When it includes their parents as well – along with their home address – and you can link the two and emphatically say ‘Here is 9 year old Mary, I know where she lives and I have other personally identifiable information about her parents (including their password and security question)’, I start to run out of superlatives to even describe how bad that is.”



Troy Hunt analyzed the data and found that VTech doesn’t even use SSL web encryption and data such as passwords are completely unprotected.

“Taking security seriously is something you need to do before a data breach, not something you say afterwards to placate people,” he added.

According to Motherboard, the hacker, who requested anonymity, said that they were able to access VTech’s database using a technique known as SQL injection. “It was pretty easy to dump, so someone with darker motives could easily get it,” the hacker said in an encrypted chat.

Joseph Nordqvist Avatar

Other News

A weaker currency can lift overseas profits without reviving factories at home

Sep 5, 2026

AI shortcuts may weaken managers’ judgment, researchers warn

Sep 4, 2026

Alibaba updates Qwen3.8 Max as Chinese AI rivals target workplace tools

Sep 3, 2026

Uber and Wayve begin supervised autonomous rides in London

Sep 3, 2026

Dutch central bank raises London share of gold reserves to 32.1%

Sep 3, 2026

Europe’s housing squeeze is becoming a labor market problem

Sep 3, 2026

Vertiv agrees $1.45 billion deal to expand onsite power for AI data centers

Sep 2, 2026

Advanced-economy bond yields are lifting borrowing costs for developing countries

Sep 2, 2026

‘Buy Now, Pay Later’ may lift prices for shoppers who pay upfront, model finds

Sep 1, 2026

Fast delivery can shield nearby sellers from competition

Sep 1, 2026

World Bank says domestic reforms could unlock more trade within Africa

Sep 1, 2026

GoPro agrees Starman merger as action-camera maker looks to AI infrastructure

Sep 1, 2026

UK opens first challenges under £100 million AI procurement scheme

Aug 31, 2026

SLB to buy Kelvion in $4.1 billion deal as it expands into data center cooling

Aug 31, 2026

EU online sellers declared €38.8 billion in VAT through one-stop systems in 2025

Aug 31, 2026

IMF says stablecoins could cut payment costs but weaken monetary control

Aug 30, 2026

Middle East energy shock drives renewables push and fossil-fuel safeguards

Aug 30, 2026

Build-A-Bear cuts outlook as retail sales fall and wholesale growth slows

Aug 30, 2026

HP raises outlook as PC revenue climbs 18% despite lower unit volume

Aug 29, 2026

OECD growth edges up to 0.5% as G7 economies slow

Aug 29, 2026