Security Flaws in Smart Toys Could Expose Kids to Hackers
.jpg)
UK consumer watchdog Which? brought on cybersecurity experts NCC Group to evaluate the safety of seven popular smart toys from major retailers including Amazon, Smyths, Argos, and John Lewis.
NCC said it found an alarming number of issues that could potentially put children at risk.
“Across all seven toys we found 20 noteworthy issues – two were high risk, three were a medium risk and the remainder were low risk,” the group said.
Karaoke toys, Singing Machine SMK250PP and TENVA were among those put through their paces by the team. NCC found that neither of the devices required authentication, such as a Pin code or Bluetooth connection.
This lapse in security means that anyone could connect to the toys and send recorded messages to a child.
“While the child cannot send messages back, an attack in Bluetooth range (around 10 metres) could suggest to the child, ‘come outside to get some free sweets’, for example.” the group said.
A similar issue was recently discovered in a popular children’s Vtech walkie talkie, KidiGear.
“A pair of walkie talkies investigated as part of this security assessment allowed for children to communicate with each other, within a range of up to 150 meters. There was no mutual authentication between the pairs of walkie talkie devices,” NCC Group said.
“This means that if an attacker purchased the same set of toys and was in the range of an unpaired, powered-on walkie talkie, they would be able to successfully pair with it and engage in a two-way conversation with the child user under certain conditions.”
However, Vtech has said this is a highly unlikely scenario as the pairing of the devices cannot be initiated by a single device. To pair, both devices must be activated at the same time within 30 seconds to connect. After a device is paired it cannot be paired with a third one.
In addition, NCC found that the karaoke toys were vulnerable to “second-order IoT attacks”, which involves someone using the toys to exploit another voice-controlled device, such as a nearby Amazon smart speaker.
“While different smart home configurations will exist, it is not inconceivable that some homes might have digital assistants configured to open smart locks on front doors, for example. One can thus imagine an attacker outside of a property, connecting without authentication to a Bluetooth toy to stream audio commands to enact a second-order objective, such as ‘Alexa, unlock the front door’.”
A similar attack could enable hackers to order goods from the victim household’s Amazon account and intercept them, according to Which?
Which? first investigated the safety of smart toys in 2017, testing a range of toys that featured a network connection, app or other smart interactive feature.
“We found concerning vulnerabilities at that time, and so it’s extremely worrying that two years on we are here reporting similar issues,” the group said.
Which? said it has shared its findings with industry body the British Toy and Hobby Association, and the Department for Culture, Media and Sport.
“Smart toys are one of the key areas identified by the government’s drive to make connected products ‘secure by design’.
“We’re calling on the toys industry to ensure that unsecure products like the ones we’ve identified are either modified or ideally made secure before being sold in the UK.”
source digit
Industry: Cyber Security

Latest Jobs
-
- Network Security Engineer
- Germany
- €550 a day
-
German- based contract opportunity This is an onsite based position, we would need the Network Security engineer to be able to work on the client site 5 days a week Seeking an experienced Network Security Engineer for a leading technology company. Strong expertise in firewall/IPS solutions, proxy solutions, and certificate management is required. Good hands-on experience in networking and web-related technologies necessary. Strong problem-solving skills and the ability to work under pressure are essential. we are looking for a Network Security Engineer with the following experience: · Expertise in Administration, Management & Troubleshooting of Firewall / IPS solutions / Proxy solutions/Certificate Management Solutions · Good Hands-on Experience on security devices (PaloAlto/ /McAfee Proxy/CISCO ISE/Certificate Management) · Good Hands-on Experience in Networking with skills of switching, routing & wireless Technologies · Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocol · Configuration of NAT / PAT, firewall policies, profiling, objects, AD-Integration, backup – restore · Knowledge of Subnetting TCP/IP Communication, VLSM Configuration of VLAN VTP · Configuration of Routing Protocols e.g. RIPv1 & v2, OSPF, EIGRP, BGP Knowledge of standard and extended ACL 12 month contract
-
- IAM Consultant
- N/A
- Upto £110,000 depending on level of position
-
Identity Access Management (IAM) Consultant Location: Germany We are seeking an experienced IAM consultants in Germany. we are looking for people from consultant through to Architect, The ideal candidate will have previous IAM deployment experience and be fluent in German. Key responsibilities: Design and implement IAM solutions for clients Provide expertise on industry best practices and standards Troubleshoot and resolve IAM-related issues Work closely with clients to understand their business requirements and provide solutions to meet those needs Qualifications: Previous deployment experience with IAM solutions Fluency in German Strong understanding of IAM technologies and principles Excellent communication and project management skills If you are an experienced IAM consultant with a strong track record of delivering successful projects, please apply today.
-
- ForgeRock Consultant
- Spain
- Upto €85000 plus benefits
-
ForgeRock deployment consultant is needed for this expanding IT Services business within Spain, to act as their ForgeRock technical lead, Responsibilities include: High level and low level design, Scoping the techical needs of the project design, configure, develop and test the forgeRock deployment. We are looking for a strong IAM consultant ideally with ForgeRock experience, Must have strong Oauth 2.0, SAML and API experience
-
- IAM Consultant
- France
- Upto €85000 plus benefits
-
An Identity & Access Management Consultant is needed for an expanding IT Security consultancy, based in France. (Remote role with monthly office meet-ups) The Identity & Access Management Consultant will be responsible for the technical design and implementation of Identity & Access Management/IAM products for a wide variety of clients. Deliver bespoke end-to-end consultancy service to our clients, from gathering requirements through to implementation. Work in a close team designing, developing, and implementing first-class IAM solutions. Manage client relationships, working closely with key stakeholders to continually evaluate business requirements and ensure the highest quality solution delivery. If you are interested we are looking for an individual with Previous experience working within the IAM or CIAM field is essential, Strong knowledge with SAML and Oauth and ideally OpenID Previous experience from any of these technologies: One Identity, SailPoint, Saviynt, Ubisecure, Ping Identity, would be advantageous