SHARE
Facebook X Pinterest WhatsApp

CloudPets’ IoT Toys Earn Scathing Security Audit

thumbnail
CloudPets’ IoT Toys Earn Scathing Security Audit

Amazon and Walmart are among the retailers that have pulled CloudPets’ IoT-based toys off their shelves.

Written By
thumbnail
Sue Walsh
Sue Walsh
Jun 21, 2018

Sixteen months ago, Spiral Toys made headlines globally when an investigation revealed serious IoT security issues with its CloudPet toy. The company had been running an unsecured server which contained voice recordings of millions of children and parents, plus email addresses and passwords of nearly 1 million more CloudPet owners.

The company chose to ignore the concern and outcry about its IoT-enabled stuffed toys designed to interact with children. Auditors soon discovered that the toys lacked security measures to prevent hacking. Anyone could use the toys to communicate with children. Still, Spiral Toys did nothing.

More IoT Security Fails

Mozilla contracted cybersecurity researchers Cure53 to audit the toys and company. In addition to the existing security flaws, which the company refused to address, the audit found that a domain related to the toys had expired. This expiration left it open to phishing attacks. Someone then programmed the company’s phone number to disconnect callers, and their website wouldn’t load.

See also: IIC’s IoT security model helps fine-tune spending

“The company clearly does not care about users’ security and privacy violations and makes no effort to respond to well-meaning attack reports, further facilitating and inviting malicious actions against their users. In a world where data leaks have become more routine and products like CloudPets still sit on store shelves, I’m increasingly worried about my kids’ privacy and security,” said Mozilla Vice President of Advocacy Ashley Boyd.

Mozilla sent letters to Amazon and other retailers urging them to remove the toys from their shelves. So far Amazon, eBay, Target, and Walmart have complied.

Mozilla says the company’s refusal to respond to emails, answer calls or acknowledge the security problems illustrates one of the major problems facing the Internet of Things-manufacturers who don’t care about security.

thumbnail
Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Why Satellite Connectivity Sits at the Heart of Enterprise Network Resilience
Fánan Henriques
Feb 14, 2026
Real-time Analytics News for the Week Ending January 31
Security, Next-gen Technology, and AI-powered Insights: 2026 Predictions for Satellite IoT
Alastair MacLeod
Jan 16, 2026
Top 5 Smart Manufacturing Articles of 2025

Featured Resources from Cloud Data Insights

When AI Writes the Code, Security Must Manage the Risks
Paolo Del Mundo
Feb 18, 2026
How Can AI Improve Industrial Inventory Management (Practical Use Cases)
Luke Crihfield
Feb 17, 2026
Why Intelligence Without Authority Cannot Deliver Enterprise Value
Harsha Kumar
Feb 17, 2026
Real-time Analytics News for the Week Ending February 14
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.