CloudPets’ IoT Toys Earn Scathing Security Audit

CloudPets’ IoT Toys Earn Scathing Security Audit

Amazon and Walmart are among the retailers that have pulled CloudPets’ IoT-based toys off their shelves.

Written By
Sue Walsh
Sue Walsh
Jun 21, 2018

Sixteen months ago, Spiral Toys made headlines globally when an investigation revealed serious IoT security issues with its CloudPet toy. The company had been running an unsecured server which contained voice recordings of millions of children and parents, plus email addresses and passwords of nearly 1 million more CloudPet owners.

The company chose to ignore the concern and outcry about its IoT-enabled stuffed toys designed to interact with children. Auditors soon discovered that the toys lacked security measures to prevent hacking. Anyone could use the toys to communicate with children. Still, Spiral Toys did nothing.

More IoT Security Fails

Mozilla contracted cybersecurity researchers Cure53 to audit the toys and company. In addition to the existing security flaws, which the company refused to address, the audit found that a domain related to the toys had expired. This expiration left it open to phishing attacks. Someone then programmed the company’s phone number to disconnect callers, and their website wouldn’t load.

See also: IIC’s IoT security model helps fine-tune spending

“The company clearly does not care about users’ security and privacy violations and makes no effort to respond to well-meaning attack reports, further facilitating and inviting malicious actions against their users. In a world where data leaks have become more routine and products like CloudPets still sit on store shelves, I’m increasingly worried about my kids’ privacy and security,” said Mozilla Vice President of Advocacy Ashley Boyd.

Mozilla sent letters to Amazon and other retailers urging them to remove the toys from their shelves. So far Amazon, eBay, Target, and Walmart have complied.

Mozilla says the company’s refusal to respond to emails, answer calls or acknowledge the security problems illustrates one of the major problems facing the Internet of Things-manufacturers who don’t care about security.

Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

Powering Smart Cities: Designing Rugged PoE for Outdoor and Industrial Edge Deployments
Jordan Smith
Apr 2, 2026
Securing Time Synchronization: The Overlooked Control in Modern Cybersecurity
Liz Ticong
Apr 2, 2026
Why Satellite Connectivity Sits at the Heart of Enterprise Network Resilience
Fánan Henriques
Feb 14, 2026
Real-time Analytics News for the Week Ending January 31

Featured Resources from Cloud Data Insights

Powering Smart Cities: Designing Rugged PoE for Outdoor and Industrial Edge Deployments
Jordan Smith
Apr 2, 2026
Securing Time Synchronization: The Overlooked Control in Modern Cybersecurity
Liz Ticong
Apr 2, 2026
AI-Powered Network-as-a-Service: Enabling “Lights Out” Networking for the AI Era
Jim Sullivan
Apr 2, 2026
The Industry is Designing AI for Machines, Not for Humans. That is Not a Mistake.
Onur Alp Soner
Apr 1, 2026
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.