CloudPets' IoT Toys Earn Scathing Security Audit - RTInsights

CloudPets’ IoT Toys Earn Scathing Security Audit

CloudPets’ IoT Toys Earn Scathing Security Audit

Amazon and Walmart are among the retailers that have pulled CloudPets’ IoT-based toys off their shelves.

Written By
Sue Walsh
Sue Walsh
Jun 21, 2018
2 minute read

Sixteen months ago, Spiral Toys made headlines globally when an investigation revealed serious IoT security issues with its CloudPet toy. The company had been running an unsecured server which contained voice recordings of millions of children and parents, plus email addresses and passwords of nearly 1 million more CloudPet owners.

The company chose to ignore the concern and outcry about its IoT-enabled stuffed toys designed to interact with children. Auditors soon discovered that the toys lacked security measures to prevent hacking. Anyone could use the toys to communicate with children. Still, Spiral Toys did nothing.

More IoT Security Fails

Mozilla contracted cybersecurity researchers Cure53 to audit the toys and company. In addition to the existing security flaws, which the company refused to address, the audit found that a domain related to the toys had expired. This expiration left it open to phishing attacks. Someone then programmed the company’s phone number to disconnect callers, and their website wouldn’t load.

See also: IIC’s IoT security model helps fine-tune spending

“The company clearly does not care about users’ security and privacy violations and makes no effort to respond to well-meaning attack reports, further facilitating and inviting malicious actions against their users. In a world where data leaks have become more routine and products like CloudPets still sit on store shelves, I’m increasingly worried about my kids’ privacy and security,” said Mozilla Vice President of Advocacy Ashley Boyd.

Mozilla sent letters to Amazon and other retailers urging them to remove the toys from their shelves. So far Amazon, eBay, Target, and Walmart have complied.

Mozilla says the company’s refusal to respond to emails, answer calls or acknowledge the security problems illustrates one of the major problems facing the Internet of Things-manufacturers who don’t care about security.

Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Featured Resources from Cloud Data Insights

Real-time Analytics News for the Week Ending May 23
Zero Trust Is Not a Product You Buy. But It’s Not a War You Win Alone, Either
Jamie Pugh
May 23, 2026
AI Workload Accelerators: Which Gives You the Biggest Bang for the Buck?
Why Legacy Data Stacks Are Failing in the Age of AI
Denzil Wessels
May 21, 2026
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.