3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys.

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys. The wave of new WiFi and Bluetooth-enabled gadgets for kids means more possibilities that a toy with looser security standards could be hacked, leaving you and your child vulnerable.

We previously covered three hackable toys as investigated by Mashable. Since then, groups like Which?, a U.K.-based consumer products safety testing firm, and the U.S. Public Interest Research Group have issued their own lists of unsafe toys for 2017. Here are three of their worst offenders:

My Friend Cayla

Cayla is a smart, interactive doll that can chat with children. Her Bluetooth capability works with her app and blocks pre-loaded “bad” words and subjects, but some consumers are concerned that she may violate the Children’s Online Privacy Protection Act. Cayla was classified by the German Federal Network as an “illegal espionage apparatus” and was banned in the country after concerns that access to the doll was unsecured and she could be used to “illegally spy” on children. It’s possible to connect to Cayla even without her app installed because smartphones identify her as a hands-free headset.

Furby Connect

The latest update to Furby connects to the Furby Connect World App to provide more physical and digital ways to interact. It also has LCD-screen animated eyes and can say more than 1,000 phrases. Unfortunately, researchers found that anyone within range of its Bluetooth can connect to the toy when it’s switched on without physically interacting with it due to a lack of security features when pairing with the device. You can also connect to the Furby with a laptop, and some researchers were able to upload and play a custom audio file through the toy, which means anyone with the know-how could upload inappropriate material to play for a child.

I-Que Intelligent Robot

i-Que is an interactive robot who can talk, tell jokes and quiz children. It uses Bluetooth to pair with its app, but smartphones can identify it as a hands-free headset without even installing the app. Anyone within Bluetooth range of the toy can pair with it and use a text field in the app to make the toy say whatever they want in the robot’s own voice. Which? demonstrates a worst-case scenario of someone taking advantage of this vulnerability in the video below.

In a consumer notice about internet-connected toys released in July, the FBI suggested parents take the following steps before purchasing a “smart” toy:

  1. Research any known security issues with the toy.
  2. Only connect smart toys to trusted and secured Wi-Fi.
  3. Look into the toy’s internet and device connection security measures.
  4. Use authentication when pairing the device with Bluetooth, such as a pin or password.
  5. Stay up to date with any manufacturer security update or patches.
  6. Investigate where the user data is stored, with the company, a third party source or both.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Agentic AI Will Revolutionize Cybercrime in 2025 According to New Report

    Malwarebytes, a provider in real-time cyber protection, recently released its 2025 State of Malware report, which reveals insight into the emergence of agentic artificial intelligence (AI), plus the year’s most prominent threats and cybercrime tactics. The report details a significant uptick in the number of known ransomware attacks, the total value of ransoms paid in 2024, and how IT teams can address them. Read Now

  • ESX 2025 Announces Expanded Schedule of Events

    ESX has announced its dynamic 2025 schedule, set to provide an unparalleled experience for professionals in the electronic security and life safety industry. Taking place June 16-19 at the Cobb Galleria Centre, this year’s event features an expanded lineup of educational sessions, hands-on workshops, inspiring main stage speakers, networking opportunities, and an engaging expo floor showcasing the latest technology. Read Now

  • City of New Orleans Launches NOLA Ready Public Safety App Before Super Bowl

    The City of New Orleans Office of Homeland Security and Emergency Preparedness (NOHSEP) is pleased to announce the official launch of the NOLA Ready Public Safety App, powered by Motorola Solutions. This new mobile application is designed to enhance public safety and emergency preparedness for both residents and visitors. All individuals planning to attend major events in New Orleans, including the Super Bowl, Mardi Gras, and other large gatherings, are encouraged to download the app. Read Now

  • 5 Tips to Improve Your Password Security

    Change Your Password Day is right around the corner. Observed every year on February 1, the day aims to raise awareness about cybersecurity and underscores the importance of keeping passwords strong and up to date. Read Now

New Products

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.