3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys.

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys. The wave of new WiFi and Bluetooth-enabled gadgets for kids means more possibilities that a toy with looser security standards could be hacked, leaving you and your child vulnerable.

We previously covered three hackable toys as investigated by Mashable. Since then, groups like Which?, a U.K.-based consumer products safety testing firm, and the U.S. Public Interest Research Group have issued their own lists of unsafe toys for 2017. Here are three of their worst offenders:

My Friend Cayla

Cayla is a smart, interactive doll that can chat with children. Her Bluetooth capability works with her app and blocks pre-loaded “bad” words and subjects, but some consumers are concerned that she may violate the Children’s Online Privacy Protection Act. Cayla was classified by the German Federal Network as an “illegal espionage apparatus” and was banned in the country after concerns that access to the doll was unsecured and she could be used to “illegally spy” on children. It’s possible to connect to Cayla even without her app installed because smartphones identify her as a hands-free headset.

Furby Connect

The latest update to Furby connects to the Furby Connect World App to provide more physical and digital ways to interact. It also has LCD-screen animated eyes and can say more than 1,000 phrases. Unfortunately, researchers found that anyone within range of its Bluetooth can connect to the toy when it’s switched on without physically interacting with it due to a lack of security features when pairing with the device. You can also connect to the Furby with a laptop, and some researchers were able to upload and play a custom audio file through the toy, which means anyone with the know-how could upload inappropriate material to play for a child.

I-Que Intelligent Robot

i-Que is an interactive robot who can talk, tell jokes and quiz children. It uses Bluetooth to pair with its app, but smartphones can identify it as a hands-free headset without even installing the app. Anyone within Bluetooth range of the toy can pair with it and use a text field in the app to make the toy say whatever they want in the robot’s own voice. Which? demonstrates a worst-case scenario of someone taking advantage of this vulnerability in the video below.

In a consumer notice about internet-connected toys released in July, the FBI suggested parents take the following steps before purchasing a “smart” toy:

  1. Research any known security issues with the toy.
  2. Only connect smart toys to trusted and secured Wi-Fi.
  3. Look into the toy’s internet and device connection security measures.
  4. Use authentication when pairing the device with Bluetooth, such as a pin or password.
  5. Stay up to date with any manufacturer security update or patches.
  6. Investigate where the user data is stored, with the company, a third party source or both.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Survey: 60 Percent of Organizations Using AI in IT Infrastructure

    Netwrix, a cybersecurity provider focused on data and identity threats, today announced the release of its annual global 2025 Cybersecurity Trends Report based on a global survey of 2,150 IT and security professionals from 121 countries. It reveals that 60% of organizations are already using artificial intelligence (AI) in their IT infrastructure and 30% are considering implementing AI. Read Now

  • New Research Reveals Global Video Surveillance Industry Perspectives on AI

    Axis Communications, the global industry leader in video surveillance, has released its latest research report, ‘The State of AI in Video Surveillance,’ which explores global industry perspectives on the use of AI in the security industry and beyond. The report reveals current attitudes on AI technologies thanks to in-depth interviews with AI experts from Axis’ global network and a comprehensive survey of more than 5,800 respondents, including distributors, channel partners, and end customers across 68 countries. The resulting insights cover AI integration and the opportunities and challenges that exist with regard to security, safety, business intelligence, and operational efficiency. Read Now

  • SIA Urges Tariff Relief for Security Industry Products

    Today, the Security Industry Association has sent a letter to U.S. Trade Representative Jamieson Greer and U.S. Secretary of Commerce Howard Lutnick requesting relief from tariffs for security industry products and asking that the Trump administration formulate a process that allows companies to apply for product-specific exemptions. The security industry is an important segment of the U.S. economy, contributing over $430 billion in total economic impact and supporting over 2.1 million jobs. Read Now

  • Report Shows Cybercriminals Continue Pivot to Stealthier Tactics

    IBM recently released the 2025 X-Force Threat Intelligence Index highlighting that cybercriminals continued to pivot to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined. IBM X-Force observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks. Read Now

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.