child smart watch

Millions of Children-Tracking Smartwatches Are At Risk Of Being Hacked

New findings by security firm Pen Test Partners reveal that 47 million devices worldwide could be exposed and tracked thanks to a strikingly insecure cloud platform.

Throughout 2019, security researchers have discovered striking flaws about child-tracking smartwatches that could be manipulated by hackers. But new findings reported by TechCrunch show that the smartwatches had a larger problem on their hands: a very insecure common cloud platform lacking basic cybersecurity protections.

Researchers found that the cloud platform, made by Chinese electronics company and location-tracking giant Thinkrace, puts at least 47 million devices at risk of being hacked. Because each device interacts with the cloud platform either directly or through a web domain set up by a reseller, cybersecurity firm Pen Test Partners was able to all commands for the devices back to the faulty cloud platform.

“It’s only the tip of the iceberg,” Ken Munro, the founder of the company, told TechCrunch.

The firm’s findings show that most of the commands that control the devices do not require authorization, allowing hackers to gain access to a device and track its location. There is also no randomization of account numbers, allowing the researchers to access devices in bulk by increasing each account number by one.

Disturbingly, researchers were also able to access voice messages recorded and stored in the insecure cloud that were meant to be exchanged between parents and children. The device, sold by a reseller of Thinkrace’s smartwatches, is used by some five million children and parents, according to TechCrunch.

Researchers compared their findings to CloudPets, a WiFi-enabled teddy bear that left its cloud unprotected and exposed the voice recordings of two million kids.

In 2015 and 2017, Pen Test Partners disclosed the vulnerabilities to electronic makers, including Thinkrace. Some resellers fixed their vulnerable “endpoints,” TechCrunch reported, but many companies ignored the warnings, which pushed the firm to go public with its discoveries.

While consumers may not think they own a Thinkrace smartwatch, many of its devices are sold to popular companies for resale. Some of those companies include Lenovo, Vodafone, Allianz and Huawei.

That’s why Munro recommends that consumers stay away from using the devices. Users can also contact the company selling the watch to ask if their watches are manufactured by Thinkrace, and if the business depends on Thinkrace’s cloud platform.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West
  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.