The National Commission for Data Protection (CNPD) and Securitymadein.lu, as part of the bee-secure initiative, have joined forces to raise awareness of the data leakage implications of the VTECH company, after it was revealed that one of the databases of the electronic learning toys manufacturer has leaked the profiles of nearly 5 million parents and over 6 million child profiles.
Insufficient security measures on the database meant that 4,854,209 parent and 6,368,509 child profiles were leaked, according to VTECH official communication. Of an overall 190-gigabyte database that disappeared, 5,014 children and 4,190 parents in the Grand Duchy were implicated.
Parents have been advised to contact the company to find out what data is concerned, and to change their passwords and secret question and answer on all other sites for which they use the same or a similar password. The CNPD urged those concerned to not give in to blackmail should it occur, recommending that the victim instead call the police. More information on phishing can be found at https://www.bee-secure.lu/fr/glossaire/phishing.
The VTECH company was hacked on 14 November 2015, with the attacked accessing the contents of a system database named Explor@Park/ Learning Lodge, a platform which allows consumers to download VTECH content for certain toys. The anonymous attacked inserted malignant commands in the form of a site trapping and getting other data contained in the database. VTECH France decalred that no personal address had been stolen, although postal addresses had been extracted from VTECH servers.
Photo by Motherboard