VTech hacker says he downloaded 190GB of child and parent photos, and chat logs between parents and children from late 2014 until November 2015
Hacker Obtained Childrens' Headshots and Chatlogs From Toymaker VTech — If storing the personal data of almost 5 million parents …
Context & Ripple Effects
Three days after [[a:837131|VTech's servers were breached with data on some 4.8 million parents and 200,000 kids at risk]], the story has escalated from account records to intimate media: the attacker now says he holds 190GB of children's headshots and parent-child chat logs spanning late 2014 to November 2015.
That claim lands on top of [[a:837159|Troy Hunt's teardown showing plaintext security questions, weakly hashed passwords, no SSL, and kid profiles matched to home addresses]], and VTech has already confirmed about 5 million Learning Lodge accounts were accessed. The gap between what VTech stored and what it secured is the actual story.
First-order effects
- Parents whose family photos and messages with their children sit in an unknown third party's hands face exposure that cannot be rotated like a password — the data itself is the leak.
- VTech must now scope whether the 190GB media haul is real, since its earlier confirmation covered account records and kids' profiles, not necessarily bulk photo and chat exfiltration.
Second-order effects
- Regulators get their test case: the breach's severity — children's imagery tied to home addresses — is exactly the profile that drew the FTC's attention, culminating in the eventual $650K FTC fine against VTech.
- Connected-toy makers across the category face forced scrutiny of their own data retention practices, because the VTech record shows what happens when chat logs between parents and children are stored server-side by default.
Third-order effects
- If the pattern holds, children's data becomes its own liability class for hardware companies, pushing toy makers toward on-device storage and deletion defaults rather than centralized app-store archives like Learning Lodge.
- Enforcement against IoT toys sets a de facto security floor — SSL, hashing, minimal retention — for an industry that previously treated compliance as optional.
The trend: Connected toys are colliding with child-privacy enforcement, forcing manufacturers to treat kids' stored media and communications as regulated infrastructure rather than product features.