
The play
CloudPets were stuffed teddy bears and other plush toys that let a parent and child exchange recorded voice messages through a companion app, storing the recordings in a cloud account tied to the toy. In late December 2016 and early January 2017, independent security researchers found that a database behind the CloudPets service was reachable on the open internet with no password at all.
What the evidence says
Security researcher Troy Hunt's contemporaneous write-up, published 27 February 2017, states that the exposed database referenced roughly 821,296 user accounts and about 2,182,337 voice recordings between parents and children, left in a publicly facing network segment without any authentication required and indexed by the internet-of-things search engine Shodan. He reports being given verified access to 583,503 of the exposed email addresses, calling that a majority but not the full set of accounts. His timeline records two researchers separately attempting to warn the company on 30 and 31 December, a warning sent to the hosting provider on 4 January, the database's deletion alongside a ransom note on 7 January, further ransom demands the next day, and no further publicly reachable copies by 13 January. Hunt writes that unauthorised parties accessed the data before it was deleted and ransomed, and that affected parents were, by his account, never notified. This is a security researcher's own investigation and disclosure timeline, not a regulator's finding, and should be read as that kind of evidence.
Age fit and safety
Neither this write-up nor the FTC's own COPPA compliance FAQ assigns an age range to voice-messaging toys; the FAQ's relevance here is narrower, confirming that an audio file containing a child's voice falls within COPPA's definition of children's personal information, which is the category of data this incident exposed. Neither source states that any enforcement action followed this specific incident.
What to look for
This is an editorial reading, not additional reporting: a toy that stores a recording in the cloud is only as secure as the database behind the app, something a caregiver cannot inspect directly and must instead judge by a company's stated security practices and its history of disclosure.
- Does the company describe how recordings are stored and who can access the underlying database?
- Has the company had a prior, publicly documented security lapse, and how did it respond?
- Is there a way to delete stored recordings, and does the company say how quickly that happens?
The CloudPets case is one documented incident involving one product line; it describes what happened to that database, not a general finding about voice-recording toys as a category.
Sources & reading trail
Contemporaneous security-research write-up describing the exposed database's scope, cause, and disclosure timeline.
Source published: 27 February 2017 · Retrieved: 16 September 2026
Confirms that an audio file containing a child's voice is children's personal information under COPPA.
Source published: Not established · Retrieved: 16 September 2026
Standards, recall notices, studies and records establish the entry; the what-to-look-for reading is Toy Almanac editorial analysis. This retrospective draft does not imply the site published on the event date.