VTech Electronics Limited (FTC Matter/File No. 162 3032)
- Document
- 8 January 2018
- Event
- 8 January 2018
- Retrieved
- 16 September 2026
The play
VTech's Kid Connect was a messaging app bundled with the company's children's tablets and camera toys, letting a child exchange messages, photos, and drawings with contacts a parent had approved, including adults who installed the companion app. Parents set up Kid Connect through VTech's Learning Lodge app store, and by November 2015 close to 638,000 children had a Kid Connect account, according to the federal complaint later filed against the company. On 8 January 2018 the United States, acting for the FTC, filed a complaint against VTech Electronics in the Northern District of Illinois, alongside a proposed settlement.
What the evidence says
The complaint alleges that in November 2015 a hacker exploited commonly known and reasonably foreseeable vulnerabilities to reach VTech's test environment and then its live systems, where the company stored parents' names, addresses, emails, and security questions in clear text, alongside children's usernames linked back to their parents' records. Children's photos and audio files were encrypted, the complaint states, but the same breached database held the decryption keys, which would have let the hacker access that material in a readable format. VTech, the complaint says, did not detect the intrusion itself; it learned of it only after a journalist contacted the company. The complaint separately alleges that VTech's privacy policy, in force from October 2012 to January 2016, told parents that personal information would be transmitted encrypted using HTTPS technology, a statement the complaint calls false or misleading given what it alleges about the actual transmission of registration data. The case's own docket page records these as allegations resolved by a stipulated order, not as admissions VTech made independent of settling.
Age fit and safety
Neither document sets a play-appropriate age range; Kid Connect was built for children old enough to type messages to approved contacts. The relevant safety finding is about data handling, not developmental fit: the complaint describes children's account data, once created, as reachable through the same systems that held their parents' information.
What to look for
The stipulated order required VTech to pay $650,000 and to build a written, comprehensive information security program with administrative, technical, and physical safeguards — a structural remedy a caregiver cannot see on a shelf but can ask a current connected-toy maker whether it has adopted something comparable.
- Does the maker say how registration and account data are transmitted and stored, and whether it is encrypted?
- Is there a stated process for how the company detects and discloses a data breach?
- Does a privacy claim about encryption match what the company's own technical documentation describes?
A settled complaint records allegations the company chose not to litigate, not a court's finding of fact; the remedies it imposed are, however, a matter of public record.
Sources & reading trail
FTC's own case docket confirming the complaint filing date, civil action number, and the stipulated order resolving the matter.
Source published: 8 January 2018 · Retrieved: 16 September 2026
Alleges the November 2015 breach mechanics, the data exposed, and the COPPA and misrepresentation counts against VTech.
Source published: 8 January 2018 · Retrieved: 16 September 2026
Sets the $650,000 civil penalty and requires a comprehensive written information security program.
Source published: 8 January 2018 · Retrieved: 16 September 2026
Standards, recall notices, studies and records establish the entry; the what-to-look-for reading is Toy Almanac editorial analysis. This retrospective draft does not imply the site published on the event date.