Updated
Updated · The New York Times · Aug 14
Researchers Hijack 36 Million Kids' Smartwatches, Turning Cameras and Mics Into Spy Tools
Updated
Updated · The New York Times · Aug 14

Researchers Hijack 36 Million Kids' Smartwatches, Turning Cameras and Mics Into Spy Tools

2 articles · Updated · The New York Times · Aug 14

Summary

  • At Black Hat in Las Vegas, Kumio researchers showed a reporter's kids smartwatch could be remotely tracked and its microphone and camera silently activated for eavesdropping and photos.
  • The attack required no prior details about the child and also let intruders intercept or spoof messages and, on some models, change emergency contacts without parents noticing.
  • Dozens of cheap white-label watches sold under brands including Aimoto Smart, Garett Kids, KidiWatch, SafeKid, SaveFamily and Wonlex trace back to platforms such as NewGPS2012, SETracker and SinoTrack.
  • Only 1 of 3 affected companies had taken corrective steps after disclosure, and the researchers said they found signs others may already have accessed the systems.
  • The findings add to a broader estimate that about 36 million children's GPS watches may be exposed, underscoring calls for parents to favor established brands with stronger security.

Insights

How can one hidden backend flaw let hackers spy on millions of children’s watches sold under dozens of different brand names?
If changing smartwatch brands changes only the sticker, how can parents tell whether a child’s GPS watch is actually safe?
Are white-label kids’ wearables creating a supply-chain security trap regulators and families can no longer ignore?