39 smart watches for children on the market transfer data to China.

Children’s smartwatches can help overseas parents know their child’s location at all times, but what they may not know is that the watch can autonomously take photos and record audio, transmitting sensitive data to a server in China.

At the Black Hat cybersecurity conference held on August 6, Greek researchers presented their findings from a security analysis of 39 popular children’s GPS smartwatches supply chain, revealing serious security vulnerabilities in these products.

These children’s watches are prone to being tracked by hackers, disabling and altering location functions, intercepting and deceiving received messages and voice information, replacing emergency contacts with contacts chosen by hackers, engaging in silent audio eavesdropping, and capturing photos and videos through the camera devices.

“If you have bought this kind of device for your child, burn it, smash it… because it has been compromised,” said Vangelis Stykas, Chief Technology Officer of Greek tech company Kumio, at the conference.

A survey led by the company found that 39 seemingly independent children’s smartwatches are all connected to the same server located in China for data storage, on a backend server with security vulnerabilities on Alibaba Cloud in Mainland China, at https://myaqsh.com.

Furthermore, these children’s smartwatches have 45 different vulnerabilities that could allow hackers to eavesdrop on children’s smart devices, enforce video monitoring, and take full control of the backend server storing sensitive data.

In general, children’s trackers and parental control applications require invasive permissions to operate.

Parental monitoring applications collect vast amounts of sensitive data about families and children. If such sensitive information falls into the hands of hackers or is misused, it poses numerous risks.

Researchers point out that children or family members may face harassment or even more serious consequences, depending on the nature of the malicious actors behind the scenes. The boundaries between parental monitoring and tracking software entirely depend on who has access to the children’s device data, and such companies lack even the most basic security oversight.

Especially when malicious actors overseas gain access to what should be secure connections, the situation becomes even more complicated, as revealed in this investigation.

Stykas mentioned that without parental authorization mechanisms enabled, monitoring applications can be infiltrated by hackers to run automatically and easily breach device networks.

Researchers expressed that their initial goal was just to search for vulnerabilities on a single monitoring platform, not anticipating the discovery of such widescale vulnerabilities.

They highlight that the worst part is, hackers just need a free account to launch attacks on users.

The team demonstrated the practical application of this vulnerability on-site. By remotely running scripts, they were able to prompt a children’s smartwatch to dial a phone number and provide real-time audio streaming, without any indication on the watch that it was listening, taking pictures, or being invaded by hackers.

Prior to this, “The Wire” journalist Andy Greenberg conducted firsthand testing on children’s smartwatches.

He purchased a children’s smartwatch from CJC, a Chinese manufacturer, for less than $30 from Amazon and wore it while leaving his apartment, taking the subway, and walking to the office.

During this time, researchers accurately tracked the journalist’s exact location in a Brooklyn neighborhood in New York using the watch, covertly capturing photos of him in the elevator and sitting at his desk, even eavesdropping on live conversations in the office through the microphone, clearly capturing conversations between him and colleagues. Throughout the process, the watch never displayed any signs of listening, taking photos, or being invaded by hackers.

Greenberg stated that the watch was produced by a relatively unknown manufacturer, Yiqingteng Electronics in Shenzhen, China.

The online platform that the watch relies on – the same platform thoroughly invaded by Greek researchers – is also used by several other smartwatch brands, many of which may also be susceptible to similar digital tracking attacks.

The Greek research team mentioned that they might not be the only team to discover this vulnerability since they found tampering traces dating back two years, indicating that malicious actors might still be monitoring these devices.

Despite sending over 30 emails to the manufacturers of these devices, the team has not received any responses.

“I had hoped for a better resolution to this, to tell everyone that we had fixed the problem, but that’s not the case. No one knows how this will end or what we should do next,” Stykas stated.

While manufacturers refuse to engage, an unnamed device distributor has responded and claimed to be assisting in the investigation.

“To my knowledge, they are violating every law,” Stykas mentioned at the Black Hat conference, also accusing these companies of constantly avoiding responsibility and punishment.