On 27 November 2015 Motherboard published a story by Lorenzo Franceschi-Bicchierai about a toymaker. An anonymous hacker had sent the site a database copied from Learning Lodge, the app store behind VTech's children's tablets, and from Kid Connect, which lets a child message a parent's phone. It held 4,833,678 parents' email addresses and more than two hundred thousand children's profiles: first names, genders and birthdays, each tied to a parent's home address. The way in, the hacker said, had been SQL injection, a technique older than most of the children in the file. VTech confirmed the intrusion and dated the unauthorised access to 14 November, Hong Kong time. Its spokeswoman, Grace Pang, told the reporter the company had not known until he alerted them.
Troy Hunt, who runs the breach index Have I Been Pwned, was given the files and published his findings the next day. There was no SSL anywhere, he wrote: passwords, parents' details and children's information all travelled in the clear. Passwords were stored as unsalted MD5 hashes; he turned the first one back into text — welcome81 — instantly. Security questions and their answers sat in plain text. API calls returned raw SQL statements; the stack rested on Flash and ASP.NET 2.0. Rather than assume it was genuine, Hunt wrote to subscribers of his own service whose records were in the dump, asking each to confirm a birth month or a city; six did. The children in the file had been five years old on average when their accounts were made.
What separated this from an ordinary breach came out over the days that followed. The hacker had also taken photographs — the headshots parents and children were invited to make for their Kid Connect profiles — together with chat logs running back to late 2014 and audio recordings, some 190 gigabytes in all. He told Motherboard he had no plan to profit from any of it, and said that it made him sick he had been able to get it. VTech's own accounting settled the scale: 4,854,209 parent accounts and 6,368,509 children's profiles across sixteen countries. The largest share was American, 2,212,863 parents and 2,894,091 children, then France, the United Kingdom, Germany and Canada. Something over a million of the parent accounts — about 1.2 million — had Kid Connect enabled.
The company suspended Learning Lodge, Kid Connect and thirteen other sites, brought in the security firm FireEye to run the incident response, and within days Hong Kong's Privacy Commissioner opened a compliance check. On 15 December the South East Regional Organised Crime Unit arrested a 21-year-old man in Bracknell, Berkshire, on suspicion of offences under sections 1 and 2 of the Computer Misuse Act; the unit's cyber crime head, Craig Jones, said the investigation was at an early stage. He was never named, and no charge or conviction has since been reported. In February 2016 VTech rewrote its terms so that customers acknowledged data sent to it might be intercepted by unauthorised parties. On 8 January 2018 the Federal Trade Commission announced its first connected-toy case.
A brave new world of hacking
On 10 November 2015 prosecutors in Manhattan unsealed a twenty-three-count indictment against Gery Shalon, 31, Joshua Samuel Aaron, 31, and Ziv Orenstein, 40. Its centrepiece was the 2014 intrusion at JPMorgan Chase — contact details for 76 million households and 7 million small businesses — which prosecutors described as the largest theft of customer data from a US financial institution. The bank was one of twelve victims. E*Trade, Scottrade, TD Ameritrade, Fidelity and Dow Jones, publisher of The Wall Street Journal, were among the rest — more than 100 million records in all. The counts ran to securities fraud, wire fraud, identity theft, illegal internet gambling and money laundering, because the stolen lists were feedstock: shares were talked up, then sold by callers working from names the intrusions supplied. Shalon and Orenstein were also said to have run at least twelve unlicensed online casinos since 2007. Preet Bharara, the US Attorney, called the scheme breathtaking in scope and in size, a brave new world of hacking for profit. Shalon and Orenstein had been arrested in Israel that July; Aaron, living between Moscow and Tel Aviv, surrendered in December 2016.
The argument after Paris
On the evening of Friday 13 November coordinated attacks in Paris and Saint-Denis killed 130 people. Within days the encryption argument had resumed, on evidence that never arrived. A Forbes headline of 14 November said the attackers had used a PlayStation 4 to plan the attacks; it was rewritten to say they may have. The remark under it — Belgium's interior minister, Jan Jambon, on monitoring PlayStation traffic — predated the attacks and was not about them. The New York Times reported the attackers were believed to have used encryption, then amended it: officials believed so but offered none. On 17 November Brian Krebs recalled an August memo by the intelligence community's Robert Litt: opinion could turn after a terrorist attack. In Britain the Home Secretary, Theresa May, published a draft Investigatory Powers Bill that month; it received Royal Assent a year later. Elsewhere the month was commercial: card-stealing malware in tills at more than fifty Sheraton and Westin hotels, disclosed on 20 November, and Hilton's on the 24th; Dell's eDellRoot certificate, shipped with its private key since August — the Digital Guard desk's story; and Comcast resetting 200,000 passwords while denying one.
Signed in London, missing at home
On 12 November 2015 Narendra Modi and David Cameron issued a joint statement in London that folded cyber security into a new Defence and International Security Partnership. The text recorded satisfaction at the progress made at that year's India–UK Cyber Dialogue, committed both governments to promote cyber security, combat cyber crime and advance voluntary norms of responsible state behaviour, and undertook to improve cooperation between their technical, law-enforcement, research, standards and testing and capacity-building institutions, with public–private partnerships to support all of it. They welcomed the 2015 report of the United Nations Group of Governmental Experts and said they looked forward to broader agreement on the principles that should guide states in cyberspace.
What India did not have was closer to home. Seven weeks earlier, on 21 September, the Department of Electronics and Information Technology had published a draft National Encryption Policy requiring citizens to retain plain-text copies of their encrypted communications for ninety days and produce them on demand; it was withdrawn the next day after an outcry. Gulshan Rai had taken office earlier that year as the country's first National Cyber Security Coordinator. CERT-In logged 49,455 incidents across 2015, more than half of them website defacements. But there was no data-protection statute and no breach-notification clock, so a disclosure like VTech's would have had nothing in Indian law to be measured against. Both arrived much later: CERT-In's April 2022 directions imposed a six-hour reporting rule, and the Digital Personal Data Protection Act of 2023 treats everyone under eighteen as a child and forbids tracking, behavioural monitoring and advertising directed at them.
Google opens TensorFlow, and the field follows
On 9 November 2015 Google released TensorFlow under the Apache 2.0 licence. Jeff Dean and Rajat Monga presented it as the Brain team's replacement for DistBelief, the 2011 system they called narrowly targeted, difficult to configure and tightly coupled to Google's internal infrastructure; by their account the new library was twice as fast on some benchmarks, had built image search in Google Photos and had improved speech recognition in the Google app by 25 per cent. Six days earlier the same research had appeared in a shipping product: Smart Reply, two recurrent networks that read an incoming message into what its authors called a thought vector and wrote three short answers back, reaching Inbox on Android and iOS that week. Microsoft put its Distributed Machine Learning Toolkit on GitHub on the 12th, and IBM's SystemML had entered the Apache Incubator on the 2nd. The framework Google gave away that month is why the later desks in this archive describe an ecosystem rather than a few laboratories.
The same key in every laptop
On 24 November 2015 Dell acknowledged that a certificate installed by its Dell Foundation Services support application had, in its words, unintentionally introduced a security vulnerability. The certificate, eDellRoot, sat in the Windows trusted root store with its private key beside it, the same key on every machine, so anyone who extracted it could mint certificates the laptop would trust and read its HTTPS traffic. Dell said it was not malware or adware but a way of passing the service tag to online support, published removal instructions and pushed an update that day; the statement deeply regretted the matter without apologising, a distinction critics noted. A second self-signed root with its key attached, DSDTestProvider, turned up in Dell System Detect the next day, and Microsoft's advisory of 30 November stripped both of Windows's trust. Earlier that month Dr.Web had named Linux.Encoder.1, reckoned the first ransomware for Linux servers; Bitdefender broke it within days because its keys were seeded from the system clock. The durable lesson was not about certificates but about what a manufacturer adds after the operating system is built.
⏳ Time capsule — November 2015
- On 8 November Myanmar held its first openly contested general election since 1990; the National League for Democracy took 255 seats in the House of Representatives and 135 in the House of Nationalities. Barred by the constitution from the presidency, Aung San Suu Kyi was appointed State Counsellor on 6 April 2016.
- The same day the Bihar count was declared. The Grand Alliance of the RJD, Nitish Kumar's JD(U) and the Congress won 178 of the 243 seats — 80, 71 and 27 respectively — against 53 for the BJP, after voting in five phases from 12 October to 5 November.
- On 20 November Adele released 25. It sold 3.38 million copies in the United States in its first week, the first album past three million since Nielsen began counting point-of-sale purchases in 1991, beating a record set by *NSYNC in March 2000.
- On 23 November Blue Origin's New Shepard reached an apogee of 100.5 kilometres over West Texas and brought its booster back to a controlled vertical landing — the first recovery of a rocket that had flown to space.
A category nobody had protected
A decade on, November 2015 reads as the month children's data stopped being an afterthought. The pattern repeated almost at once: in February 2017 the plush toys sold as CloudPets were found to have left 820,000 accounts and 2.2 million voice recordings in an open database; researchers found the records sitting in a database that asked for no password at all, and Troy Hunt again told the story. The Federal Trade Commission's VTech order of 8 January 2018 was its first under the children's privacy law for a connected toy — $650,000 and twenty years of audits, for a company that had collected data on some three million children while telling parents it was encrypted when none of it was. India wrote the category into statute in 2023, when the DPDP Act made anyone under eighteen a child and banned targeted advertising aimed at them.
The other threads ran long. The JPMorgan case took five more years to reach the man at the keyboard: Andrei Tyurin, extradited from Georgia in 2018, was sentenced in January 2021 to twelve years. The argument Paris sharpened moved to a California courtroom in February 2016 and has never closed; Britain's Investigatory Powers Act became law a year after its draft. Starwood's infected tills turned out to be the smaller problem — intruders had been inside its reservation database since 2014, as Marriott disclosed in November 2018, drawing a penalty of about £18 million from the UK regulator. And Dell's shared private key belongs beside Lenovo's Superfish from February 2015: within a single year, twice, a laptop arrived from the factory already broken.