
Photo blog.kaspersky.kz
In a study presented at the Black Hat USA conference, Vangelis Stikas and Felipe Solferini hacked a children’s smartwatch costing less than $30 that was being used by a WIRED journalist. The researchers were able to track his movements, take photos with the built-in camera, and activate the microphone. Meanwhile, the device showed no signs that the owner was being monitored.
The problem turned out to be much broader than just this one watch model. The researchers tested more than 70 GPS devices, including children’s watches and car trackers, and found that more than 60 brands use the infrastructure of the Chinese platforms SETracker and NewGPS2012. Another major system—SinoTrack—also serves a large number of similar devices. Collectively, this amounts to tens of millions of gadgets.
The main cause of the risk was flaws in the security of the device management systems. In some cases, attackers could gain access to the gadgets’ functions without proper user authentication. This allowed them to track and spoof locations, intercept messages, change emergency contacts, and remotely activate the camera and microphone.
Researchers also discovered serious issues in the infrastructure that supports these devices. In certain systems, they found ways to access user data, including location information, passwords, and vehicle details. The experts also noted signs of a possible previous breach of some platforms.
SETracker stated that it had addressed the identified issues, but the researchers were unable to confirm that all vulnerabilities had been patched. According to their findings, issues in SinoTrack and NewGPS2012 persisted at the time of the study.
The study showed that devices purchased to protect children and monitor vehicles can, if inadequately secured, become tools for surveillance. Instead of enhancing security, they can expose data on users’ movements and surroundings to attackers.

























