{"slug": "39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas", "title": "39 Popular Parental Control Apps Are Secretly Feeding Data to One Overseas Server", "summary": "At the Black Hat security conference, an investigation by Vangelis Stykas, CTO of Kumio, and Felipe Solferini, principal AI security engineer, found that 39 parental control apps and kid trackers all connect to the same server in China, exposing children's data to potential malicious actors. The investigation uncovered 45 distinct vulnerabilities that could allow hackers to wiretap devices, force-enable video monitoring, and take control of backend servers, with attacks possible using only a free account. Despite over 30 emails to manufacturers, the team received no response, and signs of tampering dating back two years suggest active exploitation.", "body_md": "LAS VEGAS—You might not be the only one keeping tabs on your child’s location. [Parental control apps](/parental-control/67305/the-best-parental-control-software) and kid trackers seem like quick and easy tools for ensuring your little one is safe when they’re away from home, but they may actually disclose your child’s location and activities to malicious third parties.\n\nAt the [Black Hat](/black-hat) security conference, an investigation helmed by Vangelis Stykas, CTO of [Kumio](https://kumio.ai/), and Felipe Solferini, principal AI security engineer, found that 39 seemingly separate consumer brands of parental monitoring tools all connected to the same server in China to store data. Not only did the investigation reveal that brand diversity in certain areas of the parental control market is superficial, but it also uncovered 45 distinct vulnerabilities that would allow a hacker to wiretap children’s smart devices, force-enable video monitoring, and take full control of backend servers full of sensitive data.\n\nThe worst part? A hacker could carry out the attack with nothing more than a free account to one of the services.\n\n## The Privacy Trade-Off: Why Kid Trackers Are a Hacker's Goldmine\n\nKid trackers and parental control apps often require invasive permissions to function. Even in the best cases, parental monitoring apps catalog a ton of sensitive data about you and your child.\n\nBeyond basic GPS tracking, many go further, allowing screen recording and even control of the camera and microphone. That information may be useful as a parent of a young child, but opening up a child’s device to such an elevated level of monitoring comes with risks, such as:\n\n- Camera surveillance\n- Location tracking\n- Monitoring of private conversations\n- Recording screen, app, and browsing activity\n- Theft of personal identifying information (PII)\n\nIf that data is stolen or used improperly, a child or family member could face harassment or worse, depending on the nature of the person behind the exploit. The line between parental monitoring and [stalkerware](/security/135153/protect-yourself-from-abuse-how-to-find-and-remove-stalkerware-on-your-phone-and-pc) depends entirely on who has access to the child’s device data. The situation gets even more complicated when malicious actors abroad gain access to what should be a secure connection, and that's exactly what this investigation discovered was possible.\n\nStykas and Solferini found that there was no authorization in place across various parental monitoring apps, and they were able to hack into the device network with ease. While they originally set out to find vulnerabilities on a single monitoring platform, they didn't expect the sheer scale of what they would uncover.\n\n## Unpatched, Ignored, and Active: The Hidden Scale of the Exploit\n\nThe team gave a demonstration showing this exploit in action. By running a script remotely, they were able to trigger a children's smartwatch to call a phone number and provide a live audio feed, with no indication on the watch that a call was taking place. The investigation was conducted ethically, using only devices in the team's possession, but they might not be the only ones to have found this vulnerability.\n\nThey found signs of tampering dating back two years, suggesting that a malicious actor may still be monitoring these devices.\n\nDespite sending more than 30 emails to the manufacturers of these devices, the team never received a response. “I really wanted this to be a nice story and say that we fixed it, but we didn’t. Nobody really knows where this will end up, or what we are going to do from here,\" said Stykas. While the manufacturers refused to communicate, an unnamed reseller of the devices did respond and claims to be assisting with the ongoing investigation.\n\n\"They have broken every law that I know,” continued Stykas. Despite blatantly flouting regulations, these companies have continued to dodge responsibility and consequences. Stykas implored the audience to discontinue use of these monitors: \"If you have one of those devices for your kid. Burn it. Break it. I don’t care. It is compromised,\" he said.\n\n## How to Protect Your Family Without Exposing Their Data\n\nThird-party parental controls make sense on paper. They promise a one-app solution to monitoring screen time, app activity, location, and more. However, like [age-verification measures](/security/159414/is-age-verification-really-keeping-kids-safe-or-just-risking-your-privacy), the privacy caveats are too invasive and risky to truly protect children, especially given that many of these companies lack security oversight. We have a list of [popular options here](/parental-control/67305/the-best-parental-control-software), but we recommend using built-in tools like Apple Screen Time, Google Family Link, and Microsoft's Family Safety first. Beyond monitoring, understanding the [applications your children use](/parental-control/165411/stay-kind-online-a-parents-guide-to-cyberbullying-in-the-social-media-era) and the threats they face is key to ensuring safety online.", "url": "https://wpnews.pro/news/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas", "canonical_source": "https://uk.pcmag.com/parental-control/166615/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas-server", "published_at": "2026-08-07 18:15:07+00:00", "updated_at": "2026-08-09 09:56:17.888457+00:00", "lang": "en", "topics": ["ai-ethics"], "entities": ["Black Hat", "Vangelis Stykas", "Kumio", "Felipe Solferini"], "alternates": {"html": "https://wpnews.pro/news/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas", "markdown": "https://wpnews.pro/news/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas.md", "text": "https://wpnews.pro/news/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas.txt", "jsonld": "https://wpnews.pro/news/39-popular-parental-control-apps-are-secretly-feeding-data-to-one-overseas.jsonld"}}