Security researchers Joseph Thacker and Joel Margolis found that Bondu’s web-based portal for its AI-enabled children’s toy allowed broad, unauthorized access to sensitive data simply by logging in with an arbitrary Google (Gmail) account—without needing to exploit a vulnerability beyond the broken access controls. The exposed data included children’s names, birth dates, family member names, parent-defined “objectives,” and detailed summaries/transcripts of children’s conversations with the toy; Bondu acknowledged that more than 50,000 chat transcripts were accessible via the public-facing console, representing nearly all conversations except those manually deleted.
After the issue was secured, the researchers warned that the incident highlights systemic privacy and security risks in AI-toy ecosystems, including the potential for misuse of highly personal child data and the importance of controlling and monitoring internal access to such datasets. They also indicated that Bondu appeared to rely on third-party LLM services (including Google Gemini and OpenAI GPT-5) to generate responses and run safety checks, raising questions about what conversation content is transmitted to external providers; Bondu stated it uses enterprise AI services with controls intended to minimize shared data and prevent training on prompts/outputs. Separate commentary on AI toys broadly describes how children’s companion toys commonly integrate mainstream LLMs and outlines general safety and privacy concerns, but does not add incident-specific details about the Bondu exposure.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
After the researchers reported the issue, Bondu confirmed that over 50,000 chat transcripts were exposed through the portal, covering essentially all conversations except those manually deleted by parents or staff. Company representative Anam Rafid also confirmed Bondu used third-party enterprise AI services for response generation and safety checks.
Security researchers Joseph Thacker and Joel Margolis found that Bondu’s web portal allowed anyone with an arbitrary Google account to access children’s chat transcripts and related personal data without any exploit. The exposed interface appeared to be used by parents and Bondu staff, but effectively leaked virtually all stored conversations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.