UKnowKids turns against researcher who found 1,700 children’s data was at risk
Child-focused security firm embroiled in row with security expert over insecure database

Child-tracking app uKnowKids.com has accused a security researcher of "hacking" its systems after he warned it that its data was at risk.
Researcher Chris Vickery found that one of uKnowKids.com's databases was misconfigured on Monday, exposing 1,700 children's detailed profiles, including email addresses, full names, dates of birth and even GPS co-ordinates for nearly 50 days.
The at-risk data also included 6.8 million personal messages and nearly two million images, many of which were of children.
This data was stored on a MongoDB database configured for public access, and Vickery claimed he did not even need a password to access it.
"I don't know about you, but I would consider it not a 'reasonable procedure' to give the public open, unfettered access to a database containing detailed child information," the Kromtech security researcher wrote on MacKeeper.
Steve Woda, CEO of the child safety app company, acknowledged the problem in a blog, and said his technology team patched the vulnerability 90 minutes after Vickery notified him.
He added that the leak affected just 0.5 per cent of the children uKnowKids is charged with protecting.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
But he also questioned Vickery's intentions, and wrote: "The hacker claims to be a white-hat' hacker which means he tries to obtain unauthorised access into private systems for the benefit of the public good'.
"We are doing our best to fully identify Mr. Vickery in order to validate his stated benign' intentions."
Woda wrote that Vickery notified uKnowKids of the data leak 12 minutes after downloading the database, having taken screenshots of business data and customer data.
The firm demanded that Vickery delete the downloads, which he did, but he has kept a number of screenshots, which he claimed to have redacted.
Speaking to CSOOnline, Vickery said he was holding onto the screenshots to ensure uKnowKids remains "(minimally) honest in their claims".
He said that Woda expressed fears in an email conversation with him that revealing the database insecurity could put uKnowKids out of business.
Woda's firm has reconfigured all encryption keys and data schemas to fend off cyber criminals, and has hired two security firms to help expose any other vulnerabilities in its systems. It also reported the breach to the Federal Trade Commission.
-
Meta just revived plans to train AI models using European user data
News Meta has confirmed plans to train AI models using European users’ public content and conversations with its Meta AI chatbot.
By Nicole Kobie
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman