May 18, 2017 By Mark Samuels 2 min read

A talented 11-year-old boy shocked security experts when he hacked into their Bluetooth devices to control his robotic teddy bear during a cybersecurity conference at the World Forum in The Hague on May 16.

Reuben Paul, a sixth grade pupil from Austin, Texas, used this clever Bluetooth hack to show the audience how even connected toys can be weaponized. The presentation illustrated the risk associated with connected devices in modern homes and businesses.

Not Your Average Bear

Paul demonstrated his abilities by using his bear, which connected to the cloud via Wi-Fi and Bluetooth, to receive and transmit messages. He plugged a Raspberry Pi into his computer and scanned the conference hall for Bluetooth-connected devices.

According to SecurityWeek, Paul downloaded dozens of numbers, including some of the devices held by key executives at the event. He then used the programming language Python to hack into his bear through one of the numbers he collected, turn on the toy’s lights and record a message from the audience.

Paul, whose father is information technology expert Mano Paul, has already made a name for himself as a “cyber ninja,” according to Mirror Online. He has been speaking at conferences since he was 8 years old. He also helped found CyberShaolin, a nonprofit organization that aims to teach children cybersecurity skills.

The Message Behind the Teddy Bear Bluetooth Hack

Paul, who wants to study cybersecurity at either CalTech or MIT, later tweeted that, although it was fun to take part in the event, he hoped people did not miss his key message, which is to secure the Internet of Things (IoT) before it becomes the “Internet of Threats.”

Many IoT devices also have Bluetooth connectivity, and the range of connected devices — from lights to cars to toys — is growing. Both end users and IT decision-makers must be alert to the potential to use Bluetooth and other mechanisms to compromise and control these devices.

A recent study by Research and Markets suggested that worldwide spending on the IoT, which reached $16.3 billion in 2016, could hit $185.9 billion by 2023. The report likened the IoT to the Industrial Revolution and asserted that it will impact the way all businesses, governments and consumers interact with the physical world.

Initiating IoT Security Conversations

Live demonstrations at last year’s DEF CON also demonstrated the potential risk associated with connected devices, according to Tom’s Guide. For example, researchers at the event showed how 75 percent of Bluetooth smart locks can be breached.

Experts have also pointed to the potential threat to connected medical devices. Many of these potentially lifesaving items use Bluetooth to connect to devices such as smartphones. Manufacturers and health providers must work to ensure the integrity of connected medical equipment.

Managing security in the fast-changing age of connectivity is a significant challenge. According to Gartner, security leaders should work toward a foundation model that deals with prevention, detection, response and prediction concerns. Organizations with this kind of foundation should be better prepared in the event of an attack.

More from

DOD establishes Office of the Assistant Secretary of Defense for Cyber Policy

2 min read - The federal government recently took a new step toward prioritizing cybersecurity and demonstrating its commitment to reducing risk. On March 20, 2024, the Pentagon formally established the new Office of the Assistant Secretary of Defense for Cyber Policy to supervise cyber policy for the Department of Defense. The next day, President Joe Biden announced Michael Sulmeyer as his nominee for the role.“In standing up this office, the Department is giving cyber the focus and attention that Congress intended,” said Acting…

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today