May 18, 2017 By Mark Samuels 2 min read

A talented 11-year-old boy shocked security experts when he hacked into their Bluetooth devices to control his robotic teddy bear during a cybersecurity conference at the World Forum in The Hague on May 16.

Reuben Paul, a sixth grade pupil from Austin, Texas, used this clever Bluetooth hack to show the audience how even connected toys can be weaponized. The presentation illustrated the risk associated with connected devices in modern homes and businesses.

Not Your Average Bear

Paul demonstrated his abilities by using his bear, which connected to the cloud via Wi-Fi and Bluetooth, to receive and transmit messages. He plugged a Raspberry Pi into his computer and scanned the conference hall for Bluetooth-connected devices.

According to SecurityWeek, Paul downloaded dozens of numbers, including some of the devices held by key executives at the event. He then used the programming language Python to hack into his bear through one of the numbers he collected, turn on the toy’s lights and record a message from the audience.

Paul, whose father is information technology expert Mano Paul, has already made a name for himself as a “cyber ninja,” according to Mirror Online. He has been speaking at conferences since he was 8 years old. He also helped found CyberShaolin, a nonprofit organization that aims to teach children cybersecurity skills.

The Message Behind the Teddy Bear Bluetooth Hack

Paul, who wants to study cybersecurity at either CalTech or MIT, later tweeted that, although it was fun to take part in the event, he hoped people did not miss his key message, which is to secure the Internet of Things (IoT) before it becomes the “Internet of Threats.”

Many IoT devices also have Bluetooth connectivity, and the range of connected devices — from lights to cars to toys — is growing. Both end users and IT decision-makers must be alert to the potential to use Bluetooth and other mechanisms to compromise and control these devices.

A recent study by Research and Markets suggested that worldwide spending on the IoT, which reached $16.3 billion in 2016, could hit $185.9 billion by 2023. The report likened the IoT to the Industrial Revolution and asserted that it will impact the way all businesses, governments and consumers interact with the physical world.

Initiating IoT Security Conversations

Live demonstrations at last year’s DEF CON also demonstrated the potential risk associated with connected devices, according to Tom’s Guide. For example, researchers at the event showed how 75 percent of Bluetooth smart locks can be breached.

Experts have also pointed to the potential threat to connected medical devices. Many of these potentially lifesaving items use Bluetooth to connect to devices such as smartphones. Manufacturers and health providers must work to ensure the integrity of connected medical equipment.

Managing security in the fast-changing age of connectivity is a significant challenge. According to Gartner, security leaders should work toward a foundation model that deals with prevention, detection, response and prediction concerns. Organizations with this kind of foundation should be better prepared in the event of an attack.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today