Advertisement

Breach Exposes Details Of 3.3 Million Hello Kitty Users, But No Data Is Stolen

More than three million accounts associated with the Hello Kitty brand on SanrioTown.com, HelloKitty.com and MyMelody.com were left vulnerable to data theft, according to a report from CSO Online. Sanrio, the retailer and designer that owns the Hello Kitty brand, said it has since secured the servers.

Online security researcher Chris Vickery uncovered the database vulnerability on Dec. 19, contacting CSO Salted Hash and Databreaches.net. The leaked information included users’ first and last names, birthdays, genders, countries of origin, email addresses, password hashes, password hint questions and answers and other data, according to Vickery.

In a statement, Sanrio Digital said, “At this time we have no indication that any personal information was stolen.” Credit card and additional payments information was not included in the leaked data, and user passwords were encrypted.

In addition to the primary SanrioTown database, two additional backup servers containing mirrored data also were discovered. The earliest logged exposure of this data is November 22, 2015.

Advertisement

Vickery, who explores security vulnerabilities in his spare time and reports them to the affected companies, said the hole in the Hello Kitty site was the result of a database misconfiguration, leaving it open to public access without a password or authentication, according to Reuters.

This is the second time Sanrio has had to deal with a database leaking information. Earlier in 2015, the company investigated a database leak that exposed information on more than 6,000 shareholders.

The incident comes on the heels of the data breach of another Hong Kong-based children’s product brand, VTech. That hack exposed personal data, chat logs and photos of as many as 6.3 million people, including 200,000 children. This month, UK police arrested a 21-year-old man in connection with the VTech breach.

 

Featured Event

Join the Retail Trendcaster Webinar Series to uncover key 2025 retail trends, from AI and personalization to social commerce. Gain expert insights, data-driven predictions, and actionable takeaways to stay ahead in a rapidly evolving market.

Advertisement

Advertisement

Retail Trendcaster Webinar Series
Days
Hours
Minutes
Seconds

Uncovering What’s Next in Retail

March 17-19, 2025  |  Free On-Demand Digital Event

Q1 is a pivotal time for retail, with experts analyzing holiday sales and forecasting trends. Join Retail TouchPoints’ Retail Trendcaster webinar series for insights on consumer spending, AI, personalization, social commerce, and more—helping you focus on what truly matters in 2025.

Brought to you by
Retail TouchPoints
Register Now
Retail TouchPoints is a brand of Emerald X LLC. By clicking the button and submitting information, you acknowledge and agree that your information may be shared with corporate affiliates of Emerald X LLC, and other organizations such as event hosts, speakers, sponsors, and partners. Please read our Privacy Policy and our Terms Of Use for more information on our policies.

Access The Media Kit

Interests:

Access Our Editorial Calendar




If you are downloading this on behalf of a client, please provide the company name and website information below: