Lovense Considers Legal Action Following Resolution of Security Flaws That Exposed User Data
Lovense, a producer of internet-connected adult products, has confirmed the resolution of two security flaws that had put users’ personal email addresses at risk and allowed unauthorized access to accounts.
While the company claims these issues have been “completely resolved,” its CEO is considering legal action amid the recent disclosures.
In a statement to TechCrunch, Lovense CEO Dan Liu indicated that the company is “exploring the possibility of legal action” over what it sees as inaccurate reports regarding the vulnerabilities. When TechCrunch sought clarification, the company did not specify whether it was referring to news coverage or findings from a security researcher.
Information about the vulnerabilities emerged this week after a security researcher, identified as BobDaHacker, disclosed they had previously notified Lovense about the two security issues earlier in the year. The researcher made their findings public after Lovense stated it would take 14 months to fully resolve the vulnerabilities, rather than executing a quicker, one-month fix that would have required notifying users to update their apps.
Lovense noted, via Liu, that users must update their apps to access all features post-fix.
In his statement, Liu claimed there is “no evidence indicating that any user data, including email addresses or account details, has been compromised or misused.” It is still uncertain how Lovense arrived at this conclusion, as TechCrunch (among others) validated the email exposure issue by creating a new account and asking the researcher to reveal the associated email address.
TechCrunch inquired about the technical methods, such as log data, the company has to assess any compromise of user data, but a spokesperson did not respond.
It is not unusual for organizations to resort to legal actions and threats in an effort to stifle the revelation of sensitive security incidents, even though there are few robust regulations in the U.S. against such reporting.
Earlier this year, a U.S. independent journalist faced legal threats from a U.K. court injunction for accurately reporting on a ransomware attack targeting the U.K. private healthcare giant HCRG. In 2023, a county official in Hillsborough County, Florida, threatened to pursue criminal charges against a security researcher for identifying and privately disclosing a security vulnerability in the county’s court records system that granted access to sensitive documents.


