What we found
Roblox: FOn October 8, 2024, Hindenburg Research called Roblox "an X-rated pedophile hellscape." Searching "adult" revealed a group called "Adult Studios" with 3,334 ...
Hindenburg Research's October 2024 report called Roblox an X-rated pedophile hellscape. Searching adult revealed Adult Studios with 3,334 members trading CSAM and soliciting children. 38 connected groups, one with 103,000 members. Former employees said Roblox chose not to implement parental controls because it would hurt growth metrics. Stock dropped 9%. SEC and FTC opened investigations.
Meta Quest 3: DVR headset that maps your room, tracks your eyes, and knows what makes you look twice.
The companion app (com.oculus.twilight) embeds Meta Audience Network — Meta's advertising SDK — alongside Facebook Analytics. Meta's head of global affairs Nick Clegg confirmed to the Financial Times that eye tracking data could be used "to understand whether people engage with an advertisement." The policy language "personalise your experiences and improve Meta Quest" is standard industry phrasing for ad targeting. Eye tracking reveals what captures attention, cognitive load, and emotional responses — precisely the data an advertising platform needs.
Switch OLED Model (HEG-001): DNintendo says it protects children's privacy and follows the law for kids under 13, but the game store on the Switch secretly sends your child's browsing and...
The Switch eShop silently added Google Analytics tracking in December 2020. US Nintendo Accounts are opted in by default with no age-gating for this telemetry. Telemetry opt-out settings are only available to EU/EEA users — NA/JP/AU users (including children with parental-consent accounts) have no way to disable eShop tracking without changing their account region. Children's browsing and purchase behavior is tracked by Google regardless of parental controls.
PlayStation 5: DSony says it does not monitor your voice chats, but the PS5 is always recording the last 5 minutes of every voice conversation.
Firmware analysis shows DualSense controller has a built-in microphone enabled by default. Voice.api.playstation.com is a hardcoded endpoint. PS5 maintains a rolling 5-minute recording of all party voice chats at all times — any participant can submit a clip to Sony for moderation. Users have no ability to prevent being recorded by others in their party. The always-on recording contradicts the claim of not actively monitoring.
Fortnite (Epic Games): DEpic Games knew millions of Fortnite players were children.
In December 2022, the FTC fined Epic Games $275 million for violating COPPA -- the largest COPPA penalty in history. Epic collected personal information from children under 13 without obtaining verifiable parental consent. Children's real names, email addresses, and voice recordings were collected and stored. Epic's age gate was trivially bypassed -- children could enter any birthdate. The company knew millions of its players were under 13 and did nothing to implement meaningful age verification. Internal documents showed Epic was aware of COPPA risks but prioritized growth over compliance. FTC Chair Lina Khan stated Epic used "privacy-invasive default settings" that harmed children. The company that made the most popular game among children treated child protection law as an afterthought.
Xbox Series X: DMicrosoft boasts about removing 368 million pieces of harmful content from Xbox while the FTC fined them $20 million for hoovering up children's data without...
The FTC fined Microsoft $20 million in 2023 for COPPA violations — collecting children's data without parental consent on Xbox Live. Microsoft retained children's avatars, photos, and personal info even when parents didn't complete consent.
Razer Synapse: DRazer says data protection is central to everything it does.
In August 2020, researcher Volodymyr Diachenko discovered a misconfigured Elasticsearch cluster exposing approximately 100,000 Razer customers' full names, email addresses, phone numbers, customer internal IDs, order numbers, order details, and billing/shipping addresses. The data was publicly accessible since 18 August 2020 and was indexed by search engines. A company "committed to safeguarding privacy" left a database of 100,000 customers' personal and financial details findable via Google.