From Cars to Chaos: Jaguar Land Rover Cyber Fallout

This week on The Awareness Angle:

  • UK background checker APCS suffers a breach, exposing passports and driving licences used for DBS checks
  • ShinyHunters claim 1.5 billion Salesforce records stolen, hitting more than 760 companies including Google and Cloudflare
  • Jaguar Land Rover halts production after a cyberattack, leaving suppliers and workers facing weeks without pay
  • Plus: Apple patches ancient iPhones, teenagers in hoodies charged over the TfL hack, and an AI comedy sketch that skewers vendor buzzwords in the extras

 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

Listen Now

Podcast · Risky Creative

Cyber Security Awareness Month videos with Hoxhunt

We’ve teamed up with Hoxhunt again this year to create a series of short, snappy videos for Cyber Security Awareness Month. Each one is just one to two minutes long and covers social engineering in messaging apps, the psychology behind social engineering, how AI is powering spear phishing, and how to spot deepfakes. They’re quick, practical, and perfect for sharing with your colleagues, friends, or family. You can grab them directly from the Hoxhunt toolkit, and there are unbranded versions if you’d like to use them in your own awareness programmes.

Get the toolkit here - https://hoxhunt.com/cybersecurity-awareness-month-toolkit-2025

This week's stories...

APCS Data Breach Exposes Sensitive Identity Documents

Watch the discussion - https://youtu.be/CYJR7Oq6H7E?t=300

UK criminal background checking firm APCS has confirmed a data breach after its software supplier, Intradev, was attacked. The incident may have exposed highly sensitive documents such as passports, driving licences, and National Insurance numbers, all tied to DBS checks for people working with children, vulnerable adults, or in financial services. APCS works with more than 19,000 organisations, though the true scale of those affected is still unclear.

The BBC initially reported the breach as limited to Guernsey which is why we didn't report on it but reports now suggest the impact is wider. It underlines just how fragile the chain of trust can be when it comes to third-party providers. Submitting identity documents has become routine for everything from job applications to volunteering, yet once those documents are out of our hands, control over where they end up is often lost.

There are also broader concerns about government policy. With online safety rules requiring citizens to provide ID to access certain services, breaches like this raise hard questions about how that data is protected, and what happens when it isn’t.

Read more - https://www.theregister.com/2025/08/22/apcs_breach/

∠The Awareness Angle

  • Third-party weakness – A supplier compromise opened the door, showing how fragile the chain really is.
  • Highly sensitive data – This isn’t just email addresses. We’re talking identity documents that criminals can use for fraud.
  • Government oversight – The UK’s online safety rules now force people to submit ID to access sites, yet breaches like this raise serious questions about where that data ends up.

      ShinyHunters Claim 1.5 Billion Salesforce Records Stolen

      Watch the discussion - https://youtu.be/CYJR7Oq6H7E?t=790

      The ShinyHunters group claim to have stolen 1.5 billion Salesforce records from more than 760 companies. The way in was through OAuth tokens linked to Salesloft Drift, after secrets were discovered in GitHub repos earlier this year. From there, attackers were able to siphon huge amounts of Salesforce data.

      Big names are caught up in this - Google, Cloudflare, Tenable, Palo Alto. Even companies whose whole business is security. And the exposure goes well beyond simple contact details. Salesforce support cases often contain credentials, AWS keys, and sensitive internal system notes, the sort of data that attackers can immediately put to use.

      One detail that stands out is the attackers’ use of TruffleHog, a legitimate security tool, to scan for secrets. It’s a reminder that the same tools used for defence are also available to attackers, and nothing is stopping them from turning those tools against us.

      Read more - https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/

      ∠The Awareness Angle

      • Supply chain cascade – A GitHub leak became a mass data theft campaign.

      • Tokens as gold – OAuth tokens can be as valuable as passwords, sometimes more.

      • No one’s immune – If Cloudflare and Palo Alto are in the list, anyone can be.

        Jaguar Land Rover Cyberattack Halts Production

        Watch the discussion - https://youtu.be/CYJR7Oq6H7E?t=1292

        Jaguar Land Rover (JLR) is still struggling to recover from a cyberattack that has forced it to shut down IT systems and halt production at all UK factories. What started on September 1st, one of the busiest sales days of the year for new cars, has stretched into weeks of disruption, with some industry sources warning operations may not be fully restored until November. The outage is costing JLR millions per day and threatening billions in lost revenue if delays continue.

        The impact is hitting far beyond JLR itself. Hundreds of smaller suppliers depend on the manufacturer, and many are already laying off staff or asking workers to apply for universal credit. For some, JLR is their only customer, and without production lines running, their survival is uncertain. Unite, the workers’ union, has described the situation as a crisis for thousands across the supply chain.

        Researchers have linked the attack to groups associated with Scattered Spider, Lapsus$, and ShinyHunters. It's the same playbook seen in previous attacks on MGM, Marks & Spencer, and others. What makes this case stand out is the human and economic fallout. Unlike a website outage, shutting down factories means machines stop, staff have nothing to do, and entire supply chains grind to a halt.

        Read more - https://industrialcyber.co/manufacturing/jaguar-land-rover-cyberattack-deepens-with-prolonged-production-outage-supply-chain-fallout/

        ∠The Awareness Angle

        • Operational tech disruption – Cyber incidents can literally turn off the production line.

        • Supply chain fragility – Smaller suppliers with no financial buffer are left most exposed.

        • Wider economic fallout – Thousands of jobs and billions in revenue are at risk when a major manufacturer goes offline.

            ICO Jumps on TikTok During JLR Fallout

            Watch the discussion - https://youtu.be/CYJR7Oq6H7E?t=1621

            One unexpected twist from the Jaguar Land Rover incident was the Information Commissioner’s Office (ICO) turning up on TikTok to talk about it. The video itself was as low-fi as it gets. Someone sat in a car with a handheld mic, no backdrop, no branding, just a quick message recorded in the same style as any other TikTok clip on your feed.

            It might look rough, but that’s the point. Rather than trying to polish a corporate video, the ICO blended into the platform’s style and spoke directly to the audience where they already spend their time. For a regulator often seen as distant and formal, this is a bold move into relatable, human messaging.

            Read more - https://www.tiktok.com/@informationcommissioner/video/7551817307400703234?_t=ZN-8zrd9gQta8Q&_r=1

            ∠The Awareness Angle

            • Meet people where they are – TikTok might not feel like a regulator’s natural home, but that’s exactly why it works.

            • Style over polish – Content that looks like the rest of the feed can land better than something overproduced.


            • A lesson for awareness pros – Security messages don’t need a glossy studio; sometimes simple is more effective.

                  Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                  Awareness Awareness

                  CyberSecure Leeds
                  This Wednesday, 24 September, KnowBe4 are hosting CyberSecure Leeds 2025: When AI Strikes, Humans Defend as part of Leeds Digital Festival. Ant will be on a panel with Javad Malik, Jack Chapman, and James Dyer, discussing AI-driven threats, building resilience, and reducing phishing risk. If you’re in the north of England, it’s a great opportunity to join the conversation.

                  More information at https://leedsdigitalfestival.org/events/cybersecure-leeds-2025-when-ai-strikes-humans-defend/

                  HuFiCon agenda now live
                  SoSafe’s Human Firewall Conference takes place in Cologne this November and the agenda has just been published. Ant will be attending the two-day event, which focuses on human risk and security culture, and features some excellent speakers. If you’re heading out too, let him know, it’s always good to connect. If you are located in Europe, it should be pretty affordable!

                  More information at https://humanfirewallconference.com/

                        This Week's Discussion Points...


                         News

                        Criminal background checker APCS faces data breach

                        Watch | Read

                        ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
                        Watch | Read

                        Self-propagating supply chain attack hits 187 npm packages
                        Watch | Read

                        Jaguar Land Rover cyberattack deepens, with prolonged production outage, supply chain fallout
                        Watch | Read

                        Apple backports zero-day patches to older iPhones and iPads
                        Watch | Read

                        Fake Empire Podcast invites target crypto industry with macOS AMOS Stealer
                        Watch | Read

                        Teenagers charged over Transport for London cyber attack
                        Watch | Read

                        New attack on ChatGPT research agent pilfers secrets from Gmail inboxes
                        Watch | Read

                        As Ellison Buys Out TikTok, US Moves Toward One-Party Media
                        Watch | Read

                         Extras

                        CyberSecure Leeds 2025 – Leeds Digital Festival panel with Ant

                        Watch | Read

                        HuFiCon agenda now live
                        Watch | Read

                        AI comedy sketch poking fun at vendor buzzwords
                        Watch | Read

                        Phil AI image edit demo: Trump & Starmer “kiss”
                        Watch | Read


                         Subscribe to the Newsletter

                        https://www.riskycreative.com

                           

                          Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                          And finally…Most vendors now

                          We spotted something on LinkedIn this week that shows just how easy AI manipulation has become. Adversarial Physical Security Specialist, Phil Smith, took a photo of Donald Trump and Keir Starmer together and, with a single prompt, altered it so the two looked like they were about to kiss. The results were both bizarre and a little unsettling.

                          It’s a light-hearted example, but it highlights a serious issue: deepfakes don’t need Hollywood budgets anymore. Anyone with a free tool can now create realistic, or at least believable, images that change context and meaning entirely. What happens when the subject isn’t comedy, but politics, finance, or even your own executives?

                          Moments like this are a useful reminder to challenge what we see online, especially as manipulated media keeps getting easier to make and harder to spot.

                          Watch - https://www.linkedin.com/posts/phil-smith-554462255_i-had-to-see-this-now-you-can-too-ugcPost-7374794135070744576-Tlko/

                          If you need to undo the nightmare fuel, here's a little something.

                          ∠The Awareness Angle

                          • Deepfakes on demand – Simple AI prompts can now twist real photos into convincing but false images, showing how easy it is to manipulate context.

                          • From comedy to concern – While this one was light-hearted, the same tech could be used to create fake press conferences, financial announcements, or damaging rumours.
                          • Pause before you share – If an image or video feels odd, double-check the source before passing it on. Not everything that looks real online actually is.

                          Apple Calendar Invites Are Being Turned Into Phishing Scams

                          This week on The Awareness Angle:

                          • Apple’s iCloud calendar gets abused to send phishing emails that look all too real
                          • Qantas cuts executive bonuses after a massive breach, showing leadership accountability in action

                          • Nexar’s dashcam database is hacked, spilling video footage and GPS data into the wild

                          • Huntress researchers get a rare inside look at how cyber attackers really operate

                          • Plus: Plex suffers another breach, new awareness content from Hoxhunt, and more in the extras

                          🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                          Listen Now

                          Podcast · Risky Creative

                          Cyber Security Awareness Month videos with Hoxhunt

                          We’ve teamed up with Hoxhunt again this year to create a series of short, snappy videos for Cyber Security Awareness Month. Each one is just one to two minutes long and covers social engineering in messaging apps, the psychology behind social engineering, how AI is powering spear phishing, and how to spot deepfakes. They’re quick, practical, and perfect for sharing with your colleagues, friends, or family. You can grab them directly from the Hoxhunt toolkit, and there are unbranded versions if you’d like to use them in your own awareness programmes.

                          Get the toolkit here - https://hoxhunt.com/cybersecurity-awareness-month-toolkit-2025

                          This week's stories...

                          Apple Calendar Invites Are Being Turned Into Phishing Scams

                          Watch the discussion - https://youtu.be/k4iTtfaLtaw?t=151

                          Attackers have found a way to abuse Apple’s own iCloud calendar system to send phishing emails that look like they’re coming straight from Apple. By creating and sharing malicious calendar invites, scammers can bypass many email security filters. The example we saw was a fake PayPal invoice for $600, complete with an “@email.apple.com” sender address. Because the messages ride on Apple’s trusted infrastructure, they carry an extra layer of legitimacy, and that makes them harder to spot.

                          Read more - https://www.bleepingcomputer.com/news/security/icloud-calendar-abused-to-send-phishing-emails-from-apples-servers/

                          ∠The Awareness Angle

                          • Trust can be exploited – Just because an invite or email comes from a big name like Apple doesn’t mean it’s safe.
                          • Look closer before clicking – Unexpected calendar invites, especially those with links or payment requests, should raise red flags.

                          • Report and delete – If something feels off, don’t interact. Remove it and let IT or your security team know.

                            Qantas cuts executive bonuses by 15% after a July data breach

                            Watch the discussion - https://youtu.be/k4iTtfaLtaw?t=362

                            Qantas suffered a cyber attack in July that exposed data from 5.7 million customers. The breach has been linked to the Scattered Spider group, who have targeted multiple airlines this year. In response, Qantas announced a 15% cut to executive bonuses, despite reporting $1.5 billion in profit. It’s a rare example of leadership being held financially accountable for a security failure, and a strong signal that cybersecurity is a board-level responsibility.

                            Read more - https://securityaffairs.com/181954/data-breach/qantas-cuts-executive-bonuses-by-15-after-a-july-data-breach.html

                            ∠The Awareness Angle

                            • Accountability matters – Security isn’t just IT’s problem, it’s a leadership responsibility.
                            • Culture starts at the top – When executives take a hit, it shows the whole organisation that protecting data is everyone’s job.

                            • Learn from mistakes – Breaches happen, but how leaders respond sets the tone for resilience and trust.

                              Nexar dashcam video database hacked

                              Watch the discussion - https://youtu.be/k4iTtfaLtaw?t=520

                              Hackers broke into Nexar’s cloud storage, exposing around 130 terabytes of dashcam footage and metadata. The data included video clips, GPS locations, and driving insights uploaded automatically from connected Nexar devices. Beyond the privacy risk, the footage could be misused for stalking or tracking routines. Nexar also monetises this data by selling access to blurred images and road insights to third parties, raising further questions about what users actually sign up for when they connect a “smart” dashcam.

                              Read more - https://www.malwarebytes.com/blog/news/2025/09/nexar-dashcam-video-database-hacked

                              ∠The Awareness Angle

                              • Your devices see more than you think – Dashcams don’t just record accidents, they capture where you go, who’s with you, even conversations.
                              • Convenience vs. Risk – Smart features like 4G uploads sound useful, but they increase exposure if data isn’t properly secured.

                              • Secure your data – Keep devices updated, use unique credentials, and think twice about what you allow to be stored in the cloud.

                                  Attacker’s Blunder Gave Huntress a Rare Look Inside Their Operations

                                  Watch the discussion - https://youtu.be/k4iTtfaLtaw?t=898

                                  Researchers at Huntress stumbled across exposed command-and-control servers and got a rare glimpse into the daily workings of a cybercrime group. The access revealed playbooks, stolen data, even real-time chats between attackers. It was like peeking behind the curtain at how professional and organised these operations have become. The blog post reads more like a story than a technical brief, making it a fascinating read for anyone curious about the business-like side of cybercrime.

                                  Read more - https://www.huntress.com/blog/rare-look-inside-attacker-operation

                                  ∠The Awareness Angle

                                  • Attackers are organised – Cybercrime runs like a business, complete with processes, tools, and collaboration.
                                  • Awareness is defence – Understanding how attackers think helps us prepare and spot their tricks earlier.

                                  • Every click counts – These campaigns still rely on someone letting them in, so cautious habits remain the strongest shield.

                                        Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                        Awareness Awareness

                                        CyberSecure Leeds
                                        On 24 September, KnowBe4 are hosting CyberSecure Leeds 2025: When AI Strikes, Humans Defend as part of Leeds Digital Festival. Ant will be on a panel with Javad Malik, Jack Chapman, and James Dyer, discussing AI-driven threats, building resilience, and reducing phishing risk. If you’re in the north of England, it’s a great opportunity to join the conversation.

                                        More information at https://leedsdigitalfestival.org/events/cybersecure-leeds-2025-when-ai-strikes-humans-defend/

                                        HuFiCon agenda now live
                                        SoSafe’s Human Firewall Conference takes place in Cologne this November and the agenda has just been published. Ant will be attending the two-day event, which focuses on human risk and security culture, and features some excellent speakers. If you’re heading out too, let him know, it’s always good to connect. If you are located in Europe, it should be pretty affordable!

                                        More information at https://humanfirewallconference.com/

                                        Watch the discussion - https://youtu.be/Qfwq2z7EyFs?t=1320

                                              This Week's Discussion Points...


                                              News

                                              iCloud Calendar abused to send phishing emails from Apple’s servers
                                              Watch | Read

                                              Qantas cuts executive bonuses by 15% after a July data breach
                                              Watch | Read

                                              Nexar dashcam video database hacked
                                              Watch | Read

                                              How an Attacker’s Blunder Gave Us a Rare Look Inside Their Day-to-Day Operations
                                              Watch | Read

                                              Plex suffers data breach, warns customers to change passwords
                                              Watch | Read


                                              Extras

                                              HuFiCon agenda now live
                                              Watch | Read

                                              Reddit thread: Wildest breach stories you’ve been a part of
                                              Watch | Read

                                              Framing security alerts beyond “true vs false positive”
                                              Watch | Read

                                              Subscribe to the Newsletter

                                              https://www.riskycreative.com

                                                Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                Phishing goes old school

                                                Ozan from Keepnet shared a phishing letter he received through the post, not an email, but an actual printed letter promising millions of dollars if he helped “claim” an unclaimed fortune. It’s basically the Nigerian prince scam with a new twist, and a good reminder that social engineering isn’t limited to inboxes. Sometimes it arrives in an envelope.

                                                Watch - https://youtu.be/k4iTtfaLtaw?t=1750

                                                ∠The Awareness Angle

                                                • Old tricks, new packaging – Scams don’t always arrive by email. Letters, phone calls, and texts can be just as dangerous.
                                                • Too good to be true – Promises of unexpected money are almost always a red flag, no matter how official the message looks.

                                                • Check before you trust – If something unexpected lands in your inbox or your letterbox, pause and question it before you respond.

                                                  Guest Spot: AI Experience Podcast

                                                  Ant recently joined Julien Redelsperger on the AI Experience podcast to talk about how AI is reshaping cybersecurity. From deepfake voices to flawless phishing emails, scams are getting harder to spot, and yet sometimes the best defence still comes down to analogue checks and trusting your instincts.

                                                  The episode is available on all major podcast platforms.  Click here to listen.

                                                  700+ Companies Hit by SalesLoft Drift Hack, Are You At Risk?

                                                  The Awareness Angle - The Newsletter

                                                  700+ Companies Hit by SalesLoft Drift Hack, Are You At Risk?

                                                  This week’s news takes us from password managers with a hidden flaw to the first glimpse of AI-powered ransomware, and from Jaguar Land Rover’s production lines grinding to a halt to hackers pushing ultimatums at Google. Add in fallout from the Salesloft breach rippling across big-name security vendors, and it’s a week packed with stories that hit close to home.

                                                  🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                  Listen Now

                                                  Podcast · Risky Creative

                                                  New Hoxhunt Videos for Cyber Awareness Month 2025 

                                                  We’ve teamed up with Hoxhunt again to create a fresh set of short videos for their 2025 Cyber Awareness Month Toolkit. From spotting deepfakes to understanding social engineering in chat apps, these 1–2 minute clips are designed to be shared widely and spark awareness conversations.


                                                  Get the toolkit here - https://hoxhunt.com/cybersecurity-awareness-month-toolkit-2025

                                                  This week's stories...

                                                  Password Managers Under Attack

                                                  Watch the discussion - https://youtu.be/Qfwq2z7EyFs?t=367

                                                  A new report has revealed a clickjacking flaw in major password manager browser extensions, including 1Password, Bitwarden, Dashlane, LastPass, NordPass and ProtonPass. The bug could expose sensitive details from up to 40 million users by tricking autofill into handing over data through invisible page overlays. Experts are stressing this isn’t a reason to ditch password managers, which remain one of the strongest defences against password reuse, but it is a reminder to tweak how you use them.

                                                  Read more - https://www.pcworld.com/article/2887955/password-managers-vulnerable-40-million-users-at-risk-of-stolen-data.html

                                                  ∠The Awareness Angle

                                                  • Autofill off – Turn off automatic autofill in your password manager and switch to manual “on-click” mode.

                                                  • MFA everywhere – Keep two-factor authentication on for all accounts, especially your password manager.

                                                  • Don’t panic – Password managers are still one of the best tools to keep your accounts secure. 

                                                  AI Ransomware Arrives: Meet PromptLock

                                                  Watch the discussion - https://youtu.be/Qfwq2z7EyFs?t=653

                                                  Researchers have discovered PromptLock, believed to be the first ransomware powered by artificial intelligence. Instead of relying on fixed malicious code, it runs an AI model locally on the victim’s machine to generate attack scripts on the fly. This makes it harder for traditional security tools to detect and block. For now, it looks more like a proof-of-concept than a widespread threat, but it shows how AI is being weaponised to make attacks smarter, faster and more adaptable.

                                                  Read more - https://cybersecuritynews.com/first-ai-ransomware/

                                                  ∠The Awareness Angle

                                                  • Proof of concept today – PromptLock isn’t widespread yet, but it’s a sign of what’s coming.
                                                  • AI arms race – Criminals are experimenting with AI just as much as defenders are.

                                                  • Stay prepared – Basics like patching, backups, and detection tools remain the first line of defence.

                                                  Cyber Attack Stalls Jaguar Land Rover

                                                  Watch the discussion - https://youtu.be/Qfwq2z7EyFs?t=776

                                                  Jaguar Land Rover’s production was severely disrupted after a cyber attack forced systems offline on one of the busiest new car registration days in the UK. Employees were told not to return to work until systems were restored, and dealers had to fall back on manually phoning the DVLA to register new cars. Hackers claiming links to groups like Scattered Spider and ShinyHunters say they exploited a flaw in SAP NetWeaver, raising questions over patching and whether attackers had ever fully left the network after earlier incidents.

                                                  Read more - https://www.autocar.co.uk/car-news/new-cars/police-and-cyber-experts-brought-jlr-remains-crippled-hack

                                                  ∠The Awareness Angle

                                                  • Business impact – Cyber attacks don’t just steal data, they can stop production lines in their tracks.
                                                  • Patch management – Known vulnerabilities remain one of the most common entry points.

                                                  • Persistence matters – Attackers may already be inside, even after a previous breach is “fixed.”

                                                    Salesloft Breach Ripples Across Big Vendors

                                                    Watch the discussion - https://youtu.be/Qfwq2z7EyFs?t=1320

                                                    A breach at Salesloft’s Drift chatbot platform has spilled over into some of the biggest names in cybersecurity. Attackers stole authentication tokens that connected Drift with tools like Salesforce, Google Workspace, AWS and Slack. So far, victims include Zscaler, Cloudflare, Palo Alto Networks, and more, and the list is still growing. Salesloft revoked all access and rotated tokens, while Google’s threat team linked the activity to a group known as UNC6395 (aka “Grub One”). For any business using Drift, the advice is simple: treat all tokens as compromised, rotate credentials, and review integrations for unusual activity.

                                                    Read more - https://www.crn.com/news/security/2025/5-cybersecurity-vendors-impacted-in-salesloft-drift-breach

                                                    ∠The Awareness Angle

                                                    • Third-party risk – Integrations add value, but also open cracks in your defences.
                                                    • Token takeover – Authentication tokens are as valuable as passwords to attackers.

                                                    • Reset and review – Revoke, rotate, and investigate whenever a connected service is hit.

                                                        Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                        This Week's Discussion Points...

                                                        Password managers vulnerable: 40 million users at risk
                                                        Watch | Read

                                                        First AI ransomware ‘PromptLock’ discovered
                                                        Watch | Read

                                                        Jaguar Land Rover hit by cyber attack
                                                        Watch | Read

                                                        Salesloft breach grows bigger
                                                        Watch | Read

                                                        Reddit: Cyber Awareness Month phishing campaign ideas
                                                        Watch | Read

                                                        Joe Rogan tricked by AI video
                                                        Watch | Read

                                                        Gemini photo prompt exploit
                                                        Watch | Read

                                                        📬 Subscribe to the Newsletter

                                                        https://www.riskycreative.com

                                                           

                                                          Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                          Guest Spot: AI Experience Podcast

                                                          Ant recently joined Julien Redelsperger on the AI Experience podcast to talk about how AI is reshaping cybersecurity. From deepfake voices to flawless phishing emails, scams are getting harder to spot, and yet sometimes the best defence still comes down to analogue checks and trusting your instincts.

                                                          The episode is available on all major podcast platforms.  Click here to listen.

                                                          Grok Chatbot Leaks 370,000 Private Conversations

                                                          This week we’ve got leaks, lawsuits, and legislation. From Elon’s Grok chatbot spilling hundreds of thousands of private chats into Google search results, to Mac users being tricked by a fake “fix” that hides an info-stealer, to a developer jailed for sabotaging his ex-employer with a kill switch. Add in a major telecoms breach, Android’s new plan to verify every app developer, and Denmark pushing bold new deepfake laws, and there’s plenty to talk about.

                                                          Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                          Listen Now

                                                          Podcast · Risky Creative

                                                          Hundreds of thousands of Grok chats exposed in Google results

                                                          Watch the discussion - https://youtu.be/v64EH9pK_w8?t=127

                                                          Elon Musk’s Grok chatbot was caught up in a major privacy incident after more than 370,000 user conversations were found in Google search results. A flaw in the Share button meant chats that were supposed to be private were being indexed, making them accessible to anyone searching. The leaked conversations were not harmless either. They included medical information, passwords, and even instructions on making explosives. It follows similar incidents with other AI platforms earlier this year, raising serious questions about how much we can trust these tools with sensitive information.

                                                          Read more - https://www.bbc.co.uk/news/articles/cdrkmk00jy0o

                                                          ∠The Awareness Angle

                                                          • Privacy is not guaranteed – AI chats may appear private but unless privacy is designed into the platform, they can leak just like a public post.
                                                          • Sensitive data at risk – Health details, credentials, and personal secrets were all exposed, showing how valuable this information is.

                                                          • Think before you share – Treat AI chats like social media and never share anything you would not want to end up online.

                                                          Fake Mac fixes trick users into installing new Shamos infostealer

                                                          Watch the discussion - https://youtu.be/v64EH9pK_w8?t=267

                                                          A new malware strain called Shamos is targeting Mac users by posing as a system fix. Attackers are using malvertising and fake websites like mac-safer.com to trick people into pasting commands into Terminal. Instead of solving a problem, the code installs an infostealer that grabs browser data, passwords, Keychain items, Apple Notes, and even crypto wallets. Since June more than 300 Mac environments have been hit.

                                                          Read more - https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/

                                                          ∠The Awareness Angle

                                                          • Looks helpful, ends harmful – Fake fixes prey on people desperate to solve a problem quickly.
                                                          • High-value data stolen – Shamos can access passwords, notes, and financial accounts, making it highly damaging.

                                                          • Safe support routes – Never run commands from random sites. Always go directly to Apple’s official support channels.

                                                          Dev gets 4 years for creating kill switch on ex-employer’s systems

                                                          Watch the discussion - https://youtu.be/v64EH9pK_w8?t=548

                                                          Former software developer Davis Lu was sentenced to four years in prison after sabotaging his ex-employer’s network. Lu had secretly embedded malicious code into Eaton Corporation’s systems that triggered when his account was disabled. The “kill switch” crashed servers, deleted profiles, and locked out thousands of users, costing the company hundreds of thousands of dollars.

                                                          Read more - https://www.bleepingcomputer.com/news/security/dev-gets-4-years-for-creating-kill-switch-on-ex-employers-systems/

                                                          ∠The Awareness Angle

                                                          • Insider risk is real – While most insider incidents are accidental, malicious acts can cause devastating damage.
                                                          • Planned sabotage – Lu named his code after himself, showing how brazen and deliberate insider threats can be.

                                                          • Controls matter – Monitoring for unusual code, enforcing separation of duties, and regular audits can reduce this risk.

                                                            Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                            This Week's Discussion Points...

                                                            Hundreds of thousands of Grok chats exposed in Google results
                                                            Watch | Read

                                                            Fake Mac fixes trick users into installing new Shamos infostealer
                                                            Watch | Read

                                                            Dev gets 4 years for creating kill switch on ex-employer's systems
                                                            Watch | Read

                                                            Orange Belgium discloses data breach impacting 850,000 customers
                                                            Watch | Read

                                                            You Won’t Be Able to Install Apps from Unverified Android Developers Soon
                                                            Watch | Read

                                                            4chan launches legal case against Ofcom in US federal court
                                                            Watch | Read

                                                            How 16 billion becomes 231 million, then 9 million
                                                            Watch | Read

                                                            MoD staff warned not to share hidden data before Afghan leak
                                                            Watch | Read

                                                            Denmark’s bold move to protect citizens from deepfakes
                                                            Watch | Read

                                                            Why are hackers always shown in hoodies?
                                                            Watch | Read

                                                            WiFi signals reveal human movement indoors
                                                            Watch | Read

                                                            Gmail unsubscribe hack
                                                            Watch | Read

                                                             Subscribe to the Newsletter

                                                            https://www.riskycreative.com

                                                              The Gmail unsubscribe hack you might not know about

                                                              Watch - https://youtu.be/v64EH9pK_w8?t=2418

                                                              A TikTok clip revealed a simple Gmail trick to clear out unwanted emails. In the left-hand menu under “More,” there’s a Manage Subscriptions option. It lists every newsletter and marketing email you’re signed up to, with a one-click unsubscribe button. It even shows how often you receive them, making it much easier to tidy your inbox.

                                                              ∠The Awareness Angle

                                                              • Hidden feature – Gmail has a built-in tool to manage and cancel subscriptions in bulk.
                                                              • Time saver – Instead of hunting through emails, you can unsubscribe directly in one place.

                                                              • Inbox hygiene – Keeping clutter under control reduces the risk of missing important security messages.

                                                               

                                                              Watch it at - https://vm.tiktok.com/ZNd4NNg1V/

                                                              Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                              Your VPN Extension Might Be Watching You Right Now!

                                                              Your VPN Extension Might Be Watching You Right Now!

                                                              This week’s episode is packed with cyber scams, shady extensions, and even hackers opening floodgates at a dam in Norway. We’re talking about how censorship laws could reshape the internet, the UK quietly backing down in its Apple privacy fight, and a new infostealer campaign disguised as copyright warnings. Add in PayPal credential dumps, Workday’s social engineering breach, and Chrome extensions spying on users, and there’s plenty to dive into. Plus, we take a look at the latest SANS 2025 Security Awareness Report and what it means for awareness teams everywhere.

                                                              🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                              Listen Now

                                                              Podcast · Risky Creative

                                                              Fake Copyright Emails Delivering Malware

                                                              Watch the discussion - https://youtu.be/Vcol4c93Eg8?t=670

                                                              Attackers are sending out spear-phishing emails that pretend to be legal threats from law firms over copyright or IP infringement. The emails look convincing, mentioning details like Facebook page IDs or company names, and urge recipients to download a file. That “PDF” is actually a disguised archive carrying the Noodlophile infostealer, which steals cookies, saved cards, and login credentials while hiding on the system.

                                                              Read more - https://www.helpnetsecurity.com/2025/08/18/noodlophile-infostealer-spear-phishing-campaign-copyright-infingement/

                                                              ∠The Awareness Angle

                                                              • Fear as a Trigger – Legal threats create panic, pushing people to click quickly without questioning.
                                                              • Malware Masquerade – The file looks like a PDF but is really an installer that sideloads malware into trusted apps.

                                                              • Expanding Threat – This isn’t just hitting small creators anymore, it’s now targeting businesses worldwide.

                                                                                          Workday Breach via Social Engineering

                                                                                          Watch the discussion - https://youtu.be/Vcol4c93Eg8?t=1251

                                                                                          Workday, the HR and enterprise software provider, disclosed a breach after attackers posed as HR or IT staff over phone and text to trick employees into handing over credentials. The attackers accessed a connected CRM platform, exposing business contact details like names, emails, and phone numbers. While no sensitive HR or financial data was taken, those details can be weaponised in phishing and social engineering campaigns.

                                                                                          Read more - https://securityaffairs.com/181271/data-breach/human-resources-firm-workday-disclosed-a-data-breach.html

                                                                                          ∠The Awareness Angle

                                                                                          • Social Engineering Wins – A simple call or text can bypass strong technical controls if trust isn’t questioned.
                                                                                          • Small Data, Big Risk – Even “just” names and emails can fuel convincing phishing or extortion attempts.

                                                                                          • Third-Party Weakness – Breach came through a connected CRM, highlighting supply chain and SaaS risks.

                                                                                              PayPal Credentials for Sale

                                                                                              Watch the discussion - https://youtu.be/Vcol4c93Eg8?t=1250

                                                                                              A cybercriminal claims to be selling 15.8 million PayPal logins in plain text for just $750. While researchers say it’s unlikely PayPal itself was breached, the data probably comes from infostealer malware logs that harvested credentials from infected devices. Even if many accounts are fake or outdated, the inclusion of PayPal login URLs makes it easier for attackers to launch automated credential stuffing and fraud attempts.

                                                                                              Read more - https://hackread.com/threat-actor-selling-plain-text-paypal-credentials/

                                                                                              ∠The Awareness Angle

                                                                                              • Not a PayPal Breach – The danger comes from malware stealing credentials on personal devices, not PayPal’s systems.
                                                                                              • Password Reuse Problem – Recycled passwords could expose accounts on other services, not just PayPal.

                                                                                              • MFA is Essential – Multi-factor authentication remains the best defence if passwords are compromised.

                                                                                                                Pro-Russian Hackers Breach Norwegian Dam

                                                                                                                Watch the discussion - https://youtu.be/Vcol4c93Eg8?t=1929

                                                                                                                Norway’s Police Security Service confirmed that pro-Russian hackers briefly seized control of a hydropower dam earlier this year. Attackers remotely opened floodgates, releasing 500 litres of water per second for four hours before being stopped. No damage occurred, but the hackers later posted video proof of the breach on Telegram to amplify fear. The attack highlights how critical infrastructure can be manipulated as part of hybrid influence campaigns rather than outright destruction.

                                                                                                                Read more - https://securityaffairs.com/181143/hacktivism/norway-confirms-dam-intrusion-by-pro-russian-hackers.html

                                                                                                                ∠The Awareness Angle

                                                                                                                • Not a PayPal Breach – The danger comes from malware stealing credentials on personal devices, not PayPal’s systems.
                                                                                                                • Password Reuse Problem – Recycled passwords could expose accounts on other services, not just PayPal.

                                                                                                                • MFA is Essential – Multi-factor authentication remains the best defence if passwords are compromised.

                                                                                                                                  Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                                                                                                  This Week's Discussion Points...

                                                                                                                                  Censorship is going to destroy the internet
                                                                                                                                  Watch | Read

                                                                                                                                  UK backs down in Apple privacy row
                                                                                                                                  Watch | Read

                                                                                                                                  Noodlophile infostealer behind fake copyright notices
                                                                                                                                  Watch | Read

                                                                                                                                  15.8M PayPal credentials for sale
                                                                                                                                  Watch | Read

                                                                                                                                  Workday data breach via social engineering
                                                                                                                                  Watch | Read

                                                                                                                                  Android–iPhone messaging security upgrade
                                                                                                                                  Watch | Read

                                                                                                                                  Norway dam intrusion by pro-Russian hackers
                                                                                                                                  Watch | Read

                                                                                                                                  Chrome VPN extension spying on users
                                                                                                                                  Watch | Read

                                                                                                                                  Google patches critical Chrome flaw
                                                                                                                                  Watch | Read

                                                                                                                                  SANS 2025 Security Awareness Report
                                                                                                                                  Watch | Read

                                                                                                                                  NowTV anti-piracy ad
                                                                                                                                  Watch | Read

                                                                                                                                  Chipotle phishing simulation backlash
                                                                                                                                  Watch | Read

                                                                                                                                  📬 Subscribe to the Newsletter

                                                                                                                                  https://www.riskycreative.com

                                                                                                                                    Free Chipotle? It’s a Phish

                                                                                                                                    Watch - https://youtu.be/Vcol4c93Eg8?t=3296

                                                                                                                                    A viral Instagram video shows an employee falling for a simulated phishing email offering free Chipotle. She clicked the link, filled in her order, and turned up at work expecting lunch — only to discover it was a test. Instead of burritos, she got three hours of mandatory phishing training. While it makes for a funny video, it raises serious questions about how organisations run phishing campaigns. Humiliating staff and punishing them harshly for one mistake can backfire, creating resentment instead of awareness.

                                                                                                                                    ∠The Awareness Angle

                                                                                                                                    • Humour or Harm? – Funny to watch, but heavy-handed training risks damaging trust with employees.
                                                                                                                                    • Punishment vs Learning – Phishing simulations should build awareness, not embarrass staff.

                                                                                                                                    • Better Approaches – Supportive feedback, coaching, and bite-sized training are more effective than punitive measures.

                                                                                                                                    Watch it at - https://www.instagram.com/p/DNkKhYssbRW/

                                                                                                                                            Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                                                                                                            Next podcast episode...

                                                                                                                                            Days Hours Minutes Seconds

                                                                                                                                            Could Your Webcam Be Spying on You?

                                                                                                                                            This week, we’re bringing you a mix of Chicago heat, cyber scares, and a bit of nostalgia. I’ve just wrapped up an incredible few days at the SANS Security Awareness Summit, where 350 awareness pros (and over 5,000 virtually) came together to share stories, strategies, and yes, a few laughs. From romance scam keynotes to Champions Network chats, it was packed. You can catch our two live streams (plus a brilliant bonus bit) from the summit on YouTube if you missed them.

                                                                                                                                            Back in the news, we dig into a wild Lenovo webcam flaw that turns cameras into hacking tools, a scam piggybacking on car finance compensation, and fresh zero-days cracking open password vaults. Plus, there’s a telecom breach, a city hit with ransomware has breached data made available, and a reminder that even “strong” passwords aren’t always as strong as we think.

                                                                                                                                            And because we like to balance the serious with the fun, we also talk AOL dial-up (RIP after 30 years), calendar spam scams, and the rise of “Major Data Breach” as a military rank.

                                                                                                                                            🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                                                                                                            Listen Now

                                                                                                                                            Podcast · Risky Creative

                                                                                                                                            Conversations From The Summit

                                                                                                                                                    The SANS Security Awareness Summit is the biggest gathering of people who live and breathe security awareness, human risk, and culture. This year, more than 350 professionals met in Chicago, with thousands more joining online. For two days the focus was on one thing: how to make security stick with people.

                                                                                                                                                    Here are some of the big takeaways from the conversations and sessions:

                                                                                                                                                    • Stories make it stick – time and again, people highlighted that storytelling is one of the most powerful tools we have in awareness. A good story is remembered years later, while a policy or slide deck is often forgotten.

                                                                                                                                                    • Words matter – the language we use can either build trust or shut people down. Some traditional buzzwords are starting to feel stale or even negative, and many are turning towards warmer, more human messaging.

                                                                                                                                                    • Culture over compliance – the strongest programs are moving away from box-ticking exercises and instead building genuine relationships across the business. It’s about nurturing behaviours, not policing them.

                                                                                                                                                    • Champions need investment – security champions and ambassador networks are widely seen as one of the best ways to influence culture, but they only thrive when they have proper support, budget, and dedicated people running them.

                                                                                                                                                    • Community is everything – awareness professionals are learning as much from each other as they are from the talks. Peer-to-peer sharing, whether at the summit or in ongoing practice groups, is driving new ideas and confidence.

                                                                                                                                                    • Human risk is front and centre – the conversation is shifting from “awareness training” to measuring and reducing actual behaviours that create risk, supported by better data and behavioural science.

                                                                                                                                                    • The power of in-person – many said the real magic of the summit is in the connections: the chats over coffee, the sense of community, and the reassurance that you’re not the only one facing these challenges.

                                                                                                                                                    You can watch both LinkedIn Lives and a bonus session on YouTube.

                                                                                                                                                    Watch here - https://www.youtube.com/playlist?list=PLEsOj51Q0PfBp55nkDIS0S3sA8cTJFJkk

                                                                                                                                                    Lenovo Webcams Can Be Turned Into BadUSB Devices

                                                                                                                                                    Watch the discussion - https://youtu.be/Ce8cjxsYXDY?t=527

                                                                                                                                                    Researchers have found a serious flaw in certain Lenovo webcams (CVE-2025-4371) that allows attackers to remotely reprogram them into so-called BadUSB devices. Originally demonstrated back in 2014, this attack takes advantage of USB firmware itself, turning what looks like an innocent webcam into a malicious tool. Once compromised, the camera can inject keystrokes, deliver payloads, or log data.  What's even more worrying is that it can survive a full operating system reinstall.

                                                                                                                                                    Lenovo has released firmware updates to fix the issue, but it’s a reminder that even everyday accessories like webcams aren’t always as simple as they seem. These devices often run their own operating systems and can be weaponised without the user ever realising.

                                                                                                                                                    Read more - https://thehackernews.com/2025/08/linux-based-lenovo-webcams-flaw-can-be.html

                                                                                                                                                    ∠The Awareness Angle

                                                                                                                                                    • Peripheral Trust Risks – Even “innocent” devices like webcams can run their own OS and be remotely weaponised.
                                                                                                                                                    • Persistence Beyond OS Wipe – Firmware-level malware survives reinstallation, requiring hardware-level fixes.

                                                                                                                                                    • Supply Chain & Physical Access Threats – Malicious devices could be shipped to targets or swapped in by insiders.

                                                                                                                                                                              uBlock Origin Lite Finally Comes to Safari

                                                                                                                                                                              Watch the discussion - https://youtu.be/Ce8cjxsYXDY?t=763

                                                                                                                                                                              Safari users have been missing a reliable ad blocker for years, but that gap is now filled. uBlock Origin Lite is a lightweight, privacy-friendly version of the popular ad blocker and is finally available on macOS, iOS, and iPadOS. Unlike the original extension, it uses Safari’s “declarative rules API,” which means the browser handles all the blocking natively, without draining CPU or memory.

                                                                                                                                                                              Why does this matter? Malicious Advertising (or Malvertising) is still a common infection route, and a good ad blocker doesn’t just clean up your browsing experience. It also helps protect against malicious ads. For Apple users who’ve been stuck without proper options, this is a welcome (and safer) addition.

                                                                                                                                                                              Read more - https://www.howtogeek.com/ublock-origin-lite-is-finally-available-on-safari/

                                                                                                                                                                              ∠The Awareness Angle

                                                                                                                                                                              • Lightweight Privacy Tool – Blocks ads and trackers without draining device resources.
                                                                                                                                                                              • Apple Ecosystem Gap Filled – Safari users on iPhone and iPad finally get official support.

                                                                                                                                                                              • Declarative Security Model – Reduces attack surface by letting the browser handle blocking logic natively.

                                                                                                                                                                                Scammers Jump on Fake Car Finance Payouts

                                                                                                                                                                                Watch the discussion - https://youtu.be/Ce8cjxsYXDY?t=963

                                                                                                                                                                                The UK’s Financial Conduct Authority (FCA) has warned motorists about scam calls offering fake compensation for mis-sold car finance deals. Real compensation of up to £950 per driver is being considered, but the scheme isn’t live yet. Fraudsters are exploiting the publicity by posing as lenders and tricking people into handing over personal and banking details.

                                                                                                                                                                                The FCA has been clear: it will never ask for PINs or passwords. If someone calls about a payout, it’s a scam. Hang up immediately and report it. With so much publicity around the genuine legal cases, these scams are only likely to grow.

                                                                                                                                                                                Read more - https://www.bbc.co.uk/news/articles/c860021w3g8o

                                                                                                                                                                                ∠The Awareness Angle

                                                                                                                                                                                • No Scheme Yet – Any compensation offers right now are fake as the FCA is still in consultation.
                                                                                                                                                                                • Data Theft Risk – Scammers aim to harvest bank and personal details under the guise of claims.

                                                                                                                                                                                • Avoid Middlemen – Claims firms may take up to 30% of payouts unnecessarily.

                                                                                                                                                                                                  Google Calendar Spam Invites Trick Users Into Scams

                                                                                                                                                                                                  Watch the discussion - https://youtu.be/Ce8cjxsYXDY?t=2531

                                                                                                                                                                                                  A sneaky scam is making its way into people’s schedules, literally. Attackers are sending fake Google Calendar invites that look like business opportunities, complete with WhatsApp numbers and vague “partnership” offers. Because Calendar is often set to automatically add invitations, these bogus meetings appear right in your diary even if the invite goes to spam.

                                                                                                                                                                                                  The hook is simple: reply to the WhatsApp number and they’ll try to extract personal details, bank info, or upfront payments for a fake deal. Several versions are circulating, all using different email addresses but the same WhatsApp contact.

                                                                                                                                                                                                  The fix is straightforward:

                                                                                                                                                                                                  • In Google Calendar, go to Settings → Event settings → Automatically add invitations → No, only show invitations I’ve responded to.

                                                                                                                                                                                                  • Under View options, uncheck Show declined events.

                                                                                                                                                                                                  This is basically phishing delivered through your calendar instead of your inbox, and it’s a reminder that spam can slip in from unexpected places.

                                                                                                                                                                                                  Read more - https://www.bitdefender.com/en-gb/blog/hotforsecurity/use-google-calendar-heres-the-one-change-that-can-protect-your-business-from-scams

                                                                                                                                                                                                  ∠The Awareness Angle

                                                                                                                                                                                                  • Calendar Phishing – Scams don’t just arrive by email anymore; invites and reminders can be weaponised too.
                                                                                                                                                                                                  • Default Settings Risk – “Automatically add” gives attackers a free pass to your schedule.

                                                                                                                                                                                                  • Simple Fix – Changing one setting shuts down this entire attack vector.

                                                                                                                                                                                                                      Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                                                                                                                                                                                      This Week's Discussion Points...

                                                                                                                                                                                                                      Linux-Based Lenovo Webcams' Flaw Can Be Remotely Exploited for BadUSB Attacks
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      uBlock Origin Lite Is Finally Available on Safari
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Drivers warned about scam car finance payout calls
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Critical Zero-Days Crack Open CyberArk Password Vaults
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Bouygues Telecom Hit by Cyberattack, 6.4 Million Customers Affected
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Interlock Ransomware Group Leaks 43GB of Data in City of St. Paul Cyberattack
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Reddit: Strong Passwords Weaker Than Weak Ones
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Reddit Meme: Age Verification Scam Ads
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Password Power – CyberHerd Awareness Game
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      AOL Ends Dial-Up Service After More Than 30 Years
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Major Data Breach Meme (Major Data Breach Reporting for Duty)
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      Google Calendar Spam Scam
                                                                                                                                                                                                                      Watch | Read

                                                                                                                                                                                                                      📬 Subscribe to the Newsletter

                                                                                                                                                                                                                      https://www.riskycreative.com

                                                                                                                                                                                                                        Major Data Breach… Reporting for Duty

                                                                                                                                                                                                                        Watch - https://youtu.be/Ce8cjxsYXDY?t=2361

                                                                                                                                                                                                                        Sometimes security awareness doesn’t need a 50-page whitepaper, it just needs a good laugh. On an Australian news broadcast, the words “Major Data Breach” flashed up on screen while a military officer in uniform stood perfectly in frame. The unintentional mash-up looked like the officer’s name badge was literally “Major Data Breach.”

                                                                                                                                                                                                                        The clip from the Toni and Jon Podcast last year has since gone viral and for good reason. It’s a reminder that humour can break down barriers when talking about cyber. Sharing memes, light-hearted clips, and cultural moments like this in your workplace can spark conversations that stick far longer than another all-staff email.

                                                                                                                                                                                                                        ∠The Awareness Angle

                                                                                                                                                                                                                        • Humour Works – A funny clip can start the security conversation better than another warning.
                                                                                                                                                                                                                        • Front of Mind – Little viral moments keep “cyber” relevant in everyday chatter.

                                                                                                                                                                                                                        • Relatable Training Tool – Sharing memes in newsletters, chats, or town halls can make security feel human and approachable.


                                                                                                                                                                                                                        Watch it at - https://www.instagram.com/reel/DNPuMmOsQC0/?igsh=MTZpNmViaW8xNGl3

                                                                                                                                                                                                                        Microsoft Recall Is Still Saving Your Passwords?

                                                                                                                                                                                                                        This week on The Awareness Angle, we’re digging into the UK’s Online Safety Act again, but this time looking at the hidden privacy risks of handing your most sensitive data to unregulated overseas firms. From facial scans to passport details, we ask whether the cure is worse than the disease.

                                                                                                                                                                                                                        We also unpack Microsoft Recall’s ongoing privacy failings, with tests still showing it can capture credit cards, passwords and other sensitive details, even with filters supposedly in place. And in Canada, the City of Hamilton’s $5M cyber insurance claim has been denied after skipping a basic security control, multi-factor authentication.

                                                                                                                                                                                                                        Elsewhere, scammers are faking endorsements with AI, the UK's Liberal Democrats want tighter vetting of YouTube ads, Google joins the list of Salesforce breach victims, and Pandora confirms a third-party attack. Plus, a staggering 6.8 million WhatsApp scam accounts taken down, and the strange world of North Korea’s undercover IT workforce.

                                                                                                                                                                                                                        And finally, Ant is getting ready for two LinkedIn Lives from the SANS Security Awareness Summit in Chicago, so if you can’t be there, you can still soak up the atmosphere from wherever you are.

                                                                                                                                                                                                                        New Website Now Live!

                                                                                                                                                                                                                        This week saw us launch our new website.  It's now easier than ever to view past episodes. You can also now sign up to become a member and buy Awareness Angle merchandise.  We've got new items coming to the store in the coming weeks, so keep your eyes peeled.  Check out the site at riskycreative.com

                                                                                                                                                                                                                        🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                                                                                                                                                                                        Listen Now

                                                                                                                                                                                                                        Podcast · Risky Creative

                                                                                                                                                                                                                        SANS Security Awareness Summit - A Different Remote Experience

                                                                                                                                                                                                                                🎙️ Live From Chicago...

                                                                                                                                                                                                                                This week, Ant will be bringing the energy of the SANS Security Awareness Summit straight to you with two live LinkedIn broadcasts direct from the community area in Chicago.

                                                                                                                                                                                                                                On Thursday, 14th August and Friday, 15th August (12:15–13:30 Chicago time, 18:15–19:30 UK), he'll be chatting with awareness professionals, vendors and other attendees to capture the buzz of the summit. You can already watch the official talks online, but these lunchtime lives will give you the conversations, atmosphere and insights from the floor, including the bits you don’t usually see.

                                                                                                                                                                                                                                It’s a chance to meet some of the people driving change in the awareness space, hear what’s hot in the industry right now and maybe even spot some of our new podcast merchandise making their debut.

                                                                                                                                                                                                                                Register for the live streams below:

                                                                                                                                                                                                                                Thursday's Event - https://www.linkedin.com/events/7359692338895503361/
                                                                                                                                                                                                                                Friday's Event - https://www.linkedin.com/events/7359693582628196353/

                                                                                                                                                                                                                                Online Safety Act or Privacy Risk?

                                                                                                                                                                                                                                Watch the discussion - https://youtu.be/c9CzNOszjxI?t=248

                                                                                                                                                                                                                                Under the UK’s new Online Safety Act, people now have to verify their age to use platforms like X, Reddit and Bluesky. That means millions are handing over biometric data, ID documents and even financial information to third-party companies outside the UK. Many of these firms have poor or unknown privacy track records, and some have ties to controversial figures or former intelligence officers.

                                                                                                                                                                                                                                Critics warn there’s no public oversight, no register of approved providers and no enforced privacy standards. The result is a system where your most sensitive data could end up in the hands of the cheapest bidder, stored in a country with weaker protections, with little way to know if it will ever be deleted. For most users, the choice is stark. Share the data or accept a censored internet.

                                                                                                                                                                                                                                A big thank you to Matt Gordon-Smith for messaging us and raising this point! Ant meant to give a shout-out in the episode but forgot!

                                                                                                                                                                                                                                Read more - https://bylinetimes.com/2025/07/31/the-online-safety-act-is-forcing-brits-to-hand-over-personal-data-to-unregulated-overseas-corporations-with-questionable-privacy-records/

                                                                                                                                                                                                                                ∠The Awareness Angle

                                                                                                                                                                                                                                • Privacy by Compulsion – UK users are being forced to give facial scans, passport details and other sensitive data to unregulated foreign companies to access mainstream platforms.
                                                                                                                                                                                                                                • Trusting the Untrustworthy – Some providers have a history of breaches or links to surveillance groups, with vague privacy policies that allow data reuse and AI training.

                                                                                                                                                                                                                                • No Real Oversight – Without approved provider lists or mandatory standards, platforms can choose cost over safety when it comes to handling user data.

                                                                                                                                                                                                                                                        Microsoft Recall Still Spying on Your Screen

                                                                                                                                                                                                                                                        Watch the discussion - https://youtu.be/c9CzNOszjxI?t=587

                                                                                                                                                                                                                                                        Microsoft’s Recall feature on Copilot+ PCs is still capturing sensitive information, despite the company’s promises and new security filters. Tests by The Register showed that Recall can record credit card numbers, usernames and passwords if they appear on screen without obvious labels. Once saved, these screenshots can be accessed by anyone with the device’s PIN, even via remote access tools,  making it possible to bypass Microsoft’s security claims.

                                                                                                                                                                                                                                                        While Microsoft encrypts Recall data and ties access to Windows Hello, these measures are undermined by weak entry points like PIN access. Critics warn that the feature poses a significant privacy risk for everyday users, especially those in vulnerable situations. With Recall still in testing but expected to roll out widely, there are growing concerns it could quietly become the default on millions of devices before its flaws are fixed.

                                                                                                                                                                                                                                                        Read more - https://www.theregister.com/2025/08/01/microsoft_recall_captures_credit_card_info/

                                                                                                                                                                                                                                                        ∠The Awareness Angle

                                                                                                                                                                                                                                                        • Security Bypassed by Simplicity – Encryption means little if someone can unlock Recall with just your PIN, locally or remotely.
                                                                                                                                                                                                                                                        • Sensitive Data Still Slipping Through – Credit cards, passwords and other personal info are still being stored, showing Recall’s detection logic is far from reliable.

                                                                                                                                                                                                                                                        • Privacy Implications for Vulnerable Users – Once captured, private moments and personal data are permanently logged with little control over what’s kept or shared.

                                                                                                                                                                                                                                                                        No MFA, No Coverage: Hamilton’s Costly Cyber Mistake

                                                                                                                                                                                                                                                                        Watch the discussion - https://youtu.be/c9CzNOszjxI?t=892

                                                                                                                                                                                                                                                                        In 2024, the City of Hamilton was hit by a ransomware attack that paralysed 80% of its systems. Hackers demanded $18.5 million, which the city refused to pay. Recovery costs have since exceeded $20 million and will continue into 2026.

                                                                                                                                                                                                                                                                        City officials expected their $5 million cyber insurance policy to soften the blow, but the claim was denied. The reason? Many departments had failed to implement multi-factor authentication (MFA), a requirement clearly stated in the policy. Staff resistance to MFA slowed its rollout, and the insurer cited the lack of it as a “root cause” of the breach. Despite the scale of the incident, no individuals have been held accountable, leaving residents to foot the bill.

                                                                                                                                                                                                                                                                        Read more - https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713

                                                                                                                                                                                                                                                                        ∠The Awareness Angle

                                                                                                                                                                                                                                                                        • MFA Neglect Has Real Costs – Ignoring a basic security control didn’t just make the attack possible. It also voided insurance coverage.
                                                                                                                                                                                                                                                                        • Resistance to Security = Vulnerability – Internal pushback left critical systems exposed, showing that security culture matters as much as technology.

                                                                                                                                                                                                                                                                        • Accountability Gap – Leadership indecision and lack of ownership can multiply the damage from cyber incidents, both operationally and financially.

                                                                                                                                                                                                                                                                                        Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                                                                                                                                                                                                                                                        This Week's Discussion Points...

                                                                                                                                                                                                                                                                                        UK Online Safety Act, age verification & privacy risks
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        Microsoft Recall still capturing sensitive data
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        City of Hamilton ransomware & MFA insurance refusal
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        Proton launches free cross-platform authenticator app
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        “Ghost store” scams selling fake weight-loss treatments
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        Calls to vet YouTube ads like TV ads
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        Google Salesforce breach via vishing, ShinyHunters
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        Pandora cyberattack & possible ShinyHunters link
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        WhatsApp deletes 6.8m scam accounts
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        North Korean IT workers funding regime
                                                                                                                                                                                                                                                                                        Watch | Read

                                                                                                                                                                                                                                                                                        📬 Subscribe to the Newsletter

                                                                                                                                                                                                                                                                                        https://www.riskycreative.com

                                                                                                                                                                                                                                                                                          Instagram’s New Location Feature

                                                                                                                                                                                                                                                                                          Watch - https://youtu.be/c9CzNOszjxI?t=3872

                                                                                                                                                                                                                                                                                          Instagram has added a location-sharing feature in the inbox that can show your followers where you last posted from. If location permissions are on, this might be enabled by default.

                                                                                                                                                                                                                                                                                          That might sound harmless, but think about it! The people who follow you on Instagram aren’t always close friends. They could be old acquaintances, casual contacts, or even people you barely know. Do you really want all of them to know your current or recent location?

                                                                                                                                                                                                                                                                                          How to switch it off

                                                                                                                                                                                                                                                                                          1. Open Instagram and go to your Inbox.

                                                                                                                                                                                                                                                                                          2. Tap the pin/Friends Map banner above Notes.

                                                                                                                                                                                                                                                                                          3. Select Location settings.

                                                                                                                                                                                                                                                                                          4. Turn off Share location and Show on map. If you see Visibility, set it to No one.

                                                                                                                                                                                                                                                                                          For extra privacy, you can also remove Instagram’s location permission in your phone’s settings.

                                                                                                                                                                                                                                                                                          ⚠️ Some users report this feature may not be available in the UK or EU yet, but it’s worth checking so you’re ready if or when it arrives.

                                                                                                                                                                                                                                                                                          ∠The Awareness Angle

                                                                                                                                                                                                                                                                                          • Assumed Trust – Just because someone follows you on Instagram does not mean you want them to know where you are. Location sharing blurs the line between friendly connection and personal exposure.
                                                                                                                                                                                                                                                                                          • Default On, Default Risk – If you have location permissions enabled, this feature may be switched on without you realising, making it easy to overshare.

                                                                                                                                                                                                                                                                                          • Check Before It Spreads – Even if it is not live in your region yet, keep checking your settings so you will not be caught off guard when it rolls out.

                                                                                                                                                                                                                                                                                                Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                                                                                                                                                                                                                                                                Is the UK Online Safety Act Flawed?

                                                                                                                                                                                                                                                                                                This week on The Awareness Angle, we discuss the knock-on effects of the UK’s Online Safety Act, from free VPNs topping the app charts, to Sims characters and AI face-swapping being used to fool age checks. It’s a fascinating look at what happens when compliance meets real-world behaviour.

                                                                                                                                                                                                                                                                                                We also talk about a viral Reddit post where a new starter is facing the sack after failing phishing simulations that were so aggressive, they blurred the line between awareness and sabotage. And we run through four major breaches, Allianz Life, NASCAR, Orange France, and the city of St. Paul, all showing different shades of third-party risk and response failure.

                                                                                                                                                                                                                                                                                                Also: QR code suspicion, awareness tools with no sales pitch, intimate tech privacy leaks, and Ant’s ongoing confusion over his new bin schedule.

                                                                                                                                                                                                                                                                                                Plus, a quick plug, Ant will be heading to Chicago for the SANS Security Awareness Summit. If you're there or joining online, keep an eye out for the LinkedIn Lives.

                                                                                                                                                                                                                                                                                                New Website Now Live!

                                                                                                                                                                                                                                                                                                This week saw us launch our new website.  It's now easier than ever to view past episodes. You can also now sign up to become a member and buy Awareness Angle merchandise.  We've got new items coming to the store in the coming weeks so keep your eyes peeled.  Check out the site at riskycreative.com

                                                                                                                                                                                                                                                                                                🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

                                                                                                                                                                                                                                                                                                Listen Now

                                                                                                                                                                                                                                                                                                Podcast · Risky Creative

                                                                                                                                                                                                                                                                                                Magic, Mindset, and Metrics - Harley Sugarman on Rethinking Training

                                                                                                                                                                                                                                                                                                        🎙️ Out Now On The Awareness Angle Interviews!

                                                                                                                                                                                                                                                                                                        Security awareness is often full of smoke and mirrors, and not always in a good way.

                                                                                                                                                                                                                                                                                                        In this episode, Ant chats with Harley Sugarman, founder of Anagram Security, about why traditional training falls flat, how bad metrics lead us astray, and what it really takes to change behaviour. They get into mindset shifts, nudge fatigue, and why calling people “risks” might be the worst move of all.

                                                                                                                                                                                                                                                                                                        People’s journeys into security awareness are rarely straightforward, and Harley’s has a twist that makes his whole approach make sense (you’ll see what we mean).

                                                                                                                                                                                                                                                                                                        If you want awareness that sticks (and maybe even amazes), don’t miss this one.

                                                                                                                                                                                                                                                                                                        🎧 This episode is available at https://riskycreative.com/supporters/video_embeds/146832, and wherever you get your podcasts and on YouTube.

                                                                                                                                                                                                                                                                                                        Previous Episodes - 

                                                                                                                                                                                                                                                                                                        To catch our previous episodes of The Awareness Angle Interviews - visit https://riskycreative.com/supporters/videos

                                                                                                                                                                                                                                                                                                        If you’ve got a story to tell, a lesson to share, or a perspective you think more people should hear, get in touch. We’d love to hear from you. Email us at hello@riskycreative.com

                                                                                                                                                                                                                                                                                                        VPN Chaos as UK Age Checks Go Live

                                                                                                                                                                                                                                                                                                        Watch the discussion - https://youtu.be/J3qw0NvSTgc?t=188

                                                                                                                                                                                                                                                                                                        The UK’s Online Safety Act is now in force, requiring age verification for access to adult content. Predictably, VPN downloads have skyrocketed, with free apps topping the App Store charts. But experts warn these apps often come with serious risks, from shady data practices to outright malware.

                                                                                                                                                                                                                                                                                                        The new law has triggered a wave of workarounds, from VPN use to AI-generated facial spoofing. Meanwhile, platforms like Spotify are threatening to delete accounts that fail to verify, and YouTube is testing AI that estimates your age based on your watch history.

                                                                                                                                                                                                                                                                                                        ∠The Awareness Angle

                                                                                                                                                                                                                                                                                                        • Free VPNs Are Risk Magnets – Popular free VPNs are often insecure, ad-supported, or even malicious. And now they’re being used by kids.
                                                                                                                                                                                                                                                                                                        • Tech Controls Are Being Bypassed – AI facial spoofing, game characters, and loophole-sharing on social media show how quickly people find ways around policy.

                                                                                                                                                                                                                                                                                                        • Compliance ≠ Safety – Platforms risk promoting tools that undermine the very rules they’re trying to follow. Time to focus on real outcomes, not just box-ticking.

                                                                                                                                                                                                                                                                                                                              Phishing Fail? You're Fired.

                                                                                                                                                                                                                                                                                                                              Watch the discussion - https://youtu.be/J3qw0NvSTgc?t=3308

                                                                                                                                                                                                                                                                                                                              A Reddit user shared their experience of joining a new company, only to be told months later that they were one phishing fail away from being terminated. They’d already failed five, but the real issue? The tests were borderline unfair. They used real branding, copied genuine internal emails (like PTO requests), and were sent from legitimate-looking addresses. One arrived on their first day. No warnings until failure number four. No support. No clarity. Just a countdown to being fired.

                                                                                                                                                                                                                                                                                                                              The user was new to MS Outlook had never even worked in a company that ran phishing simulations before. They were flagging genuine threats and excelling in their role otherwise, but that didn’t matter. They now live in fear of their inbox.

                                                                                                                                                                                                                                                                                                                              Read more - https://www.reddit.com/r/cybersecurity/comments/1mbwp26/are_my_companys_phishing_tests_in_bad_faith_or_am/

                                                                                                                                                                                                                                                                                                                              ∠The Awareness Angle

                                                                                                                                                                                                                                                                                                                              • Is This Really What “Awareness” Looks Like – If your phishing tests are causing fear, silence, or people gaming the system just to avoid punishment, your programme has failed, no matter what your dashboard says.
                                                                                                                                                                                                                                                                                                                              • Simulations Should Teach, Not Trap – First-day tests? Mimicking HR processes with no prior context? That’s not training. That’s entrapment. Especially for new joiners who don’t yet know what “normal” looks like.

                                                                                                                                                                                                                                                                                                                              • You're Measuring Fear, Not Resilience – You can scare people into compliance, but it doesn’t build better behaviour. It builds resentment, disengagement, and a toxic relationship with security.

                                                                                                                                                                                                                                                                                                                              Ant's Take - 

                                                                                                                                                                                                                                                                                                                              I'm not a fan of phishing simulations but they have their place.  I feel that while phishing simulations aren't the enemy, badly designed ones are. The goal isn’t to "catch people out." It’s to help them catch themselves before clicking next time.

                                                                                                                                                                                                                                                                                                                              As I said in this episode:

                                                                                                                                                                                                                                                                                                                              "Phishing simulations should support people — not entrap them."
                                                                                                                                                                                                                                                                                                                              "If your first experience at a company is being tricked by a phishing test on day one, something’s gone wrong."

                                                                                                                                                                                                                                                                                                                              We’re supposed to be building confidence and culture, not testing whether someone can read minds under pressure.

                                                                                                                                                                                                                                                                                                                              And it’s not just me. Simon Sinek is often quoted as saying, “A culture is strong when people work with each other, for each other.” I also hear Maxime Cartier from Hoxhunt speak often about the importance of psychological safety, and how fear-based training undermines it.

                                                                                                                                                                                                                                                                                                                              Fear doesn’t create better behaviour. It creates silence. It isolates people. And it makes security feel like a trap, not a support system.

                                                                                                                                                                                                                                                                                                                              If your programme relies on shame, secrecy, or silence, are you really managing risk or are you creating it.

                                                                                                                                                                                                                                                                                                                                              Four Breaches, One Theme?

                                                                                                                                                                                                                                                                                                                                              Watch the discussion - https://youtu.be/J3qw0NvSTgc?t=1626

                                                                                                                                                                                                                                                                                                                                              It’s been a rough week for security teams. Allianz Life, the city of St. Paul, NASCAR, and Orange France were all hit by serious breaches, exposing everything from Social Security numbers to city infrastructure.

                                                                                                                                                                                                                                                                                                                                              • Allianz Life lost personal and financial data of most US customers. The entry point? A third-party CRM tool.

                                                                                                                                                                                                                                                                                                                                              • St. Paul, Minnesota was hit so hard by ransomware, the National Guard had to step in to restore city operations.

                                                                                                                                                                                                                                                                                                                                              • NASCAR was extorted for $4 million after attackers accessed contracts, ID documents, and health data via a third-party vendor.

                                                                                                                                                                                                                                                                                                                                              • Orange France confirmed attackers accessed customer contracts and ID info through an IT services provider.

                                                                                                                                                                                                                                                                                                                                              ∠The Awareness Angle

                                                                                                                                                                                                                                                                                                                                              • Third-Party Risk Isn’t Abstract – Three of these breaches involved external systems or suppliers. If someone else has access to your data, their breach is your breach.
                                                                                                                                                                                                                                                                                                                                              • It’s Not Just Data, It’s Disruption – From payroll freezes to city-wide outages, the impact is more than reputational. Real people and services were affected.

                                                                                                                                                                                                                                                                                                                                              • Basic Access Still Gets Exploited – Weak passwords, slow detection, and social engineering continue to be the entry points. This is not advanced cyber-wizardry. It’s the same old doors left unlocked.

                                                                                                                                                                                                                                                                                                                                                          Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!

                                                                                                                                                                                                                                                                                                                                                          Awareness Awareness

                                                                                                                                                                                                                                                                                                                                                          🎤 SANS Security Awareness Summit – Ant’s Heading to Chicago

                                                                                                                                                                                                                                                                                                                                                          The SANS Security Awareness Summit is happening August 14–15, live in Chicago and online, and Ant will be there in person, learning, and livestreaming bits of it from the floor.

                                                                                                                                                                                                                                                                                                                                                          Expect a couple of LinkedIn Lives, some behind-the-scenes moments, and maybe a few chats with awareness pros as they come out of sessions. If you’re joining online, definitely hop into the SANS Slack, the conversation there is always lively.

                                                                                                                                                                                                                                                                                                                                                          This summit is one of the best for anyone working on the human side of security. It’s all about behaviour, culture, and communication, not just policy and platforms.

                                                                                                                                                                                                                                                                                                                                                          🔗 Check out the Summit

                                                                                                                                                                                                                                                                                                                                                          SebDB 4.0 is live
                                                                                                                                                                                                                                                                                                                                                          Oz Alashe announced the latest CybSafe update to their Security Behaviour Database, now aligned to MITRE, NIST, and more. It’s open-source, and free to use.
                                                                                                                                                                                                                                                                                                                                                          🔗 See the announcement

                                                                                                                                                                                                                                                                                                                                                          A Free Maturity Model That Doesn’t Sell You Stuff
                                                                                                                                                                                                                                                                                                                                                          Jason Hoenich’s new tool at humanrisk.com gives you a benchmark across strategy, engagement, assessment, and training.  The best part is that there is no sales pitch attached (but you can reach out to Jason for guidance and support if you wish!!)
                                                                                                                                                                                                                                                                                                                                                          🔗 Try it now

                                                                                                                                                                                                                                                                                                                                                          FYI - Jason has made a bunch of updates since we recorded this, so it will have only gotten better!

                                                                                                                                                                                                                                                                                                                                                          🧪 Fable Comes Out of Stealth
                                                                                                                                                                                                                                                                                                                                                          There’s a new human risk startup on the scene. Fable Security just launched publicly, with big investment and even bigger promises around "agentic AI" for behaviour change. Think bite-sized nudges, deepfake detection, and phishing defence, all delivered with a sleek interface and some very polished branding.

                                                                                                                                                                                                                                                                                                                                                          It’s early days, but the pitch is bold: smarter, scalable human risk intervention with less noise and more action. We’ll be keeping an eye on it to see how it stands out in a rapidly growing space.

                                                                                                                                                                                                                                                                                                                                                          🔗 Check out Fable

                                                                                                                                                                                                                                                                                                                                                                          This Week's Discussion Points...

                                                                                                                                                                                                                                                                                                                                                                          VPN Use Surges After UK Age Checks
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Labour Rules Out VPN Ban, Warns Households
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Loopholes Used to Bypass Online Safety Act
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Spotify Threatens to Delete Unverified Accounts
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          YouTube Using AI to Guess Your Age
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Google AI Search Launches in UK
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Lovense App Flaw Leaks User Emails
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Microsoft Edge Adds ‘Copilot Mode’ AI Assistant
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Allianz Life Breach – Personal Data Stolen
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          City of St. Paul Hit by Ransomware, National Guard Deployed
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          NASCAR Data Breach – $4M Ransom Demanded
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Orange France Cyberattack via IT Supplier
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Reddit Story – Harsh Phishing Test Penalties
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          Hertfordshire Bin Chaos
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          TikTok Clip – Hidden Messages in Birdsong
                                                                                                                                                                                                                                                                                                                                                                          Watch | Read

                                                                                                                                                                                                                                                                                                                                                                          📬 Subscribe to the Newsletter

                                                                                                                                                                                                                                                                                                                                                                          https://www.riskycreative.com

                                                                                                                                                                                                                                                                                                                                                                            Bin Watch 2025

                                                                                                                                                                                                                                                                                                                                                                            Watch - https://youtu.be/J3qw0NvSTgc?t=3647

                                                                                                                                                                                                                                                                                                                                                                            Ant recently found himself navigating a new local bin system. Five bins. Three different collection cycles. Two separate letters from the council, each giving different instructions. 

                                                                                                                                                                                                                                                                                                                                                                            It’s a small thing, but it stuck with him, because it’s exactly what happens when security controls get too complex.

                                                                                                                                                                                                                                                                                                                                                                            If people don’t know what’s expected, or the rules keep changing, they don’t follow the system, they work around it. Not out of laziness, but survival. They’re just trying not to get it wrong.

                                                                                                                                                                                                                                                                                                                                                                            In awareness, we talk a lot about risk, but confusion is its own kind of risk. If your policies feel like bin day maths, don’t be surprised when people stop engaging with them.

                                                                                                                                                                                                                                                                                                                                                                            Simplicity isn’t a shortcut. It’s the strategy.

                                                                                                                                                                                                                                                                                                                                                                            ∠The Awareness Angle

                                                                                                                                                                                                                                                                                                                                                                            • Complexity Kills Compliance – When people can’t understand or remember the rules, they stop following them. Confusion creates risk, even if your policy is technically sound.
                                                                                                                                                                                                                                                                                                                                                                            • Intent Doesn’t Equal Clarity – Just because you’ve communicated something doesn’t mean it landed. Conflicting instructions, like conflicting security messages, erode trust fast.

                                                                                                                                                                                                                                                                                                                                                                            • Simplicity Builds Behaviour – Clear, consistent guidance makes it easier for people to do the right thing. If security is intuitive, people won’t need a calendar, chart, or cheat sheet to follow it.

                                                                                                                                                                                                                                                                                                                                                                                Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

                                                                                                                                                                                                                                                                                                                                                                                Chicago, We’re Coming In Hot!

                                                                                                                                                                                                                                                                                                                                                                                In two weeks, I’ll be heading to the SANS Security Awareness Summit in Chicago, and I’m bringing The Awareness Angle with me.

                                                                                                                                                                                                                                                                                                                                                                                I’ll be doing two live streams from the event, plus recording a special episode of the podcast with Luke while I’m there. Expect real-time reactions, honest takes, and plenty of behind-the-scenes moments from one of the biggest events in the awareness calendar.

                                                                                                                                                                                                                                                                                                                                                                                Ill be catching up with some familiar faces in the awareness industry, founders, leaders and other pros finding out their thoughts of the event and getting some great insights.

                                                                                                                                                                                                                                                                                                                                                                                Stream are planned for Thursday 14th and Friday 15th. Keep an eye out for stream times and podcast drops. It’s going to be a good one.

                                                                                                                                                                                                                                                                                                                                                                                See you stateside!

                                                                                                                                                                                                                                                                                                                                                                                Ant

                                                                                                                                                                                                                                                                                                                                                                                Magic, Mindset, and Metrics – Harley Sugarman from Anagram Security

                                                                                                                                                                                                                                                                                                                                                                                When it comes to security awareness, most tools are solving the wrong problem. That’s the starting point for this conversation with Harley Sugarman, founder of Anagram Security – and from there, we go deep.

                                                                                                                                                                                                                                                                                                                                                                                Harley’s background isn’t your typical cybersecurity CV. Before launching Anagram, he worked in engineering and security, often wondering why awareness was treated as an afterthought. Despite being labelled the biggest risk in most organisations, people rarely get the investment or attention they deserve. And training? Too often it’s just a compliance box ticked once a year.

                                                                                                                                                                                                                                                                                                                                                                                In this episode, Harley talks about how that disconnect pushed him to start building something different. Something that treats behaviour change as a core goal – not a side effect. Anagram’s approach? Short, engaging content, interactive puzzles, and mindset shifts that help people think like attackers. The result is more than knowledge. It’s habit-building.

                                                                                                                                                                                                                                                                                                                                                                                We dig into:

                                                                                                                                                                                                                                                                                                                                                                                • Why phishing click rates can be gamed – and why they don’t tell the full story

                                                                                                                                                                                                                                                                                                                                                                                • What makes a good “nudge” (and what just becomes noise)

                                                                                                                                                                                                                                                                                                                                                                                • How AI could enable contextual, real-time awareness – if used right

                                                                                                                                                                                                                                                                                                                                                                                • The real reason security awareness gets such a small slice of the budget

                                                                                                                                                                                                                                                                                                                                                                                • And why vague compliance standards might actually be a hidden opportunity

                                                                                                                                                                                                                                                                                                                                                                                One of the most interesting parts of the conversation is around metrics. We’ve all been asked to prove impact. But most of the metrics we rely on – completions, clicks, reports – are poor proxies for real behaviour. Harley argues that many CISOs already know who their riskiest users are. The challenge is moving from identification to actual change. And doing it in a way that feels human, not punishing.

                                                                                                                                                                                                                                                                                                                                                                                There’s also a brilliant moment where Harley talks about how much of today’s awareness training would be considered totally unacceptable in a classroom. If we taught children the way we teach adults about cyber, there’d be protests. He’s not wrong.

                                                                                                                                                                                                                                                                                                                                                                                Oh, and somewhere in the second half of the episode, there’s a small detail about Harley’s earlier career that explains a lot about how he sees behaviour, storytelling, and audience engagement. Let’s just say it involves a certain flair for the unexpected. You’ll spot it when it comes.

                                                                                                                                                                                                                                                                                                                                                                                Whether you work in security awareness, lead a team, or are just trying to make your organisation care a bit more about human risk, this episode offers a refreshing take on what’s possible – and a reminder that we can do better than "click here to complete your annual training."

                                                                                                                                                                                                                                                                                                                                                                                Listen now and start thinking about what your awareness programme could be if you reimagined it from the ground up.

                                                                                                                                                                                                                                                                                                                                                                                You can find Harley at anagramsecurity.com or connect with him on LinkedIn.