<turbo-stream action="append" target="posts_list"><template><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146267">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146267/watch_times"
  data-youtube-player-video-id-value="PsBI-ClNVAY"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/bnfhn1qxqhx0fqixih1f90c8y9il" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146267">
          Jun 23, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146267">
            Is Your Security Awareness Program Just Ticking Boxes?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This episode is a little different. No news. No phishing breakdowns. Just two awareness professionals (on holiday, sort of) talking through something that affects every security team come October: what do we actually<span> </span><em>do</em><span> </span>for Cybersecurity Awareness Month?</p>
<p>It’s a familiar scene. You sit down with a blank whiteboard, maybe a fresh pack of Post-its, and ask the question we all dread: “What’s our campaign this year?”</p>
<p>Well, in this special episode, we tried something new. We asked ChatGPT for its “Top 10 Strategies to Enhance Cybersecurity Awareness Among Colleagues” and then reacted live. What’s solid advice? What’s tired and overdone? And what’s actually harmful to your internal brand?</p>
<p>Spoiler: we have thoughts.</p>
<h3><strong>Training Isn’t Top. Engagement Is.</strong></h3>
<p>The list ChatGPT gave us ended with “implement regular cybersecurity training sessions” as the number one strategy.</p>
<p>We disagreed. Strongly.</p>
<p>Yes, training has its place. It ticks compliance boxes. It satisfies auditors. But it's rarely what<span> </span><em>changes behaviour</em>. In fact, if it’s bad training, lengthy, irrelevant, unrelatable, it can actively harm your internal credibility.</p>
<p>Instead, we believe in<span> </span><strong>engagement</strong>.</p>
<p>If you're nudging, educating, storytelling, and staying visible year-round, that<span> </span><em>is</em><span> </span>training. You're building a culture, not just ticking a box. You’re shifting perception. That should be the goal.</p>
<h3><strong>Our Take on the “Top 10” (and where it goes right)</strong></h3>
<p>Here’s what stood out from the rest of the list:</p>
<h3>10. Open Communication Channels</h3>
<p>A strong start. Most people don’t report security concerns because they don’t know how. Or worse, they feel stupid doing so. Your job is to remove that barrier. Whether it’s Slack, Teams, email, or a champions network, make it easy and human.</p>
<h3>9. Recognise and Reward</h3>
<p>Yes. Celebrate the wins. Not just from security nerds or your champions, but from Kevin in Accounts who reported a dodgy email. From the tech team that patched ahead of schedule. Recognition is cheap and powerful. Use it.</p>
<h3>8. Gamify the Learning</h3>
<p>Escape rooms. Simulations. Even a quiz that isn’t painful. Interactivity matters. Just keep it user-first. Don’t add fluff because it looks fun. Make it feel useful.</p>
<h3>7. Real-World Consequences</h3>
<p>Bring the stories to life. Don’t say “a retailer was attacked.” Say “M&amp;S was breached, where you buy Percy Pigs.” That makes people pay attention. If it’s public, use names. Be human about it.</p>
<h3>6. Clear Policies</h3>
<p>Policies shouldn’t be written in legalese. Why do we still do that? Flip the script. Say what someone<span> </span><em>can</em><span> </span>do. Use natural language. And maybe explore ideas like interactive policy lookups or AI chatbots that explain the rules like a friend.</p>
<h3>5. Culture is Everything</h3>
<p>Security isn’t just a poster on a wall. It’s how often your team talks about it, how leaders model it, how peers treat it. Embed it everywhere. Celebrate it. Live it.</p>
<h3>4. Push MFA</h3>
<p>No debate here. Just maybe next year we’re saying “push passkeys.” Either way, MFA is still the best bang-for-buck control. And people should be using it at home too, not just at work.</p>
<h3>3. Strong, Unique Passwords</h3>
<p>Still relevant. Still a mess. Most people reuse passwords. Or use Arsenal1886 across all sites. Use this moment to promote password managers. Long is better than complex. Unique is better than clever.</p>
<h3>2. Simulated Phishing</h3>
<p>Controversial. It has a place, but only if it’s done well. Don’t traumatise staff. Don’t make it about punishment. Use it as a prompt for better conversations. Otherwise, just talk to your people. Teach. Don’t trap.</p>
<h2>Ideas for October: More Than Just Posters</h2>
<p>If you’re planning Cybersecurity Awareness Month, we also shared five initiatives that go beyond “raise awareness” and actually drive behaviour:</p>
<ul>
<li>
<p><strong>Photo Challenges</strong><span> </span>– Get personal. Ask staff to show how they stay secure.</p>
</li>
<li>
<p><strong>Escape Rooms</strong><span> </span>– Team-based, hands-on, and fun.</p>
</li>
<li>
<p><strong>Myth-Busting Webinars</strong><span> </span>– Kill off old beliefs with relatable stories.</p>
</li>
<li>
<p><strong>Device Security Check-Ups</strong><span> </span>– Help people secure their real lives.</p>
</li>
<li>
<p><strong>Interactive Phishing Games</strong><span> </span>– Teach people what to look for, not just test them.</p>
</li>
</ul>
<h2>Final Thought</h2>
<p>Training isn’t dead. But it’s not the hero.</p>
<p>What matters is how we show up. How we make people feel. How often we get in their ear. If your training is 30 minutes once a year, but your engagement is weekly, daily, embedded, that’s your awareness programme.</p>
<p>So as October approaches, don’t just ask “What’s our training?” Ask:<span> </span><strong>“What are we doing to actually connect?”</strong></p>
<p>And if you need help making that happen, well, you know where to find us.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146267?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146267?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146267%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146267%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146269">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146269/watch_times"
  data-youtube-player-video-id-value="etqNb8NW7xQ"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/9fkuojgr040hraej8ypmlopvwxpd" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146269">
          Jun 19, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146269">
            “Real-time beats simulation” - Terry McCorkle on Rethinking Phishing
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>Phishing Simulations Are Broken – Here’s What Terry McCorkle Is Doing About It</strong></p>
<p>Phishing comes up<span> </span><em>every</em><span> </span>time awareness professionals get in a room. No matter the agenda, it always sneaks in. That’s because it’s still one of the biggest threats we face – and one of the trickiest to manage.</p>
<p>In this episode of<span> </span><em>The Awareness Angle</em>, I speak to Terry McCorkle, a red team veteran with more than 25 years in cybersecurity, about why phishing simulations might not be working the way we think they are – and what we can do instead.</p>
<p>Terry’s been on the frontlines. As a red teamer, he used phishing to gain access to networks across the world. Now, he’s switched sides. He’s the founder of<span> </span><a href="https://phishcloud.com/" target="_blank" rel="noopener">PhishCloud</a>, a platform that takes a completely different approach to phishing defence: real-time support for users, without the surveillance, fear, or gotchas.</p>
<p>And if you think this is just another anti-simulation rant, it’s not. Terry knows simulations can have value. But he’s seen first-hand the harm they can do when they’re designed to catch people out, especially when those clicks turn into warnings, HR meetings, or worse.</p>
<p>So what do we talk about?</p>
<p>First, we get into the core problem with traditional phishing simulations – they rely on tricking people. You run a test, someone clicks, and then you show them what they should have done. That’s like letting someone get mugged and then saying, “Next time, don’t walk down that alley.” It’s not helpful, and it’s not fair.</p>
<p>Terry shares a story about someone who clicked on a simulated phish during a red team engagement. That person<span> </span><em>immediately</em><span> </span>reported it, changed their password, did all the right things – but still got fired. The security team didn’t even respond for two days. That’s not a user failure. That’s a broken system.</p>
<p>PhishCloud flips the model. Instead of testing people after the fact, it gives them support<span> </span><em>at the moment of risk</em>. A simple browser overlay shows a green, yellow, or red warning when a user sees a link – not just in email, but in search results, chat messages, social media, and more. It’s like having a trusted friend sat next to you, quietly nudging you before you make a mistake.</p>
<p>And yes, the platform uses machine learning and threat intelligence – but Terry doesn’t pitch it like it’s magic. He talks about confidence levels, transparency, and giving users the tools they need without invading their privacy. It’s smart tech designed to make people smarter, not just tick boxes.</p>
<p>We also cover some familiar ground, like how phishing isn’t just an email problem anymore, and how simulation metrics can be easily gamed. Want a low click rate? Send an obvious phish. Want to scare your stakeholders? Send a nasty one and watch the clicks roll in. It’s easy to shape the data to suit your story – but that doesn’t make it meaningful.</p>
<p>Terry’s approach is rooted in empathy. He’s not here to bash users or hand out click-shaming reports. He’s here to build something that actually helps. That gives people a chance to<span> </span><em>learn in the moment</em><span> </span>and change their behaviour in a way that sticks.</p>
<p>We also talk about automation, and how a system like PhishCloud doesn’t just help users – it helps the security team too. By cutting down false positives, giving better visibility, and pushing useful metrics into the SOC, it frees up time and reduces burnout.</p>
<p>It’s a proper rethinking of how we handle phishing. Less fear. More support. Less finger-pointing. More partnership.</p>
<p>And if you’ve ever felt uncomfortable about running phishing tests that feel more like traps than training, this episode might just give you the words – and the model – to do it differently.</p>
<p>You can find out more about PhishCloud at<span> </span><a href="https://phishcloud.com/" target="_blank" rel="noopener">phishcloud.com</a>, and connect with Terry on<span> </span><span class="ml-rte-link-wrapper"><a href="https://www.linkedin.com/in/terrymccorkle/" target="_blank" rel="noopener">LinkedIn</a></span>.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146269?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146269?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146269%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146269%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146270">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146270/watch_times"
  data-youtube-player-video-id-value="DXTmp1gdgIQ"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/17lyyt3iz3dac5wka5w5nhaktojh" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146270">
          Jun 16, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146270">
            The Hidden Danger of LNK Files on Your Computer
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>Episode 34 of The Awareness Angle is packed with real-world breaches, practical advice, and a surprisingly useful pigeon. Ant and Luke break down the stories behind the headlines, from major retail ransomware to the hidden dangers of shortcut files, and share why awareness still matters more than ever.</p>
<p>We start with Marks &amp; Spencer, who have finally resumed online orders six weeks after a devastating cyberattack. The incident disrupted everything from contactless payments to click-and-collect, and is estimated to have cost the retailer around £300 million. Ant and Luke reflect on the wider impact this has had across the retail sector, praising M&amp;S for getting back online and raising awareness of cyber threats in the process.</p>
<p>Next up, US-based food wholesaler UNFI – a key supplier to Whole Foods – confirmed it had been hit by a cyberattack, forcing some systems offline and delaying orders. It’s a reminder that cyberattacks on supply chains have knock-on effects far beyond the target, affecting customers, retailers, and even the stock market.</p>
<p>Back in the UK, the British Horseracing Authority was also impacted by a cyber incident. Despite the disruption, race meetings continued, showing the importance of contingency plans and operational resilience. In contrast, NHS Professionals, a major staffing agency for the NHS, took over a year to disclose its breach. Attackers reportedly stole the Active Directory database using a compromised Citrix account. Deloitte’s investigation suggests stolen credentials, lack of MFA, and poor endpoint detection contributed to the damage. Ant and Luke question the delay in disclosure and talk about the importance of basic security hygiene.</p>
<p>In the phishing and threats section, the duo look at a new macOS malware campaign involving the Atomic Stealer. Using a fake CAPTCHA, the attack tricks users into pasting code into their terminal. It’s part of a growing trend called ClickFix, which relies on fake error messages and security prompts to manipulate users. It’s not just Windows users at risk anymore.</p>
<p>Microsoft’s Patch Tuesday brings 66 security fixes, including one zero-day flaw already being exploited in the wild. But another unpatched threat is getting attention: a vulnerability in Windows shortcut (.LNK) files that lets attackers embed malicious network paths. Just viewing the file in Explorer can trigger a hidden payload. Microsoft is relying on Defender and Smart App Control for now, with no full patch available yet.</p>
<p>The episode also revisits the FAA’s long-overdue plan to replace Windows 95 and floppy disks in US air traffic control. While it might sound like a punchline, it highlights just how much critical infrastructure still relies on outdated tech. Meanwhile, WhatsApp has joined Apple in challenging the UK Home Office’s demand for a backdoor into encrypted data.</p>
<p>And with Windows 10 support ending in October 2025, Ant and Luke discuss the grassroots movement encouraging users to switch to Linux instead of buying new hardware. The "End of 10" project promotes open-source alternatives, with benefits for privacy, the environment, and user control.</p>
<p>Ant also introduces the concept of an "attack atmosphere," a broader way of thinking about cybersecurity risks that considers the entire environment, not just obvious vulnerabilities. This ties in with a conversation about human behaviour, and how changing that is more effective than any tool you can buy.</p>
<p>Oh, and the pigeon? You’ll have to listen to the episode for that one – but trust us, it makes more sense than you think.</p>
<p>New episodes of The Awareness Angle are released every Monday, with interviews dropping every other Thursday. Subscribe via your favourite podcast app or visit riskycreative.com to sign up for the newsletter.</p>
<p><strong>M&amp;S resumes online orders after cyber attack</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=87" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=87</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.retailgazette.co.uk/blog/2025/06/marks-spencer-resumes-online-orders-after-cyberattack/</a></p>
<p><strong>UNFI cyberattack disrupts Whole Foods supply chain</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=210" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=210</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.securityweek.com/unfi-hit-by-cyberattack-impacting-operations/</a></p>
<p><strong>British Horseracing Authority confirms cyber breach</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=294" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=294</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.thoroughbrednews.com.au/news/story/bha-hit-by-cyber-attack-163838</a></p>
<p><strong>NHS Professionals breach kept quiet for 13 months</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=375" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=375</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.theregister.com/2025/06/06/nhs_professionals_data_breach/</a></p>
<p><strong>Atomic macOS Stealer campaign using ClickFix</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=723" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=723</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/macos-users-targeted-with-atomic-stealer-in-fake-spectrum-sites/</a></p>
<p><strong>Microsoft June Patch Tuesday – 66 flaws, 1 zero-day</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=1076" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=1076</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2025-patch-tuesday-fixes-exploited-zero-day-66-flaws/</a></p>
<p><strong>LNK shortcut file flaw – no patch yet</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=1189" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=1189</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/microsoft-warns-of-windows-lnk-zero-day-used-in-attacks/</a></p>
<p><strong>FAA still using Windows 95 and floppy disks</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=2207" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=2207</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.tomshardware.com/tech-industry/faa-finally-eliminating-floppy-disks-from-air-traffic-control</a></p>
<p><strong>WhatsApp joins Apple in UK encryption fight</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=2432" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=2432</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/technology-68948697</a></p>
<p><strong>End of Windows 10 – should you switch to Linux?</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=2697" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=2697</a><br>Read –<span> </span><a href="https://endof10.org/" target="_blank" rel="noopener">https://endof10.org/</a></p>
<p><strong>New 'attack atmosphere' mindset in cybersecurity</strong><br>Watch –<span> </span><a href="https://youtu.be/DXTmp1gdgIQ?t=3148" target="_blank" rel="noopener">https://youtu.be/DXTmp1gdgIQ?t=3148</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bitdefender.com/blog/businessinsights/the-evolution-from-attack-surface-to-attack-atmosphere/</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146270?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146270?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146270%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146270%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146272">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146272/watch_times"
  data-youtube-player-video-id-value="0w38e9hdtZU"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/w891vbfyhnz4i938gexih3tk8z5w" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146272">
          Jun 9, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146272">
            Why Gen Z Is Going Passwordless
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>Two Awards, Ten Breaches, and One Periwinkle Tempest – What a Week in Cybersecurity</strong></p>
<p>This episode is packed with cybersecurity stories, clever phishing scams, and some big questions about security awareness.</p>
<p>We kick things off with a celebration.<span> </span><em>The Awareness Angle</em><span> </span>is now an award-winning podcast. We picked up two wins at the European Cybersecurity Blogger Awards: Best Back to Basics Podcast, and Ant was named Contributor of the Year. It was an incredible night full of brilliant people, unexpected selfies, and some very questionable cyber-themed cocktails. Graham Cluley even took our photo, and KnowBe4 handed over Lego fishermen for the kids. Definitely one for the scrapbook.</p>
<p>But it wasn’t all glitter and swag. The retail sector is still under attack, with both The North Face and Cartier reporting recent cyber incidents. Credential stuffing, unauthorised access, and exposed customer data are all part of the story. We also dig into the Marks &amp; Spencer breach, where a class action lawsuit is now underway. Over 350 customers have joined the claim, with compensation being sought for the fallout. It’s a strong reminder that third-party risk and transparency still need serious attention.</p>
<p>We also talk about Microsoft’s big move to delete saved passwords from the Authenticator app starting in August. It’s part of the shift to a passwordless future, but are users ready for it? And are organisations supporting that transition clearly enough?</p>
<p>On the privacy front, Signal has taken a stand by blocking Windows Recall from taking screenshots of private chats. This is one of the first concrete moves we’ve seen against Recall, and it raises important questions about consent, AI tools, and how much visibility users really have over what’s captured on their screens.</p>
<p>We also highlight new research from NordPass showing how shockingly weak password practices are still common in the automotive industry. Passwords like “123456” and “P@ssw0rd” are being used to secure connected vehicle systems, often without any multi-factor authentication in place. It’s a worrying glimpse into a part of the industry that often flies under the radar.</p>
<p>Meanwhile, Australia has introduced new rules requiring large businesses to report ransomware payments within 72 hours. Rather than banning ransom payments outright, they’re pushing for transparency. It’s a bold step, and one that other countries may be watching closely.</p>
<p>We also explore Microsoft and CrowdStrike’s new effort to simplify threat actor naming. Instead of multiple vendors calling the same group by different names, they’re trying to align terms to reduce confusion. Say goodbye to Wizard Spider. Say hello to Periwinkle Tempest.</p>
<p>There’s also a quick heads-up for creative teams. A malicious Blender file disguised as a free 3D chair model has been spotted spreading malware. If your team uses Blender, now is a good time to review auto-run settings and safe file practices.</p>
<p>And finally, we break down a scam that’s making the rounds via WhatsApp and iMessage. It promises thousands of pounds a month for less than an hour a day. It’s clearly a scam, but with the right timing and the wrong circumstances, people are still getting caught out. It’s a reminder that even old tricks still work.</p>
<p>This episode has a bit of everything. Real stories, important lessons, and a few good laughs along the way. Whether you’re deep in the world of cybersecurity or just trying to stay safer online, this one’s worth a listen.</p>
<p>🎉 Blogger Awards Win<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=129" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=129</a></p>
<p>🧥 The North Face &amp; 💍 Cartier Breaches<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=851" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=851</a><br>Read –<span> </span><a href="https://www.digit.fyi/the-north-face-and-cartier-latest-to-face-cyber-attacks/" target="_blank" rel="noopener">https://www.digit.fyi/the-north-face-and-cartier-latest-to-face-cyber-attacks/</a></p>
<p>📉 M&amp;S Class Action Lawsuit<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=983" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=983</a><br>Read –<span> </span><a href="https://www.itv.com/news/2025-06-03/m-and-s-faces-unprecedented-customer-lawsuit-over-cyberattack-data-breach" target="_blank" rel="noopener">https://www.itv.com/news/2025-06-03/m-and-s-faces-unprecedented-customer-lawsuit-over-cyberattack-data-breach</a></p>
<p>🔐 Microsoft Authenticator Password Deletion<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=1081" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=1081</a><br>Read –<span> </span><a href="https://www.forbes.com/sites/zakdoffman/2025/05/31/microsoft-confirms-password-deletion-now-just-8-weeks-away/" target="_blank" rel="noopener">https://www.forbes.com/sites/zakdoffman/2025/05/31/microsoft-confirms-password-deletion-now-just-8-weeks-away/</a></p>
<p>🚫 Signal Blocks Windows Recall<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=1241" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=1241</a><br>Read –<span> </span><a href="https://www.theverge.com/news/672210/signal-desktop-app-microsoft-recall-block-windows-11-ai" target="_blank" rel="noopener">https://www.theverge.com/news/672210/signal-desktop-app-microsoft-recall-block-windows-11-ai</a></p>
<p>🚗 Smart Cars, Dumb Passwords<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=1411" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=1411</a><br>Read –<span> </span><a href="https://hackread.com/smart-cars-dumb-passwords-auto-industry-weak-passwords/" target="_blank" rel="noopener">https://hackread.com/smart-cars-dumb-passwords-auto-industry-weak-passwords/</a></p>
<p>🇦🇺 Australia Ransomware Disclosure Law<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=1688" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=1688</a><br>Read –<span> </span><a href="https://www.darkreading.com/threat-intelligence/australia-ransomware-payment-disclosure-rules" target="_blank" rel="noopener">https://www.darkreading.com/threat-intelligence/australia-ransomware-payment-disclosure-rules</a></p>
<p>🧑‍💻 Gen Z and Passkey Adoption<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=1779" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=1779</a><br>Read –<span> </span><a href="https://www.androidauthority.com/google-scams-survey-gen-z-passkey-3563937/" target="_blank" rel="noopener">https://www.androidauthority.com/google-scams-survey-gen-z-passkey-3563937/</a></p>
<p>🌪️ Threat Actor Naming – Periwinkle Tempest<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=2100" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=2100</a><br>Read –<span> </span><a href="https://www.microsoft.com/en-us/security/blog/2025/06/02/announcing-a-new-strategic-collaboration-to-bring-clarity-to-threat-actor-naming/" target="_blank" rel="noopener">https://www.microsoft.com/en-us/security/blog/2025/06/02/announcing-a-new-strategic-collaboration-to-bring-clarity-to-threat-actor-naming/</a></p>
<p>🪑 Blender File Malware Warning<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=2497" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=2497</a><br>Read –<span> </span><a href="https://www.reddit.com/r/blender/s/FSyggEQlic" target="_blank" rel="noopener">https://www.reddit.com/r/blender/s/FSyggEQlic</a></p>
<p>💸 WhatsApp £8k Job Scam<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=2680" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=2680</a><br>Read –<span> </span><a href="https://www.reddit.com/r/Scams/comments/1koqxhw/uk_unfamiliar_scam/" target="_blank" rel="noopener">https://www.reddit.com/r/Scams/comments/1koqxhw/uk_unfamiliar_scam/</a></p>
<p>📱 Meta AI on WhatsApp<br>Watch –<span> </span><a href="https://youtu.be/0w38e9hdtZU?t=2856" target="_blank" rel="noopener">https://youtu.be/0w38e9hdtZU?t=2856</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.meta.com/blog/whatsapp/introducing-meta-ai-in-whatsapp/</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146272?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146272?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146272%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146272%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146279">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146279/watch_times"
  data-youtube-player-video-id-value="y6qltCVInR8"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/551oj67iqu0gkhpncno7lkz7z3w1" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146279">
          Jun 5, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146279">
            "Security awareness IS marketing" – Sara Carty on Being Unboring
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>We’re continuing our interview series, conversations with people doing honest, thoughtful, and sometimes unexpected work both in and out of the cyber security awareness space.</p>
<p>The goal? To bring new perspectives to the table. Whether it's reshaping how we talk about risk, rethinking our tools, or digging into what really drives behaviour.</p>
<h3>🎙️ The Awareness Angle Interviews continue!</h3>
<p>When Sara Carty got tired of seeing the same old marketing in cybersecurity,  padlocks, hoodies, and generic FUD, she didn’t just complain. She built <em>Unboring</em>, a marketing studio helping vendors tell better stories, connect with real people, and stand out in a sea of sameness.</p>
<p>In this episode, Sara joins Ant for a smart, funny, and refreshingly honest conversation about what awareness professionals can borrow from great marketing. And why standing out doesn’t need to cost a fortune.</p>
<p>Expect bold takes, practical ideas, and plenty of laughs as we get into:</p>
<p>• Why “humans are the weakest link” is lazy messaging. And what to say instead<br>• The magic of storytelling and how marketers and awareness teams can connect through emotion, relatability, and human-centred narratives<br>• Marketing lessons from Red Bull, Surreal Cereal, and James Bond<br>• What security awareness can learn from B2C brands. And why we’re still playing it safe<br>• AI fatigue, buzzword bingo, and the danger of campaigns that speak “tech” but not “human”</p>
<p>You’ll also hear:</p>
<p>• How a cyber espionage course sharpened Sara’s thinking on communication and influence<br>• The real reason your internal comms might be getting ignored<br>• Why you should treat awareness like a brand. And why employees are your best storytellers</p>
<p>This one is for anyone trying to make security stick. Because attention isn’t free. You have to earn it.</p>
<p>Connect with Sara on <a href="https://www.linkedin.com/in/saracarty/" target="_blank" rel="noopener">LinkedIn </a>and check out<span> </span><a href="https://www.unboring.digital/" target="_blank" rel="noopener">unboring.digital</a> to learn more.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146279?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146279?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146279%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146279%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146282">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146282/watch_times"
  data-youtube-player-video-id-value="XgogrdK_NvU"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/acb4npkw0h975h9vsnyzavbjsylz" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146282">
          Jun 2, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146282">
            These Old Cyber Tricks STILL Work?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>What do Victoria’s Secret, TikTok, and a Scottish train station have in common?</strong><br>They all feature in this week’s episode—alongside malware, fake IT calls, and a growing pile of breached data.</p>
<p>Episode 31 is full of weird, worrying, and very real cyber stories. Retailers are still getting hit. TikTok is spreading malware using AI-generated videos. SIM swap attacks are back. And a voice actor says her voice was cloned by ScotRail without permission. There's also a bit of good news—Microsoft and Apple are making some smart software updates that might actually help.</p>
<p>Let’s break it all down…</p>
<p>🛍️<span> </span><strong>Victoria’s Secret and Adidas – Different Attacks, Same Worry</strong><br>Victoria’s Secret pulled down its entire US website after a security incident. Stores are still open, and the UK site is fine, but details are scarce. Meanwhile, Adidas confirmed that customer contact info was stolen via a third-party help desk. No credit cards were taken, but attackers now have names and email addresses—perfect for phishing.</p>
<p>The bigger trend? Help desks being socially engineered to reset passwords or provide access. It’s the same pattern we saw with MGM, M&amp;S, and others. Social engineering is winning because it’s fast and it works. You don’t need zero-days when you can just ask someone nicely.</p>
<p>🎣<span> </span><strong>AI-Generated TikToks Are Now Spreading Malware</strong><br>In a particularly grim twist, we found out this week that attackers are using TikTok to distribute info-stealing malware. The videos show fake software tips like “activate Microsoft Office” or “get Spotify Premium for free”—but they’re actually convincing users to open PowerShell and paste in malicious code.</p>
<p>One of these videos racked up half a million views.</p>
<p>This isn’t phishing in the traditional sense. There’s no dodgy link or email. Just a fake video and a bit of social engineering that hits people’s curiosity and FOMO. It’s especially dangerous on BYOD devices—because what gets installed at home could end up back on the corporate network.</p>
<p>📞<span> </span><strong>Google Meet Scam – Same Trick, New Platform</strong><br>We also spotted a fake Google Meet error message asking users to “fix” their microphone by pressing Win+R and pasting in a command. It looks like Google Meet, but it’s a full clone, and the code gets copied to the clipboard automatically. You barely have to think. Just press, paste, and enter. And just like that, someone else has control of your device.</p>
<p>Same goes for fake Cloudflare verifications targeting WordPress admins and even a Coursera-themed phishing campaign that leads to a fake Facebook login page. It's all part of a wider trend: fewer links, more human behaviour tricks.</p>
<p>The lesson? If a webpage tells you to open PowerShell or press Win+R,<span> </span><strong>don’t do it. Ever.</strong></p>
<p>🔄<span> </span><strong>SIM Swap Scams Are Back (And Still Working)</strong><br>This story came in from a listener—Oli spotted that someone he knows had been SIM swapped. They got a legitimate-looking message from EE confirming a new eSIM had been ordered, then a flurry of calls from an unknown number. They called EE, and yep—it had happened. Their mobile number had been reassigned, and SMS-based logins were no longer theirs.</p>
<p>It’s easy to forget just how much is tied to your phone number. SMS codes. Banking apps. Password resets. All it takes is one help desk that doesn’t ask the right questions. We talk about whether mobile providers should let users lock their SIM from porting—and why EE’s current process is nowhere near good enough.</p>
<p>🧠<span> </span><strong>The Awareness Angle – Tell People What’s<span> </span><em>Not</em><span> </span>Normal</strong><br>This week’s awareness messaging is simple:<br>If a website or video asks you to open Run (Win+R), PowerShell, or paste in a command—walk away. It’s not normal. It’s never okay. Your IT team will never ask you to do this.</p>
<p>The same goes for weird login pages, especially if they’re offering something free, urgent, or exclusive. Encourage your users to<span> </span><em>pause</em><span> </span>and check before entering credentials or following instructions.</p>
<p>🎙️<span> </span><strong>ScotRail Voice Controversy – AI and Consent</strong><br>Voice actor Gayanne Potter recorded some lines for accessibility tools back in 2021. This year, she discovered her voice had been turned into “Iona”—the new voice of ScotRail. She never gave permission for that. She’s spent two years trying to get it removed.</p>
<p>It’s a real-world version of the video we made last year—<em>Likeness</em>. It’s about how easily your identity can be used by an AI system once you've signed the wrong contract or clicked "agree" without reading. There’s currently no legal protection in the UK for voice or likeness. GDPR might not even apply if the company owns the original recordings.</p>
<p>This one’s a wake-up call for anyone working with audio, video, or their face and name online. Creators deserve more protection. And organisations using AI need to be upfront about how and why they’re doing it.</p>
<p>💰<span> </span><strong>Would You Sell Your Data for £40 a Month? Gen Z Might.</strong><br>A new app called<span> </span><em>Verb.AI</em><span> </span>is paying Gen Zers $50 a month to track their scrolling, clicking, and buying. It builds a “digital twin” that companies can query like a chatbot to understand habits and preferences. It’s being sold as a fair value exchange. But is it?</p>
<p>Apparently, 88% of Gen Z are okay with sharing personal data if there’s compensation. And yet they’re also more likely than older generations to use encrypted messaging, block cookies, and browse privately. There's a tension here between<span> </span><em>knowing the risks</em><span> </span>and<span> </span><em>doing it anyway</em>. And it’s something awareness teams need to understand.</p>
<p>The takeaway? Awareness isn’t just about teaching risk—it’s about helping people care. Especially when short-term rewards (like £40 a month) seem more tangible than long-term data consequences.</p>
<p>🔄<span> </span><strong>Smaller Bits Worth Your Time</strong></p>
<ul>
<li>
<p>WhatsApp is now offering<span> </span><em>passkey</em><span> </span>support for login—so you can ditch SMS codes and use fingerprint or face unlock instead.</p>
</li>
<li>
<p>Microsoft is building a new<span> </span><em>update orchestrator</em><span> </span>that will automatically patch all your drivers, apps, and system components in one go.</p>
</li>
<li>
<p>Apple’s switching to<span> </span><em>year-based naming</em><span> </span>for their OS updates—iOS 26, macOS 26, and so on—alongside a full redesign coming at WWDC.</p>
</li>
</ul>
<p>🧠<span> </span><strong>The Awareness Angle – This Week’s Takeaways</strong></p>
<p><strong>Don’t Run Commands from Random Websites</strong><br>That might sound obvious to security folks, but if TikTok videos and fake error messages are convincing thousands of people to paste code into PowerShell, we’ve still got work to do.</p>
<p><strong>Tell Better Help Desk Stories</strong><br>Attackers are getting in by calling IT. Seriously. The same way someone could walk into McDonald’s wearing a uniform and say “I work here now.” Teach your people to question unexpected requests, even from inside.</p>
<p><strong>People Care About People, Not Protocols</strong><br>£300 million lost. A cloned voice. A password on a post-it note. These are the kinds of details that stick. So make sure your awareness stories are human—not just technical.</p>
<p>🎙️<span> </span><strong>Quick Plugs</strong></p>
<p>We’re up for<span> </span><em>Best Newcomer</em><span> </span>and<span> </span><em>Back to Basics</em><span> </span>at the European Cybersecurity Blogger Awards 2025. Results announced Wednesday 5th June at InfoSec Europe. Ant will be there—say hi if you’re around!</p>
<p>Don’t Miss It!<br>Our<span> </span><em>Awareness Angle Interview</em><span> </span>with<span> </span><strong>Sara Carty</strong><span> </span>from Unboring is out on Thursday.<br>It’s full of honest chat about drama school, storytelling, cyber marketing, and why we need to ditch blue, padlocks, and hoodie stock images.</p>
<p>Listen back—this one’s got loads for awareness pros.</p>
<p>📉<span> </span><strong>Victoria’s Secret Breach</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=149" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=149</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/business-69081682</a></p>
<p>👟<span> </span><strong>Adidas Helpdesk Cyber Attack</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=190" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=190</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/technology-69073785</a></p>
<p>📹<span> </span><strong>TikTok Malware via PowerShell Commands</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=384" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=384</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.infosecurity-magazine.com/news/ai-tiktok-infostealer-malware/</a></p>
<p>🪟<span> </span><strong>Microsoft’s Unified Update System</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=523" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=523</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.windowscentral.com/software-apps/windows-11/microsoft-is-working-on-a-unified-update-platform-to-keep-your-pc-up-to-date</a></p>
<p>🍎<span> </span><strong>Apple OS Rename: iOS 26 and macOS 26</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=723" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=723</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://9to5mac.com/2025/05/28/ios-26-name-change/</a></p>
<p>📄<span> </span><strong>Tajikistan Targeted via Word Macros</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=847" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=847</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/russia-aligned-tag-110-targets-tajikistan-with-dotm-files/</a></p>
<p>☁️<span> </span><strong>Fake Cloudflare Verification Scam</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=996" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=996</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.wordfence.com/blog/2025/05/fake-cloudflare-page-malware/</a></p>
<p>🎥<span> </span><strong>Fake Google Meet PowerShell Attack</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=1080" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=1080</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.cyware.com/news/new-phishing-scam-fake-google-meet-page-tricks-users-into-running-malware-67df4f27</a></p>
<p>🎓<span> </span><strong>Coursera/Meta Phishing Scam</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=1214" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=1214</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://cofense.com/blog/fake-meta-certificates-coursera-phishing-campaign/</a></p>
<p>📱<span> </span><strong>SIM Swap Attack on EE</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=2490" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=2490</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://community.ee.co.uk/t5/Mobile-Services/SIM-Swap-Scam-warning/m-p/1317527</a></p>
<p>💵<span> </span><strong>Gen Z Selling Their Data for $50/month</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=2880" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=2880</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.fastcompany.com/91134124/gen-z-selling-personal-data-verb-app</a></p>
<p>🎙️<span> </span><strong>ScotRail AI Voice Controversy</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=3133" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=3133</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/uk-scotland-69085678</a></p>
<p>📜<span> </span><strong>T&amp;Cs Tool – TOSDR.org</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=3505" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=3505</a><br>Read –<span> </span><a href="https://tosdr.org/" target="_blank" rel="noopener">https://tosdr.org/</a></p>
<p>🔐<span> </span><strong>WhatsApp Adds Passkey Support</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=3660" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=3660</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.whatsapp.com/blog/passkeys-on-android</a></p>
<p>📧<span> </span><strong>Phishing Email Spoofing Luke</strong><br>Watch –<span> </span><a href="https://youtu.be/XgogrdK_NvU?t=3773" target="_blank" rel="noopener">https://youtu.be/XgogrdK_NvU?t=3773</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146282?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146282?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146282%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146282%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146283">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146283/watch_times"
  data-youtube-player-video-id-value="yR2iBWZlDVU"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/wwceeayyyk6duorii851thz2ffqi" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146283">
          May 26, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146283">
            Is Voice Phishing the Next Big Cyber Threat?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>What’s the cost of a retail ransomware attack? For M&amp;S, it’s £300 million.</strong></p>
<p>This episode is full of high-impact cyber stories—from supplier ransomware and spoofed IT calls to fake Chrome extensions and Discord privacy concerns. We also give credit where it's due with a rare win for the UK government, and dive into why your train, hospital, or ATM might still be running Windows XP.</p>
<p>Let’s break it all down...</p>
<p><strong>🛍️ M&amp;S Cyber Attack: £300m and Counting</strong><br>The attack hit at Easter and recovery is expected to last until July. It came via a third-party supplier, used social engineering (not fancy malware), and took down key services. Just browsing is back online—but you still can’t buy anything.</p>
<p><strong>🥩 Tesco &amp; Sainsbury’s Supplier Held to Ransom</strong><br>Cold storage logistics firm Peter Green Chilled was forced to stop taking new orders after a ransomware attack, leaving meat pallets at risk of spoiling. Food supply chains are becoming a soft target—and it’s starting to show on shelves.</p>
<p><strong>📞 3AM Ransomware: Fake IT Calls, Real Access</strong><br>A new campaign mixes email bombing with phone calls spoofed to look like internal IT support. Victims are persuaded to open Quick Assist and hand over control. It's bold, direct, and sadly, very effective.</p>
<p><strong>💸 HSBC CEO: “Cyber Threats Keep Me Awake”</strong><br>Ian Stuart told MPs that cyber risk is a top concern for banks—and a massive ongoing cost. With financial services under constant attack, the push for stronger authentication (like passkeys and number matching) is gaining momentum.</p>
<p><strong>📍 O2 Bug Leaked Your Location During Calls</strong><br>A flaw in O2’s VoLTE and WiFi calling systems exposed IMSI, IMEI, and cell tower data for over a year. It’s now fixed, but highlights how verbose network protocols can become a serious privacy risk.</p>
<p><strong>🚗 Goodbye QR Codes in Car Parks?</strong><br>The UK government is rolling out a National Parking Platform so drivers can use any parking app in any supported location. It’s a big step toward ending QR confusion and fake codes in car parks.</p>
<p><strong>🧩 Chrome Extensions Gone Rogue</strong><br>More than 100 fake Chrome extensions have been caught stealing credentials, hijacking sessions, and injecting ads. Many posed as known tools or services. Don’t trust what you find in the Chrome Web Store—especially if you got there via an ad.</p>
<p><strong>💬 2 Billion Discord Messages Scraped</strong><br>Brazilian researchers scraped public Discord messages from over 3,000 servers and released the dataset for academic use. It’s anonymised, but the backlash shows how fragile our expectations of online privacy really are.</p>
<p><strong>🧠 The Awareness Angle – This Week’s Takeaways</strong></p>
<p><strong>Trust Is Still the Weak Link</strong><span> </span>– Ransomware groups aren’t breaking in. They’re being let in, by confused or tricked staff who think it’s IT calling.</p>
<p><strong>Legacy Systems Are Hidden Risks</strong><span> </span>– From O2’s metadata leak to lifts running Windows XP, old tech can cause new problems.</p>
<p><strong>People Remember What’s Relatable</strong><span> </span>– A £300m price tag sticks. So does a fake IT call. Tell the real stories, not just the technical ones.</p>
<p><strong>🎙️ Quick Plugs</strong></p>
<p>We’re up for Best Newcomer and Back to Basics at the European Cybersecurity Blogger Awards. Voting closes on 27th May. You can vote now at<span> </span><a href="https://riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a></p>
<p><strong>Don't Forget!  <br></strong>The Awareness Angle interview with Amy Stokes-Waters is out now.  Go back one episode and listen. It’s full of personality, honesty, and escape rooms. Don’t miss it.</p>
<p></p>
<p><strong>M&amp;S Cyber Attack – £300m Loss and Third-Party Access</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=373" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=373</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/business-69050058</a></p>
<p><strong>Tesco &amp; Sainsbury’s Supplier Ransomware Attack</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=602" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=602</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.theregister.com/2025/05/21/peter_green_cyberattack/</a></p>
<p><strong>3AM Ransomware – Fake IT Calls and Email Bombing</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=779" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=779</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/3am-ransomware-uses-email-bombing-and-fake-it-calls-to-breach-companies/</a></p>
<p><strong>HSBC CEO – “Cyber Threats Keep Me Up at Night”</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=937" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=937</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/business-68939456</a></p>
<p><strong>O2 Mobile Bug – User Location Leaked via Call Metadata</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=1099" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=1099</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/o2-uk-bug-exposed-mobile-users-location-during-voice-calls/</a></p>
<p><strong>UK Government Unifies Parking Apps to Reduce QR Risks</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=1338" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=1338</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bbc.co.uk/news/technology-68993852</a></p>
<p><strong>100+ Fake Chrome Extensions Stealing Data</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=1477" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=1477</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/over-100-malicious-chrome-extensions-used-to-hijack-browsers/</a></p>
<p><strong>2 Billion Discord Messages Scraped and Published</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=1770" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=1770</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.404media.co/researchers-scrape-and-release-2-billion-discord-messages/</a></p>
<p><strong>Still Booting – Ancient Windows Systems in Use Today</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=2514" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=2514</a><br>Read –<span> </span><a href="https://www.bbc.com/future/article/20240513-the-people-still-using-ancient-windows-computers" target="_blank" rel="noopener">https://www.bbc.com/future/article/20240513-the-people-still-using-ancient-windows-computers</a></p>
<p><strong>Vishr.ai – Live Demo of AI Vishing Simulator</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=2830" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=2830</a><br>Try –<span> </span><a href="https://vishr.ai/" target="_blank" rel="noopener">https://vishr.ai</a></p>
<p><strong>Deepfake Investment Scam Featuring Fake Anthony Bolton</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=3135" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=3135</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://www.fnlondon.com/articles/fidelitys-anthony-bolton-targeted-by-instagram-deepfake-scam-20240513</a></p>
<p><strong>Google Veo – AI Video Generation with Audio</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=3424" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=3424</a><br>Read –<span> </span><a target="_blank" rel="noopener">https://blog.google/technology/ai/google-veo-video-generation-ai-io-2025/</a></p>
<p><strong>Notebook LM – Turn Transcripts into Podcast Conversations</strong><br>Watch –<span> </span><a href="https://youtu.be/yR2iBWZlDVU?t=3858" target="_blank" rel="noopener">https://youtu.be/yR2iBWZlDVU?t=3858</a><br>Try –<span> </span><a href="https://notebooklm.google/" target="_blank" rel="noopener">https://notebooklm.google</a></p>
<p></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146283?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146283?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146283%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146283%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146284">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146284/watch_times"
  data-youtube-player-video-id-value="6-kB6Bi3zFw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/en0ykvzdglc3qhk89fpx9fh6q0ya" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146284">
          May 22, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146284">
            Escape the Boring: Amy Stokes-Waters on Engaging Awareness
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>When Amy Stokes-Waters realised traditional cyber awareness training wasn’t landing, she didn’t tweak the slides. She built a game. What started as a one-off weekend project became<span> </span><em>The Cyber Escape Room Co</em>, a business turning heads (and turning people into hackers) across the UK and beyond.</p>
<p>In this episode, Amy joins Ant for a brilliant, funny, and straight-talking conversation about disrupting the stale world of compliance-based training and replacing it with something people actually want to do.</p>
<p>Expect brutal honesty, memorable stories, and loads of laughs as we cover:</p>
<ul>
<li>
<strong>Why annual training isn’t working</strong><span> </span>– and why "tick the box" exercises don’t lead to behaviour change<br><br>
</li>
<li>
<strong>The power of play</strong><span> </span>– how escape rooms create moments that stick and get people asking questions<span> </span><em>after</em><span> </span>the session</li>
<li>
<strong>Letting people be the attacker</strong><span> </span>– flipping the script to make learning immersive, emotional, and fun<br><br>
</li>
<li>
<strong>Marketing tactics for awareness</strong><span> </span>– from brand voice to omnichannel campaigns, what security can learn from Coca-Cola<br><br>
</li>
<li>
<strong>Champions, scalability and authenticity</strong><span> </span>– building internal advocates and staying true to your tone, even in financial services<br><br>
</li>
</ul>
<p>You’ll also hear:</p>
<ul>
<li>The escape room horror story Amy learned from</li>
<li>Why she built a fake lingerie website to teach cyber lessons</li>
<li>How a school session at “Hogwarts” led to faculty asking about password managers</li>
<li>What’s next for escape rooms, including expansion to the US and into the world of OT security</li>
</ul>
<p><em>“Training in a box, never tick a box.”</em></p>
<p><br>This one’s packed with practical takeaways for anyone trying to make security engaging.</p>
<p>Connect with Amy on<span> </span><a href="https://www.linkedin.com/in/amystokeswaters/" target="_blank" rel="noopener">LinkedIn<span> </span></a>and check out<span> </span><a href="https://www.cyberescaperoom.co/" target="_blank" rel="noopener">cyberescaperoom.co</a><span> </span>to learn more.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146284?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146284?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146284%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146284%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146285">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146285/watch_times"
  data-youtube-player-video-id-value="1gP3YwQD1ew"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/j9jityq1fgg013wvk28xgnh9sq2h" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146285">
          May 19, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146285">
            Did That Freelancer Just Steal $88 Million for North Korea?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>What’s the cost of a Counter-Strike skin? Apparently $1.2 million.</strong><br>This episode is packed with cyber stories, from fake AI tools and North Korean fraud to deepfake investment scams and dodgy booking messages. We also look at the UK government’s Windows 3.1 problem, Steam's not-so-scary leak, and why your Windows 10 machine just got a few more years of life.</p>
<p>Let’s break it all down...</p>
<p>🎮<span> </span><strong>Steam Panic That Wasn't</strong><br>Reports claimed 89 million Steam accounts were leaked, but Valve confirmed no breach. Just some expired SMS codes with no link to passwords or account info. Nothing to do here—but maybe time to stop relying on text messages for your 2FA.</p>
<p>🪟<span> </span><strong>Microsoft Extends Windows 10 Support</strong><br>Microsoft’s changed its mind. Office apps and Defender on Windows 10 will now be supported until 2028. That gives users more time to upgrade and hopefully means fewer devices heading straight to landfill.</p>
<p>🧥<span> </span><strong>Dior Breach: Names, Numbers, and Purchase Histories</strong><br>No credit cards stolen, but Dior confirmed customer data was exposed in South Korea and China. Just another reminder that even luxury brands are vulnerable. Support your users if they’re affected, especially when it comes to phishing risks.</p>
<p>💣<span> </span><strong>North Korean Freelancers Infiltrate Tech Firms</strong><br>Using fake LinkedIn and Upwork profiles, North Korean operatives posed as US tech workers and raked in $88 million—straight into missile funding. This wasn’t hacking. It was hiring fraud. And it worked.</p>
<p>🧠<span> </span><strong>AI Malware Masquerades as AI Video Tools</strong><br>Fake ads for video generators like "Dream Machine" are tricking people into downloading a new info-stealer called Noodlophile. Spoiler: it steals everything. Don’t download tools from Facebook ads. Ever.</p>
<p>🏛️<span> </span><strong>Government Still Using Windows 3.1</strong><br>A new report found that 28% of public sector IT systems are outdated, with some still running Windows 3.1. That’s software from the 90s, unsupported since 2001. Apparently we’re aiming to fix that... by 2030.</p>
<p>📱<span> </span><strong>Google Pushes Passkeys and Scam Protection</strong><br>Android 16 brings scam detection right to your device and warns users if they open a banking app while on a dodgy call. Google is also testing a feature to convert saved passwords into passkeys automatically. Passwords, your days are numbered.</p>
<p>🧠<span> </span><strong>The Awareness Angle – This Week's Takeaways</strong></p>
<ul>
<li>
<p><strong>Trust Is the Attack Vector</strong><span> </span>– From North Korea’s job scams to fake Booking.com chats, social engineering is the real risk. Tech is just the delivery method.</p>
</li>
<li>
<p><strong>Old Systems, Big Risks</strong><span> </span>– If your infrastructure is still running legacy systems, it’s not just inefficient. It’s vulnerable.</p>
</li>
<li>
<p><strong>Training That Doesn’t Stick</strong><span> </span>– Abnormal Security’s latest report says SAT is effort-heavy and impact-light. Maybe it’s time to rethink how we engage people.</p>
</li>
</ul>
<p>🎙️<span> </span><strong>Quick Plugs</strong></p>
<ul>
<li>
<p>We’ve been nominated for the European Cybersecurity Blogger Awards! Voting’s open until 27th May. Vote for us at<span> </span><a href="https://riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a></p>
</li>
<li>
<p>Our interview with Amy Stokes-Waters from The Cyber Escape Room Co. drops this Thursday. It’s full of fun, reality checks, and a bit of colourful language. Headphones advised!</p>
</li>
</ul>
<p></p>
<p><strong>Microsoft's Windows 10 U-Turn – Support extended to 2028</strong><br>Watch the discussion -<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=290" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=290<br>Read - </a><a href="https://www.extremetech.com/computing/microsoft-extends-windows-10-support-for-office-apps-until-2028" target="_blank" rel="noopener">https://www.extremetech.com/computing/microsoft-extends-windows-10-support-for-office-apps-until-2028</a><strong></strong><strong></strong><strong></strong></p>
<p><strong>Google Starts Auto-Upgrading Your Passwords to Passkeys<br></strong>Watch - <a href="https://youtu.be/1gP3YwQD1ew?t=1728" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=1728</a><br>Read -<span> </span><a href="https://www.androidpolice.com/google-may-auto-convert-passwords-to-passkeys-on-android/" target="_blank" rel="noopener">https://www.androidpolice.com/google-may-auto-convert-passwords-to-passkeys-on-android/</a></p>
<p><strong>North Korean Hackers Infiltrate US Tech Companies</strong><br>Watch the discussion -<span class="ml-rte-link-wrapper"><a href="https://youtu.be/1gP3YwQD1ew?t=1100" target="_blank" rel="noopener"><span> </span>https://youtu.be/1gP3YwQD1ew?t=1100</a></span><br>Read more -<span> </span><a href="https://hackread.com/north-korean-hackers-stole-88m-posing-us-tech-workers/" target="_blank" rel="noopener">https://hackread.com/north-korean-hackers-stole-88m-posing-us-tech-workers/</a><strong></strong></p>
<p><strong>Steam “Leak” of Expired SMS Codes</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=460" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=460</a><br>Read –<span> </span><a href="https://www.bleepingcomputer.com/news/security/steam-user-data-leak-just-expired-verification-codes/" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/steam-user-data-leak-just-expired-verification-codes/</a></p>
<p><strong>Dior Cyberattack – Customer Data Exposed</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=646" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=646</a><br>Read –<span> </span><a href="https://www.bleepingcomputer.com/news/security/dior-discloses-data-breach-customer-purchase-data-exposed/" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/dior-discloses-data-breach-customer-purchase-data-exposed/</a></p>
<p><strong>Co-op and M&amp;S Cyber Incidents</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=729" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=729</a><br>Read –<span> </span><a href="https://www.bbc.co.uk/news/articles/cwy382w9eglo" target="_blank" rel="noopener">https://www.bbc.co.uk/news/articles/cwy382w9eglo</a></p>
<p>Fake AI Tools Spreading Noodlophile Malware<br>Watch -<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=1292" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=1292</a><br>Read -<span> </span><span class="ml-rte-link-wrapper"><a href="https://www.bleepingcomputer.com/news/security/fake-ai-tools-spread-noodlophile-malware-stealing-data/" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/fake-ai-tools-spread-noodlophile-malware-stealing-data/</a></span></p>
<p><strong>UK Government Still Running Windows 3.1</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=1536" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=1536</a><br>Read -<span> </span><a href="https://www.theregister.com/2025/05/10/uk_cybersecurity_legacy_systems_report/" target="_blank" rel="noopener">https://www.theregister.com/2025/05/10/uk_cybersecurity_legacy_systems_report/</a></p>
<p><strong>Android 16 Adds Scam Detection and USB Lockdown<br></strong>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=1859" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=1859</a><br>Read –<span> </span><a href="https://www.cyberscoop.com/google-android-16-security-anti-scam/" target="_blank" rel="noopener">https://www.cyberscoop.com/google-android-16-security-anti-scam/</a></p>
<p><strong>Booking.com Chat Scam Targeting Travellers</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=3090" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=3090</a><br>Read –<span> </span><a href="https://vm.tiktok.com/ZNd6sahwo/" target="_blank" rel="noopener">https://vm.tiktok.com/ZNd6sahwo/</a></p>
<p><strong>GoDaddy’s Fake Bonus Phishing Test (2020 Throwback)</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=3490&amp;feature=shared" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=3490</a><br>Read –<span> </span><a href="https://www.cbsnews.com/news/godaddy-apologizes-insensitive-phishing-email-offering-bonuses/" target="_blank" rel="noopener">https://www.cbsnews.com/news/godaddy-apologizes-insensitive-phishing-email-offering-bonuses/</a></p>
<p><strong>Phishing Passkeys Using Device Code Flow</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=1957" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=1957</a><br>Read –<span> </span><a href="https://denniskniep.github.io/posts/09-device-code-phishing/" target="_blank" rel="noopener">https://denniskniep.github.io/posts/09-device-code-phishing/</a></p>
<p><strong>Abnormal Security Awareness Report</strong><br>Watch –<span> </span><a href="https://youtu.be/1gP3YwQD1ew?t=2055" target="_blank" rel="noopener">https://youtu.be/1gP3YwQD1ew?t=2055</a><br>Read –<span> </span><a href="https://abnormal.ai/resources/state-of-security-awareness-training" target="_blank" rel="noopener">https://abnormal.ai/resources/state-of-security-awareness-training</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146285?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146285?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146285%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146285%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_146286">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/146286/watch_times"
  data-youtube-player-video-id-value="1EEv-bnKHs4"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/ps6vtbprck6str89rdvkjpk4wks4" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/146286">
          May 12, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/146286">
            Is That Voice Note from Your Child, or an AI Voice Clone?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week’s episode is packed. We’re kicking off with the ongoing mess in UK retail. Co-op is still battling a cyber incident that’s disrupted deliveries, while M&amp;S and Harrods stay eerily quiet. It’s a sobering reminder that even the biggest names can be caught off guard, and it’s a golden opportunity for awareness teams to highlight why secure password resets and helpdesk verification really matter. If you ever needed a case study to get leadership attention, this is it.</p>
<p>We also explore a new twist on an old scam. The “Hi Mum” WhatsApp con is back, but this time it comes with cloned AI voice notes. Imagine hearing your child’s voice asking for help, only it’s not really them. We talk about how these scams are evolving, how to spot them, and what conversations we should be having with our families and teams to stay safe.</p>
<p>From there, we dive into Microsoft’s new OneDrive feature that could quietly lead to serious data leaks if not configured properly. We also break down the LockBit ransomware gang breach, which exposed affiliate credentials, victim chats, and some embarrassing passwords. It’s a strange comfort to know that even cybercriminals struggle with good security practices.</p>
<p>Finally, it’s all about passkeys. Microsoft, the UK Government, and the FIDO Alliance are leading the charge toward a passwordless future. But are people actually ready for this shift? We look at what awareness teams need to do now, and how to explain this to non-technical users in a way that sticks. All that, plus some odd AI moments and a proud moment for us with three nominations at the European Cybersecurity Blogger Awards.</p>
<p></p>
<p><strong>Co-op cyber incident update</strong><br><a href="https://www.telegraph.co.uk/business/2025/05/08/co-op-halts-delivery-non-essential-goods-cyber-attack/" target="_blank" rel="noopener">https://www.telegraph.co.uk/business/2025/05/08/co-op-halts-delivery-non-essential-goods-cyber-attack/</a></p>
<p><strong>WhatsApp “Hi Mum” scam with AI voice cloning</strong><br><a href="https://www.theguardian.com/money/2025/may/04/hi-mum-whatsapp-text-scam-parents-friends-bank" target="_blank" rel="noopener">https://www.theguardian.com/money/2025/may/04/hi-mum-whatsapp-text-scam-parents-friends-bank</a></p>
<p><strong>OneDrive’s risky new sync feature</strong><br><a href="https://hansbrender.com/2025/05/02/onedrive-microsofts-new-rollout-may-be-a-gift-wrapped-data-leak/" target="_blank" rel="noopener">https://hansbrender.com/2025/05/02/onedrive-microsofts-new-rollout-may-be-a-gift-wrapped-data-leak/</a></p>
<p><strong>LockBit ransomware gang breached</strong><br><a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-hacked-victim-negotiations-exposed/" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-hacked-victim-negotiations-exposed/</a></p>
<p><strong>Microsoft pushes passkeys for World Passkey Day</strong><br><a href="https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/" target="_blank" rel="noopener">https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/</a></p>
<p><strong>UK Government joins passkey movement</strong><br><a href="https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services" target="_blank" rel="noopener">https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services</a></p>
<p><strong>Cyber chief warns firms not to pay hackers</strong><br><a href="https://www.itv.com/news/2025-05-07/dont-pay-hackers-cyber-security-chiefs-warning-after-major-retail-attacks" target="_blank" rel="noopener">https://www.itv.com/news/2025-05-07/dont-pay-hackers-cyber-security-chiefs-warning-after-major-retail-attacks</a></p>
<p><strong>Angry NHS staff call leaked to YouTube</strong><br><a href="https://www.bbc.co.uk/news/articles/c2dedp9nkwro.amp" target="_blank" rel="noopener">https://www.bbc.co.uk/news/articles/c2dedp9nkwro.amp</a></p>
<p><strong>CoGUI phishing platform sends 580 million scam emails</strong><br><a href="https://www.bleepingcomputer.com/news/security/cogui-phishing-platform-sent-580-million-emails-to-steal-credentials/" target="_blank" rel="noopener">https://www.bleepingcomputer.com/news/security/cogui-phishing-platform-sent-580-million-emails-to-steal-credentials/</a></p>
<p><strong>AI-generated testimony accepted in court</strong><br><a href="https://www.404media.co/email/0cb70eb4-c805-4e4e-9428-7ae90657205c/" target="_blank" rel="noopener">https://www.404media.co/email/0cb70eb4-c805-4e4e-9428-7ae90657205c/</a></p>
<p><strong>Clipboard warning for Samsung phone users</strong><br><a href="https://www.linkedin.com/posts/craigpickles_implement-auto-delete-clipboard-history-to-activity-7324758602190102528-Nuxs" target="_blank" rel="noopener">https://www.linkedin.com/posts/craigpickles_implement-auto-delete-clipboard-history-to-activity-7324758602190102528-Nuxs</a></p>
<p><strong>Discussion about Royal Mail ryml.me link</strong><br><a href="https://www.reddit.com/r/mildlyinfuriating/s/Zv5ZhvLeds" target="_blank" rel="noopener">https://www.reddit.com/r/mildlyinfuriating/s/Zv5ZhvLeds</a><br><br><strong>Clipboard warning from Craig Pickles</strong><br><a href="https://www.linkedin.com/posts/craigpickles_implement-auto-delete-clipboard-history-to-activity-7324758602190102528-Nuxs" target="_blank" rel="noopener">https://www.linkedin.com/posts/craigpickles_implement-auto-delete-clipboard-history-to-activity-7324758602190102528-Nuxs</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/146286?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/146286?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146286%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F146286%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame></template></turbo-stream>

<turbo-stream action="remove" target="posts_load_more"></turbo-stream>

  <turbo-stream action="append" target="posts_list"><template><turbo-frame id="posts_load_more">
  <a data-turbo-stream="true" data-controller="infinite-scroll" href="/supporters/load_more?last_id=146286&amp;last_live_at=2025-05-12T05%3A00%3A00.000%2B00%3A00&amp;order=desc"></a>
  <div class="loader">
  <svg class="loader__icon" viewBox="0 0 100 100">
    <circle class="loader__circle" cx="50" cy="50" r="45" />
  </svg>
</div>
</turbo-frame>
</template></turbo-stream>
