<turbo-stream action="append" target="posts_list"><template><turbo-frame class="main-list__list-item" data-testid="Post" id="post_199093">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/199093/watch_times"
  data-youtube-player-video-id-value="fuG0UsphrS8"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/fuG0UsphrS8/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/199093">
          Jan 19, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/199093">
            Instagram Passwords, Ransomware Claims, and AI Controls
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, we cover a busy mix of breaches, claims, and security moments that blurred the line between what happened and what people thought happened. Instagram password reset emails caused widespread confusion, ransomware groups made high-profile breach claims without releasing data, and a well-known hacking forum found itself dealing with a leak of its own.</p>
<p class="ember-view reader-text-block__paragraph">We also look at cyber incidents with real-world impact, including attacks linked to drug smuggling at major European ports and attempted intrusions targeting national energy infrastructure. On the technology side, we discuss Microsoft’s latest Patch Tuesday, growing control over AI tools on work devices, and why some organisations want clearer choices around when those tools appear.</p>
<p class="ember-view reader-text-block__paragraph">The episode also explores emerging questions about identity and trust, from reused passwords and long-lived leaked data to eye-scanning technology promoted as a way to prove you are human online.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle is best served in full. Watch on YouTube, or listen on Spotify or your favourite podcast platform to get the complete discussion and context.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">This week's stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Instagram password reset emails and data leak claims</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=410" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.techlicious.com/blog/ignore-instagram-password-reset-scam-email/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A large number of Instagram users reported receiving password reset emails they did not request. Meta confirmed it fixed an issue that allowed an external party to trigger legitimate password reset emails at scale and said there was no breach of Instagram systems. According to Meta, user accounts were not compromised, and the emails were caused by abuse of a feature rather than a hack.</p>
<p class="ember-view reader-text-block__paragraph">At the same time, security firm Malwarebytes reported that data linked to around 17.5 million Instagram accounts was being advertised online. The dataset is said to include usernames, email addresses, phone numbers, and, in some cases, physical addresses. Meta has denied any link between the password reset emails and the data, stating that it likely came from older scraping activity rather than a new Instagram breach.</p>
<p class="ember-view reader-text-block__paragraph">While there is no public evidence tying the two events together, the timing created widespread confusion. Unexpected security emails combined with reports of leaked data looked and felt like a breach to many users, regardless of the technical explanation.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Timing shapes perception</strong><span class="white-space-pre"> </span>- When alerts and leak claims land together, people assume the worst</li>
<li>
<strong>Users see impact, not root cause</strong><span class="white-space-pre"> </span>- Bug or breach matters less than how it feels</li>
<li>
<strong>Old data still circulates</strong><span class="white-space-pre"> </span>- Historic scraping can resurface and fuel new scams</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Ports hacked to support drug smuggling, hacker jailed</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1195" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.bleepingcomputer.com/news/security/hacker-gets-seven-years-for-breaching-rotterdam-and-antwerp-ports/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A hacker has been sentenced to 7 years in prison for cyberattacks that disrupted operations at the Port of Rotterdam and the Port of Antwerp. The attacks took place between 2021 and 2023 and involved unauthorised access to container logistics systems.</p>
<p class="ember-view reader-text-block__paragraph">Prosecutors said the access was used to manipulate the release and movement of shipping containers, enabling organised crime groups to collect drug shipments without detection. The case highlights how cyber access can directly enable real-world criminal activity rather than just data theft.</p>
<p class="ember-view reader-text-block__paragraph">Authorities said the sentence reflects the seriousness of targeting critical infrastructure and the wider risks posed to safety, trade, and national security.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Cyber enables physical crime</strong><span class="white-space-pre"> </span>- Access to systems can unlock real-world harm</li>
<li>
<strong>Logins are high-value targets</strong><span class="white-space-pre"> </span>- Human access often matters more than malware</li>
<li>
<strong>Impact goes beyond IT</strong><span class="white-space-pre"> </span>- Disruption affects supply chains and public safety</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Microsoft may allow Copilot to be uninstalled on managed devices</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=900" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.bleepingcomputer.com/news/microsoft/microsoft-may-soon-allow-it-admins-to-uninstall-copilot-on-managed-devices/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Microsoft is planning to give IT administrators the option to uninstall Copilot from managed Windows devices, rather than just hide or disable it. The change would apply to enterprise-managed devices and address concerns about control, data handling, and readiness.</p>
<p class="ember-view reader-text-block__paragraph">The move gives organisations more choice over when and how AI tools appear on work devices, particularly as teams continue to work through policies, training, and acceptable use. Copilot remains positioned as a productivity feature, but many organisations are still deciding how to introduce it safely.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Control matters</strong><span class="white-space-pre"> </span>- IT teams want clear choices, not forced rollouts</li>
<li>
<strong>AI affects behaviour</strong><span class="white-space-pre"> </span>- Tools change how people work, not just systems</li>
<li>
<strong>Readiness comes first</strong><span class="white-space-pre"> </span>- Introducing AI before guidance creates risk</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">AI is not selling, is interest waning?</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1066" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.zdnet.com/article/ai-pcs-arent-selling-and-microsofts-pc-partners-are-scrambling/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Despite heavy investment in AI-powered PCs and tools, some manufacturers are reporting weaker-than-expected demand. Executives at Dell said consumers are not buying devices for AI features, and that AI-focused messaging often creates confusion rather than clarity.</p>
<p class="ember-view reader-text-block__paragraph">The comments suggest a gap between how vendors promote AI and how everyday users understand its value. While AI continues to be embedded across products, its presence alone does not appear to be driving purchasing decisions.</p>
<p class="ember-view reader-text-block__paragraph">This comes as organisations continue to balance innovation with concerns about data use, trust, and whether people actually want AI involved in their daily work.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>AI does not automatically sell</strong><span class="white-space-pre"> </span>- Features need clear, practical value</li>
<li>
<strong>Confusion slows adoption</strong><span class="white-space-pre"> </span>- Unclear benefits create hesitation</li>
<li>
<strong>Trust still matters</strong><span class="white-space-pre"> </span>- Data questions shape acceptance</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This week's discussion points...</h2>
<p class="ember-view reader-text-block__paragraph">Everest Ransomware Claims Nissan Data Breach –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=58" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://hackread.com/everest-ransomware-nissan-data-breach/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Spanish Energy Giant Endesa Reports Major Customer Data Breach –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=222" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.securityweek.com/spanish-energy-company-endesa-hacked/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Instagram Password Reset Emails –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=410" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.techlicious.com/blog/ignore-instagram-password-reset-scam-email/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Breachforums Data Leak –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=623" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Microsoft Patch Tuesday –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=770" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://cyberscoop.com/microsoft-patch-tuesday-january-2026/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Microsoft Copilot Removal Option –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=900" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.bleepingcomputer.com/news/microsoft/microsoft-may-soon-allow-it-admins-to-uninstall-copilot-on-managed-devices/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">AI PCs Not Selling –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1066" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.zdnet.com/article/ai-pcs-arent-selling-and-microsofts-pc-partners-are-scrambling/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Hacker Jailed for Attacks on Rotterdam and Antwerp Ports –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1195" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.bleepingcomputer.com/news/security/hacker-gets-seven-years-for-breaching-rotterdam-and-antwerp-ports/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Poland Cyber Attack on Energy Infrastructure Stopped –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1350" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.euronews.com/2026/01/15/polands-pm-praises-cyber-defences-after-attempted-attack-on-energy-infrastructure-foiled" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Scam Email Knows My Password –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1444" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.reddit.com/r/phishing/s/lcA2L24Ccy" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Worldcoin and Eye Scans for Human Verification –<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1600" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.forbes.com/sites/danfitzpatrick/2025/05/19/i-let-sam-altmans-orb-scan-my-eyes-now-im-a-verified-human/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">And finally...Scanning your eyes to prove you are human, Sam Altman’s Orb</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://youtu.be/fuG0UsphrS8?t=1600" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.forbes.com/sites/danfitzpatrick/2025/05/19/i-let-sam-altmans-orb-scan-my-eyes-now-im-a-verified-human/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">This one is proper Black Mirror territory, because it takes a real problem, bot spam, fake accounts, AI-generated nonsense everywhere, and answers it with something that feels way too permanent. Worldcoin’s Orb scans your iris to create a unique digital identifier, a World ID, basically a way to prove you are a real human online. In some places, they even pay you in crypto to do it.</p>
<p class="ember-view reader-text-block__paragraph">The pitch is “we do not store your eye images, we just turn it into a cryptographic code”, but the bit that makes my skin crawl is the direction of travel. Once you normalise scanning bodies to access digital services, it is hard to un-invent that. Passwords can be changed, devices can be replaced, but biometrics are forever. If a system like this ever gets abused, breached, repurposed, or linked up with other data sources, you do not get to rotate your eyeballs and start again.</p>
<p class="ember-view reader-text-block__paragraph">And the crypto incentive matters. Paying people to hand over biometric data is not neutral as it changes the deal. It nudges adoption through cash, not through genuine understanding or informed consent. And if the goal is to build trust online, starting with “here is some money, let a shiny sphere scan your iris” is a weird way to do it.</p>
<p class="ember-view reader-text-block__paragraph">This story is not just about one gadget in a shopping centre. It is about what comes next. If “prove you are human” becomes a standard requirement, who controls that proof, who decides when it is needed, and who gets locked out if they do not want to play along?</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Biometrics are permanent</strong><span class="white-space-pre"> </span>- If something goes wrong, you cannot reset it like a password</li>
<li>
<strong>Incentives change consent</strong><span class="white-space-pre"> </span>- Paying people to sign up shifts behaviour faster than understanding</li>
<li>
<strong>This will not stay niche</strong><span class="white-space-pre"> </span>- If it works once, it will get pushed into more places</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="aKgoauviAZxJAadjRGfyvORexGDtmbTuwaEng " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/199093?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/199093?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F199093%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F199093%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_197210">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/197210/watch_times"
  data-youtube-player-video-id-value="edRdK5HrKlw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/edRdK5HrKlw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/197210">
          Jan 12, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/197210">
            Subscriber Data Exposed and Hotels ClickFix Phished
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, it is a reminder of just how much data follows us around, and how often it ends up exposed in places we barely think about. From magazine subscriptions and radio stations holding millions of records, to healthcare providers, gas stations, and even space agencies dealing with serious breaches, the theme this week is scale, and how quickly it can spiral.</p>
<p class="ember-view reader-text-block__paragraph">We look at incidents that were first reported as small, only to grow into hundreds of thousands or millions of affected people months later. We also dig into the way modern attacks blend into normal work, fake blue screens, booking emails, sideloaded apps, and even trusted security tools being used as a way in.</p>
<p class="ember-view reader-text-block__paragraph">There is a longer view, too, with Equifax still discussing culture years after its breach, new government cyber plans taking shape, and insurers quietly spelling out what they will not cover when cyber incidents spill into the physical world.</p>
<p class="ember-view reader-text-block__paragraph">It is a packed episode, full of practical lessons and uncomfortable reminders about trust, habit, and the digital footprints we all leave behind.</p>
<h2 class="ember-view reader-text-block__heading-2">This week's stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Condé Nast breach and the risk hiding in forgotten subscriptions</h3>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=82" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.pymnts.com/news/security-and-risk/2025/conde-nast-hack-exposes-40-million-users-data/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Condé Nast is responding to a breach claim that could affect up to 40 million users across brands, including Vogue, GQ, Wired, and The New Yorker. An attacker using the name “Lovely” shared data samples allegedly taken from subscription systems and claimed to have access across multiple Condé Nast properties. The exposed information reportedly includes names, email addresses, usernames, phone numbers, dates of birth, and location data. According to reports, the attacker alleged they attempted to flag vulnerabilities before releasing proof, though Condé Nast disputes parts of that account and says it has taken steps to disable the accounts involved in the unlawful access.</p>
<p class="ember-view reader-text-block__paragraph">During the discussion on the show, the focus was less on the headline number and more on how ordinary this type of data feels. Subscription accounts like these are often created years earlier and then forgotten entirely. They don’t feel sensitive or important, yet the data persists long after interest fades. That long lived, low attention data is what makes incidents like this so uncomfortable, it surfaces quietly and is easy to abuse without ever feeling like a major breach at the time.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Subscription data is still valuable</strong><span class="white-space-pre"> </span>- names and email addresses alone can fuel phishing and scams</li>
<li>
<strong>Forgotten accounts create blind spots</strong><span class="white-space-pre"> </span>- users move on while data remains</li>
<li>
<strong>Proof leaks are rarely the end</strong><span class="white-space-pre"> </span>- small samples often point to wider exposure</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">European Space Agency breach shows even critical organisations aren’t immune</h3>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=751" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.theregister.com/2026/01/07/european_space_agency_breach_criminal_probe/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The European Space Agency confirmed a cyber incident that is now under criminal investigation, after attackers gained unauthorised access to parts of its internal IT environment. Reporting suggests a public vulnerability was exploited, with attackers claiming to have taken hundreds of gigabytes of internal files. ESA said mission-critical spacecraft operations were not affected, but the incident was serious enough to involve law enforcement and trigger a wider forensic review.</p>
<p class="ember-view reader-text-block__paragraph">The discussion wasn’t really about whether ESA<span class="white-space-pre"> </span><em>should</em><span class="white-space-pre"> </span>be better protected, it was more about frustration. There was a sense that some things just shouldn’t be messed with at all. Space, like healthcare or charities, doesn’t feel like a fair game. But that feeling clashes with reality. Attackers don’t draw ethical lines. If a vulnerability exists and remains open, it becomes an opportunity, regardless of how harmless or important the organisation feels.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Attackers don’t respect boundaries</strong><span class="white-space-pre"> </span>- ethical lines don’t factor into targeting decisions</li>
<li>
<strong>Unpatched weaknesses still get exploited</strong><span class="white-space-pre"> </span>- it only takes one open door</li>
<li>
<strong>Sensitive data isn’t limited to operations</strong><span class="white-space-pre"> </span>- internal documents and partner information still carry risk</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Fake blue screens are being used to trick hotel staff into installing malware</h3>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=1372" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.theregister.com/2026/01/06/russia_hackers_hotel_bsods/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Hotels across Europe are being targeted by phishing emails that impersonate booking-related messages, often posing as reservation updates or cancellations. The emails lead staff to malicious pages that display a fake Windows blue screen and instruct users to follow recovery steps. Those steps involve running commands that install malware directly onto the system. It is a ClickFix-style attack, but disguised as a system failure rather than a security warning.</p>
<p class="ember-view reader-text-block__paragraph">The conversation focused on how easy this is to fall into when it lands in the middle of a normal working day. Hotel staff deal with booking emails constantly, and fixing problems quickly is part of the job. When something looks technical and urgent, the instinct is to resolve it and move on, not stop and question whether it should be escalated. That pressure, combined with something that looks familiar, is what makes this technique effective.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Urgency drives behaviour</strong><span class="white-space-pre"> </span>- fake system errors push people into fast decisions</li>
<li>
<strong>Normal workflows lower scepticism</strong><span class="white-space-pre"> </span>- familiar-looking emails get less scrutiny</li>
<li>
<strong>ClickFix keeps evolving</strong><span class="white-space-pre"> </span>- attackers rely on users to run the malware for them</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">ChatGPT Health raises the stakes for account security</h3>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=2272" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.cnbc.com/2026/01/07/openai-chatgpt-health-medical-records.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">OpenAI announced ChatGPT Health, a feature that allows users to connect medical records and wellness apps to their ChatGPT account. The company says the feature is not intended for diagnosis or treatment, and that connected health data won’t be used to train models. The goal, according to OpenAI, is to make responses more useful by grounding them in a user’s own health context.</p>
<p class="ember-view reader-text-block__paragraph">The discussion wasn’t really about whether this is a good or bad feature, it was about concentration of value. On the show, the point was made that for many people ChatGPT is already a second brain. It holds questions, ideas, work context, and personal thinking. Adding health data into that mix means a single account can now represent a very complete picture of someone. That makes the impact of account compromise much higher than it used to be, even if the feature itself is well intentioned.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Accounts are becoming life hubs</strong><span class="white-space-pre"> </span>- more context means higher impact if compromised</li>
<li>
<strong>Login security matters more than ever</strong><span class="white-space-pre"> </span>- strong MFA and recovery controls are critical</li>
<li>
<strong>Convenience quietly expands risk</strong><span class="white-space-pre"> </span>- connecting data should always be a conscious choice</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points...</h2>
<p class="ember-view reader-text-block__paragraph">Condé Nast breach claims and subscriber data risk –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=82" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.pymnts.com/news/security-and-risk/2025/conde-nast-hack-exposes-40-million-users-data/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Covenant Health breach grows to nearly half a million people –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=281" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.securityweek.com/covenant-health-data-breach-impacts-478000-individuals/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Tokyo FM breach highlights how radio stations hold vast listener data –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=438" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://hackread.com/tokyo-fm-data-breach-hacker-3-million-records-stolen/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">US gas station operator breach exposes payment cards and ID data after delayed notification –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=613" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://hackread.com/data-breach-us-gas-stations-company/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">European Space Agency breach placed under criminal investigation –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=751" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.theregister.com/2026/01/07/european_space_agency_breach_criminal_probe/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Equifax says security culture is now built in, after one of the biggest breaches on record –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=1063" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.csoonline.com/article/4109026/javier-checa-equifax-now-the-security-culture-is-part-of-our-dna-as-a-company.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Fake Blue Screen of Death attacks targeting hotel staff –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=1372" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.theregister.com/2026/01/06/russia_hackers_hotel_bsods/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">HSBC blocks customers using sideloaded Bitwarden apps –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=2089" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.theregister.com/2026/01/07/hsbc_bitwarden_sideloaded/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">OpenAI launches ChatGPT Health and raises questions about account value –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=2272" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.cnbc.com/2026/01/07/openai-chatgpt-health-medical-records.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">UK government publishes new cyber action plan –<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=2523" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.gov.uk/government/publications/government-cyber-action-plan/government-cyber-action-plan" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...Cybersecurity Training That Ticks Boxes but Changes Nothing</h2>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEigM2r9d6-dA/article-inline_image-shrink_1000_1488/B4EZupcJIvLwAQ-/0/1768074288245?e=1769644800&amp;v=beta&amp;t=I-aFl70QLn4j8zs_EU11t2PhBDk8mmIat1aWMXcQCG0" onerror="this.style.display='none'"></span>We discussed NCSC's training for Schools.</p>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://youtu.be/edRdK5HrKlw?t=2680" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">This week we talked about NCSC cybersecurity training being issued to school staff, a 36 minute video, stock slides, synthetic narration, no interaction, and no assessment. Everyone completes it, signs it off, and moves on. On paper, the risk is managed. In reality, very little of that content will be remembered when someone receives a real scam, a fake text, or a convincing phishing email. It is a familiar pattern in security awareness, training designed to satisfy a requirement rather than change behaviour. The problem is not that people do not care, it is that long, generic training delivered once a year does not reflect how threats actually show up in daily life.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Completion is not protection</strong><span class="white-space-pre"> </span>- Watching a video does not mean someone can spot a scam under pressure</li>
<li>
<strong>Relevance beats length</strong><span class="white-space-pre"> </span>- Five minutes of current, relatable examples beats 36 minutes of theory every time</li>
<li>
<strong>Engagement is the control</strong><span class="white-space-pre"> </span>- If people do not remember it, it cannot protect them<span class="white-space-pre"> </span>
</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="buxWJtzTkvojqTcWmwRQyhFcnEPZxwis " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/197210?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/197210?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F197210%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F197210%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_195383">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/195383/watch_times"
  data-youtube-player-video-id-value="oboBJxlM4Nc"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/oboBJxlM4Nc/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/195383">
          Jan 5, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/195383">
            Spotify Scraped and Google Phish Steals Microsoft Logins
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, we are back after the Christmas break and straight into two weeks’ worth of cyber news that didn't slow down just because the calendar said it should. From phishing emails abusing real Google services and browser extensions quietly infecting millions, to Ubisoft taking Rainbow Six Siege offline after attackers started banning players live (with a little bit of Shaggy), there is plenty to unpack.</p>
<p class="ember-view reader-text-block__paragraph">We look at airlines and retailers exposing customer data through supplier and access failures, including Korean Air and Coupang, where smashed laptops, rivers and forgotten access played a bigger role than sophisticated hacking. We also dig into ClickFix attacks being sold as a service, sleeper browser extensions stealing data months after install, and a British hacker who quite literally hacked his way into an Australian visa by doing things the right way.</p>
<p class="ember-view reader-text-block__paragraph">Add in Meta quietly shaping how scam ads are policed, smart hacking tools being banned from a mayoral inauguration, and a growing tension between security, perception, and trust, and a clear theme starts to emerge.</p>
<p class="ember-view reader-text-block__paragraph">All of that and more in this week’s Awareness Angle, so let’s get into it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or Listen to the episode today -<span class="white-space-pre"> </span></strong><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Spotify scraping shows why “just metadata” is never just metadata</h3>
<p class="ember-view reader-text-block__paragraph">Claims a couple of weeks ago suggested<span class="white-space-pre"> </span><strong>Spotify</strong><span class="white-space-pre"> </span>content was scraped at massive scale, with Anna’s Archive alleging access to metadata for around 256 million tracks and audio files for roughly 86 million songs. The archive, reported to be around 300TB in size, has been distributed via torrents. Spotify said it identified and disabled accounts involved in unlawful scraping, describing the activity as a mix of public metadata access and illicit tactics, but stopped short of confirming the full scale of what is circulating.</p>
<p class="ember-view reader-text-block__paragraph">What makes this story uncomfortable is that it doesn't look like a traditional breach. As we discussed on the show, this appears to be access working as designed, just abused at scale. It is easy to wave this away as “just metadata,” but metadata carries context. It reveals behaviour, popularity, listening patterns, and connections over time. Combined with other sources, it becomes far more revealing than most people expect. Add in the fact that torrents and unofficial archives are a common delivery mechanism for malware, and this stops being just a copyright issue.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Metadata is not harmless</strong><span class="white-space-pre"> </span>– Even without names or passwords, metadata can expose behaviour, habits, and patterns when collected at scale or combined with other data sources</li>
<li>
<strong>Abuse accelerates quietly</strong><span class="white-space-pre"> </span>– When automated access or credentials work once, they can be reused rapidly, turning small gaps into mass scraping before anyone notices</li>
<li>
<strong>Trust the file, not the story</strong><span class="white-space-pre"> </span>– Archives framed as preservation or culture can still be high risk, unofficial downloads are a common place for malicious content to hide</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">The browser extensions you forgot about might be the riskiest thing you use</h3>
<p class="ember-view reader-text-block__paragraph">Security researchers recently uncovered a long running campaign that saw malicious browser extensions infect<span class="white-space-pre"> </span><strong>millions of users across Chrome, Edge, and Firefox</strong>, often without raising any suspicion. The activity, linked to a threat cluster dubbed DarkSpectre, involved extensions that appeared completely legitimate, complete with positive reviews, large install numbers, and official store badges. In some cases, these extensions sat quietly for days or weeks before activating malicious behaviour.</p>
<p class="ember-view reader-text-block__paragraph">What makes this story so unsettling is how normal it all looks. As we talked about on the show, these were not shady downloads from obscure websites. They were tools people installed to customise tabs, improve productivity, or tweak their browsing experience. Once trusted, they were largely forgotten. That trust gave attackers ongoing access to sessions, credentials, meeting data, and in some cases crypto wallets, turning the browser into a silent surveillance tool.</p>
<p class="ember-view reader-text-block__paragraph">This is a reminder that your browser is not just a window to the internet. It is part of your attack surface. Extensions run with deep privileges, often seeing everything you type, click, or view. When they turn malicious later, detection is hard and user suspicion is low, because nothing appears to change.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Install once does not mean safe forever</strong><span class="white-space-pre"> </span>– Extensions can change behaviour after updates, long after reviews and store checks have passed</li>
<li>
<strong>Dormant threats are deliberate</strong><span class="white-space-pre"> </span>– Waiting days or weeks before activating is a common way to evade detection and earn user trust</li>
<li>
<strong>Your browser is a security boundary</strong><span class="white-space-pre"> </span>– Extensions have access to sensitive data and sessions, making them a direct path into work and personal accounts</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Meta knew about scam ads, and people kept getting hurt anyway</h3>
<p class="ember-view reader-text-block__paragraph">A<span class="white-space-pre"> </span><strong>Reuters</strong><span class="white-space-pre"> </span>investigation a couple of weeks ago laid out something many people already suspected.<span class="white-space-pre"> </span><strong>Meta</strong>, the company behind Facebook and Instagram, knew scam ads were a problem, knew how to reduce them, and still chose to manage the situation rather than fix it properly.</p>
<p class="ember-view reader-text-block__paragraph">This is not about edge cases or clever users spotting red flags. These are the fake loan offers, investment scams, and impersonation ads that show up while people are tired, stressed, or just scrolling. Reuters reported that Meta was aware stronger advertiser checks would cut scams, but held back because of cost and potential impact on ad revenue. In other words, the scams kept running, and real people kept paying the price.</p>
<p class="ember-view reader-text-block__paragraph">As we said on the show, this is where the blame needs to move. When the same scams appear again and again, it stops being a question of awareness or education. If a platform knows what works and delays using it, that is a choice. And when that choice leads to people losing money, confidence, or trust, it is not on the user to be more careful, it is on the platform to do better.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>People are not failing here</strong><span class="white-space-pre"> </span>– When scams keep appearing, the problem is not judgement, it is enforcement</li>
<li>
<strong>Meta had options</strong><span class="white-space-pre"> </span>– Stronger checks would have reduced harm, and choosing not to use them has consequences</li>
<li>
<strong>Scams are a design issue</strong><span class="white-space-pre"> </span>– What platforms allow, tolerate, or profit from shapes who gets hurt</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This week's discussion points...</h2>
<p class="ember-view reader-text-block__paragraph">Anna’s Archive claims massive Spotify scrape, raising questions about data access and abuse –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=76" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.androidauthority.com/spotify-annas-archive-3627023/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Android Authority)</p>
<p class="ember-view reader-text-block__paragraph">Rainbow Six Siege hit by major hack, Ubisoft takes servers offline after chaos in game economy and bans –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=325" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.tomshardware.com/video-games/pc-gaming/rainbow-six-siege-x-servers-are-back-online-after-a-hack-completely-shut-down-the-game-ubisoft-rolling-back-free-ultra-rare-skins-and-billions-of-credits" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Tom’s Hardware)</p>
<p class="ember-view reader-text-block__paragraph">Korean Air discloses passenger data exposure after supplier cyberattack –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=632" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://securityaffairs.com/186275/data-breach/korean-air-discloses-data-breach-after-the-hack-of-its-catering-and-duty-free-supplier.html?web_view=true" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Security Affairs)</p>
<p class="ember-view reader-text-block__paragraph">Coupang breach uncovered after smashed laptop data recovered by investigators –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=779" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://therecord.media/coupang-recovers-smashed-laptop-data-breach" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(The Record)</p>
<p class="ember-view reader-text-block__paragraph">Phishing campaign abuses real Google services to look legit, then steals Microsoft logins –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=953" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.techradar.com/pro/security/yet-another-phishing-campaign-impersonates-trusted-google-services-heres-what-we-know" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(TechRadar)</p>
<p class="ember-view reader-text-block__paragraph">British hacker wins Australian visa after legally hacking government website –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=1247" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://cybernews.com/security/hacker-australia-visa/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Cyber News)</p>
<p class="ember-view reader-text-block__paragraph">ErrTraffic sells “fake browser glitch” pages to push ClickFix attacks –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=1440" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.bleepingcomputer.com/news/security/new-errtraffic-service-enables-clickfix-attacks-via-fake-browser-glitches/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<p class="ember-view reader-text-block__paragraph">DarkSpectre browser extension malware infected 8.8 million users across Chrome, Edge and Firefox –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=1700" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://cybersecuritynews.com/darkspectre-hackers-infected-8-8-million-chrome-users/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Cybersecurity News)</p>
<p class="ember-view reader-text-block__paragraph">Meta built “playbook” to delay crackdowns on scam ads, internal documents reveal –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=2530" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.reuters.com/investigations/meta-created-playbook-fend-off-pressure-crack-down-scammers-documents-show-2025-12-31/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(Reuters)</p>
<p class="ember-view reader-text-block__paragraph">NYC mayoral inauguration bans Flipper Zero and Raspberry Pi devices over security fears –<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.youtube.com/watch?v=oboBJxlM4Nc&amp;t=2068" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.bleepingcomputer.com/news/security/nyc-mayoral-inauguration-bans-flipper-zero-raspberry-pi-devices/" target="_blank" rel="noopener">Read</a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<h3 class="ember-view reader-text-block__heading-3">And Finally...When AI Jailbreaks Get Pushed Underground</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQE6O2BTA0N0mw/article-inline_image-shrink_1000_1488/B4EZuCpgoLJwAQ-/0/1767423478743?e=1769040000&amp;v=beta&amp;t=NnHW9-pLEETvezReDpPfl-bBqn_Yy3JdPtTmNi18_i0" onerror="this.style.display='none'"></span>A subreddit used by researchers gets closed down</p>
<p class="ember-view reader-text-block__paragraph">A subreddit focused on ChatGPT jailbreaks has been shut down, and on the surface that sounds like a win. Fewer prompts being shared, less obvious misuse, and fewer screenshots doing the rounds.</p>
<p class="ember-view reader-text-block__paragraph">But that space was doing more than showing people how to break things. It was one of the few places where you could see what people were actually trying in the wild. What worked. What failed. What guardrails were being walked straight around. By removing it from Reddit, the behaviour has not stopped, it has just moved somewhere quieter.</p>
<p class="ember-view reader-text-block__paragraph">This is the awkward bit. A lot of security learning comes from watching real behaviour, not ideal behaviour. Taking away visibility does not suddenly make AI safer, it just makes the problems easier to ignore. The jailbreaks will still exist, fewer defenders will see them.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>You cannot fix what you cannot see</strong><span class="white-space-pre"> </span>– Removing public discussion hides problems, it does not remove them</li>
<li>
<strong>People will keep pushing systems</strong><span class="white-space-pre"> </span>– Curiosity and misuse do not disappear just because a platform closes a space</li>
<li>
<strong>Visibility beats comfort</strong><span class="white-space-pre"> </span>– Seeing how things break is uncomfortable, but it is how security actually improves</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="qnYTlArzYtboRwdjbntMpxxVLYbykXIogw " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/195383?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/195383?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F195383%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F195383%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_192568">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/192568/watch_times"
  data-youtube-player-video-id-value="lWZGOf0NpA8"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/lWZGOf0NpA8/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/192568">
          Dec 22, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/192568">
            Microsoft Account Hacks, WhatsApp Ghost Pairing, and Extensions Spy On AI |#taa #EP67
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, Luke is back, and we have a lot to get through together. We are talking about a real estate firm quietly exposing tens of thousands of people, SoundCloud losing control of user data while breaking its own VPN access, and Pornhub dealing with extortion after deeply personal viewing history leaked via a third-party analytics mess.</p>
<p class="ember-view reader-text-block__paragraph">We also look at malware hiding inside movie subtitles, browser extensions harvesting millions of AI chats in plain sight, and a new Microsoft account takeover technique that bypasses passwords, MFA, and passkeys without dropping malware. Add in WhatsApp account hijacking through ghost pairing, a UK government hack still being downplayed, and smart TVs quietly shaping what we can and cannot do in our own homes, and there is a clear theme running through this week.</p>
<p class="ember-view reader-text-block__paragraph">All of that and more in this week’s Awareness Angle, so let’s get straight into it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or Listen to the episode today -<span class="white-space-pre"> </span></strong><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">The Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Browser extensions secretly harvesting AI chats<span class="white-space-pre"> </span>
</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQFB7r2EPZW0Dg/article-inline_image-shrink_1500_2232/B4EZtAbCHeJwAU-/0/1766312387840?e=1767830400&amp;v=beta&amp;t=gtOPssRfKRrzUbG5GUnvx785fzG5Am6Y8_rZ-EMdzX8" onerror="this.style.display='none'"></span>Image source - KOI Security, via The Hacker News</p>
<p class="ember-view reader-text-block__paragraph"><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=1727" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://thehackernews.com/2025/12/featured-chrome-browser-extension.html?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A Chrome browser extension with millions of users and a trusted Featured badge was found silently intercepting AI conversations from tools like ChatGPT, Copilot, Gemini, and others. Prompts, responses, timestamps, and session data were routed back to the developer and shared with an affiliated analytics firm. The behaviour was introduced through an update and documented quietly in a privacy policy, rather than being the result of a technical flaw.</p>
<p class="ember-view reader-text-block__paragraph">During the discussion, Ant summed up the risk clearly:<span class="white-space-pre"> </span><em>“If it’s free, you’re probably the product.”</em><span class="white-space-pre"> </span>AI tools are now being used for genuine work, with people pasting emails, notes, ideas, and sensitive context into them without hesitation. This story highlights how browser extensions can turn everyday behaviour into large-scale data exposure without users ever realising.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Trust signals are misleading</strong><span class="white-space-pre"> </span>– Featured badges and ratings are not security guarantees</li>
<li>
<strong>AI prompts are high-value data</strong><span class="white-space-pre"> </span>– Inputs often contain information people would never share elsewhere</li>
<li>
<strong>Extension sprawl increases exposure</strong><span class="white-space-pre"> </span>– Fewer extensions means fewer silent risks</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Microsoft accounts hijacked without passwords, MFA, or passkeys<span class="white-space-pre"> </span>
</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQHl1PFyyIHj6g/article-inline_image-shrink_1000_1488/B4EZtAah.0I0AQ-/0/1766312256103?e=1767830400&amp;v=beta&amp;t=LQ74pUbka8RP5sF1Zs2KmnptMLmQGUMYX9W-xSoYIIk" onerror="this.style.display='none'"></span>Image Source - Push Security</p>
<p class="ember-view reader-text-block__paragraph"><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=1315" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://pushsecurity.com/blog/consentfix" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A new browser-based attack technique is allowing attackers to take over Microsoft accounts without stealing passwords, bypassing MFA, or deploying malware. Victims are tricked into copying and pasting a URL that grants OAuth access to their account. Because the user is already logged in, the attacker receives a valid session token and gains access without triggering traditional alerts or controls.</p>
<p class="ember-view reader-text-block__paragraph">The attack stood out because it relies entirely on normal-looking behaviour. Everything happens inside the browser, often via compromised websites or search results, and nothing appears broken. It reflects a broader shift away from exploiting technology and towards exploiting people, where strong technical controls still depend on users recognising when something does not look right.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Consent is the weak point</strong><span class="white-space-pre"> </span>– Access can be granted, not stolen</li>
<li>
<strong>Modern controls still rely on judgement</strong><span class="white-space-pre"> </span>– MFA reduces risk but does not remove it</li>
<li>
<strong>Browser-based attacks change the game</strong><span class="white-space-pre"> </span>– Old detection assumptions no longer hold</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">WhatsApp ghost pairing enables silent account hijacks<span class="white-space-pre"> </span>
</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEzgvgvg7f0Xg/article-inline_image-shrink_1500_2232/B4EZtAauwNHMAU-/0/1766312308308?e=1767830400&amp;v=beta&amp;t=O5QWCwtp41HWgRtyo9mgymaPnZoF7Pv6V2MnvTFOQV4" onerror="this.style.display='none'"></span>Image Source - Gen Digital</p>
<p class="ember-view reader-text-block__paragraph"><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=2289" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bleepingcomputer.com/news/security/whatsapp-device-linking-abused-in-account-hijacking-attacks/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Attackers are hijacking WhatsApp accounts by abusing the platform’s built-in device linking feature. Victims are socially engineered into approving a new linked device, often through messages that appear to come from trusted contacts. Once paired, attackers can read messages in real time, impersonate the victim, and monitor conversations without disrupting normal use.</p>
<p class="ember-view reader-text-block__paragraph">As Luke noted during the episode,<span class="white-space-pre"> </span><em>“A working account is not the same thing as a secure one.”</em><span class="white-space-pre"> </span>WhatsApp is widely used for informal work conversations, leadership chats, and quick decisions outside official systems. Because there are often no visible signs of compromise, attackers can remain connected for long periods unless users actively check their linked devices.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Convenience features are attack paths</strong><span class="white-space-pre"> </span>– Normal functionality is being weaponised</li>
<li>
<strong>Compromise can be invisible</strong><span class="white-space-pre"> </span>– No alerts does not mean no attacker</li>
<li>
<strong>Routine checks reduce risk</strong><span class="white-space-pre"> </span>– Linked devices should be reviewed regularly</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This week's discussion points...<span class="white-space-pre"> </span>
</h2>
<p class="ember-view reader-text-block__paragraph">NYC and DC real estate developer notifies 47,000 people of data breach –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=96" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.comparitech.com/news/nyc-dc-real-estate-developer-notifies-47000-people-of-data-breach/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(Comparitech)</p>
<p class="ember-view reader-text-block__paragraph">SoundCloud confirms breach after member data stolen, VPN access disrupted –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=267" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<p class="ember-view reader-text-block__paragraph">PornHub extorted after hackers steal Premium member activity data –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=495" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<p class="ember-view reader-text-block__paragraph">Inquiry ongoing after UK government hacked, says minister –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=807" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bbc.co.uk/news/articles/cj4qpwprw9vo" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(BBC News)</p>
<p class="ember-view reader-text-block__paragraph">Fake “One Battle After Another” torrent hides malware in subtitles –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=1009" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bleepingcomputer.com/news/security/fake-one-battle-after-another-torrent-hides-malware-in-subtitles/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<p class="ember-view reader-text-block__paragraph">Microsoft account takeover alerts surge as attackers test logins at scale –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=1315" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://pushsecurity.com/blog/consentfix" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(Push Security)</p>
<p class="ember-view reader-text-block__paragraph">Featured Chrome browser extension caught intercepting millions of users’ AI chats –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=1727" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://thehackernews.com/2025/12/featured-chrome-browser-extension.html?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(The Hacker News)</p>
<p class="ember-view reader-text-block__paragraph">LG backtracks on Copilot web app deletion after user backlash –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=2094" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.theverge.com/news/847685/lg-copilot-web-app-delete" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(The Verge)</p>
<p class="ember-view reader-text-block__paragraph">Ghost Pairing, WhatsApp account hijack technique –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=2289" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.bleepingcomputer.com/news/security/whatsapp-device-linking-abused-in-account-hijacking-attacks/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(BleepingComputer)</p>
<p class="ember-view reader-text-block__paragraph">North Korean infiltrator caught working in Amazon IT department via keystroke lag –<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.reddit.com/r/technology/s/yvvOBY7D23" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>(Reddit)</p>
<h3 class="ember-view reader-text-block__heading-3">And Finally...The Amazon Insider Caught by 110 Milliseconds</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.reddit.com/r/technology/s/yvvOBY7D23" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A North Korean infiltrator worked inside Amazon’s IT function, and the thing that gave them away was not malware, phishing, or suspicious logins.</p>
<p class="ember-view reader-text-block__paragraph">It was typing.</p>
<p class="ember-view reader-text-block__paragraph">Security teams noticed a consistent 110 millisecond delay between keystrokes. Tiny. Almost imperceptible. But enough to raise questions. The laptop was physically in the US. The person typing was not. The machine was being remotely controlled from North Korea, using legitimate access, doing legitimate work, until behaviour gave them away.</p>
<p class="ember-view reader-text-block__paragraph">This is what modern insider risk looks like. No broken controls. No alarms. Valid credentials, authorised access, and activity that looked normal on the surface. The risk only surfaced because someone was paying attention to behavioural patterns rather than waiting for alerts.</p>
<p class="ember-view reader-text-block__paragraph">It also raises an uncomfortable question about awareness. Behavioural signals can protect organisations, but they sit close to the line between monitoring and spying. In this case, it stopped a state-sponsored infiltration. In another, the same techniques could feel intrusive or excessive. Awareness is not just about spotting attackers, it is about understanding how security decisions affect people, trust, and culture.</p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="ZQhwTcMUGTmwKWLrBYxTHXTSORxzFEcxkPKQ " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/192568?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/192568?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F192568%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F192568%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_190876">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/190876/watch_times"
  data-youtube-player-video-id-value="QsoH3G7GfU0"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/QsoH3G7GfU0/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/190876">
          Dec 15, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/190876">
            <span class="emoji">🎙️</span> In This Week’s Episode – <span class="emoji">💥</span> Data breaches everywhere, <span class="emoji">📺</span> LG TVs force Copilot, <span class="emoji">🧑‍💼</span> Insider access failures
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<h1>LG Copilot Update, Widespread Data Breaches, and Travel Privacy Fears</h1>
<p><strong></strong><strong>Hi, it's Ant! </strong></p>
<p>This week on The Awareness Angle, I am on my own, and there is a lot to get through. Data breaches are everywhere, from forgotten accounts and simple misconfigurations to ransomware hitting pharma firms and exposing sensitive data. I look at how software updates are being abused to push malware, why Apple has rushed out fixes for active zero-days, and what it means when governments start accusing each other of cyber attacks on critical infrastructure.</p>
<p>I also dig into LG quietly pushing Microsoft Copilot onto smart TVs without a clear opt-out, raising some big questions about privacy and control in our own homes. And finally, there is a proposal in the US that could see travellers handing over years of social media just to get through the border.</p>
<p>All of that and more in this week’s Awareness Angle. It is just me this time as Luke's on his holidays, so let’s get straight into it.</p>
<p><br><span> </span>Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_-4231199220004915668img CToWUd" height="150" src="https://ci3.googleusercontent.com/meips/ADKq_NYyJ897MxEIKYezSqSnlim4ZNM6N3bUZ7fupyC71dU_GWTIgfoWQuFTs1PKx3VZHtq-YtoX2BiRrAV8tdGEVnLCCeYIxR6dRj_PcffgQEIBCqsCFeWYwBN34Wngpj9Ak-OBfHrs0Nym7JwPhGGjjysS=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_-4231199220004915668img CToWUd" height="48" src="https://ci3.googleusercontent.com/meips/ADKq_NbegVyQ56xtGMctwI74KZUXXlu4FCa4ZVpt9mf_dVpie72SAytX5gzqQ1cyHC0WMueAFjuViZ6rNbTU8wFPNkZ52dXkruu8oml5nlLsSYow0A=s0-d-e1-ft#https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>




































<h2>This week's stories...</h2>
<h3>LG smart TVs quietly get Microsoft Copilot</h3>
<p><a href="https://youtu.be/QsoH3G7GfU0?t=1359" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.webpronews.com/lg-update-installs-unremovable-microsoft-copilot-on-smart-tvs-ignites-backlash/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>LG has pushed Microsoft Copilot onto a range of smart TVs via a routine firmware update, installing it as a system-level feature with no obvious way to remove it. It just appears. For a lot of people, this is not about Copilot being good or bad, it is about something being added to a device in their living room without being asked.</p>
<p>What really sits underneath this is control and data. Smart TVs already collect a lot of viewing and usage information, and adding an AI assistant only raises more questions about what is being gathered and where it goes. It is the same pattern we have seen with cars, phones, and other “smart” devices, once the hardware is in your home, the software can keep changing.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Control after purchase</strong><span> </span>– Buying hardware should not mean surrendering future decisions.</li>
<li>
<strong>Data follows features</strong><span> </span>– New functionality usually comes with new data flows.</li>
<li>
<strong>Question connected defaults</strong><span> </span>– Not everything needs to be online all the time.</li>
</ul>
<p></p>
<h3>US may require travellers to hand over social media history</h3>
<p><a href="https://youtu.be/QsoH3G7GfU0?t=2980" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRN8K2jV/" target="_blank" rel="noopener"><strong>Read</strong></a> |<span> </span><a href="https://www.aljazeera.com/news/2025/12/12/why-is-trump-demanding-travellers-social-media-handles-how-will-it-work" target="_blank" rel="noopener">Read More</a></p>
<p>The US is proposing changes to its visa waiver process that could require travellers to provide up to five years of social media history, along with contact details and other personal information. This would apply to people travelling from countries like the UK who currently enter visa-free, often for work, conferences, or holidays.</p>
<p>I am not suggesting people have anything to hide, but it does raise an uncomfortable question about where the line sits. Online posts, likes, and opinions suddenly become part of a border decision. With major global events coming up in the US, it will be interesting to see how many people rethink travel if this goes ahead.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Privacy versus security</strong><span> </span>– Extra checks always come with trade-offs.</li>
<li>
<strong>Digital history becomes identity</strong><span> </span>– Old posts can gain new meaning at borders.</li>
<li>
<strong>Friction changes behaviour</strong><span> </span>– More intrusive processes discourage travel.</li>
</ul>
<p></p>
<h3>Millions exposed by third-party data breaches</h3>
<p><a href="https://youtu.be/QsoH3G7GfU0?t=205" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.tomsguide.com/computing/online-security/nearly-5-6-million-people-hit-by-massive-data-breach-at-credit-check-company-what-you-need-to-know" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>This week’s breaches include a credit-checking firm and a veterinary services provider, exposing millions of records through a mix of poor access control and simple misconfiguration. In many cases, the people affected never chose to trust these organisations, their data was just passed along as part of the background machinery of modern services.</p>
<p>This is why third-party risk feels so unfair at a personal level. You can be careful, you can follow advice, and you still end up dealing with the fallout because someone else made a mistake. Identity data cannot be changed, and once it is out there, it stays out there.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Invisible trust chains</strong><span> </span>– Your data moves far beyond the companies you recognise.</li>
<li>
<strong>Long tail impact</strong><span> </span>– Identity exposure lasts longer than headlines.</li>
<li>
<strong>Basic hygiene still matters</strong><span> </span>– Most damage comes from simple failures.</li>
</ul>
<p></p>
<h3>Pharma firm hit by ransomware and data theft</h3>
<p><a href="https://youtu.be/QsoH3G7GfU0?t=775" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>A pharmaceutical research firm has confirmed it was hit by ransomware after attackers accessed and stole data before locking systems. This is now the standard playbook. Get in, take what you can, then encrypt everything and demand payment for both silence and recovery.</p>
<p>We still talk about ransomware as if it is mainly about downtime, but the real damage is often the data loss. In sectors like pharma and healthcare, that data can be sensitive, regulated, and tied to real people. Even when systems come back, the risk does not disappear.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Ransomware is about leverage</strong><span> </span>– Stolen data changes the pressure entirely.</li>
<li>
<strong>Backups reduce pain, not risk</strong><span> </span>– Recovery does not undo exposure.</li>
<li>
<strong>Early access is the weak point</strong><span> </span>– Phishing and stolen credentials remain common entry routes.</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>



























































<h2>This Week's Discussion Points...</h2>
<p>Coupang breach traced to ex-employee access -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=55" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/coupang-data-breach-traced-to-ex-employee-who-retained-system-access/amp/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(BleepingComputer)</p>
<p>Credit check company breach exposes millions -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=205" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.tomsguide.com/computing/online-security/nearly-5-6-million-people-hit-by-massive-data-breach-at-credit-check-company-what-you-need-to-know" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(Tom’s Guide)</p>
<p>Petco Vetco website data exposure -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=537" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://techcrunch.com/2025/12/10/petco-takes-down-vetco-website-after-exposing-customers-personal-information/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(TechCrunch)</p>
<p>Inotiv ransomware attack and data theft -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=775" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(BleepingComputer)</p>
<p>Apple emergency zero-day updates -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=922" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://thehackernews.com/2025/12/apple-issues-security-updates-after-two.html" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(The Hacker News)</p>
<p>Notepad++ malicious update flaw -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=1120" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/notepad-plus-plus-fixes-flaw-that-let-attackers-push-malicious-update-files/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(BleepingComputer)</p>
<p>LG TVs install Microsoft Copilot -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=1359" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.webpronews.com/lg-update-installs-unremovable-microsoft-copilot-on-smart-tvs-ignites-backlash/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(WebProNews)</p>
<p>Germany accuses Russia of air traffic control cyber attack -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=1910" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/articles/cvgrrnylzzyo" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(BBC News)</p>
<p>Pringles account breach and password reuse -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/r/comedyheaven/comments/1pg8btm/pringle/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(Reddit)</p>
<p><a href="https://www.linkedin.com/in/harleysugarman?miniProfileUrn=urn%3Ali%3Afs_miniProfile%3AACoAAAeW1j8BBnKeEDkKz-o3YVmsnDme5_qWj_k" target="_blank" rel="noopener">Harley Sugarman</a>'s Elsbeth TV show phishing simulation -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=2390" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.linkedin.com/posts/harleysugarman_were-working-hard-so-your-team-doesnt-become-activity-7404944328344829952-b0jX" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(LinkedIn)</p>
<p>US proposal to collect travellers’ social media history -<span> </span><a href="https://youtu.be/QsoH3G7GfU0?t=2980" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRN8K2jV/" target="_blank" rel="noopener"><strong>Read</strong></a><span> </span>(TikTok)</p>



























































<h2>And Finally...Pringles Popped</h2>

























<span><img class="m_-4231199220004915668img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NYOyESud7wdU_hZI0BNZOIpWWZxvN5KLwY-0L0_Bh5TnqO7v4eu79hvce-spuNvnPE7MCkRxKE10y_0o08R_cfdCnqnQYgz2KUzFh2ZHvpvTXYuxbDOBJnY8w9lu4MMSKWQ0G7SDZj2T68fT65WMBzw=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/fTf9QurG5A0qIyq6gwE8hMyQpsFg5Sb1DrvBSJBu.png" width="540" onerror="this.style.display='none'"></span>

























<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p>This week, someone shared a screenshot of a Google warning telling them their password for the Pringles website had been exposed in a data breach. And yes, that raises the obvious question: why does anyone even have a Pringles account?</p>
<p>But that is precisely the point.</p>
<p>Most of us now have hundreds of online accounts. Brand sites, loyalty schemes, competitions, things we signed up for once and never thought about again. We forget they exist, but attackers do not.</p>
<p>When one of those random accounts gets breached, it is not about crisps. It is about whether that same password works anywhere else. Email, shopping, social media, and work tools. That is where the real damage happens.</p>
<p>So laugh at the Pringles account if you want, but it is a perfect reminder that password reuse is still one of the biggest risks out there. If your brain cannot remember every account you have, it should not be trying to remember every password either.</p>
<p>That is why password managers matter, even for the silly stuff.</p>
<ul></ul>
<p></p>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>











</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/190876?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/190876?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F190876%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F190876%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_188646">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/188646/watch_times"
  data-youtube-player-video-id-value="C60-A0Er09c"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/C60-A0Er09c/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/188646">
          Dec 8, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/188646">
            Scientology Breach, Windows Chaos and a Live ChatGPT Scam
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<h3 class="ember-view reader-text-block__heading-3">Scientology hit by the Qilin ransomware gang</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=79" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://cybernews.com/entertainment/scientology-ransomware-attack-qilin-secret-files-exposed/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The Church of Scientology has confirmed a ransomware attack after the Qilin gang claimed they stole 190 gigabytes of internal files. Samples posted online appear to include recent operational documents from its UK base. It is an unusual breach of a very private organisation, and it raises the question of what happens when a group built on secrecy loses control of its own information.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Backups protect choices</strong><span class="white-space-pre"> </span>- Good backups take the pressure out of ransom negotiations and limit long-term damage.</li>
<li>
<strong>Reputation does not reduce risk</strong><span class="white-space-pre"> </span>- Attackers care about opportunity and leverage, not public profile.</li>
<li>
<strong>Fast isolation contains fallout</strong><span class="white-space-pre"> </span>- Stopping the spread early makes the difference between a bad day and a full crisis.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Westminster Council still struggling after last month’s attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=208" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://fitzrovianews.com/2025/12/04/westminster-council-cyber-attack-services-disrupted/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Westminster Council is weeks into its recovery and still cannot process repairs, housing payments, children’s services referrals or even simple online requests. Residents are being pushed to offline workarounds while the council rebuilds systems and investigates the source of the attack. It is a clear reminder that cyber incidents do not just affect networks. They affect people and entire communities.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Critical services need manual fallbacks</strong><span class="white-space-pre"> </span>- When systems fail, people need clear alternative paths.</li>
<li>
<strong>Local impact is wide and immediate</strong><span class="white-space-pre"> </span>- Councils hold sensitive data and support essential services, so downtime hits real lives fast.</li>
<li>
<strong>Shared platforms multiply the damage</strong><span class="white-space-pre"> </span>- When multiple councils share systems, one breach becomes everyone’s problem.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Windows 10 becomes a 500,000,000 device security problem</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=967" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.forbes.com/sites/zakdoffman/2025/12/01/security-disaster-500-million-microsoft-users-say-no-to-windows-11/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">More than five hundred million people are still on Windows 10. Support has ended, updates have stopped, and new vulnerabilities are now left open for attackers to use. This is not a user failure. This is a Microsoft-created problem. They made the upgrade path difficult. They set hardware requirements that millions of perfectly good devices cannot meet. They pushed people toward machines that need new chips and new components, even when the old ones still work.</p>
<p class="ember-view reader-text-block__paragraph">This week’s Windows LNK zero-day proves the point. A simple shortcut file could run hidden code. Windows 11 users will get a fix. Windows 10 users are on their own. When half a billion people are stuck on an unsupported system, it is not a natural result of poor user behaviour. It is the result of a forced upgrade strategy that people cannot afford, cannot justify or simply cannot complete.</p>
<p class="ember-view reader-text-block__paragraph">Microsoft says it is about progress and security. But creating a security crisis by ending support for a product that half the world still uses should not be called progress. It should be called what it is. A company decision that shifted risk from Microsoft to everyone else.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Unsupported devices become easy targets</strong><span class="white-space-pre"> </span>- Once a product is abandoned, every new hole stays open. Attackers know exactly where to look.</li>
<li>
<strong>Upgrade friction is a business problem, not a user flaw</strong><span class="white-space-pre"> </span>- People did not reject security. They rejected the cost and complexity of replacing hardware that still works.</li>
<li>
<strong>Lifecycle planning beats last-minute panic</strong><span class="white-space-pre"> </span>- Organisations need clear plans for device refresh long before support ends. People should never be forced into insecure choices by a vendor.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points...</h2>
<h3 class="ember-view reader-text-block__heading-3">Scientology ransomware attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=79" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://cybernews.com/entertainment/scientology-ransomware-attack-qilin-secret-files-exposed/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Westminster Council still disrupted after cyber attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=208" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://fitzrovianews.com/2025/12/04/westminster-council-cyber-attack-services-disrupted/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Freedom Mobile breach</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=424" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.bleepingcomputer.com/news/security/freedom-mobile-discloses-data-breach-exposing-customer-data/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Brsk breach in the UK</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=548" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.theregister.com/2025/11/28/brsk_breach/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Marquis breach affecting seventy four US banks</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=698" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.bleepingcomputer.com/news/security/marquis-data-breach-impacts-over-74-us-banks-credit-unions/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Windows 10 security crisis and five hundred million unsupported devices</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=967" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.forbes.com/sites/zakdoffman/2025/12/01/security-disaster-500-million-microsoft-users-say-no-to-windows-11/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Windows LNK zero day actively exploited</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=967" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.bleepingcomputer.com/news/microsoft/microsoft-mitigates-windows-lnk-flaw-exploited-as-zero-day/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Microsoft Teams location and activity tracking concerns</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=1220" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.forbes.com/sites/zakdoffman/2025/11/30/this-is-when-microsoft-starts-telling-your-boss-if-youre-not-at-work/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">India drops plan to force cyber safety app on smartphones</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=1341" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.bbc.co.uk/news/articles/clydg2re4d1o" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Fake ChatGPT Atlas installer used in ClickFix attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=1551" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://hackread.com/fake-chatgpt-atlas-clickfix-steal-passwords/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">AI used to fake street footage and mislead viewers</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=2733" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.reddit.com/r/quityourbullshit/s/xuTeHJrO4l" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Employee falls for phishing but reports within minutes</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=2480" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://www.reddit.com/r/auscorp/comments/1pb219x/fell_for_a_phishing_email_and_got_hacked_will_i/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">AI generated Home Alone behind the scenes footage</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=2883" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://vm.tiktok.com/ZNRRsL9vq/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Japanese studio makes candidates draw live to prevent AI cheating</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=3314" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://80.lv/articles/japanese-game-studio-tasks-job-seekers-to-draw-in-front-of-them-to-make-sure-their-portfolios-aren-t-ai-made" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">The Fake ChatGPT Atlas Attack We Caught Live</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QJGrFqtGqHGdfvGNjGKbMnXKKgXQAqEbI " href="https://youtu.be/C60-A0Er09c?t=1870" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">This one was wild because it unfolded in real time while we were recording. A sponsored Google search result appeared, claiming to offer a Mac install of something called “ChatGPT Atlas.” At first glance, it looked legitimate. Clean branding, a simple landing page, and a Google Sites address that many people would trust without thinking twice.</p>
<p class="ember-view reader-text-block__paragraph">But the moment you clicked the download button, the trap appeared. The page told users to open their terminal, copy a command that had already been placed on the clipboard, paste it in, and press enter. That single instruction would have handed attackers full access to the device, likely including passwords and authentication tokens. No malware file, no pop-up, just social engineering wrapped inside “tech support” style instructions. Classic ClickFix.</p>
<p class="ember-view reader-text-block__paragraph">The most alarming part came when we dug deeper. The Google ad promoting the fake installer was not placed by the attackers using their own domain. It was placed through a compromised Google Ads account belonging to a genuine charity. This gave the malicious site extra credibility because it came from a trusted advertiser with a history of clean campaign activity. It also explains why it climbed so high in search results.</p>
<p class="ember-view reader-text-block__paragraph">This is what modern attacks look like. No broken English. No dodgy popups. Just familiarity, big brand names, borrowed trust and a single "copy and paste" that does the damage.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Trust is being borrowed from real brands</strong><span class="white-space-pre"> </span>- Attackers know people search for “ChatGPT app” or “ChatGPT browser” and click the first result. They do not need to fool the platform. They only need to fool the user.</li>
<li>
<strong>Terminal commands are the new phishing link</strong><span class="white-space-pre"> </span>- Tech-savvy staff are often the easiest to catch here. If you are used to running commands, you stop questioning the source.</li>
<li>
<strong>Platform trust signals are fading fast</strong><span class="white-space-pre"> </span>- Google sites, sponsored results, clean pages, even verified advertiser accounts. None of these guarantees safety anymore. The only safe rule is this. Never paste a command into your terminal unless you know exactly who wrote it.</li>
</ul>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/188646?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/188646?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F188646%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F188646%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_187337">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/187337/watch_times"
  data-youtube-player-video-id-value="sNo23-RAzCc"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/sNo23-RAzCc/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/187337">
          Dec 1, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/187337">
            Cartels, Fake Updates and One Big Budget Oops
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">ClickFix attacks are now using fake Windows updates to install malware. And a government budget was leaked because someone guessed the URL.</p>
<p class="ember-view reader-text-block__paragraph">This week’s episode looks at why the smallest human shortcuts still create the biggest openings. From predictable web addresses to fake update screens that look almost real, Ant breaks down why attackers keep coming back to the same ideas. Because they work.</p>
<p class="ember-view reader-text-block__paragraph">Also this week, London councils face a major cyber incident, the US emergency alert system is disrupted by ransomware, and Harvard reveals a vishing breach that exposed donor data. Mix in AI voice scams and a coffee machine admin menu that uses 1111 as the password, and you get a perfect snapshot of where human security habits really are.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or Listen to the episode today -<span class="white-space-pre"> </span></strong><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">Breach Watch</h2>
<h3 class="ember-view reader-text-block__heading-3">London councils hit by severe cyber incident</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=62" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.infosecurity-magazine.com/news/london-councils-hit-by-serious/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Several London boroughs, including Kensington and Chelsea and Westminster City Council, are dealing with a major incident affecting services and phone lines. They have notified the ICO and are working with the NCSC. Councils hold some of the most sensitive personal data in the country, which makes this a serious situation for anyone living in those areas.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle<span class="white-space-pre"> </span></strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Sensitive data attracts attention</strong><span class="white-space-pre"> </span>- People often forget how valuable council records can be for profiling and scams.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Service disruption hurts fast</strong><span class="white-space-pre"> </span>- When core services pause, the ripple effect hits vulnerable people first.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Partnerships matter</strong><span class="white-space-pre"> </span>- Fast support from NCSC shows how important joined up response is.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">US emergency alert system disrupted after ransomware attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=168" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bleepingcomputer.com/news/security/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">The OnSolve Code Red platform, which powers emergency notifications across the United States, was taken offline after a ransomware attack. Agencies temporarily lost the ability to send weather alerts and critical warnings. They are restoring the system from a backup more than six months old.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Backups only help if they are recent</strong><span class="white-space-pre"> </span>- Restoring from half a year ago shows why recovery needs routine testing.</li>
<li>
<strong>Criminals do not care about impact</strong><span class="white-space-pre"> </span>- Even life-saving systems are targets.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Ransomware is still a supply chain problem</strong><span class="white-space-pre"> </span>- One compromised provider can hit thousands of communities.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Harvard reports vishing breach exposing alumni data</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=306" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://securityaffairs.com/185034/security/harvard-reports-vishing-breach-exposing-alumni-and-donor-contact-data.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Attackers used voice phishing to access Harvard’s alumni and donor systems. Emails, phone numbers, addresses and donation details were exposed. No payment data was taken, but the personal context is sensitive enough to power convincing social engineering attempts.</p>
<p class="ember-view reader-text-block__paragraph">∠<strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Phone calls bypass many controls</strong><span class="white-space-pre"> </span>- People trust a real voice more than an email.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Context is power</strong><span class="white-space-pre"> </span>- Donation history and relationships make scams far more believable.</li>
<li>
<strong>Vishing is rising fast</strong><span class="white-space-pre"> </span>- It is still one of the easiest entry points for attackers.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">OBR budget leaked because the URL was predictable</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=636" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.theregister.com/2025/11/28/obr_ciaran_martin/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Journalists accessed the UK budget forty minutes early by guessing the link. It was a near copy of last year’s URL. No hack. Just poor digital housekeeping.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Predictability is a vulnerability</strong><span class="white-space-pre"> </span>- If someone can guess it, they will.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Security by obscurity does not work</strong><span class="white-space-pre"> </span>- Publishing sensitive material without protection is never safe.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Randomising filenames is basic hygiene</strong><span class="white-space-pre"> </span>- Fundamentals still matter.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">SIM swap story shows how quickly attackers can take over everything</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=427" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bbc.co.uk/news/articles/czrk7gxk2l6o" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The BBC shared the story of a woman whose number was hijacked. Attackers took over her Gmail, locked her out of her bank, opened a credit card, broke into her WhatsApp and even threatened groups she was part of. All powered by old breach data and a SIM swap request.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Your phone number is an identity key</strong><span class="white-space-pre"> </span>- If someone controls it, they can reset almost anything.</li>
<li>
<strong>Old breach data still matters</strong><span class="white-space-pre"> </span>- Information from years ago can fuel modern scams.<span class="white-space-pre"> </span>
</li>
<li>
<strong>SIM swap alerts must not be ignored</strong><span class="white-space-pre"> </span>- If your phone suddenly loses signal, call your provider fast.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Fake Windows update uses ClickFix to deliver malware</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=832" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bleepingcomputer.com/news/security/clickfix-attack-uses-fake-windows-update-screen-to-push-malware/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A fake Windows update page tells people to press Windows and R, then paste code they did not type. It looks convincing enough to fool anyone who is not deeply familiar with update screens. This continues the wider ClickFix trend attackers have been using all year.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>No one should ever paste code from a pop up</strong><span class="white-space-pre"> </span>- This is a simple behaviour that is easy to teach.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Interfaces can be faked</strong><span class="white-space-pre"> </span>- People trust what looks familiar.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Run box attacks are everywhere</strong><span class="white-space-pre"> </span>- Microsoft needs to address this, but organisations can help by educating.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Black Friday scam wave hits with polished fake surveys</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=1050" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.malwarebytes.com/blog/scams/2025/11/black-friday-scammers-offer-fake-gifts-from-big-name-brands-to-empty-bank-accounts" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Malwarebytes found more than one hundred domains pushing fake rewards for Lego, Yeti, Louis Vuitton and more. It starts with a survey and ends with a request for a small shipping fee. That final step steals payment details.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Big brands equal big trust</strong><span class="white-space-pre"> </span>- Scammers lean on names people recognise.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Shipping fee scams are everywhere</strong><span class="white-space-pre"> </span>- Small payments feel harmless, which is the point.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Holiday pressure lowers caution</strong><span class="white-space-pre"> </span>- Urgency and excitement make mistakes more likely.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points...</h2>
<h3 class="ember-view reader-text-block__heading-3">Breach Watch</h3>
<p class="ember-view reader-text-block__paragraph"><strong>London councils cyber incident</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=62" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.theguardian.com/society/2025/nov/28/london-vigilant-with-messages-cyber-attack-kensington-chelsea-council?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- The Guardian</p>
<p class="ember-view reader-text-block__paragraph"><strong>OnSolve CodeRED emergency alert outage</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=168" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bleepingcomputer.com/news/security/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- BleepingComputer</p>
<p class="ember-view reader-text-block__paragraph"><strong>Harvard vishing breach exposing alumni and donor data</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=306" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bleepingcomputer.com/news/security/harvard-university-discloses-data-breach-affecting-alumni-donors/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- BleepingComputer</p>
<p class="ember-view reader-text-block__paragraph"><strong>OBR budget leak caused by a guessable URL</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=632" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.theregister.com/2025/11/28/obr_ciaran_martin/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- The Register</p>
<h3 class="ember-view reader-text-block__heading-3">The News</h3>
<p class="ember-view reader-text-block__paragraph"><strong>SIM swap story and why old breach data still matters</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=427" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.bbc.co.uk/news/articles/czrk7gxk2l6o" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- BBC News</p>
<p class="ember-view reader-text-block__paragraph"><strong>New ClickFix wave using fake Windows updates</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=832" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.malwarebytes.com/blog/news/2025/11/new-clickfix-wave-infects-users-with-hidden-malware-in-images-and-fake-windows-updates?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- Malwarebytes</p>
<p class="ember-view reader-text-block__paragraph"><strong>Black Friday fake brand giveaways and survey scams</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=1050" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.malwarebytes.com/blog/scams/2025/11/black-friday-scammers-offer-fake-gifts-from-big-name-brands-to-empty-bank-accounts?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- Malwarebytes</p>
<p class="ember-view reader-text-block__paragraph"><strong>AI kidnapping scam using a cloned voice</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=1742" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.fox5ny.com/news/woman-targeted-terrifying-ai-assisted-kidnapping-scam?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- FOX 5 NY</p>
<p class="ember-view reader-text-block__paragraph"><strong>Corridor Crew test AI shopping scams</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=2036" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.youtube.com/watch?v=nanCGeac_-Q&amp;utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- YouTube</p>
<p class="ember-view reader-text-block__paragraph"><strong>Gmail smart features and email scanning correction</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=2383" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.malwarebytes.com/blog/news/2025/11/gmail-is-reading-your-emails-and-attachments-to-train-its-ai-unless-you-turn-it-off?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- Malwarebytes</p>
<h3 class="ember-view reader-text-block__heading-3">Awareness Awareness</h3>
<p class="ember-view reader-text-block__paragraph"><strong>Layer 8 Champions Impact Report early look</strong><span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=2466" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.linkedin.com/posts/layer8ltd_securitychampions-humanriskmanagement-securityculture-activity-7396922712188727296-C0rc?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABFpm9kBai-lb9afNEVVo9TlxsPHJv7qgik" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span>- CIISec and Layer 8</p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<h3 class="ember-view reader-text-block__heading-3">A free coffee machine hack thanks to a default password</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://youtu.be/sNo23-RAzCc?t=1614" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://vm.tiktok.com/ZNR1uA2qH/" target="_blank" rel="noopener"><strong>Watch on TikTok</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Luke found a video of someone double-tapping a Frankie coffee machine and entering 1111 to unlock the admin panel. You can edit drinks, change settings or run a free taste cycle. A perfect example of why default passwords create easy wins for attackers.</p>
<p class="ember-view reader-text-block__paragraph"><strong>∠The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Anything with a screen needs a new password</strong><span class="white-space-pre"> </span>- Even a coffee machine.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Defaults stay forever unless someone changes them</strong><span class="white-space-pre"> </span>- Build this into onboarding.<span class="white-space-pre"> </span>
</li>
<li>
<strong>Physical access still matters</strong><span class="white-space-pre"> </span>- Small devices can cause big problems.</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="BZlYAjikHPGRJsJDVXcEAIgyCHVdMWfWWELYvU " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/187337?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/187337?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F187337%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F187337%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_186072">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/186072/watch_times"
  data-youtube-player-video-id-value="i64Vd5Wy5qI"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/ojx8l1horkxi3lam8jgmdibfi1dy" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/186072">
          Nov 24, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/186072">
            WhatsApp Leak, Rail Hack and CCTV Horror Stories
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This episode dives into the attacks and scams that show how fragile everyday systems really are. From a rail IT supplier leaking terabytes of data to CCTV cameras exposing maternity wards, and a Google ad scam that fooled one of our own. It has been a busy week.</p>
<p class="ember-view reader-text-block__paragraph">Luke and I break it all down in plain language. No drama. No jargon. Just what people need to stay safe at work and at home.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or Listen to the episode today -<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="http://riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">Introducing Kindred Cyber and Kinsights</h2>
<p class="ember-view reader-text-block__paragraph">Last week, Ant launched Kindred Cyber, his new home for people-centred security work. One of the first things he is offering is<span class="white-space-pre"> </span><strong>Kinsights</strong>, a clear and honest look at how your culture is really doing. It cuts through noise, shows what is working, and gives you the actions that actually help people change their behaviour. If you want a sharper view of your awareness activities, Kinsight is where to start. Find out more at<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="http://www.kindredcyber.com/" target="_blank" rel="noopener">www.kindredcyber.com</a></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEETJKQam1bmA/article-inline_image-shrink_1500_2232/B4EZq1G1LbKcAU-/0/1763975058801?e=1765411200&amp;v=beta&amp;t=sGATyJa6ybeffQjF_AJnGzdnxoEjYleJxYwS_cOTw0I" onerror="this.style.display='none'"></span>Get in touch today for a chat!<span class="white-space-pre"> </span></p>
<h2 class="ember-view reader-text-block__heading-2">The Breach Report</h2>
<h3 class="ember-view reader-text-block__heading-3">Italian rail supplier hit with a 2.3 TB data leak</h3>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=123" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-23tb-data-from-italian-rail-group-almaviva/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A hacker claims to have taken 2.3 TB of internal data from Almaviva, an IT supplier for Italy’s rail network. Technical docs, contracts, HR files, accounting data. The lot. It is unclear whether passenger data is included but the size and depth of the leak is heavy.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Supply chains matter</strong>. Attackers often go for the vendor, not the main brand.</li>
<li>
<strong>Structured data is gold</strong>. When the leak includes internal repos, it indicates deep access.</li>
<li>
<strong>Reputation is fragile</strong>. Public sector contracts depend heavily on trust.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Salesforce customers impacted via Gainsight integration</h3>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=195" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">ShinyHunters are back. This time they appear to have used tokens from a previous breach to access Salesforce customers through a Gainsight integration. Salesforce revoked all tokens while they investigate. It is another reminder that synced tools can quietly open doors you thought were locked.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Third parties expand the attack surface</strong>. OAuth connections are often the weak link.</li>
<li>
<strong>Attackers reuse access for months</strong>. Once they have one foothold, they circle back.</li>
<li>
<strong>Token hygiene matters</strong>. Organisations need to audit old integrations more often.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">One hundred and twenty thousand CVs leaked in Cornerstone Staffing ransomware attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=318" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://cybernews.com/security/cornerstone-staffing-ransomware-attack-qilin-group-exposes-resumes/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Qilin claim to have stolen 300 GB of Cornerstone Staffing data, including 120,000 CVs and more than a million files with personal data and financial documents. CVs are a treasure trove for cybercriminals. Perfect for identity theft and targeted phishing.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>CVs expose everything</strong>. Skills, job history, phone numbers, home addresses.</li>
<li>
<strong>Double extortion is standard now</strong>. Even if you recover systems, the leaks keep coming.</li>
<li>
<strong>Threat groups move fast</strong>. Qilin have claimed almost one thousand victims since 2023.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">A WhatsApp flaw exposed 3.5 billion phone numbers</h3>
<p class="ember-view reader-text-block__paragraph"><strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=512" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></strong><strong>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://9to5mac.com/2025/11/18/whatsapp-security-flaw-exposed-3-5b-phone-numbers-including-yours/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Researchers from the University of Vienna scraped almost the entire WhatsApp user base by hammering the contact lookup system. With no rate limits in place at the time, they pulled phone numbers, profile photos and bios in bulk. phones, photos and names. All public metadata, just gathered at scale.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Metadata is enough</strong>. Attackers do not need messages to target you.</li>
<li>
<strong>Rate limits matter</strong>. Systems should never allow bulk lookups.</li>
<li>
<strong>Phone numbers are weak identifiers</strong>. They are too easy to harvest.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">The News</h2>
<h3 class="ember-view reader-text-block__heading-3">US, UK and Australia sanction Russian hosting companies linked to ransomware</h3>
<p class="ember-view reader-text-block__paragraph"><strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=748" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></strong><strong>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.reuters.com/world/asia-pacific/us-uk-australia-announce-sanctions-against-russia-based-media-land-over-2025-11-19/?utm_source=chatgpt.com" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Media Land, a well known bulletproof hosting provider, has been sanctioned for enabling ransomware gangs including LockBit and Evil Corp. It is part of a coordinated effort to choke off the infrastructure these groups rely on.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Hitting infrastructure hurts</strong>. Without servers, campaigns slow down.</li>
<li>
<strong>International coordination is improving</strong>. Sanctions across three nations is a strong signal.</li>
<li>
<strong>Enablers are in scope</strong>. Not just the hackers, but the support systems.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Twitch banned for under sixteens in Australia</h3>
<p class="ember-view reader-text-block__paragraph"><strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=885" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></strong><strong>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.bbc.co.uk/news/articles/cx2n2955g10o" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Australia’s new social media rules now include Twitch. Under sixteen accounts must be blocked or closed. Platforms face huge fines if they do not comply.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Livestreaming now equals social media</strong>. Regulators are treating them the same.</li>
<li>
<strong>Age verification is coming</strong>. Likely ID checks or face recognition in future.</li>
<li>
<strong>The internet is shifting</strong>. Young users will move to lesser known platforms.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Hackers sell maternity ward CCTV footage online</h3>
<p class="ember-view reader-text-block__paragraph"><strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=1192" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></strong><strong>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.bbc.co.uk/news/articles/cqjw2x10njeo" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Fifty thousand CCTV systems across India, including maternity hospitals, schools and homes, were hacked using default passwords and weak setups. Footage was sold on Telegram for as little as nine dollars. Eight people were arrested.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Default passwords remain a massive problem</strong>.</li>
<li>
<strong>CCTV needs proper security just like any other device</strong>.</li>
<li>
<strong>Real people suffer real harm</strong>. The victims here were at their most vulnerable.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Teenagers plead not guilty in the London Transport cyber attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=1664" target="_blank" rel="noopener"><strong>Watch</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://news.sky.com/story/teenagers-plead-not-guilty-to-london-transport-cyber-attack-13473518" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Two teenagers linked to Scattered Spider have pleaded not guilty after the TfL attack that disrupted systems and forced identity checks for every staff member. The trial is set for June 2026.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Critical infrastructure is under constant pressure</strong>.</li>
<li>
<strong>Younger attackers are being recruited and guided by bigger groups</strong>.</li>
<li>
<strong>Legal cases like this take years to resolve</strong>.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">Awareness Awareness</h2>
<h3 class="ember-view reader-text-block__heading-3">CIISec Live is this week</h3>
<p class="ember-view reader-text-block__paragraph">Ant is heading to the<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.linkedin.com/company/ciisec/" target="_blank" rel="noopener">Chartered Institute of Information Security</a><span class="white-space-pre"> </span>CIISec Live at Heathrow for a QI style session blended with a Who Wants to Be a Millionaire format. The question we are answering is simple. How do we actually change behaviour and culture in cyber?</p>
<p class="ember-view reader-text-block__paragraph">If you are in engagement, training or human risk, the event is worth your time.<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.ciisec.live/" target="_blank" rel="noopener">https://www.ciisec.live/</a></p>
<h3 class="ember-view reader-text-block__heading-3">This Week’s Topics From Us</h3>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://youtu.be/i64Vd5Wy5qI?t=2070" target="_blank" rel="noopener"><strong>Watch the topics section</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">1. The social engineering trick that asks for your phone’s unlock code</h3>
<p class="ember-view reader-text-block__paragraph">A WhatsApp style scam screenshot has been doing the rounds. It shows how easy it is for someone to ask for your phone’s passcode under the disguise of returning a lost phone. Simple but effective. Real or not, it's a useful reminder.<span class="white-space-pre"> </span></p>
<h3 class="ember-view reader-text-block__heading-3">2. The AI data leak problem is getting worse</h3>
<p class="ember-view reader-text-block__paragraph">A developer posted 200 customer records straight into ChatGPT to debug a SQL query. No policy prevented it. No DLP caught it. The browser made it invisible. Everyone is facing this problem and policy alone is not enough. Engagement matters.</p>
<h3 class="ember-view reader-text-block__heading-3">3. Sponsored Google ads strike again</h3>
<p class="ember-view reader-text-block__paragraph">Luke shared a real example after someone booked flights through a sponsored Google search result. A convincing fake site, Airpaz, took the booking and the card details. Thankfully the bank stopped it. The Trustpilot reviews for Airpaz tell the full story and they are not pretty.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Sponsored does not mean safe</strong>.</li>
<li>
<strong>Fake sites look perfect now</strong>.</li>
<li>
<strong>Always check the URL before entering details</strong>.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">Subscribe to the Newsletter</h2>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="http://www.riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a></p>
<h2 class="ember-view reader-text-block__heading-2">And finally… a quick reminder for Black Friday</h2>
<p class="ember-view reader-text-block__paragraph">If you buy any connected tech this week, especially cameras, doorbells or baby monitors, change the default passwords immediately. Cheap devices often come with weak security. A few minutes of setup can prevent a painful story later.</p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="sgFaNWsBvYRpNPPEXFFIOIIaPaSfHHpphGSmo " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/186072?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/186072?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F186072%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F186072%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_183278">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/183278/watch_times"
  data-youtube-player-video-id-value="qsS5wWZTLrg"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://storage.googleapis.com/popshopprod-membership-assets-single-b5px4371/ewt2wwk2zonlvrjcy9dz4tp4kpao" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/183278">
          Nov 17, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/183278">
            Can attackers really turn safety tools into weapons?
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><strong>This Week on The Awareness Angle - </strong></p>
<ul>
<li>Google’s own safety tools are being used to wipe people’s phones.</li>
<li>A Chinese state group ran an AI driven espionage campaign with almost no humans involved.</li>
<li>And a two billion record credential dump reminds us that password reuse is still one of the biggest risks out there.</li>
</ul>
<ul></ul>
<p>This week’s episode looks at what happens when everyday tools become attack surfaces. From cloud accounts acting like remote kill switches to AI agents running full intrusion chains, Ant and Luke break down the human choices, habits and gaps that make these attacks possible.</p>
<p>Also this week, Checkout dot com turns an extortion attempt into a win for the industry, Norway discovers its buses can be remotely stopped, and a new phishing kit shows how criminal tools are becoming as slick as the legit ones.</p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>




































<h2>This week's stories...</h2>
<p></p>
<h2>Checkout dot com stands up to extortion</h2>
<p><a href="https://youtu.be/qsS5wWZTLrg?t=536" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.checkout.com/blog/protecting-our-merchants-standing-up-to-extortion" target="_blank" rel="noopener"><strong>Read</strong></a><a href="https://youtu.be/alSyFJslrLE?t=600" target="_blank" rel="noopener"></a></p>
<p>This one deserves the spotlight because it is rare to see a company take an attack and turn it into something genuinely positive. ShinyHunters tried to extort Checkout dot com after accessing an old third-party storage system that should have been shut down years ago. No payment data, no card details, no merchant funds were touched.</p>
<p>Here is the part that matters. Checkout dot com refused to pay and then donated the same amount as the ransom demand to cybercrime research at Oxford and Carnegie Mellon. They admitted the mistake, fixed the legacy system, and redirected the money into something that helps everyone.</p>
<p>The awareness angle is simple, criminals rely on easy payouts. Every time someone refuses to pay, the business model weakens. And when a company can own an error and still come out with more trust, that is something worth celebrating.</p>
<p><strong>∠The Awareness Angle</strong><strong><br></strong></p>
<ul>
<li>
<strong></strong><strong>Refusing to pay disrupts attackers<span> </span></strong>- every rejected ransom makes cybercrime less profitable,</li>
<li>
<strong>Admitting the mistake builds trust</strong><span> </span>- transparency always lands better than silence.</li>
<li>
<strong>Donating the ransom funds progress</strong><span> </span>- the money now supports research that strengthens defences for everyone.</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>North Korean attackers turn Google’s Find Hub into a remote wipe tool</h2>
<p><a href="https://youtu.be/qsS5wWZTLrg?t=1322" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.csoonline.com/article/4088037/north-korean-hackers-exploit-googles-safety-tools-for-remote-wipe.html" target="_blank" rel="noopener"><strong>Read</strong></a><a href="https://youtu.be/alSyFJslrLE?t=1005" target="_blank" rel="noopener"></a></p>
<p>A North Korean group has worked out how to weaponise Google’s own Find Hub feature. They used phishing emails to steal Google account credentials, logged in, tracked victims, and then remotely wiped their Android devices. The worst part is that they timed the resets for when the person was physically away, so alerts were missed and recovery took longer. At the same time, the group hijacked trusted contacts on KakaoTalk and used those accounts to send malware disguised as stress relief apps. It is a clever mix of cloud account takeover and social trust.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Cloud accounts are now critical infrastructure</strong><span> </span>- if someone gets into your Google or Apple account, they can do more damage than if they stole the device itself.</li>
<li>
<p><strong>Messages from trusted contacts are not always safe</strong><span> </span>- account hijacking makes malware look friendly, so unexpected files always need a second look.</p>
</li>
<li>
<p><strong>Built in features can be misused</strong><span> </span>- this attack relied on legitimate tools, not zero days, which means everyone needs to review how their own devices handle remote actions.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>The first AI orchestrated cyber espionage campaign</h2>
<p><a href="https://youtu.be/qsS5wWZTLrg?t=1556" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.anthropic.com/news/disrupting-AI-espionage" target="_blank" rel="noopener"><strong>Read</strong></a><a href="https://youtu.be/alSyFJslrLE?t=1575" target="_blank" rel="noopener"></a></p>
<p>A Chinese state linked group ran what appears to be the first large scale cyber espionage campaign driven almost entirely by an AI agent. They jailbroke Claude Code, fed it structured tasks, and used it to infiltrate around thirty organisations. Claude handled roughly eighty to ninety percent of the operation by itself. It scanned networks, wrote exploits, harvested credentials, exfiltrated the data, and even documented the work. Only a few human decisions were needed.</p>
<p>This is a real shift. It shows what happens when attacks operate at machine speed, with machine volume, and almost no human workload. OpenAI has strengthened detection and shared the case to warn people that this is now possible.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>AI lets attackers scale attacks instantly</strong><span> </span>- this campaign shows that intrusions can now run continuously and automatically without a big human team.</li>
<li>
<p><strong>Guardrail bypassing is becoming a normal tactic</strong><span> </span>- the group did not hack Claude, they persuaded it with careful prompts, which is exactly what employees could face too.</p>
</li>
<li>
<p><strong>Defenders need automation to keep up</strong><span> </span>- if attackers use AI to speed up reconnaissance and exploitation, security teams will need AI powered detection to match the pace.</p>
</li>
</ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>
<ul></ul>


























<h3>Do you have something you would like us to talk about? Are you struggling to solve a problem, or have you had an awesome success? Reply to this email telling us your story, and we might cover it in the next episode!</h3>


























<h2>Awareness Awareness</h2>
<h3>CIISec Live is coming up and it is all about behaviour and culture</h3>
<ul></ul>
<ul></ul>
<ul></ul>



















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/gRMSd6OpFAcFTSpYPLqVBWtfUAQD3G2dpH3c2xJv.jpg" width="540" onerror="this.style.display='none'"></span>

























<p>CIISec Live takes place on the 25th of November at Heathrow and it looks like a brilliant day for anyone working in awareness or human risk. There are workshops on behaviour change, panel debates on what actually works, and sessions shaped by the audience rather than the stage. I will be on a panel that blends QI energy with a Who Wants to Be a Millionaire style format, all focused on one question. How do we really change behaviour and culture in cyber?</p>
<p>If your work touches training, engagement or behaviour, this is worth your time.<br><br><a href="https://www.ciisec.live/" target="_blank" rel="noopener">https://www.ciisec.live/</a></p>
<ul></ul>
<ul></ul>
<ul></ul>



















<h3>Think and Share, a brilliant awareness push for a good cause</h3>
<ul></ul>
<ul></ul>
<ul></ul>



















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/L5XouurCxkupjNJ5UH91RNmMPdPFCB0sBS0G442L.png" width="540" onerror="this.style.display='none'"></span>

























<p>There is a great initiative doing the rounds right now, supported by OutThink and started by Flavius. The idea is simple, share a short cyber safety tip, tag a few others, and each video raises money for cyber safety education in schools. It is a rare mix of awareness, community and impact.</p>
<p>Anna’s video deserves a special mention. She uses deepfake tools, timing and a smart creative build up to show how easily someone can fall for a convincing message. It is one of the best examples this week of turning a simple idea into something memorable. It shows what happens when you mix creativity with a security message, and it is exactly the kind of content that cuts through.</p>
<p>If your team or wider business is looking for something fresh to share, this challenge is worth supporting, and the videos make great conversation starters.</p>
<p>Watch Anna's video<span> </span><span class="ml-rte-link-wrapper"><a href="https://www.linkedin.com/posts/anna-pieczatkowska-3b776029_challengeaccepted-thinkandshare-cybersecurity-activity-7394901907900657664-Q6Hy?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABFpm9kBai-lb9afNEVVo9TlxsPHJv7qgik" target="_blank" rel="noopener">here</a></span><br><br></p>
<h2>My chat with Dan from GoldPhish</h2>
<ul></ul>
<ul></ul>
<ul></ul>



















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/vQEZkFaFQE8ZlPEO97orWV6cxL7Dt3k4vLwX9saS.png" width="540" onerror="this.style.display='none'"></span>

























<p>I joined Dan from GoldPhish for a really fun conversation about keeping security simple, honest and human. We talked about why so much training feels overdone, why people switch off, and why small moments of clarity land better than perfectly polished content. Dan has a very real, no nonsense approach that lines up with how I see awareness, so this one felt natural from the first minute.</p>
<p>If you want something easy to listen to with a few proper laughs, give it a go.</p>
<p>Watch the chat - <span class="ml-rte-link-wrapper"><a href="https://youtu.be/m5GNnSDepmQ" target="_blank" rel="noopener">https://youtu.be/m5GNnSDepmQ</a></span></p>
<ul></ul>
<ul></ul>
<ul></ul>






















<h2>
<span class="ml-rte-link-wrapper"><a href="https://www.tenable.com/blog/frequently-asked-questions-about-the-august-2025-f5-security-incident" target="_blank" rel="noopener"></a></span>This Week's Discussion Points...</h2>
<h2><strong>Breach Watch</strong></h2>
<p><strong>Doctor Alliance healthcare breach exposes 1.24 million medical records – TechRadar</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=147" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.techradar.com/pro/security/healthcare-firm-apparently-hit-by-major-cyberattack-exposing-over-a-million-medical-records" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Synnovis ends investigation into NHS ransomware attack linked to patient death – The Register</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=242" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.theregister.com/2025/11/13/synnovis_qilin_investigation/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>DoorDash employee falls for social engineering attack, user data exposed – BleepingComputer</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=426" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.bleepingcomputer.com/news/security/doordash-hit-by-new-data-breach-in-october-exposing-user-information/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Checkout dot com refuses ransom and donates equivalent to cybercrime research – Checkout dot com</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=536" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.checkout.com/blog/protecting-our-merchants-standing-up-to-extortion" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Two billion credentials indexed on Have I Been Pwned via Synthient dataset – HIBP</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=610" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://haveibeenpwned.com/" target="_blank" rel="noopener">Read</a></strong></p>
<h2><strong>The News</strong></h2>
<p><strong>Ofcom found monitoring VPN usage with undisclosed third party tool – TechRadar</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=805" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.techradar.com/vpn/vpn-privacy-security/exclusive-ofcom-is-monitoring-vpns-following-online-safety-act-heres-how" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Chinese built buses in Norway can be remotely halted by manufacturer – Euronews</strong><br><strong><span class="ml-rte-link-wrapper"><a href="https://youtu.be/qsS5wWZTLrg?t=980" target="_blank" rel="noopener">Watch</a></span></strong><span> </span>|<span> </span><strong><a href="https://www.euronews.com/next/2025/11/06/chinese-made-buses-can-be-halted-remotely-in-norway-spurring-increased-security" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>North Korean hackers misuse Google Find Hub to wipe Android devices – CSO Online</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=1319" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.csoonline.com/article/4088037/north-korean-hackers-exploit-googles-safety-tools-for-remote-wipe.html" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>AI orchestrated espionage campaign powered by jailbroken Claude Code – Anthropic</strong><br><strong><a target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.anthropic.com/news/disrupting-AI-espionage" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Scotland launches cyber observatory to protect public services – UK Defence Journal</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=1795" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://ukdefencejournal.org.uk/scotland-launches-cyber-observatory-to-protect-public-sector/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>New UK Cyber Security and Resilience Bill introduced to Parliament – ISP Review</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=1860" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.ispreview.co.uk/index.php/2025/11/new-cyber-security-and-resilience-bill-introduced-to-uk-parliament.html" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Quantum Route Redirect phishing as a service kit evades scanners – KnowBe4</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=2100" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://blog.knowbe4.com/quantum-route-redirect-anonymous-tool-streamlining-global-phishing-attack" target="_blank" rel="noopener">Read</a></strong></p>
<h2><strong>Awareness Awareness</strong></h2>
<p><strong>CIISec Live 2025 at London Heathrow – CIISec</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=2280" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.ciisec.live/" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Think and Share Challenge supporting cyber safety in schools – Anna Pieczatkowska</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=2459" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.linkedin.com/posts/anna-pieczatkowska-3b776029_challengeaccepted-thinkandshare-cybersecurity-ugcPost-7394899101223403520-pj7v" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Right Hand Cyber Halloween posters for awareness teams – Right Hand AI</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=2674" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.linkedin.com/posts/righthandai_security-awareness-halloween-2025-activity-7390055001206718464-nK2W" target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Jimmy Kimmel password on the street clip – YouTube</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=2827" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a target="_blank" rel="noopener">Read</a></strong></p>
<p><strong>Leanne Potter on how language shapes cyber and AI – LinkedIn</strong><br><strong><a href="https://youtu.be/qsS5wWZTLrg?t=3016" target="_blank" rel="noopener">Watch</a></strong><span> </span>|<span> </span><strong><a href="https://www.linkedin.com/feed/update/urn:li:activity:7393965572394418176/" target="_blank" rel="noopener">Read</a></strong><strong></strong><br><a href="https://www.linkedin.com/posts/hazelmcpherson_getyouracttogether-cyber-recruitment-activity-7388854598687563776-kofx?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAABFpm9kBai-lb9afNEVVo9TlxsPHJv7qgik" target="_blank" rel="noopener"><strong></strong></a><br><strong><a href="https://mashable.com/article/cookie-consent-pop-ups-eu-looking-to-change-law?utm_source=tldrdesign" target="_blank" rel="noopener"></a></strong></p>
<p><strong>📬 Subscribe to the Newsletter</strong><a href="https://www.magonia.io/what-framing-security-alerts-as-a-binary-true-or-false-positive-is-costing-you" target="_blank" rel="noopener"><strong></strong></a></p>
<p></p>
<p><a href="https://www.riskycreative.com/" target="_blank" rel="noopener">https://www.riskycreative.com</a></p>
<ul></ul>
 

























<h3>Thanks for reading! If you’ve spotted something interesting in the world of cyber this week — a breach, a tool, or just something a bit weird — let us know at<span> </span><span><a href="mailto:hello@riskycreative.com" target="_blank" rel="noopener">hello@riskycreative.com</a></span>. We’re always learning, and your input helps shape future episodes.</h3>


























<h2>And finally…A scammer who actually replied</h2>






















<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/e5rZTuxiMQQe0BeennEdNli2a0MZpAre7zJDGPap.png" width="540" onerror="this.style.display='none'"></span>

























<p><a href="https://youtu.be/qsS5wWZTLrg?t=3168" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.tiktok.com/@makandanimals/video/7571112505460722966?_r=1&amp;_t=ZN-91JbdigzYCk" target="_blank" rel="noopener"><strong>Watch on TikTok</strong></a></p>
<p>A text message pretending to be from Lloyds Bank made the rounds this week. The person who received it replied to say it was an obvious scam, and the scammer actually responded. That response showed there was a real person behind it, actively pushing and trying to get a reaction.</p>
<p>It is a reminder that these scams are not all harmless attempts or automated scripts. They are also run by people who know exactly how to pressure someone into acting quickly. For anyone who is older, isolated or less confident with technology, a message like this could easily feel genuine. It highlights why clear guidance, calm advice and simple steps are essential for anyone who might not recognise the signs straight away.</p>
<p><strong>∠The Awareness Angle</strong></p>
<ul>
<li>
<strong>Real people run these scams</strong><span> </span>- the scammer replying shows there is intent, pressure and manipulation behind the messages, which makes them more convincing for people who already feel stressed or unsure.</li>
<li>
<strong>Vulnerable people are the easiest targets</strong><span> </span>- anyone who is older, isolated or less confident with tech is far more likely to reply without thinking, which is exactly what these scammers rely on.</li>
<li>
<p><strong>Confidence is a defence in itself</strong><span> </span>- knowing what a scam looks like helps you pause and check, so encouraging simple checks can make a big difference for those who feel less secure online.</p>
</li>
</ul>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/183278?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/183278?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F183278%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F183278%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_175566">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/175566/watch_times"
  data-youtube-player-video-id-value="m5GNnSDepmQ"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/m5GNnSDepmQ/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/175566">
          Nov 14, 2025
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/175566">
            Human Risk, Real Talk - Dan Thornton on Keeping Security Simple
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p><a href="https://&lt;iframe%20data-testid=%22embed-iframe%22%20style=%22border-radius:12px%22%20src=%22https:" target="_blank" rel="noopener">Stream on Spotify</a></p>
<p><a href="https://apple.co/3LET7Vk" target="_blank" rel="noopener">Listen on Apple Podcast</a></p>
<p>This episode is packed with straight-talking cyber stories, smart thinking about human risk, and a brilliant look at why simple beats clever every single time.</p>
<p>I sat down with Dan Thornton, founder and CEO of Goldphish, for a conversation that cuts right to the heart of what security awareness should be. No jargon, no corporate waffle, no pretending that long training solves everything. Just two people who genuinely care about helping users stay safe talking about what actually works.</p>
<p>Dan’s path into cyber was shaped by his time in the Royal Marine Commandos and then years spent managing physical security and crisis situations in some of the toughest environments. Everything changed during the NotPetya attack, when he watched a global organisation go dark for five days. That moment showed him just how fragile companies can be when people are unprepared. It also opened the door to the idea that awareness needs to be practical, human and built around behaviour, not box ticking.</p>
<p>We talk about the reality of today’s phishing landscape and how AI is helping attackers personalise scams faster than ever. We dig into the pressure felt by small and mid-sized businesses, many of which want to improve their awareness but do not have the resources or expertise to run it properly. And we get into why so many programmes still rely on long courses and shame-based phishing tests that only push people away.</p>
<p>One of my favourite moments is Dan’s take on incentives. If you want people to care about security, give them reasons to care. Celebrate reports. Highlight good behaviour. Make it visible when teams do the right thing. Culture grows when people feel supported, not when they feel like they are being set up to fail.</p>
<p>There is plenty of fun mixed in too. Pizza-flavoured passwords. The apps we all secretly know are probably spying on us. The danger of what someone could learn if they ever got hold of your chat history. It is honest, light, and surprisingly revealing at points.</p>
<p>Most of all, this conversation is a reminder that awareness is at its best when it feels like something people actually want. Clear messaging. Good storytelling. Simple takeaways that help at work and at home. Training people do not hate. And a culture where reporting is seen as a win, not an admission of failure.</p>
<p>If you care about people, behaviour, and building a culture that actually works, this is one of those episodes that will stay with you for a while.</p>
<p>Give it a listen and let it get you thinking about what your programme could look like when you keep things simple, human and genuinely helpful.</p>
<p>Stay aware, stay secure.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/175566?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/175566?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F175566%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F175566%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame></template></turbo-stream>

<turbo-stream action="remove" target="posts_load_more"></turbo-stream>

  <turbo-stream action="append" target="posts_list"><template><turbo-frame id="posts_load_more">
  <a data-turbo-stream="true" data-controller="infinite-scroll" href="/supporters/load_more?last_id=175566&amp;last_live_at=2025-11-14T06%3A00%3A00.000%2B00%3A00&amp;order=desc"></a>
  <div class="loader">
  <svg class="loader__icon" viewBox="0 0 100 100">
    <circle class="loader__circle" cx="50" cy="50" r="45" />
  </svg>
</div>
</turbo-frame>
</template></turbo-stream>
