<turbo-stream action="append" target="posts_list"><template><turbo-frame class="main-list__list-item" data-testid="Post" id="post_220955">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/220955/watch_times"
  data-youtube-player-video-id-value="3UJkXvfcxNw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/3UJkXvfcxNw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/220955">
          Mar 30, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/220955">
            Ajax Season Tickets Stolen, OpenAI Kills Sora &amp; Apple's Age Verification Explained
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week we've got a hack that let strangers steal your season tickets and quietly erase stadium bans at one of Europe's biggest football clubs. The AI app with a billion-dollar Disney deal that vanished in six months. Meta's finally fighting back against scammers with AI. And Apple wants to know how old you are.</p>
<p>All that and more on this week's The Awareness Angle.</p>
<p><br></p>
<p>The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke give you straight talking cyber news for people who actually care about the human side of security.</p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





































































<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/pGrKvQ4i00sfBFcLuRm2L4VnYFg3ttwmbAG3VZkV.jpg" width="540" onerror="this.style.display='none'"></span>

























<p>If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p>The<span> </span><a href="https://www.linkedin.com/showcase/sansworkforce/" target="_blank" rel="noopener">SANS Workforce Security &amp; Risk Training</a><span> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is this Friday, 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p>The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p>And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p>If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p>The deadline is the 3rd of April. Two weeks. Get your submission in.</p>
<p>Submit your proposal<span> </span><a href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_blank" rel="noopener">here</a>. Get more information on the summit<span> </span><a href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_blank" rel="noopener">here.</a></p>






















<h2>This week's stories...</h2>
<h3>Ajax Amsterdam hack exposed fan data, allowed attackers to steal season tickets and lift stadium bans</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=91" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/" target="_blank" rel="noopener">Read</a></p>
<p>Ajax Amsterdam didn't find out about their own security breach from their security team. They found out from journalists. A hacker had been poking around their systems, and tipped off the press before the club had any idea there was a problem.</p>
<p>What the hacker found was pretty significant. Every user of the Ajax app shared the same digital key. By tweaking a single request, you could act as any other user entirely. Transfer their season ticket to yourself. Change their account details. Or, and this is where it gets a bit darker, quietly remove their stadium ban. As Luke and I discussed on the episode, imagine a bunch of banned supporters suddenly finding themselves back inside the ground for one match. It's got a Channel 4 drama written all over it.</p>
<p>The ticket theft is frustrating. The ban removal is a safety issue. And the fact that Ajax only found out because of a journalist is a reminder that knowing something's gone wrong matters just as much as trying to stop it happening in the first place. The vulnerabilities have since been patched and the Dutch Data Protection Authority and police have been informed.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>Ajax found out from a journalist, not their own systems</strong><span> </span>- The hacker tipped off the press before Ajax even knew there was a problem. If they'd been in it for money instead of attention, hundreds of thousands of fans could have been affected before anyone noticed. Knowing something's wrong matters just as much as stopping it happening in the first place.</p>
<p><strong>It wasn't a sophisticated hack, just a design flaw</strong><span> </span>- Every Ajax app user shared the same digital key. Change one thing in a request and you could act as someone else entirely, transfer their ticket, change their details. No advanced tools required. Some of the worst breaches are just unlocked doors.</p>
<p><strong>Lifting stadium bans is a safety issue, not just a data issue</strong><span> </span>- Those bans exist for a reason. The idea that someone could have quietly removed them, with neither the club nor the banned person knowing, is the kind of consequence you won't find in any data breach notification.</p>
<h3><br></h3>
<h3>Meta launches new anti-scam tools across WhatsApp, Facebook and Messenger using AI</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=277" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://about.fb.com/news/2026/03/meta-launches-new-anti-scam-tools-deploys-ai-technology-to-fight-scammers-and-protect-people/" target="_blank" rel="noopener">Read</a></p>
<p>It feels like at last. Meta has announced a batch of new anti-scam features across WhatsApp, Facebook and Messenger, and some of them are genuinely useful. On WhatsApp, there's a new warning when someone tries to get you to link your account to another device, which is a scam we've talked about on the show before. On Facebook, you'll start seeing alerts when a new friend request comes from an account that looks suspicious, with details like how recently the account was created and whether you have any mutual friends. Messenger is getting AI-powered detection that flags conversations showing signs of a scam, like out-of-nowhere job offers, and gives you the option to review it before you go any further.</p>
<p>Meta also says it removed 159 million scam ads in 2025. Which sounds impressive until you remember how many scam ads we all still see every week. Luke put it well on the episode: it's probably not going to scratch the surface. But it does feel like a shift. For a long time it seemed like these platforms weren't really trying. At least now they are.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>AI being used to fight AI</strong><span> </span>- Scammers use AI to make their attacks more convincing. Platforms like Meta are now fighting back with the same tools. It's an arms race, and these features show the platforms you use every day are at least trying to keep up.</p>
<p><strong>The WhatsApp device linking scam is one to know about</strong><span> </span>- Someone tricks you into sharing a code or scanning a QR code, and suddenly they've got full access to your WhatsApp on their device. The new warning gives you a moment to pause before that happens. If anyone ever asks you to scan or share a WhatsApp code for any reason, that's a red flag.</p>
<p><strong>159 million scam ads is a staggering number</strong><span> </span>- And that's just what they caught. Even with all that, some still get through. A polished ad on Facebook or Instagram is not proof that something is legitimate.</p>
<p><br></p>
<h3>OpenAI shuts down Sora video app and Disney pulls its $1 billion investment deal</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=608" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://variety.com/2026/digital/news/openai-shutting-down-sora-video-disney-1236698277/" target="_blank" rel="noopener">Read</a></p>
<p>Remember Sora? It launched six months ago, hit a million downloads in under five days, and came with a billion-dollar deal for Disney to license characters like Mickey Mouse and Cinderella. Now it's gone. OpenAI has shut it down entirely, exiting the video generation business to focus on other things, reportedly as part of tidying up its product range ahead of a potential stock market listing.</p>
<p>Disney is walking away from the deal completely. Which is a bit ironic given that before they agreed to it, they'd been sending legal letters to Meta, Google and Character[.]AI over AI using their characters without permission. The thinking seemed to be: if you can't beat them, get in there and own a piece of it. That didn't work out.</p>
<p>On the episode I raised whether this might be a pause rather than a permanent shutdown. The tech still exists. And if AI tools start needing less computing power to run, which there are signs of, something like Sora could come back under a different name. In the meantime, the people who were using it will just move to other tools, many of which aren't subject to the same kind of oversight. So the AI slop problem on your social feeds probably isn't going anywhere.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>AI tools can disappear overnight</strong><span> </span>- Sora had a billion-dollar deal and a million downloads in five days. Six months later it's gone. If you've built anything around an AI tool, whether that's a workflow, a business or just a habit, it's worth remembering these things can vanish with very little notice.</p>
<p><strong>Copyright and AI is still a mess</strong><span> </span>- Disney was sending legal letters to Meta, Google and Character[.]AI over AI using its characters before doing the Sora deal. Now that deal's fallen apart too. The question of what AI can and can't do with other people's creative work is no closer to being answered.</p>
<p><strong>AI-generated video is getting harder to spot, not easier</strong><span> </span>- One of the issues with Sora was the volume of low-quality, misleading video it made easy to create. That problem doesn't go away just because Sora does. Other tools will fill the gap.</p>
<p><br></p>
<h3>Apple rolls out age verification to UK iPhone users</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=1303" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://therecord.media/apple-rolls-out-age-verification-uk-iphone-users" target="_blank" rel="noopener">Read</a></p>
<p>Apple is rolling out age verification for UK users as part of a recent iOS update. To access certain features, you'll need to confirm you're over 18, either through payment details already on your account or by submitting ID. If you don't, or if you're under 18, web content filters will switch on automatically.</p>
<p>This is being driven by the UK's regulator Ofcom and the Information Commissioner's Office, who have been pushing platforms hard to keep children off certain types of content. Apple says it's a legal requirement in some regions, and this is their response.</p>
<p>On the episode we had a few questions about it. Where does the verification data actually go? Does it stay on the device, inside Apple's secure enclave, or does it go back to Apple's servers? We don't have a clear answer on that yet. I'm on the iOS beta and haven't been prompted yet, so we may come back to this one as it rolls out properly. What we do know is that a change this big and this unfamiliar is exactly the kind of thing scammers will try to piggyback on very quickly.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>You're handing over more data to prove you're allowed to use your own phone</strong><span> </span>- To access certain features, users will now need to submit ID or payment details. That raises fair questions about what gets stored and what happens if it's ever breached.</p>
<p><strong>This is probably just the start</strong><span> </span>- It's not just Apple. Regulators across the UK and beyond are pushing for age checks to become standard across apps and services. This is likely to become the norm, not the exception.</p>
<p><strong>Scammers will jump on this straight away</strong><span> </span>- A new, unfamiliar prompt asking people to verify their age is exactly the kind of thing that gets turned into a phishing campaign. Expect fake "your verification has expired" messages pretty quickly. If you're communicating this to colleagues or customers, show them what the real thing looks like before the fakes start circulating.</p>



























































<h2>Hoxhunt Phish Of The Week</h2>
<p><em>Thanks as always to the threat intelligence team at<span> </span></em><a href="https://www.hoxhunt.com/" target="_blank" rel="noopener">Hoxhunt</a><span> </span><em>for sharing this week's example.</em></p>

























<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/AiWTrbgLZGyzvRph89yq4mt6SrZNHDzbXpdcIACn.png" width="540" onerror="this.style.display='none'"></span>






















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/oboBJxlM4Nc?t=2687" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" target="_blank" rel="noopener"></a><a href="https://youtu.be/8pdtibfvNvo?t=2104" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_blank" rel="noopener"></a><br></p>
<h3>ChatGPT impersonation - fake subscription invoice</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=2246" target="_blank" rel="noopener">Watch</a></p>
<p>This week's phish is impersonating ChatGPT Plus. The email mimics a subscription invoice notification using ChatGPT branding and a generic layout, claims your invoice is ready for review, and asks you to click a "Verify Invoice Details" button. The button leads to a malicious website. The message creates urgency by suggesting you'll lose access to your subscription if you don't act.</p>
<p>What makes this one worth flagging is that you don't even need to be a ChatGPT subscriber to fall for it. If you're not a subscriber and you get an email saying you've been charged, the instinct is to click quickly and sort it out. That's exactly what they're counting on.</p>
<p>Red flags to watch for:</p>
<ul>
<li>An unexpected invoice or subscription notification you weren't expecting</li>
<li>Generic billing language with no specific details, just a button</li>
<li>Urgency around losing access if you don't act immediately</li>
<li>A "verify" link in the email rather than directing you to log in directly</li>
</ul>
<p>As always, if you get a billing alert for any service, go directly to the website by typing the address yourself. Don't click the link in the email.<br></p>
<ul></ul>
<ul></ul>



























































<h2>This Week's Discussion Points...<br>
</h2>
<p><br></p>
<p>Ajax Amsterdam hack exposed fan data, allowed attackers to steal season tickets and lift stadium bans<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=91" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/" target="_blank" rel="noopener">Read</a></p>
<p>Meta launches new anti-scam tools across WhatsApp, Facebook and Messenger using AI<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=277" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://about.fb.com/news/2026/03/meta-launches-new-anti-scam-tools-deploys-ai-technology-to-fight-scammers-and-protect-people/" target="_blank" rel="noopener">Read</a></p>
<p>OpenAI shuts down Sora video app and Disney pulls its $1 billion investment deal<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=608" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://variety.com/2026/digital/news/openai-shutting-down-sora-video-disney-1236698277/" target="_blank" rel="noopener">Read</a></p>
<p>How a poisoned security scanner became the key to backdooring LiteLLM<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=863" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://snyk.io/articles/poisoned-security-scanner-backdooring-litellm/" target="_blank" rel="noopener">Read</a><span> </span>Apple rolls out age verification to UK iPhone users<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1303" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://therecord.media/apple-rolls-out-age-verification-uk-iphone-users" target="_blank" rel="noopener">Read</a></p>
<p>TikTok for Business accounts targeted in new phishing campaign<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1593" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/" target="_blank" rel="noopener">Read</a></p>
<p>Lloyds app glitch let 447,000 customers see each other's transactions<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1946" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.theregister.com/2026/03/27/lloyds_app_glitch_turned_transactions/" target="_blank" rel="noopener">Read</a></p>
<p>Phish of the Week: ChatGPT impersonation - fake subscription invoice<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2181" target="_blank" rel="noopener">Watch</a></p>
<p>How do you deal with users who refuse to lock their laptop?<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2577" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.reddit.com/r/cybersecurity/s/ddlf3pv5BX" target="_blank" rel="noopener">Reddit</a></p>
<p>Six top tips for parents to keep children safe online<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2912" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://viewonline.lgfl.net/hubfs/SafeguardED/Posters/LGfL-SafeguardED-Poster-A3-Parent-Top-Tips.pdf" target="_blank" rel="noopener">Read</a></p>
<p>The Phisherman - free online safety game for kids<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3089" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://barefootgames.org/the-phisherman" target="_blank" rel="noopener">Read</a></p>
<p>Spot a deepfake using one sentence<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3295" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRQ9mCLP/" target="_blank" rel="noopener">Watch on TikTok</a></p>
<p>Real smishing campaign in France with personalised parcel photos<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3500" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.linkedin.com/posts/maximecartier_this-is-a-real-smishing-campaign-currently-share-7442492225252499456-9GgZ" target="_blank" rel="noopener">LinkedIn</a></p>
<p>French military Strava exposure<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3647" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRxrrFdB/" target="_blank" rel="noopener">Watch on TikTok</a><br></p>



























































<h2>Security Socials</h2>



















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/oboBJxlM4Nc?t=2687" target="_blank" rel="noopener"></a><br></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" target="_blank" rel="noopener"></a><a href="https://youtu.be/8pdtibfvNvo?t=2104" target="_blank" rel="noopener"></a><br></p>
<h3>Anthony's Security Social</h3>
<p>This week I've got a few things for you.</p>
<p>First, I spotted a poster at my kids' school that I thought was worth sharing. It's from<span> </span><a href="https://www.linkedin.com/showcase/lgfl-safeguarded/" target="_blank" rel="noopener">LGfL - SafeguardED</a><span> </span>and it's called Six Top Tips for Parents to Keep Your Children Safe Online. What I liked about it was the approach. Rather than the usual "ban everything and panic," it leads with something refreshing: don't worry about screen time, aim for screen quality. Scrolling through social media isn't the same as making a film, learning something new, or video calling grandma. There's also a nudge to check safety settings across devices, consoles and apps, to get your kids to show you what they're doing and who they're doing it with, and to talk to them about scary things in the news rather than shielding them from it. Worth sharing with parents in your organisation.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=2912" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://viewonline.lgfl.net/hubfs/SafeguardED/Posters/LGfL-SafeguardED-Poster-A3-Parent-Top-Tips.pdf" target="_blank" rel="noopener">See the poster</a><span> </span>|<span> </span><a href="https://lgfl.net/safeguarding" target="_blank" rel="noopener">More on SafeguardED</a></p>
<p>Second, my 11-year-old mentioned she and a friend wanted to start a games company called Barefoot Games one day, so naturally I Googled it. What I found was The Phisherman, a free online game for kids from<span> </span><a href="https://www.linkedin.com/showcase/barefoot-computing/" target="_blank" rel="noopener">Barefoot Computing</a><span> </span>and<span> </span><a href="https://www.linkedin.com/company/bt/" target="_blank" rel="noopener">BT Group</a>. It's an underwater adventure where kids earn cyber points by identifying phishing threats and learning what personal information looks like. It's gamified, it's accessible, and I'd never heard of it before. If you've got kids or you work in an organisation with parents (which is most of us), share this. It's a genuinely good tool for starting a conversation about online safety.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3089" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://barefootgames.org/the-phisherman" target="_blank" rel="noopener">Read</a></p>
<p>Third, I shared a TikTok this week of someone spotting a deepfake live on a video call using just one technique. He asked the person on the other end to hold three fingers up to the side of their face. Deepfake overlays struggle with objects interacting with the face like that and the result was pretty telling. The video has gone viral for a reason. It's a simple, memorable test that anyone can use if they're ever unsure whether the person they're talking to is real. Worth filing away.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3295" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRQ9mCLP/" target="_blank" rel="noopener">Watch on TikTok</a></p>
<p>And last, a LinkedIn post from<span> </span><a href="https://www.linkedin.com/in/maximecartier/" target="_blank" rel="noopener">Maxime Cartier</a><span> </span>at Hoxhunt that caught my eye this week. It shows a real smishing campaign circulating in France with a twist. It's a fake delivery notification, but instead of just a text, it includes a photo of a package with the recipient's name and full home address on the label, and a personalised link. The image makes it feel immediately real. You don't just read the message. You see your parcel. Maxime's friend assumed it was AI, but it looks more like a simple image template with text overlay. Either way, the point stands: scammers are personalising attacks with visual cues that our brains trust instantly. This is where it's going.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3500" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://www.linkedin.com/posts/maximecartier_this-is-a-real-smishing-campaign-currently-share-7442492225252499456-9GgZ" target="_blank" rel="noopener">LinkedIn</a></p>
<h3>Luke's Security Social</h3>
<p>This week Luke shared a TikTok showing French military personnel on what appeared to be a ship, with their Strava activity visible and their location effectively public. This isn't the first time this has happened. Back in 2018, British soldiers inadvertently revealed the location of a semi-secret military camp through their Strava data. Strava does now blur your starting point, but that only goes so far. If you're a service member or working in a sensitive environment, a fitness app with public settings on could give away far more than your split times. The broader lesson for everyone is worth repeating though: think about what your apps are sharing, with whom, and whether the default settings actually reflect what you want.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3647" target="_blank" rel="noopener">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRxrrFdB/" target="_blank" rel="noopener">Watch on TikTok</a></p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/220955?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/220955?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F220955%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F220955%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_218478">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/218478/watch_times"
  data-youtube-player-video-id-value="9n-ewD0zZuU"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/9n-ewD0zZuU/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/218478">
          Mar 23, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/218478">
            Chrome Malware, 8 Million Tips Exposed &amp; Japan Legalises Hacking Back
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle - a US general leaves maps on a train. A Chrome extension with a million users and Google's own seal of approval was quietly skimming your shopping commissions for months. Companies House left a gap in their system for five whole months that anyone could exploit just by pressing the back button. Eight million crime tips that were promised to be anonymous turned out to be anything but. New Android malware is hiding in dodgy streaming apps and going straight for your notes. And Japan has decided it's time to start hitting back.</p>
<p class="ember-view reader-text-block__paragraph">The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke give you straight talking cyber news for people who actually care about the human side of security.</p>
<p><a href="https://youtu.be/9n-ewD0zZuU" target="_blank" rel="noopener"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQHdx9OkLB9cdw/article-inline_image-shrink_1500_2232/B4EZ0PRcCYI4AU-/0/1774077725332?e=1775692800&amp;v=beta&amp;t=1MeW1GLoRwWfWI4fEkGeRjiBRJJZHlOfjGhVK_X8s_o" onerror="this.style.display='none'"></span></a>Click to watch this week's episode</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQFd9cVyLoALRQ/article-inline_image-shrink_1000_1488/B4EZ0PRm2bJUAU-/0/1774077767634?e=1775692800&amp;v=beta&amp;t=N_hIoLimD2U3wwW0IWfg_aT-Z_F3GP_nCC98xiTKAAI" onerror="this.style.display='none'"></span></p>
<h3 class="ember-view reader-text-block__heading-3">The deadline is the 3rd of April. Two weeks. Get your submission in</h3>
<p class="ember-view reader-text-block__paragraph">If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p class="ember-view reader-text-block__paragraph">The<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/showcase/sansworkforce/" target="_blank" rel="noopener"><strong>SANS Workforce Security &amp; Risk Training</strong></a><span class="white-space-pre"> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is Friday 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p class="ember-view reader-text-block__paragraph">The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p class="ember-view reader-text-block__paragraph">And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p class="ember-view reader-text-block__paragraph">If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p class="ember-view reader-text-block__paragraph">Submit your proposal<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_blank" rel="noopener"><strong>here</strong></a>. Get more information on the summit<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_blank" rel="noopener"><strong>here.</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">BREACH OF THE WEEK - The General, The Wine, and The Classified Maps</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=107" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://kyivindependent.com/former-us-commander-in-charge-of-security-assistance-to-ukraine-left-classified-maps-on-train-overindulged-in-alcohol-watchdog-finds/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Major General Antonio Aguto Jr. was the man leading US military assistance efforts to Ukraine. In March 2024, he left classified maps on a Ukrainian train. Not because he was hacked, not because of a sophisticated cyberattack, but because he didn't follow the courier protocol that exists for exactly this reason. The documents sat on the train, unattended, until the US embassy retrieved them the following day.</p>
<p class="ember-view reader-text-block__paragraph">Two months later, he got through the best part of two bottles of wine at a Kyiv dinner, sustained a concussion from the falls that followed, and showed up to meet Secretary of State Blinken the next morning. A 50-page Inspector General report, triggered by three anonymous complaints, covers the whole sorry story. He retired in August 2024.</p>
<p class="ember-view reader-text-block__paragraph">We don't really care about the drinking. We care about the maps.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Procedure exists for a reason</strong><span class="white-space-pre"> </span>- The courier protocol wasn't red tape. It was the thing standing between classified documents and a Ukrainian train seat. Shortcuts under pressure are where breaches live.</li>
<li>
<strong>Impairment in high-trust roles</strong><span class="white-space-pre"> </span>- Organisations talk a lot about insider threats. They rarely talk about what happens when someone with top-level access simply has a bad night. Most have no real mechanism for catching it.</li>
<li>
<strong>Anonymous reporting worked here</strong><span class="white-space-pre"> </span>- Three complaints. That's all it took to open a 50-page investigation. Whistleblower channels work when people trust them enough to use them.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">New Android malware is going through your notes</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=742" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://therecord.media/malware-streaming-apps-android" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Here's one for anyone who keeps passwords in their Notes app. Researchers at ThreatFabric have found a new Android malware called Perseus, hiding inside apps that look like IPTV streaming services. Once it's on your device it does the usual - fake login screens, keylogging etc. But then it does something a bit different. It goes straight for Google Keep and Evernote, pulling out whatever's stored there. Passwords, financial details, account recovery phrases. The stuff people stick in notes because it's convenient.</p>
<p class="ember-view reader-text-block__paragraph">Because IPTV apps are usually downloaded outside the Play Store, the people installing them are already in the habit of skipping the security checks. Perseus knows this.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Your notes app is not a password manager</strong><span class="white-space-pre"> </span>- Convenient, yes. Secure, no. Perseus proves attackers are actively targeting notes apps because they know that's where people hide things they shouldn't.</li>
<li>
<strong>Sideloading is where the risk lives</strong><span class="white-space-pre"> </span>- Apps outside official stores don't go through security checks. Using IPTV apps to watch football for free is exactly the kind of habit that ends with malware on your phone.</li>
<li>
<strong>Old malware never really dies</strong><span class="white-space-pre"> </span>- Perseus is built on Cerberus, a trojan whose source code leaked in 2020. Six years later it's back, repurposed and improved. Old threats get recycled. New actors pick them up.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">672,000 people's bank data stolen, and they waited seven months to tell them</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1258" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://techcrunch.com/2026/03/18/marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Marquis is a fintech company most people have never heard of. It serves over 700 banks and credit unions, handling their data analytics and marketing. In August 2025, it was hit by ransomware. Names, dates of birth, addresses, Social Security numbers, bank account details, card details, all gone. 74 banks disrupted. 36 class action lawsuits filed.</p>
<p class="ember-view reader-text-block__paragraph">The people whose data was stolen found out seven months later.</p>
<p class="ember-view reader-text-block__paragraph">Marquis has sued its firewall provider SonicWall, blaming a vulnerability in SonicWall's cloud backup service for giving the attackers a way in. SonicWall hasn't commented publicly.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Third-party vendors are a single point of failure</strong><span class="white-space-pre"> </span>- Most people whose data was in this breach had never heard of Marquis. Their bank used Marquis. That was enough. One supplier, hundreds of institutions, hundreds of thousands of people.</li>
<li>
<strong>Seven months is too long</strong><span class="white-space-pre"> </span>- Stolen financial data moves fast. The people affected spent seven months exposed without knowing it. Notification timelines matter.</li>
<li>
<strong>Suing your supplier doesn't help your customers</strong><span class="white-space-pre"> </span>- Marquis pointing the finger at SonicWall might play out in court. It doesn't change anything for the 672,000 people whose Social Security numbers are now out there.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">Google Featured it. It was stealing from you.</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1894" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/YouShouldKnow/comments/1rw65o8/ysk_a_popular_browser_extension_called_save_image/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">"Save Image as Type" was a genuinely useful Chrome extension. Over a million users. A Featured badge from Google, the thing that's you'd assume meant it'd been checked and it's safe. Then it changed hands. The new owners quietly updated it with code that hijacked affiliate links, redirecting shopping commissions from Amazon, Adidas and Shein to themselves. The malicious behaviour only kicked in after you'd saved at least 10 images, specifically to avoid detection.</p>
<p class="ember-view reader-text-block__paragraph">Microsoft Edge had removed the same extension a year earlier. Google kept featuring it until March 2026.</p>
<p class="ember-view reader-text-block__paragraph">Anthony had it installed. He removed it live on air.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A Featured badge is not a safety guarantee</strong><span class="white-space-pre"> </span>- Google's own stamp of approval didn't catch this for months after Edge flagged it. Trust the badge less than you think you should.</li>
<li>
<strong>Extensions update themselves silently</strong><span class="white-space-pre"> </span>- The original extension was fine. Then it changed hands, the code changed, and nothing told you. That's the problem with extensions, you install them once and forget they exist.</li>
<li>
<strong>Browser extensions have sweeping access</strong><span class="white-space-pre"> </span>- This one only went after affiliate commissions. The same access could have harvested your passwords, injected malware, read everything you typed. Go through your extensions. Remove anything you don't actively use.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">Phish Of The Week</h2>
<p class="ember-view reader-text-block__paragraph">Brought to you by the threat intelligence team at Hoxhunt</p>
<p class="ember-view reader-text-block__paragraph"><strong>Emirates Airline Impersonation - Loyalty Reward Notification</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEghl34wLX7RQ/article-inline_image-shrink_1500_2232/B4EZ0PVrn5J0AU-/0/1774078836193?e=1775692800&amp;v=beta&amp;t=1iZkGiDUWWxT9x91-2cc71E8teFenpLXGy7kIZJa2Mw" onerror="this.style.display='none'"></span>Legitimate services used to send phishes...yeah, that's a thing!<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">This one's sneaky because it arrives from a real email address. noreply@campaign[.]eventbrite[.]com is a legitimate Eventbrite domain. Someone has simply set up an event on Eventbrite with Emirates branding and used the platform's mailing functionality to send the phish. The sender name reads "Emirates Millies" - RN rendered close together in certain fonts looks like M, a trick we've seen used against Microsoft too.</p>
<p class="ember-view reader-text-block__paragraph">Inside: the Emirates logo, a loyalty reward of AED 498.20, and a link that deliberately won't open when clicked. That's not a bug. The attacker has disabled it because clickable links get scanned by security tools automatically. Copy and paste it manually and you land on a fake Emirates login page, credential harvesting in progress.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>The sender name doesn't match the platform</strong><span class="white-space-pre"> </span>- Emirates doesn't send loyalty notifications via Eventbrite. Full stop.</li>
<li>
<strong>The link won't click</strong><span class="white-space-pre"> </span>- Deliberate. They want you to bypass your own security tools by doing the work manually.</li>
<li>
<strong>The body text uses disguised characters</strong><span class="white-space-pre"> </span>- Some letters are pulled from different character sets to slip past spam filters. If the text looks slightly off or inconsistent, trust that instinct.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points</h2>
<p class="ember-view reader-text-block__paragraph">Former US general got drunk in Kyiv, left classified maps on a train<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=107" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://kyivindependent.com/former-us-commander-in-charge-of-security-assistance-to-ukraine-left-classified-maps-on-train-overindulged-in-alcohol-watchdog-finds/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Crime Stoppers leak exposes millions of "anonymous" tips<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=443" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://cybernews.com/security/crime-stoppers-leak-exposes-millions-tips/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">New Android malware hiding in streaming apps to spy on users' personal notes<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=742" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://therecord.media/malware-streaming-apps-android" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">FBI seizes Handala data leak site after Stryker cyberattack<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1049" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.bleepingcomputer.com/news/security/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Marquis says over 672,000 people had personal and financial data stolen in ransomware attack<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1258" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://techcrunch.com/2026/03/18/marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Companies House suspends filing service after five-month security glitch exposed directors' details<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1597" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.bbc.co.uk/news/articles/c5y41p0dy1wo" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Popular Chrome extension "Save Image as Type" removed after hijacking affiliate links for months<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1894" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/YouShouldKnow/comments/1rw65o8/ysk_a_popular_browser_extension_called_save_image/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Phish of the Week: Emirates Airline Impersonation<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">SANS Security Awareness &amp; Culture Summit 2026 - Call for Presentations<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2585" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Idris Elba's wax model unlocks his iPhone<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2718" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/Damnthatsinteresting/s/60sE5JP0ua" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Pete Tong reads out a URL like it's 1995<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2790" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.instagram.com/reel/DU-lwx_Denm/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Tinder plans to let AI scan your camera roll<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2920" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.404media.co/tinder-plans-to-let-ai-scan-your-camera-roll/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Japan to allow proactive cyber defence from October 1st<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=3007" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/" target="_blank" rel="noopener">Read</a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>Idris Elba's wax double unlocked his iPhone.</strong><span class="white-space-pre"> </span>A Madame Tussauds waxwork was a convincing enough likeness to fool Face ID. Which raises the question: what exactly is Face ID checking for?<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2718" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Pete Tong read out a full URL on BBC Radio 1. In 1995.</strong><span class="white-space-pre"> </span>A clip doing the rounds of Pete Tong carefully enunciating a web address, forward slashes and all. A lovely reminder of how different things were. We're at<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="http://riskycreative.com/" target="_blank" rel="noopener">riskycreative.com</a>, no index.html required.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2790" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Tinder wants to scan your camera roll.</strong><span class="white-space-pre"> </span>The dating app is planning to let AI browse your locally stored photos to figure out your interests and build your profile. Gym selfies, family photos, sensitive documents, whatever's in there. Ant checked his. Apparently it's mostly dinosaurs and things he's selling on eBay.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2920" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.404media.co/tinder-plans-to-let-ai-scan-your-camera-roll/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Japan legalises hacking back.</strong><span class="white-space-pre"> </span>From October 1st, Japan's Self-Defense Forces and police can identify and disable infrastructure used to attack them. They're calling it "proactive cyber defence." In less polite places it's called offensive cyber ops. Either way, it's a significant shift for a country that's been constitutionally locked into a defensive posture since 1946.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=3007" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/218478?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/218478?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F218478%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F218478%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_216868">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/216868/watch_times"
  data-youtube-player-video-id-value="ngAQEvrEMag"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/ngAQEvrEMag/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/216868">
          Mar 16, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/216868">
            Your Antivirus Won't Catch This, SMS Blasters Are Real and a USB Full of America's Secrets
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week, the threats got personal. A fake Google Meet update that hands attackers the keys to your PC. An SMS that pinged Luke's phone at a hospital and turned out to be a live scammer on the end of the line. A banking glitch that let strangers see your salary, your benefits, and your child payments. And a former government insider who allegedly walked out with the personal data of almost every living American on a thumb drive.</p>
<p class="ember-view reader-text-block__paragraph">Oh, and if you've got an old iPhone? Stop reading this and go update it first.</p>
<p class="ember-view reader-text-block__paragraph">The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke don't do death by PowerPoint, just straight talking cyber news for people who actually care about the human side of security.</p>
<p><a href="https://youtu.be/ngAQEvrEMag" target="_blank" rel="noopener"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQGjIOrqRvvQug/article-inline_image-shrink_1000_1488/B4EZzxZXOfIgAQ-/0/1773576486273?e=1775088000&amp;v=beta&amp;t=jO5iFfG7Tq6vo3-s09thJICjYZA-MOVFS_ovDWIxdb0" onerror="this.style.display='none'"></span></a>This week's episode is available to watch on YouTube</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQGgshIeQut2gg/article-inline_image-shrink_1000_1488/B4EZzwiF7rIgAQ-/0/1773561995479?e=1775088000&amp;v=beta&amp;t=RJxwsc-OcRhXl0dHfa-xs_3xXH6wXt5QnKt1wZN2M5A" onerror="this.style.display='none'"></span>SANS is off to Vegas Baby!</p>
<p class="ember-view reader-text-block__paragraph">If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p class="ember-view reader-text-block__paragraph">The<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.linkedin.com/showcase/sansworkforce/" target="_blank" rel="noopener">SANS Workforce Security &amp; Risk Training</a><span class="white-space-pre"> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is Friday 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p class="ember-view reader-text-block__paragraph">The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p class="ember-view reader-text-block__paragraph">And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p class="ember-view reader-text-block__paragraph">If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p class="ember-view reader-text-block__paragraph">The deadline is the 3rd of April. Two weeks. Get your submission in.</p>
<p class="ember-view reader-text-block__paragraph">Submit your proposal<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_blank" rel="noopener">here</a>. Get more information on the summit<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_blank" rel="noopener">here.</a></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">One click on a fake Google Meet update hands attackers the keys to your PC</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=969" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A phishing page disguised as a Google Meet update notice is being used to silently enroll victims Windows PCs into an attacker controlled device management system. No malware, no stolen passwords, just a single click.</p>
<p class="ember-view reader-text-block__paragraph">The page mimics a genuine Google Meet update prompt, but clicking the button triggers a built in Windows feature called MS Device Enrollment, the same legitimate tool your IT department would use to manage a company device. A victim who clicks through hands full remote control of their machine to the attacker, who can then silently install software, change settings, read files, or wipe the device entirely. Because the attack works entirely through the operating system, traditional antivirus tools have nothing to flag. There is no malicious file. No suspicious download. Nothing to scan for.</p>
<p class="ember-view reader-text-block__paragraph">The best defence here is a human one. Why is Google Meet asking me to update through a webpage? Is this normal? Those two questions, asked out loud, stop this attack dead.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Your antivirus will not save you here -<span class="white-space-pre"> </span></strong>This attack uses a genuine Windows feature to hand over control of your machine. If your only defence is a security tool, you have a gap that only a questioning mindset can fill.</li>
<li>
<strong>Knowing what normal looks like matters -<span class="white-space-pre"> </span></strong>Google Meet does not push updates through a webpage like this. Neither do most legitimate apps. If something prompts you to do something you have never seen before, that instinct to pause is worth listening to.</li>
<li>
<strong>If you think you might have clicked it</strong><span class="white-space-pre"> </span>- Go to Settings, Accounts, Access Work or School. If you see anything you do not recognise, especially anything referencing sunlife-finance[.]com or esper[.]cloud, disconnect it immediately.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">The SMS that pinged Luke's phone at a hospital turned out to be a live scammer on the other end of the line</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=1219" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.androidauthority.com/google-messages-sms-blaster-protection-apk-teardown-3647907/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">SMS blasters are portable rogue devices that mimic legitimate mobile towers, force nearby phones to downgrade to 2G, and deliver phishing text messages that bypass your carrier's spam filters entirely. They sound like something out of a spy thriller, but three people were convicted of using one on the London Underground just a few weeks ago.<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">This week it got personal. Luke received a suspicious SMS at a local hospital, categorised as being from Google, complete with a verification code he never requested and a support number to call if he didn't recognise the activity. Ant called the number, and the recording is in this week's episode. It wasn't a call centre in Asia with background noise and a script. It sounded like one person in a bedroom, running the whole operation solo, building trust quickly without ever asking for account details, steering the conversation toward a password reset that would have handed over full account access if a real email address had been given. The whole attack is engineered around panic. Someone sees an unexpected verification code, worries their account has been compromised, calls the number in the message, reads out the recovery code that lands on their phone moments later, and it is over before they realise what happened.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A text that appears to be from a legitimate sender is not proof that it is</strong><span class="white-space-pre"> </span>- SMS blasters spoof sender names, bypass carrier filters, and can drop a message into an existing thread with real previous messages from that contact. The name at the top means nothing.</li>
<li>
<strong>The script relies on you being worried</strong><span class="white-space-pre"> </span>- The call is designed to feel urgent and helpful at the same time. If you receive an unexpected verification code and feel the urge to call a number in the message, stop. Find the real support number from the official website and call that instead.</li>
<li>
<strong>Android users can disable 2G right now</strong><span class="white-space-pre"> </span>- Go to Settings, Network, and look for the option to avoid 2G networks. It is often opted out by default. Turning it on removes the mechanism these devices exploit entirely.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">A whistleblower says a former government staffer walked out of the Social Security Administration with the personal data of almost every living American on a thumb drive</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2091" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.npr.org/2026/03/11/nx-s1-5745153/doge-social-security-data-whistleblower-investigation" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The Social Security Administration's inspector general is investigating a whistleblower complaint alleging that a former DOGE software engineer left his role and took two tightly restricted government databases with him, with at least one stored on a personal thumb drive. One of those databases, NUMIDENT, contains Social Security numbers, dates of birth and parents' names for virtually every living American. He also allegedly claimed to have retained what he described as "god-level" access to SSA systems after leaving. The SSA and the former employee's lawyer have both denied wrongdoing, but investigations are open.</p>
<p class="ember-view reader-text-block__paragraph">No firewall stops someone walking out of the door with a thumb drive. If the allegations are true, the failure here wasn't technical at all. It was human, procedural and organisational, and the lessons apply just as much to a small business as they do to a government agency.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Revoking access when someone leaves is a critical security control, not an admin task</strong><span class="white-space-pre"> </span>- When did you last audit who still has access to systems they no longer need?</li>
<li>
<strong>Insider threats are harder to detect and harder to talk about than external attacks</strong><span class="white-space-pre"> </span>- but they are just as real and no security tool will catch them if the right processes aren't in place.</li>
<li>
<strong>The ability to plug a personal device into a government machine should never have been possible</strong><span class="white-space-pre"> </span>- USB port restrictions are unglamorous, but this is exactly why they exist.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">Starbucks disclosed a data breach this week affecting nearly 900 employees after attackers created fake login pages to steal their credentials</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=110" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Attackers gained access to Partner Central, Starbucks' internal HR platform, by building convincing imitations of the login page and harvesting employee credentials. Once in, they had access to names, Social Security numbers, dates of birth and financial account and routing numbers. The breach ran for 23 days before it was fully resolved, with Starbucks discovering the intrusion on the 6th of February but not fully removing the attackers until the 11th, leaving a five day window where they knew someone was in but couldn't get them out. Affected employees are being offered two years of free identity theft protection through Experian.</p>
<p class="ember-view reader-text-block__paragraph">The reason this one is worth highlighting isn't the scale, it's the method. Fake login page, stolen credentials, walk straight in through the front door. It's one of the oldest tricks going and it still works, including against large well resourced organisations with dedicated security teams.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>This attack didn't exploit a technical vulnerability, it exploited a human one<span class="white-space-pre"> </span></strong>- A convincing fake login page is often all it takes. Knowing what the real login page looks like and being suspicious of anything that asks for your credentials is a habit worth building.</li>
<li>
<strong>Financial account and routing numbers are a different category of risk<span class="white-space-pre"> </span></strong>- Unlike an email address or even a password, these create a direct route to fraud. If you've been notified of this breach, contact your bank directly rather than just monitoring.</li>
<li>
<strong>Third party platforms expand your attack surface whether you like it or not<span class="white-space-pre"> </span></strong>- Payroll, HR, pensions, training. Every platform your organisation uses is another login screen that can be faked. MFA on all of them isn't optional anymore.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">Phish Of The Week</h2>
<p class="ember-view reader-text-block__paragraph"><strong>A legitimate Google email was used to deliver a phishing message, and the trick was hidden in plain sight</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQHmQrjeWFyf6A/article-inline_image-shrink_1500_2232/B4EZzwm2Q7JcAU-/0/1773563242445?e=1775088000&amp;v=beta&amp;t=7A2A5gdgtjla8ZLKMS2yCqrL4_RofEie0F8yD8Kcwh8" onerror="this.style.display='none'"></span>It's clever but we do wonder how successful this will be</p>
<p class="ember-view reader-text-block__paragraph">This one is genuinely clever. The attacker submitted a Google account recovery request, but instead of using a normal email address, they put the entire phishing message into the email address field. It looked something like this: unauthorized_order_of_bitcoin_965usd_on_gpay_if_not_you_call_08XXXXXXXXX@domain[.]com. Because it's formatted like an email address, it passed Google's form validation. Because it came from Google's own systems, it landed in inboxes looking completely legitimate.</p>
<p class="ember-view reader-text-block__paragraph">The goal is to panic the recipient into calling the number, at which point the scam moves off email entirely and onto a phone call where the real manipulation happens.<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/JdSbDyaEr4A" target="_blank" rel="noopener">We've seen this pattern before with PayPal</a>, and it's becoming a recurring technique. Get the victim to make contact on a different platform where there are no spam filters, no warnings and no safety net.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A legitimate sender does not mean a legitimate message</strong><span class="white-space-pre"> </span>- This email came from Google. The domain was real, the formatting was real, and it would pass most technical checks. The content is the only thing that gave it away.</li>
<li>
<strong>When something tries to move you to a phone call, that's a red flag</strong><span class="white-space-pre"> </span>- Email, text, fake notification. The platform doesn't matter. If the end goal is getting you on a phone call to a number you didn't go looking for yourself, pause.</li>
<li>
<strong>Panic is the whole mechanism</strong><span class="white-space-pre"> </span>- Unauthorised Bitcoin purchase, urgent action required, call now. Every word is designed to stop you thinking clearly. Slowing down for ten seconds is genuinely a security control.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph">Thank you to the<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.linkedin.com/company/hoxhunt/" target="_blank" rel="noopener">Hoxhunt</a><span class="white-space-pre"> </span>Threat Intelligence team for sharing this with us!<span class="white-space-pre"> </span></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Talking Points...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>Starbucks discloses data breach affecting hundreds of employees</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=110" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Iran-linked hackers wipe data across 200,000 Stryker devices</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=366" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Lloyds, Halifax and Bank of Scotland apps exposed strangers' transactions</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=663" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.theregister.com/2026/03/12/lloyds_banking_group_glitch/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>One click on this fake Google Meet update can give attackers control of your PC</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=969" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Google Messages may soon get built-in protection against SMS blasters</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=1219" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.androidauthority.com/google-messages-sms-blaster-protection-apk-teardown-3647907/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>A whistleblower says a former DOGE staffer walked out of the SSA with Americans' data on a thumb drive</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2091" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.npr.org/2026/03/11/nx-s1-5745153/doge-social-security-data-whistleblower-investigation" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Apple rushes out patches for older iPhones and iPads against the Coruna exploit kit</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2296" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/apple/apple-patches-older-iphones-and-ipads-against-coruna-exploits/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: ClickFix evolves with a new variant that bypasses Microsoft Defender</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2889" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Darren Jones MP accidentally shares his passcode on camera</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3063" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reels/DVtYGoGk9wb/" target="_blank" rel="noopener">Watch on Instagram</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Tricking an AI scam caller</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3186" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reel/DVOXY5MiGNT/?igsh=MTlyOWxyaGJuNjF0ZA==" target="_blank" rel="noopener">Watch on Instagram</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Apple MacBook Neo Touch ID ad</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3389" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://vm.tiktok.com/ZNRuot9uf/" target="_blank" rel="noopener">Watch on TikTok</a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<h3 class="ember-view reader-text-block__heading-3">The scam caller that got asked for a Bolognese recipe</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQH4B1viW8UAKw/article-inline_image-shrink_1000_1488/B4EZzxYWEuIUAc-/0/1773576220162?e=1775088000&amp;v=beta&amp;t=qA_F0uN-gGOEda2k7nlPc3BSlTiehAg7oS03fu5cOUM" onerror="this.style.display='none'"></span></p>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reels/DVOXY5MiGNT/" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Someone received one of those relentless car finance cold calls this week and decided to have a bit of fun with it. From the start it became pretty clear the caller wasn't human, so they started pushing it. Ask it an off script question, see what happens. Eventually they got it to recite a full Bolognese recipe mid sales pitch, complete with the markdown formatting still intact, hashtags and all, read out loud in a completely earnest robotic voice.</p>
<p class="ember-view reader-text-block__paragraph">It is funny, and it is worth sharing with people in your life who might not realise how convincing these AI calling systems have become. Because the flip side of that video is that plenty of people who received the same call had no idea they were talking to a machine. If you ask it whether it is human, it says yes. It gives a name. It says it is from Manchester. And that is enough to keep a lot of people on the line.</p>
<p class="ember-view reader-text-block__paragraph">Show this to someone who needs to hear it. It is a lot easier to hang up on a robot when you know it is a robot.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/216868?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/216868?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F216868%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F216868%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_214279">
    <div class="post" access="paid-members">
  <div class="post__inner">
      <a class="post__media" data-turbo-frame="_top" href="/supporters/payments/checkout/posts/214279/available_tiers">
  <div class="post-locked">
    <img class="post-locked__video-embed-thumbnail" alt="Video thumbnail" width="712" height="400" loading="lazy" src="https://img.youtube.com/vi/WNLMBT0dcig/hqdefault.jpg" />

    <div class="post-locked__info">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M1.75 3.25a.25.25 0 0 0-.25.25v9c0 .138.112.25.25.25h7.998a.25.25 0 0 0 .25-.25v-9a.25.25 0 0 0-.25-.25 133551.684 133551.684 0 0 0-7.998 0ZM0 3.5c0-.967.784-1.75 1.75-1.75a49139.54 49139.54 0 0 0 7.998 0c.967 0 1.75.784 1.75 1.75v1.61l2.058-.89A1.75 1.75 0 0 1 16 5.826v4.385a1.75 1.75 0 0 1-2.46 1.599l-2.041-.907V12.5a1.75 1.75 0 0 1-1.75 1.75H1.75A1.75 1.75 0 0 1 0 12.5v-9Zm11.499 5.762 2.65 1.177a.25.25 0 0 0 .351-.228V5.826a.25.25 0 0 0-.35-.229L11.5 6.744v2.518Z" clip-rule="evenodd"></path></svg>

    </div>
  </div>
</a>

    <div class="post__main">
  <div class="post__content">
 

        <a class="post__meta" data-turbo-frame="_top" href="/supporters/pricing">
          Mar 9, 2026
</a>

      <div>
          <a class="post__title" data-turbo-frame="_top" href="/supporters/pricing">
            AI Attacks, Fake Hires &amp; the Phish That Fooled LastPass
</a>      </div>



        <div class="post__section post__section--column">
          <a class="button button--medium button--primary" data-turbo-frame="_top" href="/supporters/payments/checkout/posts/214279/available_tiers"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 14 16" role="img" class="button__icon"><path fill="currentColor" fill-rule="evenodd" d="M7 1.5c-.8 0-1.556.292-2.104.794-.546.5-.838 1.163-.838 1.84V5.8h5.884V4.133c0-.676-.292-1.34-.838-1.84A3.12 3.12 0 0 0 7 1.5Zm4.442 4.3V4.133c0-1.118-.485-2.176-1.325-2.945A4.62 4.62 0 0 0 7 0a4.62 4.62 0 0 0-3.118 1.188c-.839.77-1.324 1.827-1.324 2.945V5.8H2A1.75 1.75 0 0 0 .25 7.55v6.7C.25 15.216 1.034 16 2 16h10a1.75 1.75 0 0 0 1.75-1.75v-6.7A1.75 1.75 0 0 0 12 5.8h-.558ZM2 7.3a.25.25 0 0 0-.25.25v6.7c0 .138.112.25.25.25h10a.25.25 0 0 0 .25-.25v-6.7A.25.25 0 0 0 12 7.3H2Zm4.409 4.793V9.435h1.5v2.658h-1.5Z" clip-rule="evenodd"></path></svg>
Join to access</a>
        </div>

      <div class="post__section">
        <div class="post-actions">
          <form class="post-actions__item-form" data-turbo="false" action="/supporters/payments/checkout/posts/214279/available_tiers" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/payments/checkout/posts/214279/available_tiers" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
          
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/214279?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share a preview of a locked post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/214279?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F214279%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F214279%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
        </div>
      </div>

      

  </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_212316">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/212316/watch_times"
  data-youtube-player-video-id-value="8pdtibfvNvo"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/8pdtibfvNvo/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/212316">
          Mar 2, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/212316">
            Vishing Attacks, QR Code Phishing, and Hidden App Tracking Explained
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week on The Awareness Angle, attackers ditch malware and pick up the phone. Optimizely confirms a breach after a vishing attack, proving again that the helpdesk is now the attack surface.</p>
<p>We’ve got fake QR codes stuck on real parking meters, Samsung’s weather app quietly fingerprinting devices, and the UK fining Reddit over children’s data.</p>
<p>Plus mental health apps with serious security flaws, a researcher accidentally taking control of 7,000 robot vacuums, and a brilliant example of using AI to build interactive awareness training in minutes.</p>
<p>The Awareness Angle makes more sense in full. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. If you prefer your cyber news with context, challenge and a bit of straight talking, this one’s worth your time.</p>
<p></p>
<p><span><img class="an1" alt="🎧" src="https://fonts.gstatic.com/s/e/notoemoji/17.0/1f3a7/32.png" onerror="this.style.display='none'"></span><span> </span>Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_-3200921610474955789img CToWUd" height="150" src="https://ci3.googleusercontent.com/meips/ADKq_NYyJ897MxEIKYezSqSnlim4ZNM6N3bUZ7fupyC71dU_GWTIgfoWQuFTs1PKx3VZHtq-YtoX2BiRrAV8tdGEVnLCCeYIxR6dRj_PcffgQEIBCqsCFeWYwBN34Wngpj9Ak-OBfHrs0Nym7JwPhGGjjysS=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="m_-3200921610474955789img CToWUd" height="48" src="https://ci3.googleusercontent.com/meips/ADKq_NbegVyQ56xtGMctwI74KZUXXlu4FCa4ZVpt9mf_dVpie72SAytX5gzqQ1cyHC0WMueAFjuViZ6rNbTU8wFPNkZ52dXkruu8oml5nlLsSYow0A=s0-d-e1-ft#https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>


































































<h2>This week's stories...</h2>
<h3>Optimizely confirms breach after vishing attack</h3>
<p><a href="https://youtu.be/8pdtibfvNvo?t=80" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>This wasn’t some cutting edge exploit. It was a phone call.</p>
<p>Attackers impersonated IT support, convinced staff to hand over SSO and MFA details, and got access to internal systems and CRM records. Optimizely says they didn’t escalate privileges or deploy backdoors, but the real story is how they got in.</p>
<p>We keep talking about this. MFA isn’t failing. People are being redirected around it.</p>
<p>If someone sounds credible, creates urgency, and claims to be internal support, most people don’t switch into “threat actor” mode. They switch into “helpful colleague” mode and that’s the gap.</p>
<p>For awareness teams, this is a great reminder about verification scripts, call back policies, and a chance to emphasise that support staff have permission to challenge authority.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Authority Is a Shortcut</strong><span> </span>– When someone claims to be internal IT, most people default to cooperation. Attackers know that.</li>
<li>
<strong>MFA Can Be Socially Engineered</strong><span> </span>– The control works, until someone convinces you to approve or share it.</li>
<li>
<strong>Support Teams Need Different Training</strong><span> </span>– Helpdesks and IT aren’t just defenders. They are targets. Treat them that way in your awareness strategy.</li>
</ul>
<p></p>
<h3>Fake QR codes stuck on real parking meters</h3>
<p><a href="https://youtu.be/8pdtibfvNvo?t=220" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://globalnews.ca/news/11673628/fraudulent-qr-codes-found-kelowna-parking-meters/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Cybercriminals placed fake QR stickers on 75 parking meters. Drivers scanned, landed on a convincing payment page, and almost handed over their details. No inbox. No malware. Just a sticker and a bit of time pressure.</p>
<p>When you’re paying for parking, you’re not thinking about threat modelling. You’re thinking about not getting a fine.</p>
<p>This is a brilliant story to use internally because it shows that the risk of QR codes hasn't gone away and must be bringing results or the cybercriminals wouldn't continue with it!</p>
<p>The takeaway is simple. Slow down. Check the URL. Use the official app or go to the web page instead of scanning whatever is in front of you.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Context Changes Behaviour</strong><span> </span>– People don’t apply the same caution in a car park as they do in their inbox.</li>
<li>
<strong>Convenience Is the Bait</strong><span> </span>– Quick pay shortcuts are designed to reduce friction. Attackers ride that same instinct.</li>
<li>
<strong>Teach Verification, Not Fear</strong><span> </span>– The behaviour to reinforce is simple. Check the URL. Use official apps. Slow down before entering details.</li>
</ul>
<p></p>
<h3>Mental health apps with millions of installs and hundreds of flaws</h3>
<p><a href="https://youtu.be/8pdtibfvNvo?t=1050" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Researchers found over 1,500 vulnerabilities across ten Android mental health apps, including AI therapy companions and CBT trackers. Collectively, they’ve been installed 14.7 million times.</p>
<p>People are using these apps at their lowest points. Logging thoughts. Sharing deeply personal struggles. And behind the scenes, insecure storage, weak session handling, and other issues are sitting there waiting to be abused.</p>
<p>This is not a “delete all apps” panic story. It’s a reminder that popularity isn’t the same as security. It's also not laying blame at the developer's door. Maybe, with all of the AI coding tools available, it's just become too easy to build something that isn't secure.</p>
<p>If you’re in awareness, this opens up a bigger conversation with some important things to check. App permissions. Update frequency. Who built this thing. When was it last maintained.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Sensitivity Should Raise Standards</strong><span> </span>– The more personal the data, the higher the security bar should be.</li>
<li>
<strong>Install Numbers Mean Nothing</strong><span> </span>– Millions of downloads create false confidence.</li>
<li>
<strong>Awareness Goes Beyond Email</strong><span> </span>– App hygiene, updates, permissions and developer credibility are part of modern security literacy.</li>
</ul>
<h3></h3>



























































<h2>This Week's Discussion Points...</h2>
<p><strong></strong></p>
<p>Ad Tech Firm Optimizely Confirms Data Breach After Vishing Attack<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=80" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Fraudulent QR Codes Found on 75 Kelowna Parking Meters<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=220" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://globalnews.ca/news/11673628/fraudulent-qr-codes-found-kelowna-parking-meters/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Your Samsung Weather App Is a Fingerprint<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=490" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.buchodi.com/your-samsung-weather-app-is-a-fingerprint/?utm_source=tldrinfosec" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>UK Fines Reddit £14.47M for Using Children’s Data Unlawfully<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=780" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/uk-fines-reddit-19-million-for-using-childrens-data-unlawfully/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Android Mental Health Apps With 14.7M Installs Found With Security Flaws<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=1050" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Instagram to Alert Parents if Teens Search for Self-Harm and Suicide Content<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=1423" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.bbc.co.uk/news/articles/c3v7z5eyewko" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Security Flaw Allows Man to Accidentally Gain Control of 7,000 Robot Vacuums<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=1740" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/r/cybersecurity/s/YHxMXvPhkw" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Building Interactive Security Training With Gemini<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=2100" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p>We Invented the Dacia Sandman and the Internet Fell for It<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=2800" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.autocar.co.uk/car-news/features/we-invented-dacia-sandman-and-internet-fell-it" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>ClickFix Pop-Ups in the Wild<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=3103" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.reddit.com/r/mildlyinfuriating/s/1cOgyuW33j" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Samsung Privacy Display Feature<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=3283" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p>Protect Yourself From This Latest Ahrefs Phishing Attack<span> </span><a href="https://youtu.be/8pdtibfvNvo?t=3497" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p><a href="https://vm.tiktok.com/ZNRPDHuCh/" target="_blank" rel="noopener"><strong></strong></a></p>



























































<h2>And finally...Building Interactive Security Training With Gemini</h2>

























<span><img class="m_-3200921610474955789img CToWUd a6T" alt="" src="https://ci3.googleusercontent.com/meips/ADKq_NZcO5TVi-nYsxzRafqkiIJsbcRp6JpdYZCUWxqm-ZUB9zAQS-GGLLDEZ89RDyxxh9yeltKL6-8MJJ520zLUpkd-7v7qJEoktNZ09IEJ61XOyJifOJFlnM1bm-abKCLJSTOV0hoKZlQ5IIJtBN-Plk0j=s0-d-e1-ft#https://storage.mlcdn.com/account_image/769696/QKOmRAmn5NUqUlnxb0lEVQfUCgCtPUBWqANscQbk.png" width="540" onerror="this.style.display='none'"></span>






















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"></a></p>
<p><a href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_blank" rel="noopener"></a></p>
<p><a href="https://youtu.be/oboBJxlM4Nc?t=2687" target="_blank" rel="noopener"></a></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" target="_blank" rel="noopener"></a><a href="https://youtu.be/8pdtibfvNvo?t=2104" target="_blank" rel="noopener">Watch</a><a href="https://youtu.be/fuG0UsphrS8?t=1600" target="_blank" rel="noopener"><strong></strong></a></p>
<p>Luke shows how he used Google Gemini to build an interactive security awareness module in minutes.</p>
<p>With a simple prompt, Gemini generated a ClickFix training page in HTML, complete with explanations, red flags, and a knowledge check. He then refined the look and even built a retro-style phishing game with multiple levels and feedback.</p>
<p>No specialist tools. No complex setup. Just prompts and iteration.</p>
<p>The big takeaway is this. The barrier to creating engaging, customised awareness content is lower than ever. You still need to sense check, validate, and tidy things up, but as a rapid prototyping tool, it is seriously powerful.</p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/212316?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/212316?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F212316%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F212316%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_208700">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/208700/watch_times"
  data-youtube-player-video-id-value="8SegODemXOA"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/8SegODemXOA/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/208700">
          Feb 23, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/208700">
            ShinyHunters Leak 600K Records. Employee Phishing Breach. Password Manager Risks.
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This episode is packed with leaked customer data, another employee phishing story that turned into a full blown breach, and some awkward questions about how much we really trust our password managers.</p>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, ShinyHunters are back with more stolen data, Canada Goose is investigating after hundreds of thousands of customer records were leaked, and Eurail has confirmed traveller information is now up for sale on the dark web. Different brands. Same story. Collect loads of data. Store it. Hope it never gets out.</p>
<p class="ember-view reader-text-block__paragraph">We also talk about a fintech firm that disclosed a breach after a single employee was phished. One inbox. One click. Real consequences. The human layer is still where this starts.</p>
<p class="ember-view reader-text-block__paragraph">Then we get into password managers. What do they actually see? Where are the weak spots? And are we a bit too comfortable assuming the vault is untouchable?</p>
<p class="ember-view reader-text-block__paragraph">All of that, and a few opinions from us along the way, in this week’s edition of The Awareness Angle.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle is best served in full. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. If you like your cyber news with context, challenge, and a few raised eyebrows, this one’s for you.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Phishing Led Breach at Figure</h3>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=797" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://securityaffairs.com/187988/data-breach/fintech-firm-figure-disclosed-data-breach-after-employee-phishing-attack.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Fintech firm Figure has disclosed a data breach after an employee fell victim to a phishing email.</p>
<p class="ember-view reader-text-block__paragraph">According to the company’s filing, the attack began with a successful phishing email that compromised an employee account. From there, the attacker gained access to internal systems and certain customer files.</p>
<p class="ember-view reader-text-block__paragraph">Figure says there is currently no evidence that financial account credentials or customer funds were accessed. However, names, contact details and other personal information linked to customer accounts were exposed. Impacted individuals are now being notified.</p>
<p class="ember-view reader-text-block__paragraph">ShinyHunters has reportedly claimed responsibility and says the breach is linked to a wider campaign targeting organisations using single sign on providers.</p>
<p class="ember-view reader-text-block__paragraph">No zero day. No nation state. Just one convincing email.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Phishing still works</strong><span class="white-space-pre"> </span>– Even in fintech, even with mature security teams, one well crafted email can open the door.</li>
<li>
<strong>Access pathways matter</strong><span class="white-space-pre"> </span>– Inbox compromise is only step one. The real question is what that account can reach once inside.</li>
<li>
<strong>Human risk is business risk</strong><span class="white-space-pre"> </span>– This started with a person. Controls, monitoring, and response speed determine how far it spreads.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">AI Generated Passwords Might Not Be as Smart as You Think</h3>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1964" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://news.sky.com/story/bluesky-13508611" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">There’s been a bit of noise this week around AI generated passwords, and it’s worth paying attention to.</p>
<p class="ember-view reader-text-block__paragraph">Researchers looked at passwords created by tools like ChatGPT, Claude and Gemini and found something interesting. They looked strong. They had symbols, numbers, upper and lower case. They passed basic strength tests. But they weren’t truly random.</p>
<p class="ember-view reader-text-block__paragraph">Because large language models generate likely patterns, not true entropy, some passwords followed very similar structures. In some cases, near identical formats were repeated across tests. That means an attacker who understands how these models tend to construct strings could reduce the guesswork significantly.<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">It’s not that AI is useless. It’s just not built to be a cryptographic random number generator. So, if you’ve ever asked a chatbot to “give me a strong password”, it might be worth changing it.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Complex looking isn’t the same as secure</strong><span class="white-space-pre"> </span>– If something follows a pattern, attackers can learn that pattern.</li>
<li>
<strong>AI generates probability, not randomness</strong><span class="white-space-pre"> </span>– That works brilliantly for language. Not so brilliantly for passwords.</li>
<li>
<strong>Don’t outsource security decisions to convenience</strong><span class="white-space-pre"> </span>– Use a password manager, a long passphrase, or passkeys. Let tools designed for randomness handle randomness.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Infostealer Malware Now Targeting OpenClaw Secrets</h3>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1581" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">We spoke more than once over the past few weeks about OpenClaw and the rise of agent based AI tools. This week, that story moved on yet again.</p>
<p class="ember-view reader-text-block__paragraph">Security researchers have identified the first real world case of infostealer malware specifically harvesting OpenClaw configuration files. Not just browser passwords. Not just cookies. But API keys, authentication tokens and private cryptographic material tied to AI agents.</p>
<p class="ember-view reader-text-block__paragraph">The important bit here is this.</p>
<p class="ember-view reader-text-block__paragraph">People are wiring these agents into email, apps, local files and workflows. They are giving them memory. They are giving them access. And that means a single malware infection can now expose not just accounts, but the operational identity of someone’s AI assistant.</p>
<p class="ember-view reader-text-block__paragraph">This is not a futuristic attack. It is infostealer malware doing what infostealers do. It just found a new goldmine of data sitting locally on machines.</p>
<p class="ember-view reader-text-block__paragraph">AI agents are quickly becoming high value identity hubs.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>AI agents centralise access</strong><span class="white-space-pre"> </span>– Email, tokens, apps and history all in one place makes them incredibly powerful, and incredibly attractive to attackers.</li>
<li>
<strong>Malware evolves fast</strong><span class="white-space-pre"> </span>– Infostealers are not targeting “AI” as a concept. They are simply harvesting files that contain keys and secrets. AI tools just happen to store lots of them.</li>
<li>
<strong>Experimentation needs guardrails</strong><span class="white-space-pre"> </span>– Curiosity is good. But when employees plug new tools into core systems without visibility, risk expands quietly.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Eurail and Canada Goose – Contact Data Still Has Teeth</h3>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=412" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Two very different brands this week, same underlying issue.</p>
<p class="ember-view reader-text-block__paragraph">Eurail has confirmed that stolen traveller data is now being offered for sale online. The data includes names, email addresses, country of residence and booking details. Around the same time, Canada Goose began investigating claims that roughly 600,000 customer records were leaked, including names, email addresses, phone numbers and mailing addresses.</p>
<p class="ember-view reader-text-block__paragraph">In both cases, you see the familiar reassurance. No payment data accessed. But if you know someone recently booked travel or bought something expensive, you do not need their card number. You just need enough context to send a believable message. “Problem with your booking.” “Issue with your delivery.” “Click here to avoid cancellation.”</p>
<p class="ember-view reader-text-block__paragraph">That is where the real risk sits. Follow on phishing, smishing and impersonation campaigns that feel legitimate because they are built on real events.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Context is leverage</strong><span class="white-space-pre"> </span>– Real booking or purchase data makes phishing dramatically more convincing.</li>
<li>
<strong>Contact data is currency</strong><span class="white-space-pre"> </span>– Names, emails and phone numbers are more than enough to fuel targeted fraud.</li>
<li>
<strong>The second wave matters<span class="white-space-pre"> </span></strong>– The breach itself is often only the start of the story.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This week's discussion points...</h2>
<h3 class="ember-view reader-text-block__heading-3">Main Stories</h3>
<p class="ember-view reader-text-block__paragraph"><strong>73,000+ Patients Hit in Arizona Urology Data Breach</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=116" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.comparitech.com/news/arizona-urologist-warns-73000-people-of-data-breach-that-leaked-ssns-medical-and-financial-info/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Eurail Says Stolen Traveller Data Is Now for Sale</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=412" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Figure Discloses Breach After Employee Phishing Attack</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=797" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://securityaffairs.com/187988/data-breach/fintech-firm-figure-disclosed-data-breach-after-employee-phishing-attack.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Canada Goose Investigates 600,000 Customer Record Leak</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1037" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>ShinyHunters Claims CarGurus Breach</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1125" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.theregister.com/2026/02/18/shinyhunters_cargurus_breach/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>US Plans Portal to Bypass Content Bans</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1306" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.reuters.com/world/us-plans-online-portal-bypass-content-bans-europe-elsewhere-2026-02-18/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Vulnerabilities Found in Popular Password Managers</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1466" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.pcgamer.com/hardware/three-of-the-biggest-password-managers-are-vulnerable-to-a-cornucopia-of-practical-attacks-say-security-researchers/" target="_blank" rel="noopener"><strong>Read |</strong></a><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.reddit.com/r/security/s/BiPrBaRmMz" target="_blank" rel="noopener"><strong>Read (Reddit discussion)</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Infostealer Malware Targeting OpenClaw Secrets</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1581" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.bleepingcomputer.com/news/security/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>AI Generated Passwords May Be Predictable</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=1964" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://news.sky.com/story/bluesky-13508611" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">Extras</h3>
<p class="ember-view reader-text-block__paragraph"><strong>TikTok – Review Scam News Clip</strong><span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=2610" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://vm.tiktok.com/ZNRPDHuCh/" target="_blank" rel="noopener"><strong>Watch on TikTok</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...Online Review Blackmail Scam Hits Small Business</h2>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://youtu.be/8SegODemXOA?t=2610" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://vm.tiktok.com/ZNRPDHuCh/" target="_blank" rel="noopener"><strong>Watch on TikTok</strong></a></p>
<p class="ember-view reader-text-block__paragraph">An ITV News clip highlighted a small business owner who was targeted with a different kind of scam. Criminals demanded payment, threatening to flood his company with fake one star reviews if he refused. They followed through.</p>
<p class="ember-view reader-text-block__paragraph">Dozens of negative reviews appeared online, damaging his rating and threatening his livelihood. Instead of paying, he worked with Google to challenge the fake reviews. Eventually, the attackers stopped and moved on.</p>
<p class="ember-view reader-text-block__paragraph">It is a reminder that not all cyber attacks involve malware or data theft. Sometimes the weapon is reputation.</p>
<h3 class="ember-view reader-text-block__heading-3">The Awareness Angle</h3>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Reputation is attack surface</strong><span class="white-space-pre"> </span>– Reviews, ratings and search results can be manipulated and weaponised. Your digital presence is part of your security footprint.</li>
<li>
<strong>Panic is the pressure point</strong><span class="white-space-pre"> </span>– Scammers rely on urgency and fear. The goal is to trigger a quick payment before you think clearly.</li>
<li>
<strong>Do not reward the behaviour</strong><span class="white-space-pre"> </span>– When there is no financial return, attackers often move on to easier targets. Reporting and persistence matter.</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="WaaSksAwsJZZVZlCYNLQZoqqnBApTMDUGAATL " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/208700?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/208700?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F208700%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F208700%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_207284">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/207284/watch_times"
  data-youtube-player-video-id-value="HeF0pPB2mfA"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/HeF0pPB2mfA/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/207284">
          Feb 16, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/207284">
            Discord Exposed. Apple Exploited. AI Investment Scams
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, 70,000 government ID images are exposed in a Discord age verification breach, staff data is hit at the European Commission, and supplier fallout ripples out to Volvo Group after a third party incident. More data. More dependency. More risk.</p>
<p class="ember-view reader-text-block__paragraph">We also cover Apple’s emergency zero day patch already being exploited in the wild, a devastating AI deepfake investment scam that cost an 82 year old nearly £200,000, and fresh concerns around autonomous AI agents expanding enterprise attack surfaces faster than governance can keep up.</p>
<p class="ember-view reader-text-block__paragraph">On top of that, we get into the backlash around Ring’s Super Bowl advert and surveillance partnerships, why some organisations are banning Notepad++ instead of simply patching it, and how email bombing is still being used to quietly bury real account compromise in a flood of noise.</p>
<p class="ember-view reader-text-block__paragraph">All of that, and a few strong opinions along the way, in this week’s edition of The Awareness Angle.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle is best served in full. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. If you like your cyber news with context, challenge, and the occasional raised eyebrow, this one’s for you.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Discord Faces Backlash After Age Verification Breach</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=143" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/technology/s/BpQk59xUL5" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Around 70,000 government issued ID images were exposed after a third party provider used for age verification was compromised. These were not usernames. Not email addresses. Actual passport and driving licence images.</p>
<p class="ember-view reader-text-block__paragraph">This is where the age verification debate gets uncomfortable.</p>
<p class="ember-view reader-text-block__paragraph">We said on the podcast that this is the trade off problem in real time. If platforms require more sensitive data to prove age, the impact of failure increases massively. And crucially, it is not just about trusting the platform. It is about trusting who they trust.</p>
<p class="ember-view reader-text-block__paragraph">This was not Discord’s core infrastructure being breached. It was a supplier in the chain. But to the user whose passport is now exposed, that distinction does not matter.</p>
<p class="ember-view reader-text-block__paragraph">Searches for Discord alternatives reportedly spiked after the story broke. That is what trust erosion looks like.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>More Data, More Risk</strong><span class="white-space-pre"> </span>– The more sensitive the data collected, the higher the impact if breached.</li>
<li>
<strong>Third Parties Matter</strong><span class="white-space-pre"> </span>– Your risk extends to every supplier in the chain.</li>
<li>
<strong>Trust Has a Cost</strong><span class="white-space-pre"> </span>– Safety controls must not create bigger privacy problems.European Commission Discloses Staff Data Breach</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">European Commission Discloses Staff Data Breach</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=387" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.bleepingcomputer.com/news/security/european-commission-discloses-breach-that-exposed-staff-data/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The European Commission confirmed a breach affecting a system used to manage staff mobile devices. Personal data such as names and contact details may have been accessed. There is currently no indication that classified systems were compromised.</p>
<p class="ember-view reader-text-block__paragraph">The bigger issue is what happens next.</p>
<p class="ember-view reader-text-block__paragraph">Internal directories and HR data are high value targets. Once exposed, they fuel phishing, impersonation and social engineering.</p>
<p class="ember-view reader-text-block__paragraph">Containment reportedly happened within hours. But the exposure still matters.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Staff Data Is High Value</strong><span class="white-space-pre"> </span>– Internal directories and HR data are prime targeting fuel.</li>
<li>
<strong>Breaches Enable Follow On Attacks</strong><span class="white-space-pre"> </span>– Exposure often leads to phishing and impersonation.</li>
<li>
<strong>Compliance Is Not Immunity</strong><span class="white-space-pre"> </span>– Even major institutions remain attractive targets.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Volvo Group Impacted by Conduent Supplier Breach</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=537" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://securityaffairs.com/187875/security/volvo-group-hit-in-massive-conduent-data-breach.html?web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Volvo Group has been named among organisations impacted by a cyberattack at IT services provider Conduent.</p>
<p class="ember-view reader-text-block__paragraph">This is another reminder that your organisation’s risk surface is bigger than your own firewall.</p>
<p class="ember-view reader-text-block__paragraph">Conduent provides back office services such as document processing and administrative support. When a service provider like that is breached, the impact cascades outward. One breach can affect dozens, sometimes hundreds, of downstream organisations.</p>
<p class="ember-view reader-text-block__paragraph">We have said it before, but this is third party concentration risk in action. If one supplier services many large brands, the blast radius expands dramatically.</p>
<p class="ember-view reader-text-block__paragraph">Volvo is not alone here. And that is the point.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Third Party Risk Is Shared Risk</strong><span class="white-space-pre"> </span>– Your exposure includes your suppliers.</li>
<li>
<strong>One Breach, Many Victims</strong><span class="white-space-pre"> </span>– Service providers create amplified blast radius.</li>
<li>
<strong>Supply Chain Visibility Matters</strong><span class="white-space-pre"> </span>– Know who holds your data, and how it is protected.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">Apple Fixes Actively Exploited Zero Day</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=686" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Apple released emergency updates to patch a zero day vulnerability described as being used in “extremely sophisticated” attacks.</p>
<p class="ember-view reader-text-block__paragraph">When a vendor confirms exploitation is already happening, patching becomes urgent.</p>
<p class="ember-view reader-text-block__paragraph">These flaws are rarely theoretical. They are used in targeted campaigns. Targeted does not mean rare. It means deliberate.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Zero Days Are Real World</strong><span class="white-space-pre"> </span>– These are not theoretical flaws. They are exploited.</li>
<li>
<strong>Targeted Does Not Mean Safe</strong><span class="white-space-pre"> </span>– Sophisticated attacks still affect everyday users.</li>
<li>
<strong>Update Culture Matters</strong><span class="white-space-pre"> </span>– Fast patching is still one of the strongest defences.</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">82 Year Old Loses £200k in AI Deepfake Investment Scam</h3>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=1189" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://discover.swns.com/2026/02/gran-82-loses-200k-retirement-savings-in-ai-deepfake-doctor-scam/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">An 82 year old grandmother lost nearly £200,000 after seeing what appeared to be a trusted doctor promoting an investment opportunity in a professional looking video.</p>
<p class="ember-view reader-text-block__paragraph">It was AI generated.</p>
<p class="ember-view reader-text-block__paragraph">The scam did not rely on broken English or obvious red flags. It relied on authority bias, emotional manipulation, and realism. Conversations continued over Messenger. Funds were moved into cryptocurrency. The emotional driver was securing care for her autistic grandson.</p>
<p class="ember-view reader-text-block__paragraph">We said this on the show. This is not clumsy phishing. This is AI realism combined with psychology.</p>
<p class="ember-view reader-text-block__paragraph">One comment we discussed summed it up well. It is easy to look at stories like this and think gullible old people. But the speed at which AI is improving should make all of us pause. The bar for deception is rising quickly.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Trust Can Be Faked</strong><span class="white-space-pre"> </span>– Familiar faces are no longer proof.</li>
<li>
<strong>Crypto Is Hard to Reverse</strong><span class="white-space-pre"> </span>– Once funds move, recovery is unlikely.</li>
<li>
<strong>Emotion Drives Decisions</strong><span class="white-space-pre"> </span>– Scammers exploit care, not just greed.</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points...</h2>
<h3 class="ember-view reader-text-block__heading-3">🔎 Breach Watch</h3>
<p class="ember-view reader-text-block__paragraph"><strong>Discord Age Verification Breach Exposes 70,000 Government IDs</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=143" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/technology/s/BpQk59xUL5" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>European Commission Discloses Staff Data Breach</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=387" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.bleepingcomputer.com/news/security/european-commission-discloses-breach-that-exposed-staff-data/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Volvo Group Impacted by Conduent Data Breach</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=537" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://securityaffairs.com/187875/security/volvo-group-hit-in-massive-conduent-data-breach.html?web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Apple Fixes Zero Day Used in Highly Sophisticated Attacks</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=686" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.bleepingcomputer.com/news/security/apple-fixes-zero-day-flaw-used-in-extremely-sophisticated-attacks/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Our Org Is Banning Notepad++ After Supply Chain Concerns</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=970" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/cybersecurity/s/Kofbd9v2ZE" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">📰 News</h3>
<p class="ember-view reader-text-block__paragraph"><strong>82 Year Old Loses £200k in AI Deepfake Doctor Investment Scam</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=1189" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://discover.swns.com/2026/02/gran-82-loses-200k-retirement-savings-in-ai-deepfake-doctor-scam/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Reddit discussion:<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/technology/comments/1qyj0cc/gran_82_loses_200k_retirement_savings_in_ai" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Amazon Distances Itself From Flock Safety After Ring Super Bowl Backlash</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=1456" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.nbcnews.com/news/us-news/amazon-no-longer-working-police-tech-flock-safety-super-bowl-ad-rcna258855" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>How to Recognise a Deepfake, and Why It Is Getting Harder</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=1730" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.kaspersky.com/blog/how-to-recognize-a-deepfake/55247/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>OpenClaw Integrates VirusTotal After Enterprise Risk Warnings</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2292" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.csoonline.com/article/4129393/openclaw-integrates-virustotal-malware-scanning-as-security-firms-flag-enterprise-risks.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<h3 class="ember-view reader-text-block__heading-3">💬 Discussion &amp; Extras</h3>
<p class="ember-view reader-text-block__paragraph"><strong>Cloudflare “ClickFix” Style Fake Verification Page</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2515" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/Wellthatsucks/s/klOYeGfyX3" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Email Bomb Used to Hide a Real Security Alert</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2685" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.reddit.com/r/phishing/s/tGGj3f8u2k" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>The CivDiv No.1 TikTok Account Recommendation</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2830" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.tiktok.com/@thecivdiv.no1?_r=1&amp;_t=ZS-93n2DfFHoNo" target="_blank" rel="noopener"><strong>TikTok</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Most Common 4 Digit PIN Numbers Visualised</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2994" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>QR Code Binder for Child Safe YouTube Access</strong><span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=3158" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">And finally...LinkedIn AI Caricature Trend Raises Oversharing Questions</h2>
<p>See content credentials<span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQHVE9J56R5trA/article-inline_image-shrink_1500_2232/B4EZxhgCO.IYAU-/0/1771162316934?e=1772668800&amp;v=beta&amp;t=2MjW0Hs2EwPvpVMTWDE3l3L0GzMvdBg2rgFvqPMsKLE" onerror="this.style.display='none'"></span>Can you guess my password from this?</p>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://youtu.be/HeF0pPB2mfA?t=2586" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.linkedin.com/posts/matthewjary_theres-a-fun-trend-circling-at-the-mo-inviting-activity-7426532949833076736--saZ" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph">A new trend circulating on LinkedIn has people using AI to generate caricature style action figure versions of themselves. These posts often include job titles, hobbies, favourite sports teams, pets, cities, personality traits and sometimes even family details.</p>
<p class="ember-view reader-text-block__paragraph">The trend itself feels creative and harmless. But a post this week from<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/matthewjary/" target="_blank" rel="noopener">Matthew Jary</a><span class="white-space-pre"> </span>highlighted something worth pausing on. When you scroll through a feed full of these, you start learning a surprising amount about complete strangers.</p>
<p class="ember-view reader-text-block__paragraph">Individually, each detail seems insignificant. Collectively, they form a profile.</p>
<p class="ember-view reader-text-block__paragraph">Many of the attributes being shared mirror the kinds of prompts commonly used in password reset questions and social engineering attempts. First pet. Favourite team. Hometown. Employer.</p>
<p class="ember-view reader-text-block__paragraph">But here’s the alternative view.</p>
<p class="ember-view reader-text-block__paragraph">Is this actually an issue?</p>
<p class="ember-view reader-text-block__paragraph">Most of us openly share our job titles, employers, locations and interests on LinkedIn every day. That is the whole point of the platform. So is this genuinely risky, or is this just the latest “security people hate fun” moment? Is this simply anti bandwagon commentary?</p>
<p class="ember-view reader-text-block__paragraph">Maybe.</p>
<p class="ember-view reader-text-block__paragraph">The difference might not be the individual data point. It might be the packaging. When everything is neatly summarised in one visual snapshot, it lowers the effort required to profile someone.</p>
<p class="ember-view reader-text-block__paragraph">This is not about banning fun. It is about understanding aggregation. Attackers do not always need a breach when information is voluntarily shared and easily searchable.</p>
<p class="ember-view reader-text-block__paragraph">The risk is rarely one post. It is the accumulation.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Small Data Adds Up</strong><span class="white-space-pre"> </span>– Individual facts feel harmless. Combined, they become profile building fuel.</li>
<li>
<strong>OSINT Is Powerful</strong><span class="white-space-pre"> </span>– Attackers do not need a database leak if the information is public.</li>
<li>
<strong>Aggregation Changes Context</strong><span class="white-space-pre"> </span>– One detail is normal. A curated snapshot lowers the barrier for profiling.</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="ScJEQMrjIxJDFMQaFGTNWWiHvkqqtasVltuQ " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/207284?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/207284?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F207284%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F207284%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_205459">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/205459/watch_times"
  data-youtube-player-video-id-value="joGd0M8Fw8o"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/joGd0M8Fw8o/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/205459">
          Feb 9, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/205459">
            Supply Chain Hacks. Fake Encryption. Phones That Track You
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<h1>Supply Chain Hacks. Fake Encryption. Phones That Track You</h1>

























<a href="https://youtu.be/joGd0M8Fw8o" target="_blank" rel="noopener"><span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/lJoxInSqvVgjfUAVeWlwcRUlI1rrWP7gFabWRisA.png" width="540" onerror="this.style.display='none'"></span></a>

























<p>This week on The Awareness Angle, a developer tool update chain gets quietly hijacked, ransomware actors claim access to airport systems, and law enforcement moves in on a major hacking forum, with questions over how much impact that will really have.</p>
<p>We also look at how phones can be tracked at the network level without apps or permission, why McDonald’s felt the need to call out terrible password habits, and how a chaotic extortion group is turning data breaches into deeply personal harassment campaigns. On top of that, Spain is moving to ban social media for under 16s, and questions are resurfacing about whether end to end encryption really means what people think it does.</p>
<p>All of that, and more, in this week’s edition of The Awareness Angle.</p>
<p>The Awareness Angle is best served in full. Watch on YouTube, or listen on Spotify or your favourite podcast platform to get the complete discussion and context.<br><br></p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" target="_blank" rel="noopener">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" target="_blank" rel="noopener">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" target="_blank" rel="noopener"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>


































































<h2>This week's stories...</h2>
<h3>Notepad++ update chain compromised</h3>
<p><a href="https://youtu.be/joGd0M8Fw8o?t=123" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://cybernews.com/security/state-sponsored-hackers-behind-notepad-plus-plus-hack/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Notepad++, a tool a lot of developers use without a second thought, was caught up in a supply chain attack that didn’t touch the code at all. Instead, attackers went after the update process. Between June and December 2025, a small number of users were redirected to malicious update files through the hosting infrastructure.</p>
<p>This wasn’t random. It looks deliberate and targeted, likely aimed at developers or organisations working on sensitive projects. The software itself was fine, but the trust people place in automatic updates was the weak point. Notepad++ has since moved hosting providers, tightened up how updates are verified, and confirmed that versions 8.8.9 and above are safe.</p>
<p>It’s one of those stories that feels uncomfortable because it hits a blind spot. We trust tools like this precisely because they are familiar and boring.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>The risk lived outside the app</strong><span> </span>- The problem wasn’t what people installed, it was what they never see, the update mechanism.</li>
<li>
<strong>Targeted still counts</strong><span> </span>- You don’t need to hit everyone, just the right few people.</li>
<li>
<strong>Choice brings exposure</strong><span> </span>- Every extra tool adds convenience and risk, which is why organisations try to limit what gets installed.</li>
</ul>
<p></p>
<h3>Ransomware group claims access to airport systems</h3>
<p><a href="https://youtu.be/joGd0M8Fw8o?t=453" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.techradar.com/pro/security/russian-ransomware-hackers-allegedly-hit-tulsa-airport-in-cyberattack-dump-private-files-online-as-proof" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>A ransomware group is claiming it breached systems linked to Tulsa International Airport and has begun dumping internal files online as proof. The attackers say the data includes internal emails, employee IDs, passports, and financial documents. At the time of reporting, the airport has not publicly confirmed the breach and the leaked material has not been independently verified.</p>
<p>That uncertainty is part of the tactic. Modern ransomware groups do not just rely on encryption or extortion notes. They use public claims and data leaks to create pressure, force attention, and shape the narrative before facts are fully known. Airports are particularly exposed to this kind of pressure because disruption, even perceived disruption, carries immediate reputational and operational weight.</p>
<p>Verified or not, once claims and files are public, the human impact starts straight away.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Pressure starts before proof</strong><span> </span>- Publishing claims and documents is designed to trigger panic and rushed decisions.</li>
<li>
<strong>Visibility increases impact</strong><span> </span>- Highly visible organisations feel the reputational damage faster, even when details are unclear.</li>
<li>
<strong>Pause is a defence</strong><span> </span>- Calm, verification, and controlled communication matter more than speed in moments like this.</li>
</ul>
<p></p>
<h3>Your phone can be tracked without your permission, and most people do not realise it</h3>
<p><a href="https://youtu.be/joGd0M8Fw8o?t=1350" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://fumics.in/posts/2026-02-01-phone-gps-carrier-tracking" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p>Most people think they understand how location tracking works. If an app does not have permission, or GPS is turned off, they assume their phone is no longer sharing where they are. This story shows that is not how it actually works.</p>
<p>Mobile networks can locate phones at the carrier level using systems originally built for emergency services. This sits below iOS and Android, which means your phone never asks you, and you never see it happening. It is not malware and it is not a bug. It is how mobile infrastructure has worked for years.</p>
<p>When we talked about this on the podcast, the bit that really landed was how normal this feels once you realise it has been there the whole time. The technology did not change. Our assumptions did.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Permissions feel reassuring</strong><span> </span>- Turning things off gives a sense of control, even when it does not change the outcome.</li>
<li>
<strong>The real risk is invisible</strong><span> </span>- Tracking can happen below apps and operating systems people interact with.</li>
<li>
<strong>Assumptions shape behaviour</strong><span> </span>- When beliefs are wrong, people take risks without realising it.</li>
</ul>



























































<h2>This Week's Discussion Points...</h2>
<p><strong>Notepad++ supply chain attack</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=123" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://cybernews.com/security/state-sponsored-hackers-behind-notepad-plus-plus-hack/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Ransomware group claims access to airport systems</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=453" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.techradar.com/pro/security/russian-ransomware-hackers-allegedly-hit-tulsa-airport-in-cyberattack-dump-private-files-online-as-proof" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>FBI seizes RAMP hacking forum</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=583" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.itpro.com/security/cyber-crime/the-fbi-has-seized-the-ramp-hacking-forum-but-will-the-takedown-stick-history-tells-us-otherwise" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Lawsuit claims WhatsApp encryption is a lie</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=736" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://9to5mac.com/2026/02/03/lawsuit-claims-whatsapp-encryption-is-a-lie-cryptography-professor-weighs-in/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Spain announces social media ban for under 16s</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=974" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.abc.net.au/news/2026-02-03/social-media-ban-spain/106302026" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Your phone can be tracked without your permission</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=1350" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://fumics.in/posts/2026-02-01-phone-gps-carrier-tracking" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Scattered Lapsus ShinyHunters extortion tactics</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=1608" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://krebsonsecurity.com/2026/02/please-dont-feed-the-scattered-lapsus-shiny-hunters/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Ransomware attacks up 30 percent</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=1810" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://thecyberexpress.com/ransomware-attacks-soar-30-percent/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Ant's mum targeted by follow up scam call</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=2060" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<p><strong>McDonald’s calling out weak passwords</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=2206" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://www.theregister.com/2026/02/02/mcdonalds_password_advice/" target="_blank" rel="noopener">Read</a></p>
<p><strong>Getting your first job in cybersecurity</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=2552" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://shehackspurple.ca/2025/11/21/how-to-get-your-first-job-in-cybersecurity/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p><strong>Real or phishing, shockingly bad campaign emails</strong><span> </span><a href="https://youtu.be/joGd0M8Fw8o?t=2810" target="_blank" rel="noopener"><strong>Watch</strong></a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRDcrjUP/" target="_blank" rel="noopener"><strong>Read</strong></a></p>





























<h2>And finally...McDonald’s calling out weak passwords, and it lands because it’s honest</h2>

























<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/LO9bLElIwHlTgJ1zbjfEOZN73ZoMozeKaQLy7Yke.png" width="540" onerror="this.style.display='none'"></span>






















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" target="_blank" rel="noopener"></a></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" target="_blank" rel="noopener"></a><a href="https://youtu.be/fuG0UsphrS8?t=1600" target="_blank" rel="noopener"><strong></strong></a><a href="https://youtu.be/XpjyRa2W0m0?t=2834" target="_blank" rel="noopener">Watch</a></p>
<p>McDonald’s Netherlands used Change Your Password Day to highlight something security teams have been saying for years. People choose passwords based on things they like, recognise, or can remember. BigMac, HappyMeal, McNuggets, and endless variations of them showed up tens of thousands of times in breached password data.</p>
<p>As we said on the show, this works because it doesn’t pretend people are suddenly going to behave like security professionals. It accepts reality and designs around it.</p>
<p>Predictability is the real problem. Swapping letters for numbers or adding a symbol feels clever, but attackers expect it. Tools try those combinations automatically. The habit hasn’t changed, even though the threat has.</p>
<p>What’s interesting is how transferable this idea is. Almost any organisation could do a version of this with their own language, products, acronyms, or in jokes. When people see themselves reflected in the message, it lands very differently.</p>
<p><strong>The Awareness Angle</strong></p>
<ul>
<li>
<strong>Familiar beats secure</strong><span> </span>- People choose passwords that feel personal and memorable, not resilient.</li>
<li>
<strong>Old advice lingers</strong><span> </span>- Leetspeak and small tweaks still feel protective, even though they stopped working years ago.</li>
<li>
<strong>Make it local</strong><span> </span>- Campaigns are more effective when people recognise their own habits and language in the message.</li>
</ul>
<p>Would you try this in your organisation?  Let us know by getting in touch at<span> </span>hello@riskycreative.com</p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/205459?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/205459?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F205459%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F205459%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_203508">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/203508/watch_times"
  data-youtube-player-video-id-value="Knl7yOkWRwo"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/Knl7yOkWRwo/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/203508">
          Feb 2, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/203508">
             From Dating App Leaks to AI Agent Risks
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on<span class="white-space-pre"> </span><strong>The Awareness Angle</strong>, we cover hundreds of exposed Clawdbot and Moltbot AI agent gateways leaking credentials and private chats, a new malware service selling guaranteed phishing extensions through the Chrome Web Store, and sensitive government documents uploaded to ChatGPT by the acting head of the US cybersecurity agency.</p>
<p class="ember-view reader-text-block__paragraph">We also look at Google rolling out stronger ransomware protections in Drive, France accelerating plans to ban social media for under 15s, and what recent incidents involving AI powered toys reveal about data exposure risks for children.</p>
<p class="ember-view reader-text-block__paragraph">All of that, and more, in this week’s episode of<span class="white-space-pre"> </span><strong>The Awareness Angle</strong>.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle is best served in full. Watch on YouTube, or listen on Spotify or your favourite podcast platform to get the complete discussion and context.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Support the show with all new Awareness Angle merch. Stickers, notebooks, mugs, and bits that quietly say you care about people, not just passwords. Click<span class="white-space-pre"> </span></strong><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://riskycreative.com/en-gbp/collections/all" target="_blank" rel="noopener"><strong>here</strong></a><strong><span class="white-space-pre"> </span>to visit the shop.</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQGpU2i5wxd5_A/article-inline_image-shrink_1000_1488/B4EZwbaaCxJ4AU-/0/1769986434411?e=1771459200&amp;v=beta&amp;t=RMM6hxNqdHqHc4WywELWg_gUCKjGT6LxfoX1btVysQI" onerror="this.style.display='none'"></span>Just some of the exciting new merchadise you can buy!</p>
<h2 class="ember-view reader-text-block__heading-2">This week's stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Hundreds of exposed Clawdbot gateways leave credentials and private chats exposed</h3>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=782" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://cybersecuritynews.com/clawdbot-chats-exposed/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Security researchers have identified more than 900 exposed Clawdbot gateways online, caused by poor setup and insecure default settings. These exposed systems allowed access to private conversations, API keys, and other sensitive information.</p>
<p class="ember-view reader-text-block__paragraph">Clawdbot, also known as Moltbot, is an AI agent designed to make work easier by remembering information and acting on a user’s behalf inside messaging apps. Because it runs continuously and stores context over time, mistakes in setup can quietly expose far more than people realise.</p>
<p class="ember-view reader-text-block__paragraph">Incidents like this often happen without malicious intent. Tools are adopted quickly to save time, experiments move into daily use, and security steps are skipped under pressure. The result is exposure created by normal human behaviour, not bad actors.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>People prioritise speed and convenience</strong><span class="white-space-pre"> </span>– Security steps are often skipped to get work done</li>
<li>
<strong>Assumptions replace checks</strong><span class="white-space-pre"> </span>– If a tool feels helpful and familiar, risk is easily overlooked</li>
<li>
<strong>Psychological safety matters</strong><span class="white-space-pre"> </span>– People need to feel safe admitting mistakes before exposure grows</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">New malware service pushes phishing extensions into the Chrome Web Store</h3>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=1173" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.bleepingcomputer.com/news/security/new-malware-service-guarantees-phishing-extensions-on-chrome-web-store/" target="_blank" rel="noopener"><strong>Read</strong></a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Researchers have uncovered a new malware service called Stanley that allows criminals to create phishing browser extensions and successfully publish them to the Chrome Web Store. These extensions are designed to overlay legitimate websites with fake content while keeping the real web address visible, making them difficult to spot.</p>
<p class="ember-view reader-text-block__paragraph">The service is sold in tiers, offering features such as silent installation, custom branding, and a management panel for attackers. Because the extensions pass official store checks, users are more likely to trust them, install them, and continue using them without suspicion.</p>
<p class="ember-view reader-text-block__paragraph">This type of attack relies less on technical exploitation and more on habit. People install extensions to save time, solve small problems, or boost productivity, often without revisiting what access those extensions still have later on.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Trust is built on familiarity</strong><span class="white-space-pre"> </span>– Official stores and recognisable browsers lower people’s guard</li>
<li>
<strong>Convenience drives behaviour</strong><span class="white-space-pre"> </span>– Small productivity gains can outweigh perceived risk</li>
<li>
<strong>Unused access is rarely questioned</strong><span class="white-space-pre"> </span>– Extensions often stay installed long after they are needed</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">France moves to fast track a social media ban for under 15s</h3>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=1824" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://edition.cnn.com/2026/01/25/europe/macron-france-under-15-social-media-ban-intl" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">France has announced plans to fast track a ban on social media use for children under 15, with the aim of having new rules in place before the next school year. The proposal includes stricter age verification and builds on existing restrictions around mobile phone use in schools.</p>
<p class="ember-view reader-text-block__paragraph">The move follows similar action in Australia, where millions of under 16 social media accounts have already been removed. French officials have acknowledged that age limits can be bypassed, but see this as an important first step in reducing exposure to online harm and emotional manipulation.</p>
<p class="ember-view reader-text-block__paragraph">Rather than focusing on individual behaviour, the approach shifts responsibility toward platforms and regulation, recognising that expecting children to self regulate in highly persuasive online environments has not worked.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Children are not the problem</strong><span class="white-space-pre"> </span>– Platforms are designed to capture attention, not protect wellbeing</li>
<li>
<strong>Rules fill the gaps left by design</strong><span class="white-space-pre"> </span>– Regulation steps in where controls and safeguards fall short</li>
<li>
<strong>Adults set the environment</strong><span class="white-space-pre"> </span>– Safety improves when responsibility moves away from the user</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">US cybersecurity chief uploaded sensitive government documents to ChatGPT</h3>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=413" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://techcrunch.com/2026/01/28/trumps-acting-cybersecurity-chief-uploaded-sensitive-government-docs-to-chatgpt/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The acting head of Cybersecurity and Infrastructure Security Agency uploaded internal government documents marked “for official use only” into ChatGPT. The uploads triggered automated warnings, and an internal review is now assessing any potential impact.</p>
<p class="ember-view reader-text-block__paragraph">The documents were described as internal but unclassified, and the use of ChatGPT was said to be short term and previously approved as an exception. Following the incident, multiple staff members were suspended from accessing classified systems while investigations continue.</p>
<p class="ember-view reader-text-block__paragraph">The story highlights how quickly everyday tools can blur boundaries at work, especially when people are under pressure to move fast or solve problems efficiently.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>People default to familiar tools</strong><span class="white-space-pre"> </span>– Convenience often overrides caution</li>
<li>
<strong>Exceptions create confusion</strong><span class="white-space-pre"> </span>– One off permissions weaken shared understanding of risk</li>
<li>
<strong>Hierarchy does not prevent mistakes</strong><span class="white-space-pre"> </span>– Senior roles are not immune to everyday human error</li>
</ul>
<p></p>
<h2 class="ember-view reader-text-block__heading-2">Discussion Points...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>ShinyHunters swipes right on 10M records in alleged dating app data grab</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=71" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.theregister.com/2026/01/29/shinyhunters_match_group" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>US cybersecurity chief uploaded sensitive documents to ChatGPT</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=412" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://techcrunch.com/2026/01/28/trumps-acting-cybersecurity-chief-uploaded-sensitive-government-docs-to-chatgpt/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>What is Clawdbot and why it matters</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=628" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://socradar.io/blog/clawdbot-is-it-safe/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Hundreds of exposed Clawdbot gateways leave data vulnerable</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=782" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://cybersecuritynews.com/clawdbot-chats-exposed/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>The AI agent craze is turning into a security nightmare</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=978" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.techbrew.com/stories/2026/01/29/moltbot-agentic-ai-security-privacy" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Phishing malware sold as Chrome extensions</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=1173" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.bleepingcomputer.com/news/security/new-malware-service-guarantees-phishing-extensions-on-chrome-web-store/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Google Drive adds better ransomware protection</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=1520" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://tech.yahoo.com/ai/gemini/articles/google-drive-getting-better-protection-191341072.html" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>France moves to ban social media for under 15s</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=1812" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://edition.cnn.com/2026/01/25/europe/macron-france-under-15-social-media-ban-intl" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Exposed admin panel found in AI toy</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=2121" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://thecyberexpress.com/security-researcher-finds-ai-toy-admin-panel/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness, spotting phishing and AI content</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=2611" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.bbc.co.uk/news/videos/cn82p0dgwv5o" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Misleading breach headlines and fake panic</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=2985" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.reddit.com/r/GMail/s/T0NkHX4RIE" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Reverse image search exposing fake profiles</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3099" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.reddit.com/r/isthisAI/s/qqyWrMrpJU" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Gift card scam warnings appearing in stores</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3186" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.linkedin.com/posts/robertconnor-cybersecurityspecialist_cybersecurity-fraudawareness-businessrisk-activity-7418996137233113088-6LW_" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Covering phone cameras as a security habit</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3271" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.reddit.com/r/security/comments/1qp5okt/why/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Free WiFi on flight QR code prank</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3372" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://vm.tiktok.com/ZNRSaHKQT/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>TikTok Argos MacBook discount scam</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3477" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://vm.tiktok.com/ZNRAqayQ4/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Real world phishing and family account compromise</strong><span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3636" target="_blank" rel="noopener"><strong>Watch</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">And finally...This Week I Messed Up!<span class="white-space-pre"> </span>
</h2>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQElTd-kDLx2fw/article-inline_image-shrink_1000_1488/B4EZwbdx8nKwAQ-/0/1769987321711?e=1771459200&amp;v=beta&amp;t=278wi6Wsu1B0lRy7qG5Pm8lmj3rxEhGbaW0qWrn5msQ" onerror="this.style.display='none'"></span>I messed up and didn't protect those closest to me!</p>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://youtu.be/Knl7yOkWRwo?t=3640" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">This week, the story that hit closest to home wasn’t a breach headline or an AI scare. It was my mum.</p>
<p class="ember-view reader-text-block__paragraph">Her email account was compromised, no two factor authentication, a password she’d used for years, and attackers quietly sending gift card scam emails to people she trusts. I only spotted it once messages started disappearing from her inbox.</p>
<p class="ember-view reader-text-block__paragraph">When I got proper access, the reason was obvious. The attackers had set up inbox rules to automatically mark messages as read, move them into hidden folders, and silently redirect copies to a Gmail account they controlled. From the outside, everything looked normal.</p>
<p class="ember-view reader-text-block__paragraph">I spend my life talking about security awareness, and I still hadn’t locked down the person closest to me.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Inbox rules are a red flag</strong><span class="white-space-pre"> </span>– attackers often use filters and redirects to hide their activity and stay undetected</li>
<li>
<strong>No 2FA is still a big risk</strong><span class="white-space-pre"> </span>– even “quiet” email compromises can run for days without being noticed</li>
<li>
<strong>Check your family, not just your workplace</strong><span class="white-space-pre"> </span>– the people closest to you are often the least protected</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">It’s a reminder that security isn’t just an organisational problem. It’s personal. Take five minutes this week to check in on someone you care about.</p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="uzjjmrpxQeFebnMdUxptiDBQagtayOyxaRvLs " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/203508?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/203508?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F203508%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F203508%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_200933">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/200933/watch_times"
  data-youtube-player-video-id-value="XpjyRa2W0m0"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/XpjyRa2W0m0/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/200933">
          Jan 26, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/200933">
            Voice Phishing Kits, CrashFix Malware, and Schools Forced Offline
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, we cover a ransomware attack at Ingram Micro that disrupted a major part of the global IT supply chain, alongside a breach at Grubhub where customer, driver, and merchant data was accessed through a third party support system. We also look at a data breach at the Minnesota Department of Human Services affecting nearly 304,000 people, and a UK secondary school forced to close after a cyber attack knocked critical systems offline.</p>
<p class="ember-view reader-text-block__paragraph">In the news, Microsoft issued emergency out of band Windows updates after Patch Tuesday caused shutdown and Cloud PC issues, while researchers uncovered malicious browser extensions designed to crash browsers and push fake fixes. We also discuss reports of criminals selling ready made voice phishing kits, a new EU vulnerability database launched as an alternative to CVE, and a phishing campaign targeting LastPass users with fake security alerts.</p>
<p class="ember-view reader-text-block__paragraph">We round out the episode with policy and platform updates, including the UK government consulting on banning social media for under 16s, and TikTok finalising a deal to split its US operations into a new joint venture.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle is best served in full. Watch on YouTube, or listen on Spotify or your favourite podcast platform to get the complete discussion and context.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_blank" rel="noopener"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_blank" rel="noopener"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_blank" rel="noopener"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="http://riskycreative.com/" target="_blank" rel="noopener"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Support the show with all new Awareness Angle merch. Stickers, notebooks, mugs, and bits that quietly say you care about people, not just passwords.</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQHcPIpEgIaUSg/article-inline_image-shrink_1500_2232/B4EZvz9hLGJAAU-/0/1769324550119?e=1770854400&amp;v=beta&amp;t=rZxSSQ429Mr_rPBglEg55koLXfcnGRPdJ-GcawYKSpU" onerror="this.style.display='none'"></span>Just some of the stuff you can buy!</p>
<h2 class="ember-view reader-text-block__heading-2">This week's stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Voice phishing kits sold as a service</h3>
<p class="ember-view reader-text-block__paragraph"><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1105" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.theregister.com/2026/01/22/crims_sell_voice_phishing_kits/?&amp;web_view=true" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Cybercriminals are now selling ready made voice phishing kits that let almost anyone run convincing phone scams. These kits bundle scripts, call flows, dashboards, and in some cases AI generated voices that sound like banks or internal IT teams. This is not someone freelancing a scam call. This is packaged, repeatable, and designed to scale.</p>
<p class="ember-view reader-text-block__paragraph">The kits guide attackers through the entire interaction. Who to call. What to say. When to apply pressure. Victims are coached into handing over credentials, one time passcodes, or approving actions that lead to account access. It is phishing, just delivered over the phone instead of email.</p>
<p class="ember-view reader-text-block__paragraph">The problem is that phone calls still get a free pass. Many organisations have trained people to be cautious with links and emails, but far fewer have clear rules for handling unexpected calls. Attackers are leaning into that gap hard.</p>
<p class="ember-view reader-text-block__paragraph">This is social engineering getting easier and more normal. And it is aimed squarely at busy humans.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Vishing is now off the shelf</strong><span class="white-space-pre"> </span>– Anyone can buy the tooling</li>
<li>
<strong>Calls still bypass suspicion</strong><span class="white-space-pre"> </span>– The channel carries trust</li>
<li>
<strong>Call back breaks the scam</strong><span class="white-space-pre"> </span>– Verification beats confidence</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">CrashFix browser attacks push fake fixes</h3>
<p class="ember-view reader-text-block__paragraph"><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1355" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.securityweek.com/malicious-chrome-extension-crashes-browser-in-clickfix-variant-crashfix/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">CrashFix is a browser based attack where a malicious extension deliberately crashes the browser, then tells the user they need to install a fix. That fix is malware. Nothing is broken. The crash is the whole point.</p>
<p class="ember-view reader-text-block__paragraph">After the browser fails, users are shown clear, step by step instructions telling them what to do next. Run this. Install that. It works because this is exactly how people normally deal with software problems. Get it working and carry on.</p>
<p class="ember-view reader-text-block__paragraph">This is not a clever technical exploit. It is frustration as a delivery mechanism. When something breaks, people stop thinking about risk and start thinking about recovery. CrashFix is designed to catch people in that moment.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>The crash is intentional</strong><span class="white-space-pre"> </span>– Failure is the lure</li>
<li>
<strong>Fixing mode bypasses caution</strong><span class="white-space-pre"> </span>– Urgency beats scepticism</li>
<li>
<strong>Running commands is a red flag</strong><span class="white-space-pre"> </span>– Pause before you actWatch | Read</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">UK secondary school forced to close after cyber attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=676" target="_blank" rel="noopener"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.theregister.com/2026/01/19/higham_lane_school_reopens/" target="_blank" rel="noopener"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A secondary school in England was forced to close after a cyber attack took out its IT systems. There was no big data breach story and no suggestion that grades were tampered with. The school closed because it could not function safely without its systems.</p>
<p class="ember-view reader-text-block__paragraph">Security, made human.Too much failed at once. Attendance, communications, access control, and safety related systems were all affected. That only happens when everything is tied together. Systems that should be dull, isolated, and resilient were clearly part of the same environment, so when one thing went down, everything followed.</p>
<p class="ember-view reader-text-block__paragraph">This is what happens when convenience drives design. Things get connected because it is easier, cheaper, or sold as “modern”, not because it makes sense. Then something breaks, and suddenly the impact is far bigger than anyone expected.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Not everything should be connected</strong><span class="white-space-pre"> </span>– Convenience quietly increases risk</li>
<li>
<strong>Availability is a safety issue</strong><span class="white-space-pre"> </span>– Offline systems force closure</li>
<li>
<strong>Design decisions matter</strong><span class="white-space-pre"> </span>– Architecture shapes impact</li>
</ul>
<p></p>
<h3 class="ember-view reader-text-block__heading-3">This week's discussion points...</h3>
<p class="ember-view reader-text-block__paragraph"><strong>Ingram Micro ransomware attack knocks global IT supply chain offline</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=85" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.theregister.com/2026/01/19/ingram_micro_ransomware_affects/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Grubhub breach exposes customer, driver, and merchant data via third party support system</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=312" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.bleepingcomputer.com/news/security/grubhub-confirms-hackers-stole-data-in-recent-security-breach/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Minnesota Department of Human Services breach exposes demographic records of nearly 304,000 people</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=528" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://statescoop.com/minnesota-human-services-data-breach/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>UK secondary school forced to close after cyber attack disrupts systems</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=676" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.theregister.com/2026/01/19/higham_lane_school_reopens/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Microsoft releases emergency Windows updates after Cloud PCs fail to shut down properly</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1004" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-oob-windows-updates-to-fix-shutdown-cloud-pc-bugs/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Criminals are now selling ready made voice phishing kits</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1105" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.theregister.com/2026/01/22/crims_sell_voice_phishing_kits/?&amp;web_view=true" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Malicious Chrome extension crashes browsers to push fake “fix” in ClickFix variant</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1355" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.securityweek.com/malicious-chrome-extension-crashes-browser-in-clickfix-variant-crashfix/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>EU launches new vulnerability database as alternative to CVE</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1628" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://cybernews.com/security/eu-launches-cve-alternative-gcve-vulnerability-database/" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Phishing campaign targets LastPass users with fake security alerts</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=1847" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.darkreading.com/application-security/phishing-campaign-zeroes-lastpass-customers" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Government consults on banning social media for under-16s in the UK</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=2095" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.bbc.co.uk/news/articles/cgm4xpyxp7lo" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>TikTok seals deal to split US app into new joint venture, keeps platform running in America</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=2376" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.bbc.co.uk/news/articles/c3edd1l328lo" target="_blank" rel="noopener">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>AI snowstorm videos show the current state of the internet</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://vm.tiktok.com/ZNRBqJjKF/" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"><strong>Five ways to spot AI generated accounts on social media</strong><span class="white-space-pre"> </span>–<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://vm.tiktok.com/ZNRBVsTYT/" target="_blank" rel="noopener">Watch</a><span class="white-space-pre"> </span></p>
<h2 class="ember-view reader-text-block__heading-2">And finally...Action Fraud becomes “Report Fraud”, but the experience still breaks trust</h2>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEX1vU1IHExBA/article-inline_image-shrink_1000_1488/B4EZv0B3fhIEAQ-/0/1769325690478?e=1770854400&amp;v=beta&amp;t=z0Meot4HekOgbPmCzMwdlx0gq4Z2VjcoFZyGLynlcdE" onerror="this.style.display='none'"></span>Ant and Luke discuss Report Fraud's account issues</p>
<p class="ember-view reader-text-block__paragraph"><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://youtu.be/XpjyRa2W0m0?t=2834" target="_blank" rel="noopener">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">The UK’s fraud reporting service has been rebranded from Action Fraud to Report Fraud. The new name is clearer and does exactly what it says. The problem is what happens next.</p>
<p class="ember-view reader-text-block__paragraph">When users try to sign in or create an account, they are redirected to a completely different domain to complete the process. For some people, antivirus tools flag that page as suspicious or phishing. That puts users in an impossible position. They are doing the right thing by reporting fraud, and the experience immediately tells them not to trust it.</p>
<p class="ember-view reader-text-block__paragraph">This is how trust gets damaged. Not by attackers, but by confusing design. People are told to be cautious about links and domains, then asked to ignore their own instincts when it really matters. Many will simply abandon the report.</p>
<p class="ember-view reader-text-block__paragraph">If we want people to report scams and cybercrime, the process has to feel safe and consistent all the way through.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Trust is fragile</strong><span class="white-space-pre"> </span>– Mixed signals stop people acting</li>
<li>
<strong>Design shapes behaviour</strong><span class="white-space-pre"> </span>– Confusion leads to drop off</li>
<li>
<strong>Security advice must align</strong><span class="white-space-pre"> </span>– We cannot teach one thing and do another</li>
</ul>
<p></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="mailto:hello@riskycreative.com" target="_blank" rel="noopener"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.linkedin.com/in/infosecant/" target="_blank" rel="noopener"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.linkedin.com/in/lukejpme/" target="_blank" rel="noopener"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="kBgpcyXFNpkpsySUadbrgokwcBSJFTnFWYsOyo " href="https://www.linkedin.com/company/riskycreative/" target="_blank" rel="noopener"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/200933?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/200933?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F200933%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F200933%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame></template></turbo-stream>

<turbo-stream action="remove" target="posts_load_more"></turbo-stream>

  <turbo-stream action="append" target="posts_list"><template><turbo-frame id="posts_load_more">
  <a data-turbo-stream="true" data-controller="infinite-scroll" href="/supporters/load_more?last_id=200933&amp;last_live_at=2026-01-26T06%3A00%3A00.000%2B00%3A00&amp;order=desc"></a>
  <div class="loader">
  <svg class="loader__icon" viewBox="0 0 100 100">
    <circle class="loader__circle" cx="50" cy="50" r="45" />
  </svg>
</div>
</turbo-frame>
</template></turbo-stream>
