<turbo-stream action="append" target="posts_list"><template><turbo-frame class="main-list__list-item" data-testid="Post" id="post_235197">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/235197/watch_times"
  data-youtube-player-video-id-value="ECZyv2bXerw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/ECZyv2bXerw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/235197">
          May 25, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/235197">
            CISA Left Its Passwords on GitHub, Mac's Worst Malware Yet &amp; The Verizon DBIR Breakdown
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week CISA, the agency whose entire job is telling everyone else how to do cybersecurity, left admin passwords and AWS keys on a public GitHub repo for six months. The repo was called "Private-CISA." A new Mac stealer called Reaper fakes an Apple security update, grabs your password, and raids everything from your Keychain to your crypto wallets. And the 2026 Verizon DBIR landed with a stat every awareness pro needs to hear: people are 40% more likely to fall for phishing by phone or text than email.</p>
<p class="ember-view reader-text-block__paragraph">We've also got 7-Eleven breached by ShinyHunters, Portugal's postal service leaking real parcel tracking codes, Iran messing with fuel monitors at US petrol stations, and Discord encrypting your calls the same week they started asking for your government ID.</p>
<p class="ember-view reader-text-block__paragraph">All of that is in this weeks<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.linkedin.com/showcase/the-awareness-angle/" target="_self" data-turbo="false"><strong>The Awareness Angle</strong></a>!</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<p><a href="https://youtu.be/ECZyv2bXerw" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQHUGbKbI5FQJA/article-inline_image-shrink_1000_1488/B4EZ5PZ16NJAAI-/0/1779448636570?e=1781136000&amp;v=beta&amp;t=sm0FnGSamODq1NGdJ8ESLdgugCp88p65q1fpPaoAKXU" onerror="this.style.display='none'"></span></a>These faces move, if you click the image and go to YouTube!</p>
<h2 class="ember-view reader-text-block__heading-2">Last week on The Awareness Practitioners</h2>
<p>See content credentials<a href="https://youtu.be/scWsZqkwDYA" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQF_521D8iiRag/article-inline_image-shrink_1000_1488/B4EZ5PagJzHEAI-/0/1779448811387?e=1781136000&amp;v=beta&amp;t=C0v1K7DMcrX1XrMU1JQolxEvg-ALPgEdKI5ImiQVxRE" onerror="this.style.display='none'"></span></a>Ant talks about his desires....</p>
<p class="ember-view reader-text-block__paragraph">Last week on The Awareness Practitioners, Ant went down a rabbit hole about desire paths.</p>
<p class="ember-view reader-text-block__paragraph">You know those unofficial shortcuts people wear into grass verges because the official path goes the wrong way? Turns out they're one of the most useful frameworks a security awareness practitioner can borrow. What happens when you follow where people actually go, instead of where you built the path?</p>
<p class="ember-view reader-text-block__paragraph">Listen on<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://open.spotify.com/show/5iIhhaowyeehumATDBuX1U?si=0aaa85f4fdfd4f67" target="_self" data-turbo="false">Spotify</a>,<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://podcasts.apple.com/gb/podcast/the-awareness-practitioners/id1896365782" target="_self" data-turbo="false">Apple Podcasts</a>, and<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/scWsZqkwDYA" target="_self" data-turbo="false">YouTube</a>.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>CISA Left Its Passwords on Public GitHub</strong></p>
<p class="ember-view reader-text-block__paragraph"><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="http://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330" target="_self" data-turbo="false">gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330</a></p>
<p class="ember-view reader-text-block__paragraph">The US Cybersecurity and Infrastructure Security Agency, the actual federal body whose entire job is telling everyone else how to do cybersecurity, has been leaving the keys to its own systems sitting in a public GitHub repo for up to six months. The repo was called "Private-CISA", which somehow makes it worse.</p>
<p class="ember-view reader-text-block__paragraph">Inside it, researchers found a file literally named "importantAWStokens" containing admin credentials for three Amazon cloud servers used by the US government. Another file, helpfully labelled "AWS-Workspace-Firefox-Passwords.csv", listed dozens of internal usernames and passwords in plain text.</p>
<p class="ember-view reader-text-block__paragraph">The cause appears to be staggeringly mundane. A contractor working for a firm called Nightwing seems to have been using GitHub as a way to shuffle files between their work and home machine. Think of it as the digital equivalent of leaving a USB stick on the bus, except the bus is the entire internet. GitGuardian, the security firm that found it, had tried to alert the account holder nine times before going public. Their researcher Guillaume Valadon called it the worst leak he had ever seen in his career.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles:</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Nobody is immune, not even the experts</strong><span class="white-space-pre"> </span>- CISA publishes guidance on exactly this kind of thing. And it still happened. The lesson isn't to mock them, it's that controls matter more than awareness alone, because awareness clearly didn't save anyone here.</p>
<p class="ember-view reader-text-block__paragraph"><strong>If the sanctioned way is hard, people will invent shortcuts</strong><span class="white-space-pre"> </span>- The contractor wasn't malicious, they were just trying to move a file. If your organisation doesn't make safe file transfer easy and accessible, people will find their own way. Every time.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Public code repositories are constantly being scanned</strong><span class="white-space-pre"> </span>- The bad guys have the same scanning tools as the security researchers. Once a password or key touches a public repo, treat it as compromised and change it immediately. There is no "we deleted it quickly" defence anymore.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Reaper: The macOS Stealer That Fakes an Apple Security Update</strong></p>
<p class="ember-view reader-text-block__paragraph"><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="http://theregister.com/security/2026/05/19/do-fear-the-reaper-stealer-swipes-macos-users-passwords-wallets-then-backdoors-them/5242258" target="_self" data-turbo="false">theregister.com/security/2026/05/19/do-fear-the-reaper-stealer-swipes-macos-users-passwords-wallets-then-backdoors-them/5242258</a></p>
<p class="ember-view reader-text-block__paragraph">A new piece of malware targeting Mac users called Reaper is doing the rounds and it is a bold piece of work. It impersonates Apple, Microsoft and Google all in the same attack, shifting its disguise at every stage.</p>
<p class="ember-view reader-text-block__paragraph">It starts with fake installer websites for apps like WeChat and Miro, hosted on a web address that looks like Microsoft but swaps a lowercase L for the letter i. So "mlcrosoft" instead of "microsoft". Easy to miss, especially on a phone. The user clicks what looks like a legitimate installer and a popup appears pretending to be an Apple security update, asking them to type in their Mac login password.</p>
<p class="ember-view reader-text-block__paragraph">Once that password is handed over, Reaper goes shopping. It grabs data from password managers, web browsers, the Mac Keychain, iCloud, Telegram and specifically cryptocurrency wallets. It then injects itself into those wallet apps so future theft keeps happening automatically. It also hunts through your Desktop and Documents folders looking for anything that looks like a business or financial file, and sets up a backdoor disguised as "Google Software Update" that phones home every sixty seconds waiting for instructions.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles:</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Mac users are not immune, and Reaper proves it</strong><span class="white-space-pre"> </span>- The old "I use a Mac so I don't get malware" line has been wrong for a while now. Mac users need the same level of awareness training that Windows users have always needed.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Look at the URL, every single time</strong><span class="white-space-pre"> </span>- mlcrosoft[.]co[.]com (We add the square brackets to break the link) looks normal at a glance, especially on a small screen. A lowercase L where an I should be is one of the oldest tricks going. Always go to the official source by typing it yourself or using a bookmark.</p>
<p class="ember-view reader-text-block__paragraph"><strong>A popup asking for your password is the moment to stop</strong><span class="white-space-pre"> </span>- Real macOS security updates do not ask for your login through random dialogue boxes. If a popup asks for your password and you cannot immediately explain why, close it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The 2026 Verizon Data Breach Investigations Report Is Here</strong></p>
<p class="ember-view reader-text-block__paragraph"><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="http://verizon.com/business/resources/reports/dbir/" target="_self" data-turbo="false">verizon.com/business/resources/reports/dbir/</a></p>
<p class="ember-view reader-text-block__paragraph">The annual Verizon DBIR landed this week with its biggest ever dataset: 22,000 confirmed breaches analysed across 145 countries. If you work in security awareness, this is the report you will be quoting for the next twelve months.</p>
<p class="ember-view reader-text-block__paragraph">The headline finding is that exploiting vulnerabilities in systems has overtaken stolen passwords as the number one way attackers break in, accounting for 31% of breaches. That is a 55% jump in a single year. And while attackers are getting faster, the defenders are going backwards. Only a quarter of known critical vulnerabilities were fully patched last year, down from 38% the year before, and the median time to fix one went from 32 days to 43 days. Organisations are drowning in patches and running out of hours in the day.</p>
<p class="ember-view reader-text-block__paragraph">Ransomware is still in nearly half of all breaches but the economics are shifting. The average payment is down to under $140,000 and 69% of victims now refuse to pay, just like 7-Eleven did this week. Third-party breaches are the bigger worry though. Breaches involving a supplier, vendor or partner grew 60% year on year and now account for nearly half of all incidents. The ShinyHunters Salesforce campaign we have been covering for weeks is exactly this category in action.</p>
<p class="ember-view reader-text-block__paragraph">On the human side, the big finding is not that people click phishing links. We already knew that. The big finding is that they click 40% more often when the attack arrives by text message or phone call instead of email. Someone actually calling you up, building rapport, pretending to be from IT or your bank and steering you toward a bad decision is now so common that Verizon has added it as its own category.</p>
<p class="ember-view reader-text-block__paragraph">And then there is the AI section. Two thirds of employees are using AI tools on work devices with accounts their company does not control. Nearly half are regular AI users, up from 15% the year before. And some of them are uploading proprietary research and technical documents into those tools. The shadow IT problem has a new face, and it is wearing a chatbot.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles:</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Phishing training that only covers email is training for the wrong attack</strong><span class="white-space-pre"> </span>- Voice and text phishing is 40% more effective than email, and email is what the vast majority of training programmes focus on. People need to be just as suspicious of a phone call as they are of an inbox.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Your security is now your suppliers' security</strong><span class="white-space-pre"> </span>- Third-party breaches grew 60% in a year. Every vendor, integration and SaaS platform your organisation uses is part of your attack surface.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Shadow AI is shadow IT with extra data leakage</strong><span class="white-space-pre"> </span>- Two thirds of your users are pasting work data into AI tools you don't control. The answer isn't to ban AI, it's to give people a safe and approved way to use it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>69% of ransomware victims now refuse to pay</strong><span class="white-space-pre"> </span>- That is a genuine win for the defender community. The more public refusals there are, the easier it becomes for the next victim to say no. Worth celebrating and worth sharing.</p>
<h2 class="ember-view reader-text-block__heading-2">Discussion points</h2>
<p class="ember-view reader-text-block__paragraph">All stories discussed on this week's episode:</p>
<p class="ember-view reader-text-block__paragraph">7-Eleven confirms data breach claimed by ShinyHunters -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=90" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.bleepingcomputer.com/news/security/7-eleven-confirms-data-breach-claimed-by-the-shinyhunters-gang/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">468K records leaked from Portugal's national postal service -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=260" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.theregister.com/cyber-crime/2026/05/19/468k-records-allegedly-stolen-from-portugals-postal-carrier/5242457" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">CISA left its keys on public GitHub -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=432" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Iran-linked attacks on US petrol stations -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=752" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://decipher.sc/2026/05/19/data-shows-thousands-of-automatic-tank-gauges-exposed-across-the-us/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Reaper, the macOS stealer faking Apple updates -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=1074" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.theregister.com/security/2026/05/19/do-fear-the-reaper-stealer-swipes-macos-users-passwords-wallets-then-backdoors-them/5242258" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Discord enables end-to-end encryption for all calls -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=1363" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.bleepingcomputer.com/news/security/discord-rolls-out-end-to-end-encryption-on-voice-video-calls/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">The 2026 Verizon DBIR -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=1621" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.verizon.com/business/resources/reports/dbir/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Security Social: Face unlock biometric hack -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2070" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.linkedin.com/posts/bobmckayuk_infosec-cyber-biometrics-share-7462252684428025857-jDdx" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Security Social: Keshipon privacy roller -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2202" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.tiktok.com/@bungustore/video/7641704402851548447" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Security Social: Google IO and SynthID -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2436" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Security Social: Luke's HMRC robocall scam -<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2779" target="_self" data-turbo="false">Watch</a></p>
<h2 class="ember-view reader-text-block__heading-2">Security Socials</h2>
<p class="ember-view reader-text-block__paragraph"><strong>The teenage biometric hack</strong></p>
<p class="ember-view reader-text-block__paragraph">A dad on LinkedIn shared how his daughter deliberately registered her Face ID while pulling a weird face, so that if someone steals her phone or holds it up to her face while she's unconscious, it won't unlock. Does it actually work with the way facial geometry mapping works? Debatable. But kids are thinking about security in ways most adults aren't, and they're sharing these tricks with each other on the playground. Multi-face authentication might not be a thing yet, but the instinct behind it is spot on.<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2070" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.linkedin.com/posts/bobmckayuk_infosec-cyber-biometrics-share-7462252684428025857-jDdx" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>The Keshipon privacy roller</strong></p>
<p class="ember-view reader-text-block__paragraph">If you've ever tried to scribble out your name and address on a parcel before putting it in the recycling, this one's for you. The Keshipon is a Japanese roller that stamps a dense mesh of random characters over printed text, making it unreadable. It's analogue security at its finest and arguably more secure than just crossing something out with a pen, because overlapping random characters are harder to reconstruct than simple scribble lines. Available in the UK for about fifteen quid if you're interested.<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2202" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://www.tiktok.com/@bungustore/video/7641704402851548447" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Google IO and the AI watermark that's actually spreading</strong></p>
<p class="ember-view reader-text-block__paragraph">Since we recorded this episode, the SynthID story has moved on significantly. We discussed Google's invisible watermark system for AI-generated content and flagged the obvious problem: it only works if everyone agrees to play by the same rules. Well, it turns out OpenAI announced the same week that they're partnering with Google to embed SynthID watermarks into all images generated by ChatGPT. ElevenLabs and Kakao have signed on as well. Google has also rolled SynthID detection into Google Search and Chrome, so you'll be able to check whether an image is AI-generated right where you're actually looking at it rather than having to upload it somewhere else. It's still not a complete solution because open source models trained outside these partnerships will keep producing unlabelled content, but it's a much bigger step than it was when we hit record.<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2436" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Luke's HMRC robocall</strong></p>
<p class="ember-view reader-text-block__paragraph">Luke's phone screened a scam call this week claiming to be from HMRC threatening legal action over unreturned documentation. The giveaway? An American robotic voice pretending to be the UK tax office. The call asked the recipient to press one to speak to an officer, which is a common setup for routing you through to a live scam call centre. Luke found Reddit posts from two years ago describing the exact same script, which means it's still running because it's still working on enough people to be worth the effort.<span class="white-space-pre"> </span><a class="XZPZLzCGVVGMitilJQkVPYnHodichWWrlDkCbMm " href="https://youtu.be/ECZyv2bXerw?t=2779" target="_self" data-turbo="false">Watch</a></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/235197?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/235197?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F235197%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F235197%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_234001">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/234001/watch_times"
  data-youtube-player-video-id-value="wJSxzylp1Gw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/wJSxzylp1Gw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/234001">
          May 18, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/234001">
            Fired on Teams Then Deleted 96 Databases, Fake Mustache Fools Age Verification &amp; AI Finds a Stoner's Bitcoin
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week twin brothers got fired on a Teams call, forgot it was still recording, and deleted 96 government databases while talking through the whole thing out loud. Kids are beating age verification by drawing on a mustache with a makeup pencil, and it's working. Google has confirmed for the first time that hackers used AI to find and exploit a zero-day in the wild. And a stoner who lost his Bitcoin password while high in 2015 just recovered $400,000 with help from AI and possibly the greatest password ever created.</p>
<p class="ember-view reader-text-block__paragraph">We've also got an update on the Canvas breach (Instructure paid ShinyHunters, nobody believes the data is gone), a telehealth breach that hit over 700,000 patients, a fake Claude Code installer catching developers through Google Ads, and a researcher who found that anyone who can read your Audi's VIN through the windscreen can add your car to their account.</p>
<p class="ember-view reader-text-block__paragraph">All of that is in this weeks<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/showcase/the-awareness-angle/" data-turbo="false">The Awareness Angle</a>!</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><a href="https://youtu.be/wJSxzylp1Gw" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQEk84RV-MESXg/article-inline_image-shrink_1000_1488/B4EZ41gO1QH8AI-/0/1779014103658?e=1780531200&amp;v=beta&amp;t=JIdskaiaWaHqv2G-rUzCbuBp0rCf2Z_-FEB9PUasCWs" onerror="this.style.display='none'"></span></a>Click above to watch those faces move on YouTube</p>
<p class="ember-view reader-text-block__paragraph"><span class="white-space-pre"> </span><br></p>
<h3 class="ember-view reader-text-block__heading-3">Introducing The Awareness Practitioners</h3>
<p class="ember-view reader-text-block__paragraph"><strong>A new podcast for the people making security human.</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQF47bZL651aQw/article-inline_image-shrink_1000_1488/B4EZ41gySJH8AM-/0/1779014248141?e=1780531200&amp;v=beta&amp;t=_MgMOAtr2y4OsRX_SCy-iww9rs5Do5nY9wz8fE5lYkU" onerror="this.style.display='none'"></span>Oli talks about his rapid career progression over just a few years</p>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Practitioners, I'm joined by<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/oli-inkley-7724981a3/" data-turbo="false">Oli Inkley</a>. Oli is a principal security awareness and culture lead at Marks and Spencer, and someone I've known for about four and a half years. I recruited him into his first awareness role, and since then he's built champions programmes across three major retailers.</p>
<p class="ember-view reader-text-block__paragraph">We talk about what it's actually like coming into this career from a completely different world. Oli started on the Waitrose shop floor. No security background, no technical qualifications. He talks about how he learned to hold conversations with engineers, why every organisation needs a different approach even when they look the same from the outside, and where the human side of this work matters more than any tool.</p>
<p class="ember-view reader-text-block__paragraph">If you're in the space, thinking about joining it, or wondering whether you need a technical background to do this job well, this one's worth 30 minutes of your time.</p>
<p class="ember-view reader-text-block__paragraph">Listen now on<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://open.spotify.com/show/5iIhhaowyeehumATDBuX1U?si=0aaa85f4fdfd4f67" target="_self" data-turbo="false"><strong>Spotify</strong></a>,<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://podcasts.apple.com/gb/podcast/the-awareness-practitioners/id1896365782" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a>, and<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/Xl44YlhEfFA" target="_self" data-turbo="false"><strong>YouTube</strong></a>.</p>
<h3 class="ember-view reader-text-block__heading-3">LIMITED AVAILABILITY - London Security Awareness Workshop</h3>
<p class="ember-view reader-text-block__paragraph"><strong>A free workshop for Awareness Pros on June 10th in London</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQFXtlgEf0H_xg/article-inline_image-shrink_1000_1488/B4EZ41iaLqIgAI-/0/1779014673369?e=1780531200&amp;v=beta&amp;t=cPCZEGb49GbalPlw9zug2grqPP-gt2_FJXdzfZIL1ZU" onerror="this.style.display='none'"></span></p>
<p class="ember-view reader-text-block__paragraph"><strong>Secure Culture Workshop - London, 10th June</strong></p>
<p class="ember-view reader-text-block__paragraph">If you work in security awareness and your Cybersecurity Awareness Month plan is still "send some phishing emails and hope for the best," this is for you. A small, practitioner-only session powered by the wonderful people at<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/company/hoxhunt/" data-turbo="false">Hoxhunt</a><span class="white-space-pre"> </span>. No vendor pitches, no panels, no PowerPoint. Just people who do this work every day sharing what actually works and walking out with a real plan for October.</p>
<p class="ember-view reader-text-block__paragraph">Join<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/maximecartier/" data-turbo="false">Maxime Cartier</a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/susannahaavisto/" data-turbo="false">Susanna Haavisto</a><span class="white-space-pre"> </span>and me in London on June 10th. There's only 50 places and we're already running low, so grab one while you can. We'll probably grab a drink after also!</p>
<p class="ember-view reader-text-block__paragraph">Click<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.secureculture.com/pages/workshop" target="_self" data-turbo="false">here</a><span class="white-space-pre"> </span>for more information and to register your interest.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">Twin Brothers Deleted 96 Government Databases While Still on a Recorded Teams Call</h3>
<p class="ember-view reader-text-block__paragraph"><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="http://www.arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/" target="_self" data-turbo="false">www.arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Twin brothers working for a federal IT contractor got fired on a Teams call after a background check turned up a prior felony conviction. One brother's access was cut immediately. The other had connected to the VPN ten minutes before the meeting and still had full access. While HR was wrapping up, he started deleting 96 government databases.</p>
<p class="ember-view reader-text-block__paragraph">The problem? They forgot the call was still recording. The entire conversation was captured, including "People are logged out for the day, this is the perfect time" and "Don't worry about it. You don't do nothing." As we discussed on the podcast, these aren't stupid people. They could write Python scripts and manage production databases, but they forgot to hang up. Both now face potentially decades in prison.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Access should end the second someone is fired</strong><span class="white-space-pre"> </span>- One brother connected to the VPN before the termination call even started and still had full access minutes after being told he was gone. Offboarding that doesn't include immediate access revocation across every system isn't offboarding at all. Send this story to your HR team and ask if this could happen where you work.</li>
<li>
<strong>Background checks are not optional for privileged access roles</strong><span class="white-space-pre"> </span>- Both brothers had prior federal convictions for computer fraud. They were hired anyway. If you're giving someone the keys to production databases, you need to know who you're handing them to.</li>
<li>
<strong>Everything on corporate platforms is evidence</strong><span class="white-space-pre"> </span>- The entire sabotage was captured because they stayed on a recorded Teams call. Anything said or done on a corporate platform can and will be used as evidence if things go wrong.</li>
</ul>
<p><br></p>
<h3 class="ember-view reader-text-block__heading-3">Kids Are Bypassing Age Verification With a Fake Mustache</h3>
<p class="ember-view reader-text-block__paragraph"><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="http://www.techcrunch.com/2026/05/06/some-kids-are-bypassing-age-verification-checks-with-a-fake-mustache/" target="_self" data-turbo="false">www.techcrunch.com/2026/05/06/some-kids-are-bypassing-age-verification-checks-with-a-fake-mustache/</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">UK nonprofit Internet Matters surveyed around 1,300 children aged 9 to 16, and the results are roughly what you'd expect if you've ever met a child. About half said age verification checks are easy to bypass, and roughly a third said they've already done it. Methods include drawing facial hair with a makeup pencil, pointing the camera at a video game character (Death Stranding came up again from a previous episode), pulling funny faces, using fake birthdates, and borrowing a parent's ID. Only 17% said they found it difficult.</p>
<p class="ember-view reader-text-block__paragraph">Ant had a great moment on the show where he admitted that when his son went through age verification on Roblox a few weeks ago, he genuinely thought "that's all right, they're checking his age." Even doing this every week, he fell for the sense of security it creates. That's the whole problem. Parents, regulators, and platforms all feel like the box has been ticked, while the kids it's supposed to protect are sharing workarounds at school. As Luke pointed out, they're not keeping it a secret. If one kid figures it out, the whole class knows by lunchtime.</p>
<p class="ember-view reader-text-block__paragraph">Countries including the UK, Australia, and 25 US states now have some form of age verification law in place. The question this raises is whether the entire approach needs rethinking, or whether we're just building an expensive, privacy-invasive system that gives adults a false sense of security.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Security theatre creates a false sense of protection</strong><span class="white-space-pre"> </span>- When the barrier looks real but is easily bypassed, the people relying on it believe the problem is solved. It isn't. The children know this. The adults often don't. If you work in security awareness, this is a useful parallel for any compliance exercise that's more about the checkbox than the outcome.</li>
<li>
<strong>Age verification collects real data from everyone</strong><span class="white-space-pre"> </span>- To prove you're old enough, you typically have to upload a government ID or let a camera scan your face. That's a huge amount of personal data being collected and stored by third-party verification companies, and every one of those databases is a breach target.</li>
<li>
<strong>Kids will always find the workaround</strong><span class="white-space-pre"> </span>- This has been true since the beginning of the internet. If a system relies on a child not being clever enough to beat it, that system is going to fail. The same principle applies at work. If your security controls assume people won't find a shortcut, they will.</li>
</ul>
<p><br></p>
<h3 class="ember-view reader-text-block__heading-3">Claude AI Recovers Stoner's $400K Bitcoin After 11-Year Search</h3>
<p class="ember-view reader-text-block__paragraph"><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="http://www.theregister.com/offbeat/2026/05/14/claude-reunites-stoner-with-bitcoin-after-losing-password/" target="_self" data-turbo="false">www.theregister.com/offbeat/2026/05/14/claude-reunites-stoner-with-bitcoin-after-losing-password/</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">A man bought 5 Bitcoin in 2015 at a Starbucks for around $1,250 total, changed the password while high, and then completely forgot what he'd set it to. He spent 11 years trying to recover access, including brute-forcing 3.5 trillion password combinations using btcrecover on rented GPU time. After finding an old mnemonic seed phrase in a college notebook, he dumped his entire old college computer into Claude as a last resort.</p>
<p class="ember-view reader-text-block__paragraph">Claude found an old wallet backup file from 2019 that predated the password change, spotted a bug in how btcrecover was combining the passwords and keys, and the mnemonic phrase was able to decrypt the backup. The password turned out to be "lol420fuckthePOLICE!*:)". As Ant said on the show, it does technically meet most password complexity requirements. It's got uppercase, lowercase, numbers, special characters. Just maybe don't set it while you're stoned.</p>
<p class="ember-view reader-text-block__paragraph">To be clear, and Ant was very keen to stress this on the show, Claude didn't crack Bitcoin encryption. It didn't break any cryptography. What it did was sort through a messy archive of old files, find a forgotten backup that still worked with older credentials, and spot a configuration error in the recovery tool. It's a digital forensic assistant, not a master hacker. But it's a genuinely useful illustration of what AI is actually good at: pattern-matching across large, disorganised datasets that a human would take months to sift through. The 5 BTC is now worth just under $400,000. The man vowed to name his child after Anthropic CEO Dario Amodei.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>AI didn't crack anything, it organised chaos</strong><span class="white-space-pre"> </span>- The man already had everything he needed spread across old files and notebooks. Claude's value was connecting the dots across years of messy data. That's what large language models are genuinely good at, not breaking encryption, but finding patterns humans miss.</li>
<li>
<strong>Think before you upload sensitive data to AI</strong><span class="white-space-pre"> </span>- He uploaded his entire college computer into Claude, including wallet files and private keys. If you're handing that kind of material to any AI service, you need to understand who can see it and what happens to it. He transferred the Bitcoin out immediately, which was smart.</li>
<li>
<strong>Password management is not a joke</strong><span class="white-space-pre"> </span>- The password was "lol420fu**thePOLICE!*:)". Set while high. Forgotten immediately. That cost him 11 years of access to what became nearly $400,000. Use a password manager. Please.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points</h2>
<p class="ember-view reader-text-block__paragraph">Canvas pays ShinyHunters, nobody believes the data is gone<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=102" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.theregister.com/cyber-crime/2026/05/14/security-pros-doubt-canvas-attackers-really-deleted-stolen-student-data/5240799" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">716,000 patients exposed in OpenLoop Health data breach<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=356" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.securityweek.com/716000-impacted-by-openloop-health-data-breach/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Fake Claude Code installer stealing developer credentials through Google Ads<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=1158" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.ontinue.com/resource/blog-behind-a-fake-claude-code-installer/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Google confirms hackers used AI to find a zero-day for the first time<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=1474" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.reuters.com/technology/cybersecurity/hackers-pushing-innovation-ai-enabled-hacking-operations-google-says-2026-05-11/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Anyone who knows your VIN can add your Audi to their account<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2037" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://decoder.cloud/2026/05/08/oh-myaudi/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Scam letters are back: Amy shares a $60.5 million Nigerian prince letter that arrived through the post<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2432" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/posts/amystokeswaters_unbelievably-scammers-have-gone-back-to-share-7460725231746191360-_zox" target="_self" data-turbo="false">LinkedIn</a></p>
<p class="ember-view reader-text-block__paragraph">Annual corporate training be like (click, click, click, click, click)<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2672" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.tiktok.com/@evanmelk786/video/7633891333668670750" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">UK banks storing your biometric data for large payments<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2844" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://vm.tiktok.com/ZNRGNcudJ/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">Waymo recalls 3,800 self-driving cars because they drive into floods<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=3107" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.bbc.co.uk/news/articles/cdepzg83x87o" target="_self" data-turbo="false">Read</a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEJ24_2sJUFBg/article-inline_image-shrink_1000_1488/B4EZ41mS4jJEAI-/0/1779015692236?e=1780531200&amp;v=beta&amp;t=dAR4Bup0wwEG3Yne9oBOdE4xxnbi2_J5AZGOt9eZX_8" onerror="this.style.display='none'"></span>100% legal and risk-free if and only if you adhere strictly to my instructions</p>
<p class="ember-view reader-text-block__paragraph">Scammers have gone back to posting letters.<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/amystokeswaters/" data-turbo="false">Amy Stokes-Waters</a><span class="white-space-pre"> </span>, CEO at<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/company/the-cyber-escape-room-co/" data-turbo="false">The Cyber Escape Room Co. ®</a>, shared a letter her dad received this week from a "Mr. Kenji Tahara, Director &amp; Executive Officer" at the Hachijuni Nagano Bank. The letter claims a deceased oil industry entrepreneur named Smith Waters deposited $60.5 million before tragically passing away at the onset of the Russia-Ukraine conflict, and because Amy's dad shares the surname, he's been selected as the next of kin to claim the estate. The split? 50% for the scammer (which will go towards "helping refugees from Ukraine war through various NGOs around Europe," obviously), 45% for the victim, and 5% set aside for "expenses incurred during the cause of securing this deposit." Five percent of $60.5 million for expenses. That's a hefty admin fee.</p>
<p class="ember-view reader-text-block__paragraph">The best line? "I assure you that the operation is 100% legal and risk-free if and only if you adhere strictly to my instructions." As we said on the podcast, the old ways still work. In the age of AI-generated phishing and deepfake video calls, someone is still printing letters, buying stamps, and posting Nigerian prince scams through the Royal Mail. And if it didn't work, they wouldn't bother.</p>
<p class="ember-view reader-text-block__paragraph">Worth sharing with your teams as a reminder that not every scam arrives in your inbox. Sometimes it lands on your doormat.</p>
<p class="ember-view reader-text-block__paragraph"><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2432" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/posts/amystokeswaters_unbelievably-scammers-have-gone-back-to-share-7460725231746191360-_zox" target="_self" data-turbo="false">LinkedIn</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Annual corporate training be like</strong><span class="white-space-pre"> </span>- If you've ever sat through mandatory training and just clicked next, next, next, next without reading a single word, this TikTok will feel personal. Shared by<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/liamstock-rabbat/" data-turbo="false">Liam Stock-Rabbat</a><span class="white-space-pre"> </span>, it's a man sat in front of a screen doing exactly that for a solid minute. As we discussed on the show, if you look at the completion times on your training platform, you can tell exactly who's done this. And if the only question at the end is so simple you don't need to watch the video, or so obscure you'd never remember the answer anyway, what's the point? Great one to share with your compliance team next time they ask why completion rates are high but behaviour hasn't changed.<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2672" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.tiktok.com/@evanmelk786/video/7633891333668670750" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>UK banks storing your biometric data for large payments</strong><span class="white-space-pre"> </span>- Luke shared a TikTok from Jamie's Finance asking questions about UK banks collecting and storing facial biometric data for high-value transactions. The comments were split. Some said biometric data never leaves your phone, others pointed out there's a separate process for large payments where banks do store that data server-side. As Ant mentioned on the show, having worked with three large retailers recently, every single one handles it differently. Worth a look if you bank with NatWest, Lloyds or any of the others mentioned, and worth understanding the difference between using Face ID to unlock your app and giving your bank a facial scan they store on their infrastructure.<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://youtu.be/wJSxzylp1Gw?t=2844" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://vm.tiktok.com/ZNRGNcudJ/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="mailto:hello@riskycreative.com" target="_self" data-turbo="false"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/in/infosecant/" target="_self" data-turbo="false"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/in/lukejpme/" target="_self" data-turbo="false"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="xRPuXKfUpBkIORjMpZxQAvTEeNvfshyBJs " href="https://www.linkedin.com/company/riskycreative/" target="_self" data-turbo="false"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/234001?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/234001?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F234001%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F234001%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_232429">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/232429/watch_times"
  data-youtube-player-video-id-value="tCWXLJ-M6ng"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/tCWXLJ-M6ng/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/232429">
          May 11, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/232429">
            Dead Airline Still Taking Bookings, Chrome's Secret AI Download &amp; The Hackable Killer Lawn Mower
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<h3><strong>Cybersecurity news for humans, not just IT people</strong></h3>
<p><br></p>
<p>This week a dead airline's website is still letting people book flights that will never exist, and scammers are already circling the wreckage. Google Chrome has been silently downloading a 4GB AI model onto your computer without asking, and if you delete it, it comes back. And a $5,000 robot lawn mower can be hijacked by anyone on the internet, including overriding the emergency stop button. Oh, and it phones home to TikTok's parent company. You couldn't make it up.</p>
<p>We've also got two breaches linked to the same hacking group (ShinyHunters are back again), Instagram quietly killing encrypted DMs for two billion users, OpenAI adding a "trusted contact" feature to ChatGPT after a wave of self-harm lawsuits, and a student who stopped four high-speed trains with a radio he bought online.</p>
<p>It's a busy week on The Awareness Angle.<br><br></p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" data-turbo="false">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" data-turbo="false">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" data-turbo="false">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>


































































<h2>SANS 2026 Security Awareness Report Survey - Now Open</h2>

























<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/8p4AWbCxNZmAIOBvZOZaf23dOgGyaylBKc29TU9S.png" width="540" onerror="this.style.display='none'"></span>

























<p>This one's directly relevant to what we do. SANS Institute runs the biggest annual benchmark survey for security awareness and human risk management professionals, and the 2026 edition is now open. It's 24 questions, takes around eight minutes, and the findings feed into a free report that security awareness practitioners around the world use to benchmark their programmes, justify investment, and work out what actually moves the needle on human behaviour. It's been running for 11 years and it's one of the most credible data sets in the field. If you work in security awareness in any capacity, your voice belongs in this. To take part click<span> </span><a href="https://go.sans.org/IRD0Vs" target="_self" data-turbo="false">here</a>.</p>



























































<h2>This Week's Stories...</h2>
<h3>Spirit Airlines Liquidation: Zombie Infrastructure, Open Payments, and $11.48 Phishing Domains</h3>
<p><a href="https://youtu.be/tCWXLJ-M6ng?t=738" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://braydenbte.substack.com/p/spirit-airlines-liquidation" target="_self" data-turbo="false">Read</a></p>
<p>Spirit Airlines ceased operations on May 2nd. But nobody turned anything off.</p>
<p>A security researcher called Brayden Hustead, whose own sister was stranded by the shutdown, discovered that the entire booking flow on spirit[.]com was still fully functional days after the airline collapsed. You could search for flights, pick your seats, enter your personal details, and reach the payment screen for flights that will never take off. The Navitaire booking API on Azure was still active, issuing real record locators and attempting real payment transactions against a live gateway. The system returned a "payment declined" response, not a "provider unavailable" error. That means the payment processor was still connected. It hadn't been deactivated. It just rejected the test card. If someone had used a real card, there's a genuine question about whether the transaction would have gone through.</p>
<p>Spirit's IT team duct-taped a redirect onto the homepage and called it a day. But all the internal links, the API, the telemetry stack, the Azure endpoints, all of it was left running in the background with nobody monitoring it. As we discussed on the show, it's a bit like the last person leaving the office and not switching the lights off. Only these lights were processing $13 to $15 million in transactions a day just 48 hours earlier.</p>
<p>And then there's the domain situation. The most obvious phishing domains you could imagine, spiritrefunds[.]com, spiritrefund[.]com, spiritliquidation[.]com, were sitting there unregistered for $11.48 each. Hustead grabbed them defensively and redirected them to the official restructuring site. Within four hours, 43 real people had already hit spiritliquidation[.]com, typing URLs directly into their browsers looking for help. Those are real, panicking, non-tech-savvy people who would have been trivially easy to scam if someone malicious had got there first.</p>
<p><strong>The Awareness Angles:</strong></p>
<p><strong>Zombie infrastructure is a real threat</strong><span> </span>- When a company shuts down overnight, the systems don't magically switch off. Spirit's booking API, payment processor, and Azure endpoints were all still running with nobody watching. That's an open door for anyone who wants to poke around in systems that were handling millions daily.</p>
<p><strong>Obvious phishing domains get left wide open</strong><span> </span>- The most predictable scam domains were available for the price of a sandwich. In any corporate wind-down, someone needs to be thinking about domain defence. In this case, nobody was, and a student beat the scammers to it.</p>
<p><strong>Desperation makes people vulnerable</strong><span> </span>- 43 real people hit a defensive domain redirect within four hours. These are the exact people scammers target: stressed, confused, and willing to trust anything that looks official.</p>
<h3><br></h3>
<h3>Google Chrome Silently Installs 4GB AI Model on Your Device Without Consent</h3>
<p><a href="https://youtu.be/tCWXLJ-M6ng?t=1144" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://cybernews.com/security/google-chrome-ai-model-device-no-consent/" target="_self" data-turbo="false">Read</a></p>
<p>Google Chrome, the world's most popular browser, has been silently downloading a 4GB AI model called Gemini Nano onto people's computers. No prompt. No notification. No consent checkbox. And if you find it and delete it, it comes back.</p>
<p>Security researcher Alexander Hanff discovered the file sitting in a folder called OptGuideOnDeviceModel. It appeared even on a completely fresh Chrome profile with zero human interaction. No one clicked anything. No one enabled anything. It just appeared. Snopes confirmed the finding across multiple staff machines on both macOS and Windows.</p>
<p>The kicker, as we talked about on the show, is that this 4GB model isn't even powering the AI features most people would notice. The big "AI Mode" button in Chrome's address bar actually sends your queries to Google's servers. The 4GB sitting on your hard drive powers minor writing assistance features that most people have never turned on and probably don't know exist. So Chrome is eating your storage for something you've never asked for and probably wouldn't use. And as we discussed, Google eventually added an opt-out setting, but it arrived months after the downloads started and it's buried in Chrome's flags backend, the kind of settings page that warns you things might break. Your mum isn't going to find that. Nobody's mum is going to find that.</p>
<p>Under GDPR, downloading 4GB of data to someone's device, profiling their hardware to decide if it's eligible, and doing all of it without consent raises some serious legal questions. But beyond the legal stuff, it's the principle. Your browser is making decisions about what to install on your computer without asking you. We had a similar conversation a few weeks ago when Anthropic's Claude Desktop was found doing something similar with browser hooks. It's becoming a pattern: AI companies treating your device as their deployment platform and asking forgiveness later.</p>
<p><strong>The Awareness Angles:</strong></p>
<p><strong>Your browser is doing more than you think</strong><span> </span>- Chrome isn't just displaying web pages. It's downloading multi-gigabyte AI models, profiling your hardware, and making storage decisions without your knowledge. Understanding what your software does in the background matters.</p>
<p><strong>Consent should come before the download, not after</strong><span> </span>- Google added an opt-out setting months after the downloads started. That's backwards. Privacy-by-design means asking before taking, not apologising after.</p>
<p><strong>Opt-out buried in advanced settings isn't real consent</strong><span> </span>- If the only way to stop something is to navigate to a page that warns you things might break, that's not a meaningful choice. Real consent means making it easy to say no, not just technically possible.</p>
<h3><br></h3>






















<h3>Yarbo Robot Lawn Mowers: Hardcoded Passwords, Remote Hijacking, and TikTok Telemetry</h3>
<p><a href="https://youtu.be/tCWXLJ-M6ng?t=2665" target="_self" data-turbo="false">Watch |<span> </span></a><a href="https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt" target="_self" data-turbo="false">Read on The Verge</a></p>
<p>A 200-pound, blade-equipped robot sitting in your garden that can be remotely hijacked by anyone on the internet. Including overriding the physical emergency stop button. Every single Yarbo lawn mower in the world shares the same hardcoded root password, and you can't permanently change it because it resets with every firmware update.</p>
<p>Security researcher Andreas Makris found critical vulnerabilities in all 11,000 Yarbo devices worldwide. An attacker can remotely control the blades and movement, access the onboard cameras, steal the owner's Wi-Fi password, and read GPS coordinates and email addresses. It's similar to the robot vacuum and the internet-connected toaster stories we've covered before, but as Luke pointed out on the show, this one's different because a vacuum cleaner you can just pick up. A 200-pound machine with spinning blades, not so much.</p>
<p>And then there's the ByteDance detail. Yarbo's telemetry is routed through ByteDance, TikTok's parent company. The company claims to be headquartered in New York, but as the research dug into, it's actually Hangang Tech, based in Shenzhen, China. The US headquarters appears to be a small building they put a logo on. So your lawn mower is collecting your Wi-Fi credentials, GPS location, email address, and camera footage, and it's all going through ByteDance's servers. At the same time as America was having the whole uproar about TikTok's algorithm and Chinese data access, the same parent company was quietly getting access to people's gardens. Yarbo's response to the security findings was that the hardcoded password is "by design." We've heard that excuse before, Microsoft said the same thing last week about storing passwords in plain text, and it's getting old.</p>
<p><strong>The Awareness Angles:</strong></p>
<p><strong>Smart doesn't mean secure</strong><span> </span>- A $5,000 robot with cameras, GPS, and internet connectivity sounds premium. But hardcoded passwords and no ability to change them means security was never part of the design. Price is not an indicator of security.</p>
<p><strong>Physical safety meets cyber risk</strong><span> </span>- This isn't a data breach. It's a physical safety hazard. When internet-connected devices can cause real-world harm, stopping to ask about security before you buy is essential.</p>
<p><strong>Ask what your devices are phoning home to</strong><span> </span>- Yarbo's telemetry routes through ByteDance. Most people buying a lawn mower would never think to ask where their device sends data. With smart home products, that question should be standard before you buy.</p>
<p><a href="https://youtu.be/EjyAgT6txXs?t=3669" target="_self" data-turbo="false"></a><br></p>
<p><a href="https://youtu.be/hlBFZ76nIBI?t=3259" target="_self" data-turbo="false"></a><br></p>



























































<h2>This Week's Discussion Points...</h2>
<p>Zara data breach exposes 197,000 customers via third-party analytics vendor<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=103" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/" target="_self" data-turbo="false">Read</a></p>
<p>Cushman &amp; Wakefield breached via vishing, two ransomware gangs claim responsibility<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=223" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718" target="_self" data-turbo="false">Read</a></p>
<p>ConsentFix v3 targets Azure with automated OAuth abuse<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=514" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/consentfix-v3-attacks-target-azure-with-automated-oauth-abuse/" target="_self" data-turbo="false">Read</a></p>
<p>Spirit Airlines liquidation leaves zombie infrastructure and $11.48 phishing domains<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=738" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://braydenbte.substack.com/p/spirit-airlines-liquidation" target="_self" data-turbo="false">Read</a></p>
<p>Google Chrome silently installs 4GB AI model on your device without consent<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=1144" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://cybernews.com/security/google-chrome-ai-model-device-no-consent/" target="_self" data-turbo="false">Read</a></p>
<p>Instagram drops end-to-end encryption on DMs<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=1471" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.macrumors.com/2026/05/05/psa-instagram-encrypted-messaging-ends-may-8/" target="_self" data-turbo="false">Read</a></p>
<p>Anthropic CEO warns of "moment of danger" as Mythos exposes thousands of software vulnerabilities<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=1762" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://qz.com/anthropic-ceo-cybersecurity-vulnerabilities-mythos-050526" target="_self" data-turbo="false">Read</a></p>
<p>OpenAI adds "Trusted Contact" feature to ChatGPT after self-harm lawsuits<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=2125" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://cybernews.com/tech/chatgpt-trusted-contact-feature-privacy-safety-debate/" target="_self" data-turbo="false">Read</a></p>
<p>Student hacks Taiwan high-speed rail by exploiting 19-year-old radio system<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=2414" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/student-hacked-taiwan-high-speed-rail-to-trigger-emergency-brakes/" target="_self" data-turbo="false">Read</a></p>
<p>Yarbo robot lawn mowers have hardcoded passwords and can be controlled remotely by anyone<span> </span><a href="https://youtu.be/tCWXLJ-M6ng?t=2665" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt" target="_self" data-turbo="false">Read</a></p>
<p><a href="https://youtu.be/EjyAgT6txXs?t=3669" target="_self" data-turbo="false"></a><a href="https://www.techradar.com/pro/security/uk-security-agency-officially-declares-passkeys-superior-to-passwords-passkeys-should-be-the-first-choice-for-authentication" target="_self" data-turbo="false"></a><a href="https://vm.tiktok.com/ZNRVx241m/" target="_self" data-turbo="false"></a><br></p>
<ul></ul>



























































<h2>Security Socials</h2>
<p><strong></strong><strong></strong><br></p>
<p><strong>Fake Wi-Fi QR code in McDonald's</strong><span> </span>- Someone stuck a fake Wi-Fi QR code sign in a McDonald's. A guy scans it and gets the monkey giving the middle finger. Funny video, but a great one to share with your teams to show why scanning random QR codes is a bad idea.<span> </span><a href="https://www.instagram.com/reel/DX0wk3Xhl6k/?igsh=MXpiMzl0b2RvNnRy" target="_self" data-turbo="false">Watch on Instagram</a></p>
<p><strong>Joseph Cox deepfakes his own face on Microsoft Teams</strong><span> </span>- The 404 Media co-founder tested Chinese-language deepfake software that works live on video calls including Teams, Zoom, and WhatsApp. The quality is still a bit soft and slow, but it's only going to get better. Worth watching.<span> </span><a href="https://www.linkedin.com/posts/joseph-cox-2ba467173_recently-i-opened-up-microsoft-teams-and-ugcPost-7458184536867201024-8uWX" target="_self" data-turbo="false">Read</a></p>
<p><strong>Why haven't hackers deleted student loans?</strong><span> </span>- A Reddit post on No Stupid Questions asked why a benevolent hacker hasn't just deleted everyone's student debt. The top answer: because deleting a database entry doesn't delete the legally binding promissory note you signed. But it's a great question to throw at your workforce. Would your people know why that doesn't work?<span> </span><a href="https://www.reddit.com/r/NoStupidQuestions/s/ndVijL0qI0" target="_self" data-turbo="false">Read</a></p>
<p><strong>Recruitment scam targets security awareness professional</strong><span> </span>- Jessica Behles posted about receiving a perfectly crafted recruitment scam email. The irony is she teaches people to recognise scams for a living, and she still felt the pull. Your experience, your salary, your perfect match. It's designed to make you feel special so you let your guard down.<span> </span><a href="https://www.linkedin.com/posts/jebehles_it-felt-fitting-that-i-got-my-first-recruitment-share-7457082784839254016-DVGe" target="_self" data-turbo="false">Read</a></p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/232429?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/232429?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F232429%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F232429%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_230903">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/230903/watch_times"
  data-youtube-player-video-id-value="EjyAgT6txXs"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/EjyAgT6txXs/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/230903">
          May 5, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/230903">
            ADT Breached by a Phone Call, AI Wipes a Startup in 9 Seconds, and 85% of UK Breaches Are Phishing
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, we hit 1.2 million views on a single video across TikTok and Instagram, which is pretty wild for an independent podcast. Thank you to everyone who watched and shared.</p>
<p class="ember-view reader-text-block__paragraph">ADT gets breached for the third time in under a year and it all started with a phone call. An AI coding agent wipes a startup's entire database and all its backups in nine seconds, then writes its own incident report admitting it broke every safety rule it had. The supply chain attack that started with Trivy has now hit Checkmarx and Bitwarden, with three criminal groups teaming up to turn supply chain access into ransomware. And the UK government's annual cyber report says 43% of businesses were breached last year, phishing was behind 85% of them, and despite M&amp;S, Co-op and JLR making national headlines, nothing's really changed. Plus Instructure's Canvas LMS breached again, Itron's smart meters filing quietly on a Friday night, Microsoft Teams helpdesk impersonation going wild, 610,000 Roblox accounts stolen by three lads in Ukraine, QR code scams in Toronto, and a toaster with a touchscreen that nobody asked for.</p>
<p class="ember-view reader-text-block__paragraph">All of that in this week's Awareness Angle.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><a href="https://youtu.be/EjyAgT6txXs" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQFIBRYFSPda7g/article-inline_image-shrink_1500_2232/B4EZ3tUBkXHsAU-/0/1777802944257?e=1779321600&amp;v=beta&amp;t=27ZEmBz0Ld4V6F_dQRKNldkBH_kv9OGaJsMRYMSK-V8" onerror="this.style.display='none'"></span></a>Click to watch us on YouTube</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories</h2>
<h3 class="ember-view reader-text-block__heading-3">Almost Half of UK Businesses Hit by Cyber Attacks, Government Report Finds</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=2216" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.computerweekly.com/news/366642507/Almost-half-of-UK-businesses-hit-by-cyber-attacks" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">The UK government's annual Cyber Security Breaches Survey landed this week and the numbers are huge. 43% of UK businesses, roughly 612,000, experienced a cyber attack or breach in the past year. Of those that reported a breach, 85% said phishing was involved. Not "one of the top threats," nearly all of them. And as we discussed on the show, that likely includes voice phishing and other channels beyond just email. Despite a year that included M&amp;S, Co-op and Jaguar Land Rover all making national headlines, cyber hygiene among SMEs has actually gotten worse on several measures. Only 15% of businesses review the risks posed by their direct suppliers, just 6% look at the wider supply chain, and a quarter of businesses don't even know what their ransomware policy is. As Ant pointed out, that means people are making impulse decisions in the heat of the moment, and that's never wise.</p>
<p class="ember-view reader-text-block__paragraph">The cyber security minister has written to 180 of the UK's largest businesses urging them to sign a new Cyber Resilience Pledge, but as we discussed, it's not those 180 companies that need the most help. It's the smaller businesses in their supply chains, the ones making the spigot rings for a Land Rover Defender, that are really feeling the impact when something goes wrong. If you work in security awareness, this report is ammunition. Share it with your CISO. As<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/lukejpme/" data-turbo="false">Luke Pettigrew</a><span class="white-space-pre"> </span>said, these are exactly the kind of stats you need to make the case for investment and resources.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>The gap between knowing and doing</strong><span class="white-space-pre"> </span>- Most organisations know cyber is a risk. The problem is that awareness still isn't translating into action, especially among smaller businesses. If you need one stat to justify your programme's existence, 85% of breaches involved phishing is it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>High-profile breaches aren't moving the needle</strong><span class="white-space-pre"> </span>- M&amp;S, Co-op and JLR all made national headlines, and the overall picture barely shifted. We said at the time that those breaches would be a wake-up call for the country. The data says otherwise. Shock value alone doesn't drive behaviour change.</p>
<p class="ember-view reader-text-block__paragraph"><strong>A quarter of businesses don't know their own ransomware policy</strong><span class="white-space-pre"> </span>- That's not a technical problem, that's a communication problem. If your people don't know what the plan is before something happens, there is no plan.</p>
<h3 class="ember-view reader-text-block__heading-3">ADT Breached Again by ShinyHunters Vishing Attack</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=112" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Home security giant ADT has been breached for the third time in under a year after ShinyHunters used a vishing call to compromise an employee's Okta SSO credentials and pivot into ADT's Salesforce instance. No malware, no technical exploit, just a convincing phone call and one set of credentials that unlocked millions of customer records. As Ant noted on the show, this is the same playbook ShinyHunters used on MGM, and it's rumoured to be behind M&amp;S, Co-op and most of the big breaches over the last couple of years. When your business is security, having three breaches in 18 months isn't a great look, and as we pointed out, Bleeping Computer used the same stock image for all three.</p>
<p class="ember-view reader-text-block__paragraph">Luke raised an important point about how vishing awareness has traditionally been focused on help desks and privileged access teams, but this shows it needs to be much broader. As Ant put it, everyone has access to something useful to an attacker, whether that's sales data, HR records, customer information or system access. A lot of permissioning in businesses isn't great, and it could be someone very low down the pyramid that leads to the top. We used to ask people in awareness surveys whether they agreed with the statement "I am of no use to hackers, so they do not target me." This story proves exactly why that thinking is dangerous.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>It started with a phone call, not a hack</strong><span class="white-space-pre"> </span>- No malware, no vulnerability. Someone called an employee, pretended to be IT support, and talked them into handing over their login. That was enough to compromise millions of records. If your awareness training doesn't cover phone-based social engineering with the same weight as email phishing, this is your sign to change that.</p>
<p class="ember-view reader-text-block__paragraph"><strong>One account unlocked everything</strong><span class="white-space-pre"> </span>- A single set of SSO credentials gave the attacker access to Salesforce and all the customer data sitting in it. One login for everything is convenient until someone else gets hold of it.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Third breach in under a year</strong><span class="white-space-pre"> </span>- Three disclosed breaches since August 2024, with the same type of attack working each time. As we discussed, getting hit once doesn't mean you've had your turn. You can go again, and if the lessons aren't sticking, you probably will.</p>
<h3 class="ember-view reader-text-block__heading-3">AI Coding Agent Deletes Startup's Entire Database in Nine Seconds</h3>
<p class="ember-view reader-text-block__paragraph"><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=1076" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.independent.co.uk/tech/claude-ai-agent-deletes-startup-anthropic-b2966176.html" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">An AI coding agent running Anthropic's Claude through Cursor hit a problem in a staging environment and decided to fix it by deleting a production database volume. It found an overpermissioned API token in an unrelated file, used it to wipe the entire database and all backups through a single API call, and the whole thing was done in nine seconds. As Ant put it on the show, he can't get Claude to write his name in nine seconds, let alone delete an entire database. When the founder asked the agent to explain what happened, it wrote its own incident report listing every safety rule it knew it had broken, including its own system prompt telling it never to run destructive commands without being asked.</p>
<p class="ember-view reader-text-block__paragraph">For the car rental businesses using PocketOS, this meant they suddenly had no customer records at all. The data was eventually recovered, but it took days, and in the meantime customers were reconstructing bookings from Stripe payment histories and email confirmations. Luke shared a video from Hannah Fry about AI agents going rogue that tied in perfectly with this story, and as we discussed, every business wants to use AI because nobody wants to get left behind, which in some ways makes things even more dangerous. Luke also flagged that Claude's own Chrome extension, which has six million users, openly acknowledges the risk of prompt injection from websites in its Chrome Store listing. We're trying hard not to let this become an AI podcast, but when AI is doing things like this, it has to be part of the security awareness conversation.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>AI agents can take destructive action without asking</strong><span class="white-space-pre"> </span>- This agent wasn't told to delete anything. It decided to, found a way to do it, and did it faster than any human could have intervened. If your team is using AI coding tools, understand what they actually have access to.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Overly permissioned tokens are a ticking clock</strong><span class="white-space-pre"> </span>- The API token that made this possible was created for a narrow purpose but had permissions far beyond what was needed. That's not an AI problem, that's an access control problem that AI made catastrophically worse.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The "best model" isn't a safety guarantee</strong><span class="white-space-pre"> </span>- They were running the top-tier model with explicit safety rules configured. It still ignored them. Capability and reliability are not the same thing, and trusting an AI agent because it's smart is not the same as trusting it because it's safe.</p>
<h2 class="ember-view reader-text-block__heading-2">This week's discussion points</h2>
<p class="ember-view reader-text-block__paragraph">ADT Breached Again by ShinyHunters Vishing Attack<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=112" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Instructure / Canvas LMS Hit by Another Cyber Attack<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=443" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.bleepingcomputer.com/news/security/edu-tech-firm-instructure-discloses-cyber-incident-probes-impact/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Critical Infrastructure Giant Itron Confirms Cyberattack<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=818" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://techcrunch.com/2026/04/27/critical-infrastructure-giant-itron-says-it-was-hacked/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">AI Coding Agent Deletes Startup Database in 9 Seconds<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=1076" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.independent.co.uk/tech/claude-ai-agent-deletes-startup-anthropic-b2966176.html" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Supply Chain Attack Hits Checkmarx and Bitwarden<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=1528" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Roblox Account Theft: 610,000 Accounts Stolen<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=1720" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.bleepingcomputer.com/news/security/hackers-arrested-for-hijacking-and-selling-610-000-roblox-accounts/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">UK Cyber Security Breaches Survey 2025-26<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=2216" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.computerweekly.com/news/366642507/Almost-half-of-UK-businesses-hit-by-cyber-attacks" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Microsoft Teams Helpdesk Impersonation Attacks<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=2586" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">QR Code Scams in Toronto<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3141" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Smart Toasters and Unnecessary IoT<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3423" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Hannah Fry on AI Agents Going Rogue<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3669" target="_self" data-turbo="false">Watch</a></p>
<h2 class="ember-view reader-text-block__heading-2">Security Socials</h2>
<p class="ember-view reader-text-block__paragraph"><strong>QR Code Scams Hit Toronto</strong><span class="white-space-pre"> </span>-<span class="white-space-pre"> </span><a class="ember-view" href="https://www.linkedin.com/in/liamstock-rabbat/" data-turbo="false">Liam Stock-Rabbat</a><span class="white-space-pre"> </span>sent in a TikTok video showing fake QR code stickers being placed over legitimate ones on bike rental stations across the Greater Toronto Area. As we discussed, if you're a tourist you'd have no idea the flow was wrong because you've never used it before. Stickers over QR codes can be legitimate, businesses do update them, but that's exactly what makes it so hard to spot. The advice remains the same: if you can, use the app directly rather than scanning a random code.<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3141" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Smart Toasters and Unnecessary IoT</strong><span class="white-space-pre"> </span>- Someone on Reddit posted a picture of a toaster with a full touchscreen, weather report and digital photo frame. It costs £300 and it's internet connected. As Ant put it, it's yet another unnecessary risk you're bringing into your home. We went down a rabbit hole about Samsung TVs full of ads, why you might want to skip the built-in smart TV apps entirely, and what the most random connected device in your house might be. Let us know yours.<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3423" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Hannah Fry on AI Agents Going Rogue</strong><span class="white-space-pre"> </span>- Luke shared a TikTok from Hannah Fry (who went to the same school as Ant's wife, small world) talking about AI agents and the risks of giving them too much autonomy. It tied in perfectly with the PocketOS story. Luke also flagged that Claude's Chrome extension, with six million installs, openly acknowledges the risk of prompt injection in its Chrome Store listing. We're trying not to become an AI podcast, but it keeps pulling us back in.<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://youtu.be/EjyAgT6txXs?t=3669" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="mailto:hello@riskycreative.com" target="_self" data-turbo="false"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.linkedin.com/in/infosecant/" target="_self" data-turbo="false"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.linkedin.com/in/lukejpme/" target="_self" data-turbo="false"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="BcCwxaHikpyepwRwtVGKNyXGurXnwmOyGVc " href="https://www.linkedin.com/company/riskycreative/" target="_self" data-turbo="false"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/230903?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/230903?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F230903%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F230903%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_225759">
    <div class="post" access="paid-members">
  <div class="post__inner">
      <a class="post__media" data-turbo-frame="_top" href="/supporters/payments/checkout/posts/225759/available_tiers">
  <div class="post-locked">
    <img class="post-locked__video-embed-thumbnail" alt="Video thumbnail" width="712" height="400" loading="lazy" src="https://img.youtube.com/vi/JQ7IhVG3m5g/hqdefault.jpg" />

    <div class="post-locked__info">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M1.75 3.25a.25.25 0 0 0-.25.25v9c0 .138.112.25.25.25h7.998a.25.25 0 0 0 .25-.25v-9a.25.25 0 0 0-.25-.25 133551.684 133551.684 0 0 0-7.998 0ZM0 3.5c0-.967.784-1.75 1.75-1.75a49139.54 49139.54 0 0 0 7.998 0c.967 0 1.75.784 1.75 1.75v1.61l2.058-.89A1.75 1.75 0 0 1 16 5.826v4.385a1.75 1.75 0 0 1-2.46 1.599l-2.041-.907V12.5a1.75 1.75 0 0 1-1.75 1.75H1.75A1.75 1.75 0 0 1 0 12.5v-9Zm11.499 5.762 2.65 1.177a.25.25 0 0 0 .351-.228V5.826a.25.25 0 0 0-.35-.229L11.5 6.744v2.518Z" clip-rule="evenodd"></path></svg>

    </div>
  </div>
</a>

    <div class="post__main">
  <div class="post__content">
 

        <a class="post__meta" data-turbo-frame="_top" href="/supporters/pricing">
          Apr 20, 2026
</a>

      <div>
          <a class="post__title" data-turbo-frame="_top" href="/supporters/pricing">
            Hungarian Passwords, Rockstar Hacked &amp; Booking.com Scams
</a>      </div>



        <div class="post__section post__section--column">
          <a class="button button--medium button--primary" data-turbo-frame="_top" href="/supporters/payments/checkout/posts/225759/available_tiers"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 14 16" role="img" class="button__icon"><path fill="currentColor" fill-rule="evenodd" d="M7 1.5c-.8 0-1.556.292-2.104.794-.546.5-.838 1.163-.838 1.84V5.8h5.884V4.133c0-.676-.292-1.34-.838-1.84A3.12 3.12 0 0 0 7 1.5Zm4.442 4.3V4.133c0-1.118-.485-2.176-1.325-2.945A4.62 4.62 0 0 0 7 0a4.62 4.62 0 0 0-3.118 1.188c-.839.77-1.324 1.827-1.324 2.945V5.8H2A1.75 1.75 0 0 0 .25 7.55v6.7C.25 15.216 1.034 16 2 16h10a1.75 1.75 0 0 0 1.75-1.75v-6.7A1.75 1.75 0 0 0 12 5.8h-.558ZM2 7.3a.25.25 0 0 0-.25.25v6.7c0 .138.112.25.25.25h10a.25.25 0 0 0 .25-.25v-6.7A.25.25 0 0 0 12 7.3H2Zm4.409 4.793V9.435h1.5v2.658h-1.5Z" clip-rule="evenodd"></path></svg>
Join to access</a>
        </div>

      <div class="post__section">
        <div class="post-actions">
          <form class="post-actions__item-form" data-turbo="false" action="/supporters/payments/checkout/posts/225759/available_tiers" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/payments/checkout/posts/225759/available_tiers" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
          
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/225759?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share a preview of a locked post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/225759?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F225759%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F225759%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
        </div>
      </div>

      

  </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_224006">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/224006/watch_times"
  data-youtube-player-video-id-value="B_rxuKB72ow"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/B_rxuKB72ow/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/224006">
          Apr 13, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/224006">
            Missile Alert Phishing, Meeting Recordings Exposed and You Already Have A QR Code Generator
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="article-editor-paragraph article-editor-content__has-focus">This week we've got three things that are immediately useful whether you work in security or not. We discussed a phishing campaign using fake missile alerts and real geopolitical fear to steal Microsoft credentials. There is a story about what happens when a meeting recording gets sent to the wrong person after someone drops off a call, and a genuinely handy tip about generating QR codes without handing your data to a random website. It was sitting on your computer, the whole time!</p>
<p class="article-editor-paragraph">After that we've got the Breach of the Week, the Phish of the Week from the team at Hoxhunt, and everything else from this week's episode.</p>
<p class="article-editor-paragraph"><strong>Watch or listen to the episode today - </strong><a class="article-editor-link article-editor-link" href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" rel="noopener noreferrer" data-turbo="false"><strong>YouTube</strong></a><strong> | </strong><a class="article-editor-link article-editor-link" href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" rel="noopener noreferrer" data-turbo="false"><strong>Spotify</strong></a><strong> | </strong><a class="article-editor-link article-editor-link" href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" rel="noopener noreferrer" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="article-editor-paragraph">Visit <a class="article-editor-link article-editor-link" href="http://riskycreative.com/" rel="noopener noreferrer" data-turbo="false"><strong>riskycreative.com</strong></a> for past episodes, our blog, and our merch.</p>
<p>Minimize imageEdit imageDelete image<a class="article-editor-inline-image__link" href="https://youtu.be/B_rxuKB72ow" rel="noopener nofollow" target="_blank"><span><img class="article-editor-inline-image__image" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQGceOOgE1Fn_g/article-inline_image-shrink_1500_2232/B4EZ17rO8PIMAU-/0/1775896426525?e=1777507200&amp;v=beta&amp;t=aCpnu5jtex7acxWLlKZGI_mn1DB7QCrgLLnvZSe1XEA" onerror="this.style.display='none'"></span></a></p>
<h2 class="article-editor-heading">This week's stories...</h2>
<p class="article-editor-paragraph is-empty"><br class="ProseMirror-trailingBreak"></p>
<h3 class="article-editor-heading">Missile Alert Phishing Exploits Iran-US-Israel Conflict for Microsoft Logins</h3>
<p class="article-editor-paragraph"><a class="article-editor-link article-editor-link" href="https://www.youtube.com/watch?v=B_rxuKB72ow&amp;t=1094s" rel="noopener noreferrer" data-turbo="false"><strong>Watch</strong></a> | <a class="article-editor-link article-editor-link" href="https://hackread.com/missile-alert-phishing-iran-us-israel-microsoft-logins/" rel="noopener noreferrer" data-turbo="false"><strong>Read</strong></a></p>
<p class="article-editor-paragraph">A phishing campaign is exploiting genuine geopolitical tensions between Iran, Israel, and the US. The emails impersonate government civil defence warnings, with urgent subject lines, an official-looking layout, and language designed to stop you thinking and start you acting. The ask is to scan a QR code for shelter guidance and evacuation instructions.</p>
<p class="article-editor-paragraph">The QR code takes you off your device to your phone, away from your email security controls, and onto a fake Microsoft login page.</p>
<p class="article-editor-paragraph">There's a line in the email worth noting: "scan for instructions, access official emergency procedures, shelter guidance and evacuation instructions." Ask yourself why emergency procedures would require you to sign into Microsoft. In a genuine emergency, you wouldn't stop to ask that. That's the whole point.</p>
<p class="article-editor-paragraph"><strong>The Awareness Angles -</strong></p>
<p class="article-editor-paragraph"><strong>Fear is the most effective bypass</strong> - Attackers weaponise breaking news and genuine anxiety to trigger fast, uncritical action. When people feel threatened, they don't pause to verify URLs.</p>
<p class="article-editor-paragraph"><strong>QR codes move the attack off your protected device</strong> - On your phone, the URL is harder to see, security tooling may not be in play, and the Microsoft login screen might look slightly different to what you're used to. All of that helps the attacker.</p>
<p class="article-editor-paragraph"><strong>If something urgent wants you to sign in somewhere unfamiliar, stop</strong> - Emergency guidance doesn't live behind a Microsoft login. That mismatch is the tell.</p>
<p class="article-editor-paragraph is-empty"><br class="ProseMirror-trailingBreak"></p>
<h3 class="article-editor-heading">Your Meeting Recording Might Be Sending More Than You Think</h3>
<p class="article-editor-paragraph"><a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2335" rel="noopener noreferrer" data-turbo="false"><strong>Watch</strong></a></p>
<p class="article-editor-paragraph">A post on Reddit's recruitinghell caught a lot of attention this week. A candidate's wife shared that after a virtual interview, her husband was accidentally sent a full transcript and audio recording of the entire call, including the interviewers discussing him after he disconnected. Remarks about his appearance, their salary negotiation tactics, and comments you'd never want the candidate to hear.</p>
<p class="article-editor-paragraph">It probably happens all the time. Someone drops off a call, the remaining people carry on talking, and the transcript goes out automatically to all participants when the meeting ends.</p>
<p class="article-editor-paragraph">The security message here is simple but easy to overlook: if you need to debrief after a meeting, start a new one. Don't assume the recording has stopped just because someone has left.</p>
<p class="article-editor-paragraph"><strong>The Awareness Angles -</strong></p>
<p class="article-editor-paragraph"><strong>Auto-transcription catches everything</strong> - Meeting tools like Teams, Zoom, and Meet don't stop recording when a participant leaves. If transcription is on, it captures whatever is said until the host ends the meeting.</p>
<p class="article-editor-paragraph"><strong>Transcripts go to all participants by default</strong> - The person you were just talking about may receive a full written record of what you said. This isn't a theoretical risk, it happened here.</p>
<p class="article-editor-paragraph"><strong>Start a new meeting to debrief</strong> - It takes ten seconds and removes the risk entirely. Worth making it a habit, and worth sharing with your teams.</p>
<p class="article-editor-paragraph is-empty"><br class="ProseMirror-trailingBreak"></p>
<h3 class="article-editor-heading">You Can Make QR Codes Directly in Microsoft Word</h3>
<p class="article-editor-paragraph"><a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2520" rel="noopener noreferrer" data-turbo="false"><strong>Watch</strong></a> | <a class="article-editor-link article-editor-link" href="https://www.facebook.com/share/r/1C57i19yRF/?mibextid=wwXIfr" rel="noopener noreferrer" data-turbo="false"><strong>Read</strong></a></p>
<p class="article-editor-paragraph">A short video shared this week pointed out something most people don't know: you can generate a QR code directly inside Microsoft Word, no third-party tool required.</p>
<p class="article-editor-paragraph">This matters for anyone in security awareness who makes posters, internal communications, or training materials. Most people Google "QR code generator" and land on a random website, hand over their URL, and don't think twice about what that site is doing with it. Using a built-in tool removes that risk entirely.</p>
<p class="article-editor-paragraph">It's not the most intuitive feature to find, but the video walks through it clearly. Worth knowing, and worth passing on to the teams in your organisation who regularly make printed or digital materials.</p>
<p class="article-editor-paragraph"><strong>The Awareness Angles -</strong></p>
<p class="article-editor-paragraph"><strong>Check what your existing tools can already do</strong> - Before anyone in your organisation uses a third-party website or app for something, it's worth asking whether Microsoft 365, Google Workspace, or whatever your standard toolset is can already do it natively. QR codes in Word is one example. There are probably others sitting unused. Finding them and communicating them reduces shadow IT risk without asking people to change their behaviour dramatically.</p>
<p class="article-editor-paragraph"><strong>Communicate it</strong> - If your organisation has approved tools that do things people don't know about, that's a quick win for a security awareness message. A short post, a tip in a newsletter, a slide in an induction deck. "You don't need to Google a QR code generator, here's how to do it in Word" is the kind of practical, immediately useful message that lands well.</p>
<p class="article-editor-paragraph"><strong>Third-party tools are a risk even for small things</strong> - Free online tools ask for data, store URLs, and may share information with parties you've never heard of. Helping people understand that even small conveniences carry risk is a useful habit to build.</p>
<h2 class="article-editor-heading">Phish of the Week</h2>
<p class="article-editor-paragraph"><em>Thanks as always to the threat intelligence team at </em><a class="article-editor-mention" href="https://www.linkedin.com/article/edit/7448636327190761472/" rel="noopener noreferrer nofollow" target="_blank">Hoxhunt</a> <em>.</em></p>
<p>Minimize imageEdit imageDelete image<span><img class="article-editor-inline-image__image" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQGqCbF02uDQxw/article-inline_image-shrink_1000_1488/B4EZ17x0WqG4AQ-/0/1775898152304?e=1777507200&amp;v=beta&amp;t=6fAGctHrxaSSyAb32oOoiGwUe9Hs9XZPx-P8ohSu9d0" onerror="this.style.display='none'"></span></p>
<h3 class="article-editor-heading">WhatsApp / Meta Impersonation: Credential and MFA Code Theft</h3>
<p class="article-editor-paragraph">This one's well put together. It arrives as an official-looking email carrying the WhatsApp and Meta branding, addressed to someone who runs a Meta Business Messaging partner account.</p>
<p class="article-editor-paragraph">The message says their business hasn't met requirements to maintain select tier status in the Meta Business Messaging Partners Program and they have until a specific date to fix it. There is a deadline included and links everywhere, four of them, all going to the same place.</p>
<p class="article-editor-paragraph">What makes it notable is the landing page. It's not just a fake login that steals your password. It asks you to verify your identity, capturing your MFA code in real time. The likely setup: a ghost system is logging in on your behalf in the background and passing your verification code straight through. So even with MFA turned on, this attack works.</p>
<p class="article-editor-paragraph"><strong>The Awareness Angles - </strong></p>
<p class="article-editor-paragraph"><strong>Targeted phishing feels relevant because it is</strong> - This works on people who actually have Meta partner portal accounts. If you received it and didn't have one, you'd ignore it. The targeting is what makes it dangerous.</p>
<p class="article-editor-paragraph"><strong>MFA capture is real</strong> - Getting your MFA code intercepted in real time is not theoretical. This attack is designed specifically to do that. MFA is still worth having, but it doesn't make you untouchable.</p>
<p class="article-editor-paragraph"><strong>Go to source, not the link</strong> - If you get something like this, don't click. Go to Google, search for the platform directly, and navigate from there. Better still, have it bookmarked.</p>
<blockquote class="article-editor-blockquote">
<p class="article-editor-paragraph">Bookmarks are an underrated and almost entirely forgotten piece of security advice. If there's a site you log into regularly, whether that's your bank, your HR system, your email, or a partner portal, bookmark it. Then when something arrives in your inbox claiming to be from that service, you don't need to click anything. You just open the bookmark. It sounds too simple, but it removes one of the most common ways people end up on fake login pages. Worth pushing out as an awareness message. It's practical, it costs nothing, and most people have never thought about it.</p>
</blockquote>
<h2 class="article-editor-heading">This Week's Discussion Points...</h2>
<p class="article-editor-paragraph">Everything we talked about in this week's episode:</p>
<ul class="article-editor-bullet-list">
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Hackers steal and leak 7.7TB of sensitive LAPD police documents via third-party storage <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=68" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://techcrunch.com/2026/04/08/hackers-steal-and-leak-sensitive-lapd-police-documents/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Wynn Resorts confirms 21,000 employees affected by ShinyHunters breach, ransom likely paid <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=215" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.securityweek.com/wynn-resorts-says-21000-employees-affected-by-shinyhunters-hack/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Dutch healthcare software vendor ChipSoft hit by ransomware, disrupting hospital systems across the Netherlands <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=321" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.theregister.com/2026/04/08/chipsoft_ransomware/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Jones Day law firm confirms breach after Silent Ransom Group (Luna Moth) leaks client files and demands $13M <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=411" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://databreaches.net/2026/04/06/jones-day-confirms-limited-breach-after-phishing-attack-by-silent-ransom-group/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Anthropic's Project Glasswing powered by Claude Mythos autonomously finds and exploits thousands of zero-days <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=588" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://thehackernews.com/2026/04/anthropics-claude-mythos-finds.html" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">GrafanaGhost vulnerability allows data theft via AI prompt injection, Grafana disputes severity <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=822" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://hackread.com/grafanaghost-vulnerability-data-theft-via-ai-injection/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Missile alert phishing campaign exploits Iran-US-Israel tensions to steal Microsoft credentials via QR code <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=1094" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://hackread.com/missile-alert-phishing-iran-us-israel-microsoft-logins/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">BlueHammer: disgruntled researcher leaks unpatched Windows privilege escalation zero-day on GitHub <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=1369" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.bleepingcomputer.com/news/security/disgruntled-researcher-leaks-bluehammer-windows-zero-day-exploit/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">White House proposes $707M cut to CISA, a third of staff already left in Trump's second term <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=1615" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.securityweek.com/white-house-seeks-to-slash-cisa-funding-by-707-million/" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Phish of the Week: WhatsApp/Meta impersonation capturing credentials and MFA codes in real time <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=1810" rel="noopener noreferrer" data-turbo="false">Watch</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">North Korean hacker exposed during a job interview <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2135" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.reddit.com/r/interestingasfuck/s/SzL60Oa9YH" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Interview transcript accidentally sent to applicant including post-call discussion <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2335" rel="noopener noreferrer" data-turbo="false">Watch</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">Make QR codes directly in Microsoft Word <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2520" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.facebook.com/share/r/1C57i19yRF/?mibextid=wwXIfr" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
<li class="article-editor-list-item">
<p class="article-editor-paragraph">TikTok Lite installed automatically after a phone update <a class="article-editor-link article-editor-link" href="https://youtu.be/B_rxuKB72ow?t=2650" rel="noopener noreferrer" data-turbo="false">Watch</a> | <a class="article-editor-link article-editor-link" href="https://www.reddit.com/r/mildlyinfuriating/s/NFpVMzCfCO" rel="noopener noreferrer" data-turbo="false">Read</a></p>
</li>
</ul>
<h3 class="article-editor-heading">Find Us</h3>
<p class="article-editor-paragraph">Podcast: <a class="article-editor-link article-editor-link" href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener noreferrer" data-turbo="false">Spotify</a> | <a class="article-editor-link article-editor-link" href="https://podcasts.apple.com/us/podcast/the-awareness-angle-cyber-news-weekly/id1784126196" rel="noopener noreferrer" data-turbo="false">Apple Podcasts</a></p>
<p class="article-editor-paragraph">YouTube: <a class="article-editor-link article-editor-link" href="https://www.youtube.com/@riskycreative" rel="noopener noreferrer" data-turbo="false">https://www.youtube.com/@riskycreative</a></p>
<p class="article-editor-paragraph">TikTok: <a class="article-editor-link article-editor-link" href="https://www.tiktok.com/@infosecant" rel="noopener noreferrer" data-turbo="false">https://www.tiktok.com/@infosecant</a></p>
<p class="article-editor-paragraph">Instagram: <a class="article-editor-link article-editor-link" href="https://www.instagram.com/riskycreative" rel="noopener noreferrer" data-turbo="false">https://www.instagram.com/riskycreative</a></p>
<p class="article-editor-paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at <a class="article-editor-link article-editor-link" href="mailto:hello@riskycreative.com" rel="noopener noreferrer" data-turbo="false"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="article-editor-paragraph"><a class="article-editor-link article-editor-link" href="https://www.linkedin.com/in/infosecant/" rel="noopener noreferrer" data-turbo="false"><strong>Ant Davis</strong></a> and <a class="article-editor-link article-editor-link" href="https://www.linkedin.com/in/lukejpme/" rel="noopener noreferrer" data-turbo="false"><strong>Luke Pettigrew</strong></a> write this newsletter and podcast.</p>
<p class="article-editor-paragraph">The Awareness Angle Podcast and Newsletter is a <a class="article-editor-link article-editor-link" href="https://www.linkedin.com/company/riskycreative/" rel="noopener noreferrer" data-turbo="false"><strong>Risky Creative</strong></a> production.</p>
<p class="article-editor-paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
<p class="article-editor-paragraph is-empty"></p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/224006?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/224006?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F224006%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F224006%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_222829">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/222829/watch_times"
  data-youtube-player-video-id-value="ZjY-_uw9ZNw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/ZjY-_uw9ZNw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/222829">
          Apr 7, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/222829">
            FBI Wiretap System Hacked, White House App Security Concerns, and LinkedIn's Secret Browser Scans
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle, we've got Chinese hackers breaking into the system the FBI uses to watch people. The White House released an app that security researchers took apart and didn't like what they found. LinkedIn has been quietly scanning your browser extensions and linking the results to your profile without telling you. And a Carnegie Mellon professor says app privacy labels are basically the nutrition labels of the internet, which tells you everything you need to know.</p>
<p class="ember-view reader-text-block__paragraph">We've also got Google Drive getting a proper ransomware safety net, attackers using WhatsApp to deliver malware to Windows PCs, Apple quietly blocking one of the cleverest scams doing the rounds right now, and a campaign calling out the AI-generated slop that's making all of us easier to scam.<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><a href="https://youtu.be/ZjY-_uw9ZNw" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQFjchK6KTS51g/article-inline_image-shrink_1000_1488/B4EZ1hgr7_IUAQ-/0/1775457454198?e=1776902400&amp;v=beta&amp;t=wNX1NShH__R47qPpqCKQQmbG1HskMzzZu0FvCGwBEFg" onerror="this.style.display='none'"></span></a>Click the image above to watch the latest episode on YouTube</p>
<h2 class="ember-view reader-text-block__heading-2">Breach of the Week</h2>
<h3 class="ember-view reader-text-block__heading-3">Chinese Hackers Breach the System the FBI Uses to Watch People</h3>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=100" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://thehill.com/policy/technology/5815310-fbi-data-breach-surveillance-system-major-incident/" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">We had plenty to choose from this week as Hasbro got hacked, there are unconfirmed claims about a massive Adobe breach, and a few others bubbling away. But this one was the standout, and honestly it's got Hollywood written all over it.</p>
<p class="ember-view reader-text-block__paragraph">Suspected China-linked hackers broke into the FBI system that stores surveillance data, likely exposing the phone numbers of people the bureau was actively monitoring. The FBI has officially classed it as a major incident and notified Congress, confirming that access came through a third-party vendor rather than a direct attack on their own systems.</p>
<p class="ember-view reader-text-block__paragraph">The system at the centre of it manages court-authorised wiretaps. Think of it as the database that tells investigators who they're watching and who those targets are talking to. Whoever got in could potentially work out exactly who the US is surveilling, giving them the chance to tip off assets, cut ties, or stay one step ahead. This isn't just a data breach. It's a breach of the FBI's ability to do its job quietly.</p>
<p class="ember-view reader-text-block__paragraph">Our Mission Impossible take: this feels less like a money grab and more like an intelligence operation. Who's being watched? Who's safe? Who needs burning? That kind of targeted patience is what separates nation-state attacks from regular cybercrime. There'll be a film about this one day.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle -<span class="white-space-pre"> </span></strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Your data in someone else's hands</strong><span class="white-space-pre"> </span>- When a government system gets hacked, it's not just officials affected. Ordinary people whose names appear in investigations as witnesses, associates or subjects can end up exposed too.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Third party, first problem</strong><span class="white-space-pre"> </span>- Access came through a third-party vendor, not a direct attack. This is the same weak link that trips up organisations of all sizes. Your security is only as strong as the people you trust with access.</p>
<p class="ember-view reader-text-block__paragraph"><strong>This isn't random</strong><span class="white-space-pre"> </span>- State-sponsored hackers don't break in to cause chaos. They go after intelligence. What's known, who's compromised, who's being watched. That level of patience and precision is what makes these attacks so hard to defend against.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">The Security Tool We Covered Last Week Just Helped Breach the European Commission</h3>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=435" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.securityweek.com/european-commission-confirms-data-breach-linked-to-trivy-supply-chain-attack/" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">If you caught last week's episode, you'll remember the Trivy supply chain attack, a poisoned security scanner that was backdoored and used to compromise an AI tool called LiteLLM. Well, the story got a lot bigger.</p>
<p class="ember-view reader-text-block__paragraph">CERT-EU has confirmed the European Commission's cloud infrastructure was breached using that same compromised version of Trivy, with initial access obtained on March 19th through normal software update channels. No one clicked anything dodgy. No one fell for a phishing email. They just updated their software.</p>
<p class="ember-view reader-text-block__paragraph">The attackers stole an AWS API key, got into the Commission's cloud accounts, and the stolen data, including emails and personal details, was subsequently published on the dark web by ShinyHunters. Up to 71 clients across EU institutions affected, over 300GB of data. And yes, ShinyHunters are the same group behind some of the biggest breaches of the last couple of years. Not surprising they're involved.</p>
<p class="ember-view reader-text-block__paragraph">Trivy led to LiteLLM, LiteLLM led to further targets, and the security scanner designed to keep systems safe became the weapon used to break in.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Your security tools are part of your attack surface</strong><span class="white-space-pre"> </span>- We said this last week and it just took down the European Commission. The tools you trust to protect you can become the way in if they're not protected themselves.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Software updates are now a threat vector</strong><span class="white-space-pre"> </span>- Nobody did anything wrong here in the traditional sense. They just updated their software. That's exactly what makes supply chain attacks so hard to defend against.</p>
<p class="ember-view reader-text-block__paragraph"><strong>One breach feeds the next</strong><span class="white-space-pre"> </span>- They didn't hit one target and stop. Each compromise was used to reach the next one. Patient, methodical, cascading. By the time anyone notices, the damage is already well beyond where it started.</p>
<h3 class="ember-view reader-text-block__heading-3">The White House Just Released an App. Security Researchers Are Not Happy About It.</h3>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=705" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://mashable.com/article/trump-new-white-house-app-security-privacy-nightmare" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">We're keeping the politics out of this one. If they want to release an app, they're entitled to. But the security angle here is worth knowing about regardless of where you stand on anything else.</p>
<p class="ember-view reader-text-block__paragraph">The Trump administration launched an official White House mobile app for iOS and Android, promising Americans unparalleled access with live streams, breaking alerts and real-time updates. What they didn't advertise was what the app does in the background.</p>
<p class="ember-view reader-text-block__paragraph">Security researchers who decompiled it found it sending users' IP addresses, timezone, device model, OS version and a persistent unique identifier to third-party servers on every single launch, despite the app's privacy label being completely blank and claiming it collects nothing. There's also GPS tracking infrastructure baked in that's currently dormant but can be switched on remotely. It's there. It just hasn't been turned on yet.</p>
<p class="ember-view reader-text-block__paragraph">A Russia-founded third-party software company whose components are baked into the app was also found exposing personal information belonging to some White House staffers. The White House said everything is safe and secure. Security researchers disagreed, loudly. In any other news cycle this would have been a scandal.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle -</strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Read the permissions before you download anything</strong><span class="white-space-pre"> </span>- This app asked for access to precise location, biometric fingerprint data and the ability to modify or delete your shared storage. Most people tap allow without looking. Those permissions are worth a few seconds of your time for any app, not just this one.</p>
<p class="ember-view reader-text-block__paragraph"><strong>A privacy label that says nothing can still mean a lot</strong><span class="white-space-pre"> </span>- Apps are supposed to declare what data they collect. This one said nothing. The reality was very different. If an app's privacy disclosure looks too clean, that's not always reassurance. Sometimes it's a red flag.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Official doesn't mean safe</strong><span class="white-space-pre"> </span>- A .gov badge doesn't automatically mean an app has been built securely or held to a higher standard. Apply the same scepticism to government apps as you would any other.</p>
<h3 class="ember-view reader-text-block__heading-3">Apple Just Added a Safety Net for One of the Cleverest Scams Around</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQExbGjXpYZhWw/article-inline_image-shrink_1000_1488/B4EZ1hkamVG8AU-/0/1775458430604?e=1776902400&amp;v=beta&amp;t=n2CozPXGCRicV3vsNjip6yb3HZISyMBLIAw3flkq4eI" onerror="this.style.display='none'"></span>Source: Reddit</p>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=1095" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.bleepingcomputer.com/news/security/apple-adds-macos-terminal-warning-to-block-clickfix-attacks/" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">We've talked about ClickFix on this podcast more times than we can count, and we've said for a while that what it really needs is an OS-level response. Apple just got there first.</p>
<p class="ember-view reader-text-block__paragraph">A new macOS feature now blocks potentially harmful commands from running when pasted into Terminal and shows a warning explaining that scammers commonly distribute malicious instructions through websites, chat agents, apps and phone calls. If you're on a Mac and you paste something suspicious into Terminal, you now get a pop-up that says "Possible malware, paste blocked" with a Don't Paste button as the main option.</p>
<p class="ember-view reader-text-block__paragraph">If you're not familiar with ClickFix, it's worth understanding. A fake pop-up tells you there's a problem with your computer. A Fix It button appears. Clicking it copies a command to your clipboard. You paste it into Terminal, hit enter, and you've just installed the malware yourself. ClickFix jumped by more than 500% in the first half of 2025, making it the second most common attack vector after phishing.</p>
<p class="ember-view reader-text-block__paragraph">The "paste anyway" option is still there, which Luke rightly pointed out maybe it shouldn't be, but it's a long overdue step in the right direction. Hopefully Windows follows.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle -<span class="white-space-pre"> </span></strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>The scam works because it uses your own hands against you</strong><span class="white-space-pre"> </span>- ClickFix bypasses most security software because you're the one running the command. The malware never has to sneak past anything. You let it in yourself, thinking you're fixing a problem.</p>
<p class="ember-view reader-text-block__paragraph"><strong>No legitimate website will ever ask you to open Terminal</strong><span class="white-space-pre"> </span>- That is the tell. If a website, pop-up, support chat or phone caller tells you to open Terminal or Command Prompt and paste something in, stop. That is the scam, every single time.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Apple's warning helps but don't rely on it alone</strong><span class="white-space-pre"> </span>- It's not yet clear exactly which commands trigger it, so it won't catch everything. The best protection is knowing what ClickFix looks like before you ever see it, which is exactly why we keep talking about it.</p>
<h3 class="ember-view reader-text-block__heading-3">App Privacy Labels Are Like Food Nutrition Labels - And We All Know How That's Going</h3>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=1415" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.darkreading.com/data-privacy/inconsistent-privacy-labels-not-enough" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">This one came up this week because of the White House app, and it's a comparison that really stuck with us.</p>
<p class="ember-view reader-text-block__paragraph">Lorrie Cranor, director of Carnegie Mellon University's CyLab Security and Privacy Institute, says app privacy labels, the data disclosures you see on the App Store and Google Play, are basically the nutrition labels on a packet of crisps. In theory they help you make an informed choice. In practice, she says the current versions are not at all useful and, worse, they create the impression that something meaningful is being done for your privacy when it actually isn't.</p>
<p class="ember-view reader-text-block__paragraph">Studies have found widespread inaccuracies in the labels. Apple and Google don't even use the same definitions for what counts as data collection. Google defines it as any data transmitted from your device. Apple only counts it if that data is also stored. The same app can look completely different depending on which store you're looking at.</p>
<p class="ember-view reader-text-block__paragraph">We saw a live example of this exact week. The White House app declared it collected nothing, while quietly sending device data to multiple third parties on every single launch.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle -<span class="white-space-pre"> </span></strong></p>
<p class="ember-view reader-text-block__paragraph"><strong>Labels are only useful if they're accurate</strong><span class="white-space-pre"> </span>- The privacy label on an app is the closest thing you have to informed consent before downloading. Most people never check it, and research shows many labels don't reflect what apps actually do anyway.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Compliance isn't the same as protection</strong><span class="white-space-pre"> </span>- Companies post these labels for information purposes. A label existing doesn't mean your data is safe. There was a time when everyone said smoking was good for you. Look how that turned out.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Even the experts say read the privacy policy</strong><span class="white-space-pre"> </span>- If you genuinely want to know what an app does with your data, the full privacy policy is still your best bet. Nobody said it was fun, but it's the honest answer.</p>
<h3 class="ember-view reader-text-block__heading-3">Phish of the Week</h3>
<p class="ember-view reader-text-block__paragraph"><em>Thanks as always to the threat intelligence team at<span class="white-space-pre"> </span></em><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.linkedin.com/company/hoxhunt/" data-turbo="false">Hoxhunt</a><span class="white-space-pre"> </span><em>for sharing this week's example.</em></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQGRLkY4H4VFhg/article-inline_image-shrink_1000_1488/B4EZ1hpZn9I0AU-/0/1775459738246?e=1776902400&amp;v=beta&amp;t=ZsYn3KOpJ0v8PIc3dVxiKuAHzD8A5O7Lr85i3euBKIw" onerror="this.style.display='none'"></span>This is a phish with many gills....</p>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=2694" target="_self" data-turbo="false"><strong>Watch</strong></a></p>
<p class="ember-view reader-text-block__paragraph">This one's a salary increase notification, and it's more sophisticated than it first looks.</p>
<p class="ember-view reader-text-block__paragraph">The email lands with your company logo, your name, and a message saying a new policy has been added: a salary increase, effective a specific recent date. To access the updated documentation, scan the QR code below. At the bottom, there's a yellow confidentiality banner telling you not to share the link or access code with anyone else. That detail is doing a lot of work. It's nudging you to keep quiet and not check with a colleague.</p>
<p class="ember-view reader-text-block__paragraph">Here's the bit that caught us off guard when we scrolled further down on the episode: it's not just a credential capture page. Scanning the QR code takes you to a fake DocuSign page where you're given a signing code. Clicking continue takes you to a legitimate Microsoft website and a real device authentication window. The attack isn't stealing your password. It's getting you to authorise access to your device entirely. That's device code phishing.</p>
<p class="ember-view reader-text-block__paragraph">And there's a red flag right at the start that most people will miss. The phishing email itself is completely empty. The actual attack arrives as a .eml file attached to a blank email. That's not normal. If you see an empty email with an email file attached, don't open it.</p>
<p class="ember-view reader-text-block__paragraph">Hoxhunt flagged the fake salary lure as the primary hook, playing into exactly the kind of emotion that makes people act before they think, and the QR code as a deliberate choice to move you off your work device and onto your phone, away from whatever security controls your organisation has in place.</p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points...</h2>
<p class="ember-view reader-text-block__paragraph">Chinese hackers breach the FBI's wiretap surveillance system<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=100" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://thehill.com/policy/technology/5815310-fbi-data-breach-surveillance-system-major-incident/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Trivy supply chain attack leads to European Commission data breach<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=435" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.securityweek.com/european-commission-confirms-data-breach-linked-to-trivy-supply-chain-attack/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">The White House app: what security researchers actually found<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=705" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://mashable.com/article/trump-new-white-house-app-security-privacy-nightmare" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Apple adds macOS Terminal warning to block ClickFix paste attacks<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=1095" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.bleepingcomputer.com/news/security/apple-adds-macos-terminal-warning-to-block-clickfix-attacks/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">App privacy labels are not as useful as you think<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=1415" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.darkreading.com/data-privacy/inconsistent-privacy-labels-not-enough" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Google Drive ransomware detection and file restoration now generally available<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=1720" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.androidauthority.com/google-drive-ransomware-detection-file-restoration-3653354/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">LinkedIn secretly scanning 6,000+ Chrome extensions and collecting data<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=2151" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.bleepingcomputer.com/news/security/linkedin-secretely-scans-for-6-000-plus-chrome-extensions-collects-data/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">WhatsApp used to deliver malware to Windows PCs<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=2471" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://thehackernews.com/2026/04/microsoft-warns-of-whatsapp-delivered.html" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Phish of the Week: QR code salary increase leading to device code phishing<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=2694" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">SMS delivery scam in the wild<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3042" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Sloppypasta: AI-generated content and why it makes you easier to scam<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3426" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://stopsloppypasta.ai/" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Artemis II has two broken instances of Outlook and NASA had to remote in<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3724" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://bsky.app/profile/did:plc:jzhiqz7fb5dj6h7cydluryvn/post/3miik2wzosk25" target="_self" data-turbo="false">Bluesky</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Artemis II is running Microsoft 365 in space<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3834" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.bbc.co.uk/news/articles/cy51wzeq6g5o" target="_self" data-turbo="false">Read</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Artemis II astronaut enters PIN code on live stream<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3883" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCKNPtr/" target="_self" data-turbo="false">Watch on TikTok</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Apple Passwords app ad<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=4003" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCwvJYD/" target="_self" data-turbo="false">Watch on TikTok</a><span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">Supply chain attack explainer video<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=4198" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCoQBp2/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>And Finally...</strong></p>
<p class="ember-view reader-text-block__paragraph">Artemis II is orbiting the moon. The astronauts are running Windows. They have two instances of Outlook installed and neither of them work. NASA had to remote in to sort it out. Anthony's take: we've sent people round the moon and we're relying on Outlook for email up there. Luke's take: why do they even need Outlook? There's live chat for that. Both valid.<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3724" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://bsky.app/profile/did:plc:jzhiqz7fb5dj6h7cydluryvn/post/3miik2wzosk25" target="_self" data-turbo="false">Bluesky</a></p>
<p class="ember-view reader-text-block__paragraph">Which led to the obvious question. Can you imagine being phished while orbiting? A QR code salary increase lands in your inbox, you scan it on your phone, and suddenly someone's got remote access to a Windows tablet in space. We have a Phish of the Week for exactly that scenario this week. Coincidence. Probably.<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3724" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">One of the astronauts also entered their PIN code on live stream, just before launch, in full view of the cameras. It's out there now. Luke pointed out it's probably just policy baked into the device build. Anthony pointed out they could have been given an exception.<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=3883" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCKNPtr/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">Luke also shared Apple's latest ad promoting the built-in Passwords app — good awareness content, and a reminder that if your organisation runs Apple devices without MDM, staff may now be storing corporate passwords somewhere you can't see.<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=4003" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCwvJYD/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">And finally, a really nicely produced TikTok on supply chain attacks by Lewis Menloe. Worth sharing with your team, and worth watching if you make awareness content yourself — great example of what you can do with an iPhone and one decent light.<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://youtu.be/ZjY-_uw9ZNw?t=4198" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://vm.tiktok.com/ZNRCoQBp2/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="mailto:hello@riskycreative.com" target="_self" data-turbo="false"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.linkedin.com/in/infosecant/" target="_self" data-turbo="false"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.linkedin.com/in/lukejpme/" target="_self" data-turbo="false"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="FdXhzrorDWaLBTOKnIPUgpKMTuZMYEpxBU " href="https://www.linkedin.com/company/riskycreative/" target="_self" data-turbo="false"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/222829?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/222829?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F222829%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F222829%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_220955">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/220955/watch_times"
  data-youtube-player-video-id-value="3UJkXvfcxNw"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/3UJkXvfcxNw/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/220955">
          Mar 30, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/220955">
            Ajax Season Tickets Stolen, OpenAI Kills Sora &amp; Apple's Age Verification Explained
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p>This week we've got a hack that let strangers steal your season tickets and quietly erase stadium bans at one of Europe's biggest football clubs. The AI app with a billion-dollar Disney deal that vanished in six months. Meta's finally fighting back against scammers with AI. And Apple wants to know how old you are.</p>
<p>All that and more on this week's The Awareness Angle.</p>
<p><br></p>
<p>The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke give you straight talking cyber news for people who actually care about the human side of security.</p>
<p>🎧 Listen on your favourite podcast platform - <a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6?si=fdfa4d2fe0d4403c" data-turbo="false">Spotify,</a><span> </span><a href="https://podcasts.apple.com/gb/podcast/the-awareness-angle/id1784126196" data-turbo="false">Apple Podcasts</a><span> </span>and<span> </span><a href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" data-turbo="false">YouTube</a></p>





























<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank"><span><img class="img" height="150" src="https://storage.mlcdn.com/account_image/769696/sUoDecU44zz9KmMsr60hR8bNOrdlgpgPvFbnGFmO.png" width="150" onerror="this.style.display='none'"></span></a>


<h2><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank">Listen Now</a></h2>
<span><a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank">Podcast · Risky Creative</a></span>

<a href="https://open.spotify.com/show/7rwzcRsKrXbASFBfiXoCZ6" rel="noopener" target="_blank"><span><img class="img" height="48" src="https://assets.mlcdn.com/ml/images/video/play_btn_green.png" width="48" onerror="this.style.display='none'"></span></a>





































































<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/pGrKvQ4i00sfBFcLuRm2L4VnYFg3ttwmbAG3VZkV.jpg" width="540" onerror="this.style.display='none'"></span>

























<p>If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p>The<span> </span><a href="https://www.linkedin.com/showcase/sansworkforce/" data-turbo="false">SANS Workforce Security &amp; Risk Training</a><span> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is this Friday, 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p>The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p>And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p>If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p>The deadline is the 3rd of April. Two weeks. Get your submission in.</p>
<p>Submit your proposal<span> </span><a href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_self" data-turbo="false">here</a>. Get more information on the summit<span> </span><a href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_self" data-turbo="false">here.</a></p>






















<h2>This week's stories...</h2>
<h3>Ajax Amsterdam hack exposed fan data, allowed attackers to steal season tickets and lift stadium bans</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=91" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/" target="_self" data-turbo="false">Read</a></p>
<p>Ajax Amsterdam didn't find out about their own security breach from their security team. They found out from journalists. A hacker had been poking around their systems, and tipped off the press before the club had any idea there was a problem.</p>
<p>What the hacker found was pretty significant. Every user of the Ajax app shared the same digital key. By tweaking a single request, you could act as any other user entirely. Transfer their season ticket to yourself. Change their account details. Or, and this is where it gets a bit darker, quietly remove their stadium ban. As Luke and I discussed on the episode, imagine a bunch of banned supporters suddenly finding themselves back inside the ground for one match. It's got a Channel 4 drama written all over it.</p>
<p>The ticket theft is frustrating. The ban removal is a safety issue. And the fact that Ajax only found out because of a journalist is a reminder that knowing something's gone wrong matters just as much as trying to stop it happening in the first place. The vulnerabilities have since been patched and the Dutch Data Protection Authority and police have been informed.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>Ajax found out from a journalist, not their own systems</strong><span> </span>- The hacker tipped off the press before Ajax even knew there was a problem. If they'd been in it for money instead of attention, hundreds of thousands of fans could have been affected before anyone noticed. Knowing something's wrong matters just as much as stopping it happening in the first place.</p>
<p><strong>It wasn't a sophisticated hack, just a design flaw</strong><span> </span>- Every Ajax app user shared the same digital key. Change one thing in a request and you could act as someone else entirely, transfer their ticket, change their details. No advanced tools required. Some of the worst breaches are just unlocked doors.</p>
<p><strong>Lifting stadium bans is a safety issue, not just a data issue</strong><span> </span>- Those bans exist for a reason. The idea that someone could have quietly removed them, with neither the club nor the banned person knowing, is the kind of consequence you won't find in any data breach notification.</p>
<h3><br></h3>
<h3>Meta launches new anti-scam tools across WhatsApp, Facebook and Messenger using AI</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=277" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://about.fb.com/news/2026/03/meta-launches-new-anti-scam-tools-deploys-ai-technology-to-fight-scammers-and-protect-people/" target="_self" data-turbo="false">Read</a></p>
<p>It feels like at last. Meta has announced a batch of new anti-scam features across WhatsApp, Facebook and Messenger, and some of them are genuinely useful. On WhatsApp, there's a new warning when someone tries to get you to link your account to another device, which is a scam we've talked about on the show before. On Facebook, you'll start seeing alerts when a new friend request comes from an account that looks suspicious, with details like how recently the account was created and whether you have any mutual friends. Messenger is getting AI-powered detection that flags conversations showing signs of a scam, like out-of-nowhere job offers, and gives you the option to review it before you go any further.</p>
<p>Meta also says it removed 159 million scam ads in 2025. Which sounds impressive until you remember how many scam ads we all still see every week. Luke put it well on the episode: it's probably not going to scratch the surface. But it does feel like a shift. For a long time it seemed like these platforms weren't really trying. At least now they are.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>AI being used to fight AI</strong><span> </span>- Scammers use AI to make their attacks more convincing. Platforms like Meta are now fighting back with the same tools. It's an arms race, and these features show the platforms you use every day are at least trying to keep up.</p>
<p><strong>The WhatsApp device linking scam is one to know about</strong><span> </span>- Someone tricks you into sharing a code or scanning a QR code, and suddenly they've got full access to your WhatsApp on their device. The new warning gives you a moment to pause before that happens. If anyone ever asks you to scan or share a WhatsApp code for any reason, that's a red flag.</p>
<p><strong>159 million scam ads is a staggering number</strong><span> </span>- And that's just what they caught. Even with all that, some still get through. A polished ad on Facebook or Instagram is not proof that something is legitimate.</p>
<p><br></p>
<h3>OpenAI shuts down Sora video app and Disney pulls its $1 billion investment deal</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=608" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://variety.com/2026/digital/news/openai-shutting-down-sora-video-disney-1236698277/" target="_self" data-turbo="false">Read</a></p>
<p>Remember Sora? It launched six months ago, hit a million downloads in under five days, and came with a billion-dollar deal for Disney to license characters like Mickey Mouse and Cinderella. Now it's gone. OpenAI has shut it down entirely, exiting the video generation business to focus on other things, reportedly as part of tidying up its product range ahead of a potential stock market listing.</p>
<p>Disney is walking away from the deal completely. Which is a bit ironic given that before they agreed to it, they'd been sending legal letters to Meta, Google and Character[.]AI over AI using their characters without permission. The thinking seemed to be: if you can't beat them, get in there and own a piece of it. That didn't work out.</p>
<p>On the episode I raised whether this might be a pause rather than a permanent shutdown. The tech still exists. And if AI tools start needing less computing power to run, which there are signs of, something like Sora could come back under a different name. In the meantime, the people who were using it will just move to other tools, many of which aren't subject to the same kind of oversight. So the AI slop problem on your social feeds probably isn't going anywhere.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>AI tools can disappear overnight</strong><span> </span>- Sora had a billion-dollar deal and a million downloads in five days. Six months later it's gone. If you've built anything around an AI tool, whether that's a workflow, a business or just a habit, it's worth remembering these things can vanish with very little notice.</p>
<p><strong>Copyright and AI is still a mess</strong><span> </span>- Disney was sending legal letters to Meta, Google and Character[.]AI over AI using its characters before doing the Sora deal. Now that deal's fallen apart too. The question of what AI can and can't do with other people's creative work is no closer to being answered.</p>
<p><strong>AI-generated video is getting harder to spot, not easier</strong><span> </span>- One of the issues with Sora was the volume of low-quality, misleading video it made easy to create. That problem doesn't go away just because Sora does. Other tools will fill the gap.</p>
<p><br></p>
<h3>Apple rolls out age verification to UK iPhone users</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=1303" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://therecord.media/apple-rolls-out-age-verification-uk-iphone-users" target="_self" data-turbo="false">Read</a></p>
<p>Apple is rolling out age verification for UK users as part of a recent iOS update. To access certain features, you'll need to confirm you're over 18, either through payment details already on your account or by submitting ID. If you don't, or if you're under 18, web content filters will switch on automatically.</p>
<p>This is being driven by the UK's regulator Ofcom and the Information Commissioner's Office, who have been pushing platforms hard to keep children off certain types of content. Apple says it's a legal requirement in some regions, and this is their response.</p>
<p>On the episode we had a few questions about it. Where does the verification data actually go? Does it stay on the device, inside Apple's secure enclave, or does it go back to Apple's servers? We don't have a clear answer on that yet. I'm on the iOS beta and haven't been prompted yet, so we may come back to this one as it rolls out properly. What we do know is that a change this big and this unfamiliar is exactly the kind of thing scammers will try to piggyback on very quickly.</p>
<p><strong>The Awareness Angle -</strong></p>
<p><strong>You're handing over more data to prove you're allowed to use your own phone</strong><span> </span>- To access certain features, users will now need to submit ID or payment details. That raises fair questions about what gets stored and what happens if it's ever breached.</p>
<p><strong>This is probably just the start</strong><span> </span>- It's not just Apple. Regulators across the UK and beyond are pushing for age checks to become standard across apps and services. This is likely to become the norm, not the exception.</p>
<p><strong>Scammers will jump on this straight away</strong><span> </span>- A new, unfamiliar prompt asking people to verify their age is exactly the kind of thing that gets turned into a phishing campaign. Expect fake "your verification has expired" messages pretty quickly. If you're communicating this to colleagues or customers, show them what the real thing looks like before the fakes start circulating.</p>



























































<h2>Hoxhunt Phish Of The Week</h2>
<p><em>Thanks as always to the threat intelligence team at<span> </span></em><a href="https://www.hoxhunt.com/" rel="noopener" target="_blank">Hoxhunt</a><span> </span><em>for sharing this week's example.</em></p>

























<span><img class="img" alt="" src="https://storage.mlcdn.com/account_image/769696/AiWTrbgLZGyzvRph89yq4mt6SrZNHDzbXpdcIACn.png" width="540" onerror="this.style.display='none'"></span>






















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" rel="noopener" target="_blank"></a><br></p>
<p><a href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_self" data-turbo="false"></a><br></p>
<p><a href="https://youtu.be/oboBJxlM4Nc?t=2687" target="_self" data-turbo="false"></a><br></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" rel="noopener noreferrer" data-turbo="false"></a><a href="https://youtu.be/8pdtibfvNvo?t=2104" rel="noopener" target="_blank"></a><br></p>
<p><a href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_self" data-turbo="false"></a><br></p>
<h3>ChatGPT impersonation - fake subscription invoice</h3>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=2246" rel="noopener" target="_blank">Watch</a></p>
<p>This week's phish is impersonating ChatGPT Plus. The email mimics a subscription invoice notification using ChatGPT branding and a generic layout, claims your invoice is ready for review, and asks you to click a "Verify Invoice Details" button. The button leads to a malicious website. The message creates urgency by suggesting you'll lose access to your subscription if you don't act.</p>
<p>What makes this one worth flagging is that you don't even need to be a ChatGPT subscriber to fall for it. If you're not a subscriber and you get an email saying you've been charged, the instinct is to click quickly and sort it out. That's exactly what they're counting on.</p>
<p>Red flags to watch for:</p>
<ul>
<li>An unexpected invoice or subscription notification you weren't expecting</li>
<li>Generic billing language with no specific details, just a button</li>
<li>Urgency around losing access if you don't act immediately</li>
<li>A "verify" link in the email rather than directing you to log in directly</li>
</ul>
<p>As always, if you get a billing alert for any service, go directly to the website by typing the address yourself. Don't click the link in the email.<br></p>
<ul></ul>
<ul></ul>



























































<h2>This Week's Discussion Points...<br>
</h2>
<p><br></p>
<p>Ajax Amsterdam hack exposed fan data, allowed attackers to steal season tickets and lift stadium bans<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=91" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/" target="_self" data-turbo="false">Read</a></p>
<p>Meta launches new anti-scam tools across WhatsApp, Facebook and Messenger using AI<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=277" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://about.fb.com/news/2026/03/meta-launches-new-anti-scam-tools-deploys-ai-technology-to-fight-scammers-and-protect-people/" target="_self" data-turbo="false">Read</a></p>
<p>OpenAI shuts down Sora video app and Disney pulls its $1 billion investment deal<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=608" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://variety.com/2026/digital/news/openai-shutting-down-sora-video-disney-1236698277/" target="_self" data-turbo="false">Read</a></p>
<p>How a poisoned security scanner became the key to backdooring LiteLLM<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=863" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://snyk.io/articles/poisoned-security-scanner-backdooring-litellm/" target="_self" data-turbo="false">Read</a><span> </span>Apple rolls out age verification to UK iPhone users<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1303" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://therecord.media/apple-rolls-out-age-verification-uk-iphone-users" target="_self" data-turbo="false">Read</a></p>
<p>TikTok for Business accounts targeted in new phishing campaign<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1593" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/" target="_self" data-turbo="false">Read</a></p>
<p>Lloyds app glitch let 447,000 customers see each other's transactions<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=1946" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.theregister.com/2026/03/27/lloyds_app_glitch_turned_transactions/" target="_self" data-turbo="false">Read</a></p>
<p>Phish of the Week: ChatGPT impersonation - fake subscription invoice<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2181" target="_self" data-turbo="false">Watch</a></p>
<p>How do you deal with users who refuse to lock their laptop?<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2577" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.reddit.com/r/cybersecurity/s/ddlf3pv5BX" target="_self" data-turbo="false">Reddit</a></p>
<p>Six top tips for parents to keep children safe online<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=2912" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://viewonline.lgfl.net/hubfs/SafeguardED/Posters/LGfL-SafeguardED-Poster-A3-Parent-Top-Tips.pdf" target="_self" data-turbo="false">Read</a></p>
<p>The Phisherman - free online safety game for kids<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3089" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://barefootgames.org/the-phisherman" target="_self" data-turbo="false">Read</a></p>
<p>Spot a deepfake using one sentence<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3295" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRQ9mCLP/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p>Real smishing campaign in France with personalised parcel photos<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3500" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.linkedin.com/posts/maximecartier_this-is-a-real-smishing-campaign-currently-share-7442492225252499456-9GgZ" target="_self" data-turbo="false">LinkedIn</a></p>
<p>French military Strava exposure<span> </span><a href="https://youtu.be/3UJkXvfcxNw?t=3647" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRxrrFdB/" target="_self" data-turbo="false">Watch on TikTok</a><br></p>



























































<h2>Security Socials</h2>



















<p><a href="https://youtu.be/QsoH3G7GfU0?t=2029" rel="noopener" target="_blank"></a><br></p>
<p><a href="https://youtu.be/lWZGOf0NpA8?t=3452" target="_self" data-turbo="false"></a><br></p>
<p><a href="https://youtu.be/oboBJxlM4Nc?t=2687" target="_self" data-turbo="false"></a><br></p>
<p><a href="https://youtu.be/edRdK5HrKlw?t=2680" rel="noopener noreferrer" data-turbo="false"></a><a href="https://youtu.be/8pdtibfvNvo?t=2104" rel="noopener" target="_blank"></a><br></p>
<h3>Anthony's Security Social</h3>
<p>This week I've got a few things for you.</p>
<p>First, I spotted a poster at my kids' school that I thought was worth sharing. It's from<span> </span><a href="https://www.linkedin.com/showcase/lgfl-safeguarded/" data-turbo="false">LGfL - SafeguardED</a><span> </span>and it's called Six Top Tips for Parents to Keep Your Children Safe Online. What I liked about it was the approach. Rather than the usual "ban everything and panic," it leads with something refreshing: don't worry about screen time, aim for screen quality. Scrolling through social media isn't the same as making a film, learning something new, or video calling grandma. There's also a nudge to check safety settings across devices, consoles and apps, to get your kids to show you what they're doing and who they're doing it with, and to talk to them about scary things in the news rather than shielding them from it. Worth sharing with parents in your organisation.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=2912" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://viewonline.lgfl.net/hubfs/SafeguardED/Posters/LGfL-SafeguardED-Poster-A3-Parent-Top-Tips.pdf" target="_self" data-turbo="false">See the poster</a><span> </span>|<span> </span><a href="https://lgfl.net/safeguarding" target="_self" data-turbo="false">More on SafeguardED</a></p>
<p>Second, my 11-year-old mentioned she and a friend wanted to start a games company called Barefoot Games one day, so naturally I Googled it. What I found was The Phisherman, a free online game for kids from<span> </span><a href="https://www.linkedin.com/showcase/barefoot-computing/" data-turbo="false">Barefoot Computing</a><span> </span>and<span> </span><a href="https://www.linkedin.com/company/bt/" data-turbo="false">BT Group</a>. It's an underwater adventure where kids earn cyber points by identifying phishing threats and learning what personal information looks like. It's gamified, it's accessible, and I'd never heard of it before. If you've got kids or you work in an organisation with parents (which is most of us), share this. It's a genuinely good tool for starting a conversation about online safety.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3089" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://barefootgames.org/the-phisherman" target="_self" data-turbo="false">Read</a></p>
<p>Third, I shared a TikTok this week of someone spotting a deepfake live on a video call using just one technique. He asked the person on the other end to hold three fingers up to the side of their face. Deepfake overlays struggle with objects interacting with the face like that and the result was pretty telling. The video has gone viral for a reason. It's a simple, memorable test that anyone can use if they're ever unsure whether the person they're talking to is real. Worth filing away.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3295" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRQ9mCLP/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<p>And last, a LinkedIn post from<span> </span><a href="https://www.linkedin.com/in/maximecartier/" data-turbo="false">Maxime Cartier</a><span> </span>at Hoxhunt that caught my eye this week. It shows a real smishing campaign circulating in France with a twist. It's a fake delivery notification, but instead of just a text, it includes a photo of a package with the recipient's name and full home address on the label, and a personalised link. The image makes it feel immediately real. You don't just read the message. You see your parcel. Maxime's friend assumed it was AI, but it looks more like a simple image template with text overlay. Either way, the point stands: scammers are personalising attacks with visual cues that our brains trust instantly. This is where it's going.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3500" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://www.linkedin.com/posts/maximecartier_this-is-a-real-smishing-campaign-currently-share-7442492225252499456-9GgZ" target="_self" data-turbo="false">LinkedIn</a></p>
<h3>Luke's Security Social</h3>
<p>This week Luke shared a TikTok showing French military personnel on what appeared to be a ship, with their Strava activity visible and their location effectively public. This isn't the first time this has happened. Back in 2018, British soldiers inadvertently revealed the location of a semi-secret military camp through their Strava data. Strava does now blur your starting point, but that only goes so far. If you're a service member or working in a sensitive environment, a fitness app with public settings on could give away far more than your split times. The broader lesson for everyone is worth repeating though: think about what your apps are sharing, with whom, and whether the default settings actually reflect what you want.</p>
<p><a href="https://youtu.be/3UJkXvfcxNw?t=3647" target="_self" data-turbo="false">Watch</a><span> </span>|<span> </span><a href="https://vm.tiktok.com/ZNRxrrFdB/" target="_self" data-turbo="false">Watch on TikTok</a></p>







</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/220955?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/220955?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F220955%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F220955%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_218478">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/218478/watch_times"
  data-youtube-player-video-id-value="9n-ewD0zZuU"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/9n-ewD0zZuU/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/218478">
          Mar 23, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/218478">
            Chrome Malware, 8 Million Tips Exposed &amp; Japan Legalises Hacking Back
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week on The Awareness Angle - a US general leaves maps on a train. A Chrome extension with a million users and Google's own seal of approval was quietly skimming your shopping commissions for months. Companies House left a gap in their system for five whole months that anyone could exploit just by pressing the back button. Eight million crime tips that were promised to be anonymous turned out to be anything but. New Android malware is hiding in dodgy streaming apps and going straight for your notes. And Japan has decided it's time to start hitting back.</p>
<p class="ember-view reader-text-block__paragraph">The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke give you straight talking cyber news for people who actually care about the human side of security.</p>
<p><a href="https://youtu.be/9n-ewD0zZuU" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQHdx9OkLB9cdw/article-inline_image-shrink_1500_2232/B4EZ0PRcCYI4AU-/0/1774077725332?e=1775692800&amp;v=beta&amp;t=1MeW1GLoRwWfWI4fEkGeRjiBRJJZHlOfjGhVK_X8s_o" onerror="this.style.display='none'"></span></a>Click to watch this week's episode</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQFd9cVyLoALRQ/article-inline_image-shrink_1000_1488/B4EZ0PRm2bJUAU-/0/1774077767634?e=1775692800&amp;v=beta&amp;t=N_hIoLimD2U3wwW0IWfg_aT-Z_F3GP_nCC98xiTKAAI" onerror="this.style.display='none'"></span></p>
<h3 class="ember-view reader-text-block__heading-3">The deadline is the 3rd of April. Two weeks. Get your submission in</h3>
<p class="ember-view reader-text-block__paragraph">If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p class="ember-view reader-text-block__paragraph">The<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/showcase/sansworkforce/" target="_self" data-turbo="false"><strong>SANS Workforce Security &amp; Risk Training</strong></a><span class="white-space-pre"> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is Friday 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p class="ember-view reader-text-block__paragraph">The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p class="ember-view reader-text-block__paragraph">And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p class="ember-view reader-text-block__paragraph">If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p class="ember-view reader-text-block__paragraph">Submit your proposal<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_self" data-turbo="false"><strong>here</strong></a>. Get more information on the summit<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_self" data-turbo="false"><strong>here.</strong></a></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">BREACH OF THE WEEK - The General, The Wine, and The Classified Maps</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=107" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://kyivindependent.com/former-us-commander-in-charge-of-security-assistance-to-ukraine-left-classified-maps-on-train-overindulged-in-alcohol-watchdog-finds/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Major General Antonio Aguto Jr. was the man leading US military assistance efforts to Ukraine. In March 2024, he left classified maps on a Ukrainian train. Not because he was hacked, not because of a sophisticated cyberattack, but because he didn't follow the courier protocol that exists for exactly this reason. The documents sat on the train, unattended, until the US embassy retrieved them the following day.</p>
<p class="ember-view reader-text-block__paragraph">Two months later, he got through the best part of two bottles of wine at a Kyiv dinner, sustained a concussion from the falls that followed, and showed up to meet Secretary of State Blinken the next morning. A 50-page Inspector General report, triggered by three anonymous complaints, covers the whole sorry story. He retired in August 2024.</p>
<p class="ember-view reader-text-block__paragraph">We don't really care about the drinking. We care about the maps.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Procedure exists for a reason</strong><span class="white-space-pre"> </span>- The courier protocol wasn't red tape. It was the thing standing between classified documents and a Ukrainian train seat. Shortcuts under pressure are where breaches live.</li>
<li>
<strong>Impairment in high-trust roles</strong><span class="white-space-pre"> </span>- Organisations talk a lot about insider threats. They rarely talk about what happens when someone with top-level access simply has a bad night. Most have no real mechanism for catching it.</li>
<li>
<strong>Anonymous reporting worked here</strong><span class="white-space-pre"> </span>- Three complaints. That's all it took to open a 50-page investigation. Whistleblower channels work when people trust them enough to use them.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">New Android malware is going through your notes</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=742" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://therecord.media/malware-streaming-apps-android" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Here's one for anyone who keeps passwords in their Notes app. Researchers at ThreatFabric have found a new Android malware called Perseus, hiding inside apps that look like IPTV streaming services. Once it's on your device it does the usual - fake login screens, keylogging etc. But then it does something a bit different. It goes straight for Google Keep and Evernote, pulling out whatever's stored there. Passwords, financial details, account recovery phrases. The stuff people stick in notes because it's convenient.</p>
<p class="ember-view reader-text-block__paragraph">Because IPTV apps are usually downloaded outside the Play Store, the people installing them are already in the habit of skipping the security checks. Perseus knows this.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Your notes app is not a password manager</strong><span class="white-space-pre"> </span>- Convenient, yes. Secure, no. Perseus proves attackers are actively targeting notes apps because they know that's where people hide things they shouldn't.</li>
<li>
<strong>Sideloading is where the risk lives</strong><span class="white-space-pre"> </span>- Apps outside official stores don't go through security checks. Using IPTV apps to watch football for free is exactly the kind of habit that ends with malware on your phone.</li>
<li>
<strong>Old malware never really dies</strong><span class="white-space-pre"> </span>- Perseus is built on Cerberus, a trojan whose source code leaked in 2020. Six years later it's back, repurposed and improved. Old threats get recycled. New actors pick them up.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">672,000 people's bank data stolen, and they waited seven months to tell them</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1258" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://techcrunch.com/2026/03/18/marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Marquis is a fintech company most people have never heard of. It serves over 700 banks and credit unions, handling their data analytics and marketing. In August 2025, it was hit by ransomware. Names, dates of birth, addresses, Social Security numbers, bank account details, card details, all gone. 74 banks disrupted. 36 class action lawsuits filed.</p>
<p class="ember-view reader-text-block__paragraph">The people whose data was stolen found out seven months later.</p>
<p class="ember-view reader-text-block__paragraph">Marquis has sued its firewall provider SonicWall, blaming a vulnerability in SonicWall's cloud backup service for giving the attackers a way in. SonicWall hasn't commented publicly.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Third-party vendors are a single point of failure</strong><span class="white-space-pre"> </span>- Most people whose data was in this breach had never heard of Marquis. Their bank used Marquis. That was enough. One supplier, hundreds of institutions, hundreds of thousands of people.</li>
<li>
<strong>Seven months is too long</strong><span class="white-space-pre"> </span>- Stolen financial data moves fast. The people affected spent seven months exposed without knowing it. Notification timelines matter.</li>
<li>
<strong>Suing your supplier doesn't help your customers</strong><span class="white-space-pre"> </span>- Marquis pointing the finger at SonicWall might play out in court. It doesn't change anything for the 672,000 people whose Social Security numbers are now out there.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">Google Featured it. It was stealing from you.</h3>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1894" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/YouShouldKnow/comments/1rw65o8/ysk_a_popular_browser_extension_called_save_image/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">"Save Image as Type" was a genuinely useful Chrome extension. Over a million users. A Featured badge from Google, the thing that's you'd assume meant it'd been checked and it's safe. Then it changed hands. The new owners quietly updated it with code that hijacked affiliate links, redirecting shopping commissions from Amazon, Adidas and Shein to themselves. The malicious behaviour only kicked in after you'd saved at least 10 images, specifically to avoid detection.</p>
<p class="ember-view reader-text-block__paragraph">Microsoft Edge had removed the same extension a year earlier. Google kept featuring it until March 2026.</p>
<p class="ember-view reader-text-block__paragraph">Anthony had it installed. He removed it live on air.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A Featured badge is not a safety guarantee</strong><span class="white-space-pre"> </span>- Google's own stamp of approval didn't catch this for months after Edge flagged it. Trust the badge less than you think you should.</li>
<li>
<strong>Extensions update themselves silently</strong><span class="white-space-pre"> </span>- The original extension was fine. Then it changed hands, the code changed, and nothing told you. That's the problem with extensions, you install them once and forget they exist.</li>
<li>
<strong>Browser extensions have sweeping access</strong><span class="white-space-pre"> </span>- This one only went after affiliate commissions. The same access could have harvested your passwords, injected malware, read everything you typed. Go through your extensions. Remove anything you don't actively use.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">Phish Of The Week</h2>
<p class="ember-view reader-text-block__paragraph">Brought to you by the threat intelligence team at Hoxhunt</p>
<p class="ember-view reader-text-block__paragraph"><strong>Emirates Airline Impersonation - Loyalty Reward Notification</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQEghl34wLX7RQ/article-inline_image-shrink_1500_2232/B4EZ0PVrn5J0AU-/0/1774078836193?e=1775692800&amp;v=beta&amp;t=1iZkGiDUWWxT9x91-2cc71E8teFenpLXGy7kIZJa2Mw" onerror="this.style.display='none'"></span>Legitimate services used to send phishes...yeah, that's a thing!<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">This one's sneaky because it arrives from a real email address. noreply@campaign[.]eventbrite[.]com is a legitimate Eventbrite domain. Someone has simply set up an event on Eventbrite with Emirates branding and used the platform's mailing functionality to send the phish. The sender name reads "Emirates Millies" - RN rendered close together in certain fonts looks like M, a trick we've seen used against Microsoft too.</p>
<p class="ember-view reader-text-block__paragraph">Inside: the Emirates logo, a loyalty reward of AED 498.20, and a link that deliberately won't open when clicked. That's not a bug. The attacker has disabled it because clickable links get scanned by security tools automatically. Copy and paste it manually and you land on a fake Emirates login page, credential harvesting in progress.</p>
<p class="ember-view reader-text-block__paragraph"><strong>The Awareness Angle</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>The sender name doesn't match the platform</strong><span class="white-space-pre"> </span>- Emirates doesn't send loyalty notifications via Eventbrite. Full stop.</li>
<li>
<strong>The link won't click</strong><span class="white-space-pre"> </span>- Deliberate. They want you to bypass your own security tools by doing the work manually.</li>
<li>
<strong>The body text uses disguised characters</strong><span class="white-space-pre"> </span>- Some letters are pulled from different character sets to slip past spam filters. If the text looks slightly off or inconsistent, trust that instinct.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Discussion Points</h2>
<p class="ember-view reader-text-block__paragraph">Former US general got drunk in Kyiv, left classified maps on a train<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=107" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://kyivindependent.com/former-us-commander-in-charge-of-security-assistance-to-ukraine-left-classified-maps-on-train-overindulged-in-alcohol-watchdog-finds/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Crime Stoppers leak exposes millions of "anonymous" tips<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=443" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://cybernews.com/security/crime-stoppers-leak-exposes-millions-tips/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">New Android malware hiding in streaming apps to spy on users' personal notes<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=742" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://therecord.media/malware-streaming-apps-android" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">FBI seizes Handala data leak site after Stryker cyberattack<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1049" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.bleepingcomputer.com/news/security/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Marquis says over 672,000 people had personal and financial data stolen in ransomware attack<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1258" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://techcrunch.com/2026/03/18/marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Companies House suspends filing service after five-month security glitch exposed directors' details<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1597" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.bbc.co.uk/news/articles/c5y41p0dy1wo" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Popular Chrome extension "Save Image as Type" removed after hijacking affiliate links for months<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=1894" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/YouShouldKnow/comments/1rw65o8/ysk_a_popular_browser_extension_called_save_image/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Phish of the Week: Emirates Airline Impersonation<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2298" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">SANS Security Awareness &amp; Culture Summit 2026 - Call for Presentations<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2585" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Idris Elba's wax model unlocks his iPhone<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2718" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.reddit.com/r/Damnthatsinteresting/s/60sE5JP0ua" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Pete Tong reads out a URL like it's 1995<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2790" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.instagram.com/reel/DU-lwx_Denm/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Tinder plans to let AI scan your camera roll<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2920" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.404media.co/tinder-plans-to-let-ai-scan-your-camera-roll/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Japan to allow proactive cyber defence from October 1st<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=3007" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/" target="_self" data-turbo="false">Read</a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>Idris Elba's wax double unlocked his iPhone.</strong><span class="white-space-pre"> </span>A Madame Tussauds waxwork was a convincing enough likeness to fool Face ID. Which raises the question: what exactly is Face ID checking for?<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2718" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Pete Tong read out a full URL on BBC Radio 1. In 1995.</strong><span class="white-space-pre"> </span>A clip doing the rounds of Pete Tong carefully enunciating a web address, forward slashes and all. A lovely reminder of how different things were. We're at<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="http://riskycreative.com/" target="_self" data-turbo="false">riskycreative.com</a>, no index.html required.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2790" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Tinder wants to scan your camera roll.</strong><span class="white-space-pre"> </span>The dating app is planning to let AI browse your locally stored photos to figure out your interests and build your profile. Gym selfies, family photos, sensitive documents, whatever's in there. Ant checked his. Apparently it's mostly dinosaurs and things he's selling on eBay.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=2920" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.404media.co/tinder-plans-to-let-ai-scan-your-camera-roll/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Japan legalises hacking back.</strong><span class="white-space-pre"> </span>From October 1st, Japan's Self-Defense Forces and police can identify and disable infrastructure used to attack them. They're calling it "proactive cyber defence." In less polite places it's called offensive cyber ops. Either way, it's a significant shift for a country that's been constitutionally locked into a defensive posture since 1946.<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://youtu.be/9n-ewD0zZuU?t=3007" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.theregister.com/2026/03/18/japan_proactive_cyber_defense_enabled/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph">Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="mailto:hello@riskycreative.com" target="_self" data-turbo="false"><strong>hello@riskycreative.com</strong></a>. We’re always learning, and your input helps shape future episodes.</p>
<p class="ember-view reader-text-block__paragraph"><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/in/infosecant/" target="_self" data-turbo="false"><strong>Ant Davis</strong></a><span class="white-space-pre"> </span>and<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/in/lukejpme/" target="_self" data-turbo="false"><strong>Luke Pettigrew</strong></a><span class="white-space-pre"> </span>write this newsletter and podcast.</p>
<p class="ember-view reader-text-block__paragraph">The Awareness Angle Podcast and Newsletter is a<span class="white-space-pre"> </span><a class="QPSBGRTTCToxrpUoVsOUnfwcbljCvWXALY " href="https://www.linkedin.com/company/riskycreative/" target="_self" data-turbo="false"><strong>Risky Creative</strong></a><span class="white-space-pre"> </span>production.</p>
<p class="ember-view reader-text-block__paragraph">All views and opinions are our own and do not reflect those of our employers.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/218478?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/218478?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F218478%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F218478%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame><turbo-frame class="main-list__list-item" data-testid="Post" id="post_216868">
    <div class="post" access="public">
  <div class="post__inner">
      <div class="post__media">
        <div class="media-player media-player--video">
            <div
  class="embed-player"
  data-controller="youtube-player"
  data-youtube-player-watch-times-path-value="https://riskycreative.com/supporters/api/v1/media_catalog/posts/video_embeds/216868/watch_times"
  data-youtube-player-video-id-value="ngAQEvrEMag"
>
  <div class="media-player__cover" data-youtube-player-target="element">
    <img src="https://img.youtube.com/vi/ngAQEvrEMag/hqdefault.jpg" class="media-player__cover-image media-player__cover-image--cover" loading="lazy" />
    <button type="button" class="media-player__cover-button" data-action="click->youtube-player#createPlayer" data-testid="YoutubePlayer.PlayButton">
      <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" viewBox="0 0 32 32" fill="none" role="img"><path d="M28.422 14.211c1.474.737 1.474 2.84 0 3.578L2.894 30.553A2 2 0 0 1 0 28.763V3.237a2 2 0 0 1 2.894-1.789l25.528 12.764Z" fill="currentColor"></path></svg>

    </button>
  </div>
</div>

        </div>
      </div>

    <div class="post__main">
  <div class="post__content">
        <a data-turbo-frame="_top" class="post__meta" href="/supporters/video_embeds/216868">
          Mar 16, 2026
</a>

      <div>
          <a data-turbo-frame="_top" class="post__title" href="/supporters/video_embeds/216868">
            Your Antivirus Won't Catch This, SMS Blasters Are Real and a USB Full of America's Secrets
</a>      </div>

      

        <div
          class="post__body"
            data-controller="trim"
            data-trim-class-value="rich-text--trimmed-short"
            data-trim-height-value="220"
        >
          <div class="rich-text" data-trim-target="content">
            <body>
<p class="ember-view reader-text-block__paragraph">This week, the threats got personal. A fake Google Meet update that hands attackers the keys to your PC. An SMS that pinged Luke's phone at a hospital and turned out to be a live scammer on the end of the line. A banking glitch that let strangers see your salary, your benefits, and your child payments. And a former government insider who allegedly walked out with the personal data of almost every living American on a thumb drive.</p>
<p class="ember-view reader-text-block__paragraph">Oh, and if you've got an old iPhone? Stop reading this and go update it first.</p>
<p class="ember-view reader-text-block__paragraph">The full episode is an hour well spent. Watch on YouTube, listen on Spotify, Apple Podcasts, or wherever you get your podcasts. Ant and Luke don't do death by PowerPoint, just straight talking cyber news for people who actually care about the human side of security.</p>
<p><a href="https://youtu.be/ngAQEvrEMag" rel="noopener noreferrer" target="_blank"><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="" src="https://media.licdn.com/dms/image/v2/D4E12AQGjIOrqRvvQug/article-inline_image-shrink_1000_1488/B4EZzxZXOfIgAQ-/0/1773576486273?e=1775088000&amp;v=beta&amp;t=jO5iFfG7Tq6vo3-s09thJICjYZA-MOVFS_ovDWIxdb0" onerror="this.style.display='none'"></span></a>This week's episode is available to watch on YouTube</p>
<p class="ember-view reader-text-block__paragraph"><strong>Watch or listen to the episode today -<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.youtube.com/playlist?list=PLEsOj51Q0PfA0qX6BRlNnyD7lG8JlijRf" target="_self" data-turbo="false"><strong>YouTube</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1MzU4ODA2NTYsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiIzYjYwM2QwOGUwYjk3MGM5In0" target="_self" data-turbo="false"><strong>Spotify</strong></a><strong><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span></strong><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://dzxlpg.clicks.mlsend.com/tf/c/eyJ2Ijoie1wiYVwiOjc2OTY5NixcImxcIjoxNDc4Mjk5NDk1NDExMjM1MzcsXCJyXCI6MTQ3ODI5OTg5MDk5NzAxNzAwfSIsInMiOiJkMDg0MjdhODRhMTkzMzYzIn0" target="_self" data-turbo="false"><strong>Apple Podcasts</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Visit<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="http://riskycreative.com/" target="_self" data-turbo="false"><strong>riskycreative.com</strong></a><span class="white-space-pre"> </span>for past episodes, our blog, and our merch.</p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQGgshIeQut2gg/article-inline_image-shrink_1000_1488/B4EZzwiF7rIgAQ-/0/1773561995479?e=1775088000&amp;v=beta&amp;t=RJxwsc-OcRhXl0dHfa-xs_3xXH6wXt5QnKt1wZN2M5A" onerror="this.style.display='none'"></span>SANS is off to Vegas Baby!</p>
<p class="ember-view reader-text-block__paragraph">If you work in security awareness and you've got something worth saying, this is the room to say it in.</p>
<p class="ember-view reader-text-block__paragraph">The<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.linkedin.com/showcase/sansworkforce/" data-turbo="false">SANS Workforce Security &amp; Risk Training</a><span class="white-space-pre"> </span>Security Awareness and Culture Summit Call for Presentations is open right now, and the deadline is Friday 3rd April at 5pm ET. The summit itself runs on the 27th and 28th of August in Las Vegas at Caesars Palace, and it is the biggest gathering of security awareness, behaviour and culture professionals on the planet. 13th year running.</p>
<p class="ember-view reader-text-block__paragraph">The summit is looking for talks, research and case studies that focus on shifting not just behaviour, but attitudes and beliefs around cybersecurity. If you've got something that's worked in your organisation, something you've learned the hard way, or a genuinely new idea worth sharing with thousands of your peers, they want to hear from it.</p>
<p class="ember-view reader-text-block__paragraph">And if you've never presented at a conference before, this is a brilliant place to start. Mentoring is available for first time speakers, so you won't be thrown in at the deep end on your own.</p>
<p class="ember-view reader-text-block__paragraph">If Vegas isn't on the cards, that's not a reason to miss out either. You can present remotely, so there's really no barrier to getting involved.</p>
<p class="ember-view reader-text-block__paragraph">The deadline is the 3rd of April. Two weeks. Get your submission in.</p>
<p class="ember-view reader-text-block__paragraph">Submit your proposal<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://app.smartsheet.com/b/form/019c67ddb6ed77de988079d2ecab7915" target="_self" data-turbo="false">here</a>. Get more information on the summit<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026" target="_self" data-turbo="false">here.</a></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Stories...</h2>
<h3 class="ember-view reader-text-block__heading-3">One click on a fake Google Meet update hands attackers the keys to your PC</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=969" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">A phishing page disguised as a Google Meet update notice is being used to silently enroll victims Windows PCs into an attacker controlled device management system. No malware, no stolen passwords, just a single click.</p>
<p class="ember-view reader-text-block__paragraph">The page mimics a genuine Google Meet update prompt, but clicking the button triggers a built in Windows feature called MS Device Enrollment, the same legitimate tool your IT department would use to manage a company device. A victim who clicks through hands full remote control of their machine to the attacker, who can then silently install software, change settings, read files, or wipe the device entirely. Because the attack works entirely through the operating system, traditional antivirus tools have nothing to flag. There is no malicious file. No suspicious download. Nothing to scan for.</p>
<p class="ember-view reader-text-block__paragraph">The best defence here is a human one. Why is Google Meet asking me to update through a webpage? Is this normal? Those two questions, asked out loud, stop this attack dead.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Your antivirus will not save you here -<span class="white-space-pre"> </span></strong>This attack uses a genuine Windows feature to hand over control of your machine. If your only defence is a security tool, you have a gap that only a questioning mindset can fill.</li>
<li>
<strong>Knowing what normal looks like matters -<span class="white-space-pre"> </span></strong>Google Meet does not push updates through a webpage like this. Neither do most legitimate apps. If something prompts you to do something you have never seen before, that instinct to pause is worth listening to.</li>
<li>
<strong>If you think you might have clicked it</strong><span class="white-space-pre"> </span>- Go to Settings, Accounts, Access Work or School. If you see anything you do not recognise, especially anything referencing sunlife-finance[.]com or esper[.]cloud, disconnect it immediately.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">The SMS that pinged Luke's phone at a hospital turned out to be a live scammer on the other end of the line</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=1219" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.androidauthority.com/google-messages-sms-blaster-protection-apk-teardown-3647907/" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">SMS blasters are portable rogue devices that mimic legitimate mobile towers, force nearby phones to downgrade to 2G, and deliver phishing text messages that bypass your carrier's spam filters entirely. They sound like something out of a spy thriller, but three people were convicted of using one on the London Underground just a few weeks ago.<span class="white-space-pre"> </span></p>
<p class="ember-view reader-text-block__paragraph">This week it got personal. Luke received a suspicious SMS at a local hospital, categorised as being from Google, complete with a verification code he never requested and a support number to call if he didn't recognise the activity. Ant called the number, and the recording is in this week's episode. It wasn't a call centre in Asia with background noise and a script. It sounded like one person in a bedroom, running the whole operation solo, building trust quickly without ever asking for account details, steering the conversation toward a password reset that would have handed over full account access if a real email address had been given. The whole attack is engineered around panic. Someone sees an unexpected verification code, worries their account has been compromised, calls the number in the message, reads out the recovery code that lands on their phone moments later, and it is over before they realise what happened.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A text that appears to be from a legitimate sender is not proof that it is</strong><span class="white-space-pre"> </span>- SMS blasters spoof sender names, bypass carrier filters, and can drop a message into an existing thread with real previous messages from that contact. The name at the top means nothing.</li>
<li>
<strong>The script relies on you being worried</strong><span class="white-space-pre"> </span>- The call is designed to feel urgent and helpful at the same time. If you receive an unexpected verification code and feel the urge to call a number in the message, stop. Find the real support number from the official website and call that instead.</li>
<li>
<strong>Android users can disable 2G right now</strong><span class="white-space-pre"> </span>- Go to Settings, Network, and look for the option to avoid 2G networks. It is often opted out by default. Turning it on removes the mechanism these devices exploit entirely.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">A whistleblower says a former government staffer walked out of the Social Security Administration with the personal data of almost every living American on a thumb drive</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2091" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.npr.org/2026/03/11/nx-s1-5745153/doge-social-security-data-whistleblower-investigation" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">The Social Security Administration's inspector general is investigating a whistleblower complaint alleging that a former DOGE software engineer left his role and took two tightly restricted government databases with him, with at least one stored on a personal thumb drive. One of those databases, NUMIDENT, contains Social Security numbers, dates of birth and parents' names for virtually every living American. He also allegedly claimed to have retained what he described as "god-level" access to SSA systems after leaving. The SSA and the former employee's lawyer have both denied wrongdoing, but investigations are open.</p>
<p class="ember-view reader-text-block__paragraph">No firewall stops someone walking out of the door with a thumb drive. If the allegations are true, the failure here wasn't technical at all. It was human, procedural and organisational, and the lessons apply just as much to a small business as they do to a government agency.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>Revoking access when someone leaves is a critical security control, not an admin task</strong><span class="white-space-pre"> </span>- When did you last audit who still has access to systems they no longer need?</li>
<li>
<strong>Insider threats are harder to detect and harder to talk about than external attacks</strong><span class="white-space-pre"> </span>- but they are just as real and no security tool will catch them if the right processes aren't in place.</li>
<li>
<strong>The ability to plug a personal device into a government machine should never have been possible</strong><span class="white-space-pre"> </span>- USB port restrictions are unglamorous, but this is exactly why they exist.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph"><br></p>
<h3 class="ember-view reader-text-block__heading-3">Starbucks disclosed a data breach this week affecting nearly 900 employees after attackers created fake login pages to steal their credentials</h3>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=110" target="_self" data-turbo="false"><strong>Watch</strong></a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/" target="_self" data-turbo="false"><strong>Read</strong></a></p>
<p class="ember-view reader-text-block__paragraph">Attackers gained access to Partner Central, Starbucks' internal HR platform, by building convincing imitations of the login page and harvesting employee credentials. Once in, they had access to names, Social Security numbers, dates of birth and financial account and routing numbers. The breach ran for 23 days before it was fully resolved, with Starbucks discovering the intrusion on the 6th of February but not fully removing the attackers until the 11th, leaving a five day window where they knew someone was in but couldn't get them out. Affected employees are being offered two years of free identity theft protection through Experian.</p>
<p class="ember-view reader-text-block__paragraph">The reason this one is worth highlighting isn't the scale, it's the method. Fake login page, stolen credentials, walk straight in through the front door. It's one of the oldest tricks going and it still works, including against large well resourced organisations with dedicated security teams.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>This attack didn't exploit a technical vulnerability, it exploited a human one<span class="white-space-pre"> </span></strong>- A convincing fake login page is often all it takes. Knowing what the real login page looks like and being suspicious of anything that asks for your credentials is a habit worth building.</li>
<li>
<strong>Financial account and routing numbers are a different category of risk<span class="white-space-pre"> </span></strong>- Unlike an email address or even a password, these create a direct route to fraud. If you've been notified of this breach, contact your bank directly rather than just monitoring.</li>
<li>
<strong>Third party platforms expand your attack surface whether you like it or not<span class="white-space-pre"> </span></strong>- Payroll, HR, pensions, training. Every platform your organisation uses is another login screen that can be faked. MFA on all of them isn't optional anymore.</li>
</ul>
<p><br></p>
<h2 class="ember-view reader-text-block__heading-2">Phish Of The Week</h2>
<p class="ember-view reader-text-block__paragraph"><strong>A legitimate Google email was used to deliver a phishing message, and the trick was hidden in plain sight</strong></p>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQHmQrjeWFyf6A/article-inline_image-shrink_1500_2232/B4EZzwm2Q7JcAU-/0/1773563242445?e=1775088000&amp;v=beta&amp;t=7A2A5gdgtjla8ZLKMS2yCqrL4_RofEie0F8yD8Kcwh8" onerror="this.style.display='none'"></span>It's clever but we do wonder how successful this will be</p>
<p class="ember-view reader-text-block__paragraph">This one is genuinely clever. The attacker submitted a Google account recovery request, but instead of using a normal email address, they put the entire phishing message into the email address field. It looked something like this: unauthorized_order_of_bitcoin_965usd_on_gpay_if_not_you_call_08XXXXXXXXX@domain[.]com. Because it's formatted like an email address, it passed Google's form validation. Because it came from Google's own systems, it landed in inboxes looking completely legitimate.</p>
<p class="ember-view reader-text-block__paragraph">The goal is to panic the recipient into calling the number, at which point the scam moves off email entirely and onto a phone call where the real manipulation happens.<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/JdSbDyaEr4A" target="_self" data-turbo="false">We've seen this pattern before with PayPal</a>, and it's becoming a recurring technique. Get the victim to make contact on a different platform where there are no spam filters, no warnings and no safety net.</p>
<p class="ember-view reader-text-block__paragraph"><strong>Awareness Angles</strong></p>
<p class="ember-view reader-text-block__paragraph"></p>
<ul>
<li>
<strong>A legitimate sender does not mean a legitimate message</strong><span class="white-space-pre"> </span>- This email came from Google. The domain was real, the formatting was real, and it would pass most technical checks. The content is the only thing that gave it away.</li>
<li>
<strong>When something tries to move you to a phone call, that's a red flag</strong><span class="white-space-pre"> </span>- Email, text, fake notification. The platform doesn't matter. If the end goal is getting you on a phone call to a number you didn't go looking for yourself, pause.</li>
<li>
<strong>Panic is the whole mechanism</strong><span class="white-space-pre"> </span>- Unauthorised Bitcoin purchase, urgent action required, call now. Every word is designed to stop you thinking clearly. Slowing down for ten seconds is genuinely a security control.</li>
</ul>
<p><br></p>
<p class="ember-view reader-text-block__paragraph">Thank you to the<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.linkedin.com/company/hoxhunt/" data-turbo="false">Hoxhunt</a><span class="white-space-pre"> </span>Threat Intelligence team for sharing this with us!<span class="white-space-pre"> </span></p>
<h2 class="ember-view reader-text-block__heading-2">This Week's Talking Points...</h2>
<p class="ember-view reader-text-block__paragraph"><strong>Starbucks discloses data breach affecting hundreds of employees</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=110" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Iran-linked hackers wipe data across 200,000 Stryker devices</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=366" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Lloyds, Halifax and Bank of Scotland apps exposed strangers' transactions</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=663" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.theregister.com/2026/03/12/lloyds_banking_group_glitch/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>One click on this fake Google Meet update can give attackers control of your PC</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=969" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Google Messages may soon get built-in protection against SMS blasters</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=1219" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.androidauthority.com/google-messages-sms-blaster-protection-apk-teardown-3647907/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>A whistleblower says a former DOGE staffer walked out of the SSA with Americans' data on a thumb drive</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2091" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.npr.org/2026/03/11/nx-s1-5745153/doge-social-security-data-whistleblower-investigation" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Apple rushes out patches for older iPhones and iPads against the Coruna exploit kit</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2296" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.bleepingcomputer.com/news/apple/apple-patches-older-iphones-and-ipads-against-coruna-exploits/" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: ClickFix evolves with a new variant that bypasses Microsoft Defender</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=2889" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html" target="_self" data-turbo="false">Read</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Darren Jones MP accidentally shares his passcode on camera</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3063" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reels/DVtYGoGk9wb/" target="_self" data-turbo="false">Watch on Instagram</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Tricking an AI scam caller</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3186" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reel/DVOXY5MiGNT/?igsh=MTlyOWxyaGJuNjF0ZA==" target="_self" data-turbo="false">Watch on Instagram</a></p>
<p class="ember-view reader-text-block__paragraph"><strong>Topics: Apple MacBook Neo Touch ID ad</strong><span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://youtu.be/ngAQEvrEMag?t=3389" target="_self" data-turbo="false">Watch</a><span class="white-space-pre"> </span>|<span class="white-space-pre"> </span><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://vm.tiktok.com/ZNRuot9uf/" target="_self" data-turbo="false">Watch on TikTok</a></p>
<h2 class="ember-view reader-text-block__heading-2">And Finally...</h2>
<h3 class="ember-view reader-text-block__heading-3">The scam caller that got asked for a Bolognese recipe</h3>
<p><span><img class="ivm-view-attr__img--centered  reader-image-block__img evi-image lazy-image ember-view" alt="Article content" src="https://media.licdn.com/dms/image/v2/D4E12AQH4B1viW8UAKw/article-inline_image-shrink_1000_1488/B4EZzxYWEuIUAc-/0/1773576220162?e=1775088000&amp;v=beta&amp;t=qA_F0uN-gGOEda2k7nlPc3BSlTiehAg7oS03fu5cOUM" onerror="this.style.display='none'"></span></p>
<p class="ember-view reader-text-block__paragraph"><a class="aAIDarVlJjjXEMUykBwFgJhXtzETCscLwRim " href="https://www.instagram.com/reels/DVOXY5MiGNT/" target="_self" data-turbo="false">Watch</a></p>
<p class="ember-view reader-text-block__paragraph">Someone received one of those relentless car finance cold calls this week and decided to have a bit of fun with it. From the start it became pretty clear the caller wasn't human, so they started pushing it. Ask it an off script question, see what happens. Eventually they got it to recite a full Bolognese recipe mid sales pitch, complete with the markdown formatting still intact, hashtags and all, read out loud in a completely earnest robotic voice.</p>
<p class="ember-view reader-text-block__paragraph">It is funny, and it is worth sharing with people in your life who might not realise how convincing these AI calling systems have become. Because the flip side of that video is that plenty of people who received the same call had no idea they were talking to a machine. If you ask it whether it is human, it says yes. It gives a name. It says it is from Manchester. And that is enough to keep a lot of people on the line.</p>
<p class="ember-view reader-text-block__paragraph">Show this to someone who needs to hear it. It is a lot easier to hang up on a robot when you know it is a robot.</p>
</body>
          </div>
          <button class="text-button text-button--pale post__action-button hidden" data-action="click-&gt;trim#expand" data-trim-target="button">
    ...Continue reading
</button>
        </div>

      

        <div class="post__section">
          <div class="post-actions">
            <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
  <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
    <div class="post-actions__item">
      <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="m2.662 7.721 5.14 5.918a.25.25 0 0 0 .378 0l5.142-5.92c1.856-2.21 1.25-4.386.03-5.37-.62-.5-1.407-.711-2.203-.513-.796.197-1.712.833-2.504 2.243a.75.75 0 0 1-1.308-.001c-.794-1.416-1.708-2.054-2.5-2.253-.79-.2-1.573.01-2.19.51-1.214.983-1.822 3.167.015 5.386Zm5.33-5.375C7.172 1.274 6.212.623 5.202.37c-1.292-.325-2.552.032-3.5.8-1.913 1.55-2.524 4.702-.19 7.515l.012.013 5.146 5.925a1.75 1.75 0 0 0 2.642 0l5.146-5.925.008-.009c2.362-2.805 1.75-5.956-.171-7.507-.95-.766-2.213-1.124-3.508-.802-1.01.25-1.974.898-2.795 1.966Z" clip-rule="evenodd"></path></svg>

    </div>

</button></form>
              <form class="post-actions__item-form" data-turbo="false" action="/supporters/sign_up" accept-charset="UTF-8" method="get">
    <button class="text-button text-button--small text-button--pale" aria-label="Become a member">
    
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M1.75 2.25a.25.25 0 0 0-.25.25v8.067c0 .139.112.25.25.25H3c.967 0 1.75.784 1.75 1.75v1.21c0 .216.255.33.416.187l3.053-2.706a1.75 1.75 0 0 1 1.16-.44h4.871a.25.25 0 0 0 .25-.25V2.5a.25.25 0 0 0-.25-.25H1.75ZM0 2.5C0 1.534.784.75 1.75.75h12.5c.966 0 1.75.784 1.75 1.75v8.067a1.75 1.75 0 0 1-1.75 1.75H9.38a.25.25 0 0 0-.166.063L6.16 15.087c-1.13 1-2.911.199-2.911-1.31v-1.21a.25.25 0 0 0-.25-.25H1.75A1.75 1.75 0 0 1 0 10.567V2.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number"></span>
      </div>

</button></form>
            
<div class="dropdown" data-controller="dropdown link-share" data-dropdown-placement-value="bottom-start" data-action="link-share:unavailable-&gt;dropdown#toggle" data-link-share-url-value="https://riskycreative.com/supporters/video_embeds/216868?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter">
      <div class="comment__menu" data-dropdown-target="button" data-action="click->link-share#share">
      <div class="post-actions__item">
        <svg xmlns="http://www.w3.org/2000/svg" width="14" height="14" fill="none" viewBox="0 0 16 16" role="img" class="post-actions__icon"><path fill="currentColor" fill-rule="evenodd" d="M6.996.471a1.41 1.41 0 0 1 2.008 0l4.943 5.013-1.068 1.053L8.75 2.35v9.121h-1.5V2.35L3.12 6.537 2.054 5.484 6.996.471ZM1.5 11.108v3.143c0 .138.111.249.249.249H14.25c.138 0 .249-.11.249-.25v-3.142H16v3.143c0 .965-.781 1.749-1.749 1.749H1.75A1.748 1.748 0 0 1 0 14.25v-3.142h1.5Z" clip-rule="evenodd"></path></svg>

        <span class="post-actions__item-number hidden@sm">Share</span>
      </div>
    </div>


  <div class="dropdown__menu hidden" data-dropdown-target="items">
    <div class="dropdown__items">
        <div class="dropdown__title">Share this post</div>

      

  <button class="dropdown__item" data-action="click-&gt;dropdown#hide" data-controller="clipboard" data-clipboard-text="https://riskycreative.com/supporters/video_embeds/216868?utm_medium=copy-share-link&amp;utm_source=share-link&amp;utm_campaign=post-share-supporter" type="button">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" fill="none" viewBox="0 0 16 16" role="img"><path fill="currentColor" fill-rule="evenodd" d="M12.145 1.5a1.762 1.762 0 0 0-1.246.516L8.234 4.681l-1.06-1.06L9.837.955a3.264 3.264 0 0 1 4.615 0l.591.591a3.264 3.264 0 0 1 0 4.613l-3.849 3.85a3.262 3.262 0 0 1-4.614 0l-.593-.592 1.062-1.06.591.592a1.763 1.763 0 0 0 2.493 0l3.85-3.85a1.762 1.762 0 0 0 0-2.492l-.592-.591a1.764 1.764 0 0 0-1.247-.517ZM7.112 6.534c-.468 0-.916.186-1.247.516L2.016 10.9a1.762 1.762 0 0 0 0 2.492m0 0 .592.592a1.764 1.764 0 0 0 2.493 0l2.665-2.665 1.06 1.06-2.664 2.666a3.264 3.264 0 0 1-4.615 0l-.592-.592a3.263 3.263 0 0 1 0-4.614l3.85-3.85a3.264 3.264 0 0 1 4.614 0l.592.593-1.06 1.06-.592-.592c-.331-.33-.78-.516-1.247-.516" clip-rule="evenodd"></path></svg>

    </div>

  
    Copy link

</button>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://twitter.com/intent/tweet?url=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F216868%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 32 32" fill="none" role="img"><path d="M18.666 13.857 29.093 2h-2.47l-9.056 10.294L10.338 2H2l10.932 15.567L2 30h2.47l9.557-10.873L21.662 30H30M5.36 3.822h3.795L26.62 28.267h-3.794" fill="currentColor"></path></svg>

    </div>

  
    Share on X

</a>
  <a class="dropdown__item" data-action="click-&gt;dropdown#hide" href="https://facebook.com/sharer.php?u=https%3A%2F%2Friskycreative.com%2Fsupporters%2Fvideo_embeds%2F216868%3Futm_medium%3Dcopy-share-link%26utm_source%3Dshare-link%26utm_campaign%3Dpost-share-supporter" target="_blank">
    <div class="dropdown__item-icon">
      <svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 14 14" fill="none" role="img"><path d="m5.27 14-.02-6.125H2.625V5.25H5.25V3.5C5.25 1.138 6.713 0 8.82 0c1.009 0 1.876.075 2.129.109v2.468H9.488c-1.146 0-1.368.545-1.368 1.344V5.25h3.255L10.5 7.875H8.12V14H5.27Z" fill="currentColor"></path></svg>

    </div>

  
    Share on Facebook

</a>
    </div>
  </div>
</div>
          </div>

        </div>

      </div>
</div>

  </div>
</div>

</turbo-frame></template></turbo-stream>

<turbo-stream action="remove" target="posts_load_more"></turbo-stream>

  <turbo-stream action="append" target="posts_list"><template><turbo-frame id="posts_load_more">
  <a data-turbo-stream="true" data-controller="infinite-scroll" href="/supporters/load_more?last_id=216868&amp;last_live_at=2026-03-16T06%3A00%3A00.000%2B00%3A00&amp;order=desc"></a>
  <div class="loader">
  <svg class="loader__icon" viewBox="0 0 100 100">
    <circle class="loader__circle" cx="50" cy="50" r="45" />
  </svg>
</div>
</turbo-frame>
</template></turbo-stream>
