What Pizza, Payouts, and PowerShell Have in Common
This week’s episode of The Awareness Angle is packed with stories that sit right at the messy intersection of tech, trust, and human behaviour.
We kick off with a juicy one. M&S is facing a class action lawsuit over last year’s breach. But before you jump on the claims bandwagon, let’s look closer. This wasn’t some catastrophic leak of passwords or payment data. It was a third-party supplier incident. Now law firms are urging customers to sign up for “compensation.” Is it really about protecting people? Or just another case of ambulance-chasing dressed up as justice?
Speaking of trust, Nexus Mods, one of the most beloved sites in the gaming world, just changed hands. No big announcements. No transparency. Just a quiet handover. And that’s all it took for the internet to lose its mind. It’s a sharp reminder that when communities feel left out, trust disappears fast.
We also look at the biggest DDoS attack ever recorded. 37.4 million requests per second. That’s like trying to stream 10,000 HD movies at once. Cloudflare stopped it, but it raises serious questions about how smaller organisations cope when the big guns aren’t there to help.
Then there's the pizza intel story. Yes, really. Before military action between the US and Iran, people noticed spikes in Google Maps activity around gyms and pizza places near air bases. Turns out open-source intelligence is less about hacking and more about watching. A reminder that your location data, even from a pizza app, can reveal more than you think.
Elsewhere, someone leaked restricted US military flight manuals on a gaming forum to win an argument. Again. That’s nine times now on the War Thunder forums. Not a hack. Not malware. Just people making terrible judgement calls. Passion beats protocol every time.
We dive into NHS doctors using unapproved AI transcription tools during consultations without telling patients. It's a privacy minefield. There’s a clear need for better tools, but the rollout can’t skip consent and governance in the process.
And then there’s the new FileFix attack. A twist on old-school shortcut scams. This one uses File Explorer and hidden PowerShell commands to deliver malware without raising any alarms. It’s a classic case of attackers using the tools already on your machine to stay undetected.
We also cover SMS blasters. These dodgy little devices let scammers send fake texts to whole areas, pretending to be your bank or the Royal Mail. These are real. They’re cheap. And they’re hitting phones near you.
A year on from the Synnovis NHS ransomware attack, it’s now being linked to a patient’s death. A stark, sobering reminder that cyber attacks don’t just lock up data. They can cost lives.
And a heads-up for anyone still on Windows 10. Come October 2025, it’ll be out of support. If you're relying on Cyber Essentials certification, you’ll need to pay for Microsoft’s extended updates or move on. This is one of those quiet compliance risks that can catch you out if you’re not watching.
Finally, we talk about a new malware campaign using fake developer job interviews and malicious npm packages. It's slick social engineering targeting tech-savvy people, and it's working.
Oh, and a personal one. Ant’s mum nearly fell for a fake M&S hamper scam on Facebook. It's the same recycled playbook as the North Face scam we talked about a few weeks back. Fake comments, countdown timers, and dodgy URLs. Thankfully, she phoned a friend. Or in this case, her cybersecurity-aware son.
This episode covers a lot, but the thread running through it all is simple. Trust is fragile. Humans are unpredictable. And security isn’t just about systems. It’s about people.
New episodes of The Awareness Angle are released every Monday, with interviews dropping every other Thursday. Subscribe via your favourite podcast app or visit riskycreative.com to sign up for the newsletter.
M&S data breach compensation claim
Watch – https://youtu.be/EntRmhcDOBM?t=81
Read – https://vm.tiktok.com/ZNdUh6vxj/
Nexus Mods sold (but to who?)
Watch – https://youtu.be/EntRmhcDOBM?t=225
Read – https://www.reddit.com/r/gaming/s/tPzKAkElVs
The biggest DDoS attack ever
Watch – https://youtu.be/EntRmhcDOBM?t=351
Read – https://www.tomshardware.com/tech-industry/cyber-security/massive-ddos-attack-delivered-37-4tb-in-45-seconds-equivalent-to-10-000-hd-movies-to-one-victim-ip-address-cloudflare-blocks-largest-cyber-assault-ever-recorded
Pizza shops and military intelligence (Pizzint)
Watch – https://youtu.be/EntRmhcDOBM?t=549
Read – https://www.reddit.com/r/Damnthatsinteresting/s/rkBTFwbyEK
War Thunder forums leak military secrets… again
Watch – https://youtu.be/EntRmhcDOBM?t=844
Read – https://ukdefencejournal.org.uk/classified-data-once-again-leaked-on-war-thunder-forums/
Doctors using unapproved AI tools in NHS
Watch – https://youtu.be/EntRmhcDOBM?t=1061
Read – https://news.sky.com/story/doctors-are-using-unapproved-ai-software-to-record-patient-meetings-investigation-reveals-13387765
New FileFix attack via Windows shortcuts
Watch – https://youtu.be/EntRmhcDOBM?t=1285
Read – https://www.bleepingcomputer.com/news/security/filefix-attack-weaponizes-windows-file-explorer-for-stealthy-powershell-commands/
SMS blasters used in new smishing scams
Watch – https://youtu.be/EntRmhcDOBM?t=1545
Read – https://cybernews.com/news/police-alerts-about-new-sms-blaster-scams-used-for-smishing
NHS ransomware linked to patient death
Watch – https://youtu.be/EntRmhcDOBM?t=1789
Read – https://www.bbc.co.uk/news/articles/cd1gk9zqe4vo
Cyber Essentials warning: Windows 10 deadline
Watch – https://youtu.be/EntRmhcDOBM?t=1995
Read – https://www.techradar.com/computing/windows/windows-10-users-who-dont-want-to-upgrade-to-windows-11-get-new-lifeline-from-microsoft
Malware hidden in fake job interviews (NPM packages)
Watch – https://youtu.be/EntRmhcDOBM?t=2066
Comment section: NHS breaches, OneDrive sync, Jamf
Watch – https://youtu.be/EntRmhcDOBM?t=2336
Metomic demo: Human firewall nudging tool
Watch – https://youtu.be/EntRmhcDOBM?t=2762
Read – https://www.metomic.io/solution/human-firewall
TikTok Q&A: Are Groupon license keys legit?
Watch – https://youtu.be/EntRmhcDOBM?t=2895
Read – https://answers.microsoft.com/en-us/msoffice/forum/all/license-tom-on-groupon-microsoft-partner-or-scam/a0a06003-e798-424b-becf-6e390fff1f9e
Facebook M&S hamper scam fools Ant’s mum (nearly)
Watch – https://youtu.be/EntRmhcDOBM?t=3289
Scattered Spider retrospective timeline
Watch – https://youtu.be/EntRmhcDOBM?t=3568
Read – https://www.linkedin.com/posts/rosslazer_scattered-spider-timeline-ugcPost-7343292142729011201-S8N4
Windows 10 extended support pricing update
Watch – https://youtu.be/EntRmhcDOBM?t=3660
Experian “Dark Web” alert email
Watch – https://youtu.be/EntRmhcDOBM?t=3845
16 billion password leak briefly discussed
Watch – https://youtu.be/EntRmhcDOBM?t=4083
Weekly wrap-up and final thoughts
Watch – https://youtu.be/EntRmhcDOBM?t=4182