Jun 8, 2026
NHS Blood Tests Leaked Two Years Later, Dashlane 2FA Brute-Forced & FIFA Scam Sites Already Live

This week... NHS patients are only just getting letters about a breach that happened two years ago, a password manager story that rhymes a little too closely with LastPass in 2022, and the FBI cataloguing fake FIFA websites before the tournament has even kicked off. On top of that, Mac malware that passed Apple's own checks, a new tool that bypasses Microsoft MFA without ever needing your password, and the NCSC telling organisations to brace for a patch flood most of them aren't ready for.

Luke's back and Ant was at Infosecurity Europe at the Excel Centre in London earlier in the week, so there was plenty to catch up on before we even got to the news.

All of that and a whole bunch more on this week's The Awareness Angle

Watch or listen to the episode today - YouTube | Spotify | Apple Podcasts

Visit riskycreative.com for past episodes, our blog, and our merch.

Click the image to watch this week's episode

Official Media Partner of the SANS Security Awareness & Culture Summit 2026

Article contentLive streams will be available across both days!

Risky Creative is the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.

Ant will be there in person across both days - streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. Last year he did some interviews. This year it's going to be bigger. We want to hear from the people in the room - what they're working on, what's changing in their programmes, what they're taking away.

If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too. More details coming very soon.

More details on the SANS Summit is here

Breach of the Week

Your NHS Blood Test Results From 2015 Just Got Leaked. In 2026.

Watch | Read

This one lands hard because nobody did anything wrong. Patients at Bedford Hospital and Luton and Dunstable Hospital between 2011 and 2020 went for a blood test or a scan, trusted that their records were being looked after, and had no idea the supplier processing their data would be hit by ransomware in June 2024. Around 32,927 people are potentially affected. The data involved could include names, dates of birth, NHS numbers, postcodes and test results.

The reason notifications are only going out now, two years later, is that the stolen data was so fragmented and jumbled that forensic specialists needed over a year just to work out whose information was in there. A court injunction has been obtained to try to prevent the data being shared or misused, but as we said on the show, the data has potentially been out there for two years already. Anyone caught in this breach may have been susceptible to phishing long before any letter dropped through their door.

  • Your data doesn't stay in one place. It flows to suppliers and subcontractors you've never heard of. Neither you nor your hospital necessarily knows how they protect it until something goes wrong.
  • The long tail of ransomware. The attack makes headlines, operations get cancelled, everyone moves on. The real impact on real people keeps arriving slowly, sometimes years later.
  • Two years is a long time. By the time a notification arrives, harm may already have happened. Staying alert to phishing isn't a one-off task, it's ongoing.


This Week's Stories

The AI That Can Hack Your Bank Won't Let Your Bank Use It

Watch | Read

Nine major UK banks including Lloyds, HSBC and Nationwide have been trying to get access to Anthropic's Claude Mythos for nearly two months, and they still can't. The Bank of England governor flagged the access gap publicly last week. OpenAI, meanwhile, has stepped in with GPT-5.5 Cyber, and NatWest and Santander already had access under existing agreements. The UK's AI Security Institute tested both tools and found them performing at a similar level.

The reason the banks want this so urgently isn't abstract. Decades of old, unaudited code still underpins a lot of modern banking infrastructure, and they need AI to help find what's hiding in there before attackers do. Anthropic says its caution around Mythos is deliberate given what the model can do. OpenAI has decided to move faster. As we said on the show, the branding contest isn't close, GPT-5.5 Cyber isn't exactly going to stick in your memory, but the real tension here is who decides who gets access to these tools, on what terms, and why.

  • The defender's dilemma. The same AI that helps find hidden vulnerabilities is catastrophic in the wrong hands. Access decisions have real security consequences.
  • Legacy code is the underlying problem. The urgency from the banks isn't theatre. Old software written before modern security standards existed still runs critical financial systems.
  • Access isn't neutral. Whether it's Mythos or GPT-5.5 Cyber, these are policy calls, not just product decisions.



Your Password Manager Got Hacked. And Your 2FA Didn't Save You.

Watch | Read

In 2022, LastPass had customer vault backups stolen. At the time the vaults felt safe because they were encrypted. Reports later emerged of those vaults being cracked and cryptocurrency wallets being drained because some customers' master passwords weren't strong enough to hold. This week, Dashlane disclosed that hackers brute-forced their two-factor authentication system and accessed around 20 customer accounts. Automated software rapidly guessed every possible numeric combination before the short-lived 2FA codes expired. Encrypted password vaults were downloaded.

Dashlane says its own systems weren't compromised and that the vaults can't be read without the customer's master password, which the company doesn't hold. That's technically reassuring. But now attackers have all the time in the world to work on cracking those vaults. History is rhyming. Brute force protection, limiting how many failed attempts you allow before locking an account, is the obvious fix here, and it's surprising it wasn't already in place.

  • 2FA is not a force field. Brute-forcing a six-digit numeric code without rate limiting is not sophisticated. 2FA reduces risk significantly but it is not unbeatable.
  • Your master password is everything. If your vault gets stolen, that one passphrase is the only thing standing between an attacker and every password you own. Make it long, make it three random words, make it unique to your password manager.
  • The LastPass lesson keeps repeating. Stolen encrypted vaults feel safe until someone cracks them. Weak master passwords are the weak link, and attackers know it.



Even Apple Couldn't Catch This One — Mac Malware Hiding in Google and YouTube Ads

Watch | Read

Operation FlutterBridge is spreading a backdoor called FlutterShell via malicious ads bought through Google and YouTube. What makes this one different is that all the malicious apps were signed with valid Apple Developer IDs and passed Apple's own notarization checks. The automated processes Apple runs on every app before distribution didn't flag them. If you saw the ad, downloaded the app, and it cleared Apple's security screening, there was no obvious signal anything was wrong. Your browser then quietly started routing all your traffic through someone else's server.

Luke pointed out we seem to have a Mac-specific malware story almost every week lately, and the theory is that the MacBook Air's success at bringing new users into the Apple ecosystem is making Mac users a more attractive target. As that market share grows, so does the incentive to go after it. Three variants have been identified so far: PodcastsLounge, PDF-Brain and PDF-Ninja.

  • Apple's checks are not a guarantee. Notarization means automated checks ran. It doesn't mean a human reviewed the app, and it doesn't mean it's safe.
  • The ad is the attack surface. These came from paid Google and YouTube ads that looked completely normal. A legitimate platform doesn't make the ad on it legitimate.
  • Mac users aren't immune. The assumption that Macs don't get viruses is outdated and dangerous. Campaigns like this one target Mac users specifically, partly because that assumption makes them easier to catch.



The FBI Just Published a List of Fake FIFA Sites. It Includes fifa[.]beer

Watch | Read

Over 30 spoofed FIFA domains have already been identified with the 2026 World Cup still weeks away. The list includes fifa[.]beer, fifa[.]pink, fifa[.]cam and fifa[.]click. There are also fake job sites: jobs-fifa[.]com, fifa-hiring[.]com and fifaworldcup-careers[.]com. The FBI specifically warns against clicking sponsored search results when looking for the official site. Paid ads at the top of search results can be bought by anyone, including criminals. Type fifa[.]com directly into your address bar.

The fake jobs angle is the nastier part of this. Someone applying for a tournament job is handing over their CV, contact details, and often additional personal information about health status or disabilities. That's a much richer dataset than someone just looking to buy a ticket. The World Cup spans three countries and dozens of cities this year across Canada, Mexico and the US, so the pool of potential targets is genuinely global. We have listeners in over 80 countries, so if you know anyone in or around the host cities, this is worth a conversation at the dinner table.

  • The fake jobs angle is nastier than it looks. CVs, contact details, personal information. It's a far richer target than a ticket scam.
  • Typosquatting relies on you being in a hurry. One wrong character in a URL is all it takes. Type fifa[.]com directly.
  • Sponsored results are not trustworthy. The FBI specifically warns against them. If someone paid to appear at the top of your results, ask yourself why.



The UK's Top Cyber Body Says a Flood of Patches Is Coming. Most Organisations Aren't Ready.

Watch | Read

NCSC CTO Ollie Whitehouse has issued a formal warning: AI is now finding decades of hidden software vulnerabilities at a scale and pace humans never could. A wave of critical patches is coming across all types of software, open source and commercial. Some legacy systems are end-of-life and simply can't be patched. Those are replacement conversations, not patching ones.

This connects directly to the Mythos story earlier in the episode. The same capability being used defensively to find bugs is going to be used the other way too, and the window to get ahead of it isn't wide. And as anyone who has worked in an organisation knows, the culture around installing updates is genuinely hard to shift. The people moaning about their computer restarting mid-meeting are usually the ones who ignored seven days of nudges. Ant's Chrome browser literally had a pending update sitting there while we were recording this.

  • AI finds old bugs faster than humans. Bugs that sat hidden for decades are being surfaced quickly. The patching demand is going to be enormous and arrive all at once.
  • Patching isn't always possible. End-of-life systems can't receive updates. If your organisation runs legacy technology on its external attack surface, that's a replacement conversation.
  • Update by default, not by exception. Enable automatic updates. Build a culture where patching is the norm, not the thing that ruins someone's presentation.



Kali365 - MFA Bypass via Microsoft 365 Device Code Phishing

Watch | Read

This one pairs well with the Dashlane story. Two stories in one episode that both make the same point, MFA isn't the magic shield people assume it is. Kali365 is a phishing-as-a-service platform first spotted in April 2026, sold via Telegram. It bypasses Microsoft 365 MFA entirely without ever touching your password. The attack works by sending a phishing email impersonating a trusted cloud service. The victim is directed to a real Microsoft verification page and enters a device code, unknowingly authorising the attacker's device to access their account. The attacker captures OAuth tokens and gets persistent access to Outlook, Teams and OneDrive.

What makes it worse is that Kali365 has lowered the bar significantly. It comes with AI-generated phishing lures and ready-made campaign templates. You don't need to know how any of this works to launch it. As we said on the show, if InfoSecurity Europe had a dark side, this would be one of the big stands.

  • MFA bypass doesn't mean breaking MFA. Kali365 doesn't crack your code, it tricks you into authorising access yourself. The attack exploits behaviour, not technology.
  • Device code flow is being weaponised. Most users have never heard of it. If you receive an unexpected email asking you to visit a Microsoft verification page and enter a code, stop and verify before doing anything.
  • AI is lowering the bar for attackers. Ready-made campaign templates and AI-generated lures mean the quality of attacks is going up while the skill required to launch them is going down.


Phish of the Week - Claude Ads Impersonation

Article contentClaude doesn't even offer ads, it's ad free!

Watch

Thanks to the Hoxhunt Threat Intelligence team and Mette for putting this together.

This week's phish is a Claude Ads impersonation email. The sender display name is "Claude Ads" with a lookalike domain in the address. The message tells you that your advertising account is now eligible for Claude Ads, an AI-powered advertising solution. There's a big orange button that says "Get started with Claude Ads." It sounds great. The problem is Claude Ads doesn't exist.

Luke looked it up mid-show and found a blog post on Anthropic's own website confirming that Claude products are ad-free. If you get something like this and it sounds amazing, verify it. A two-second Google search and one click to the real site is all it takes.

  • If it sounds too good to be true, check before you click. A exciting new product you've never heard of, landing unsolicited in your inbox, should raise an eyebrow. Verify it exists before you do anything else.
  • Lookalike domains are the tell. The display name said Claude Ads but the sending address was a lookalike domain. Always check where an email actually came from, not just what it calls itself.
  • Claude products are ad-free. Anthropic has confirmed it publicly. If you ever get an email offering Claude advertising, it isn't real.


Security Socials

Same Ingredient, Different Delivery

Ant's pick this week was a LinkedIn post from Eulana Williams, a senior cybersecurity training and awareness specialist, and it's one of those posts that just lands. She talked about having leftover chicken breast at home and instead of serving it the same way again, she turned it into a chicken crust pizza and chicken nuggets. Same ingredient, completely different experience, and everyone was excited to eat it again. Her point was that learners aren't always disengaged because the content is bad. Sometimes it's just that they've seen it presented the same way too many times. The message doesn't need to change, the delivery does. We've all been there building training that was brilliant in year one and half the engagement in year two. Worth a read, and the infographic she included is really good.

Watch | Read on LinkedIn

Your Favourite Old Game Might Be a Hacker's Playground

Luke's pick was a video showing remote code execution exploits running in real time against old, unsupported Call of Duty PC titles that are still available to buy on Steam. Command prompts appearing mid-game, accounts being signed out, PCs being locked. It's genuinely unsettling to watch. Ant admitted on the show that his son's Half Life library is probably full of games that haven't seen a patch in a decade, and that conversation is now happening at home whether his son likes it or not. Unsupported software is unsupported software, whatever the nostalgia value.

Watch | Watch on TikTok

Recently uploaded