Jun 22, 2026
The FBI Built a Fake Town, $3.5 Billion Lost to Scammers & a School Breach Hitting 11 Million Kids

Cybersecurity news for humans, not just IT people

This week...A criminal gang walked off with the home addresses of 137,000 school staff. Americans lost three and a half billion dollars to scammers in a single year. And the FBI built an actual fake town in Alabama, traffic lights and all, just to train its agents. Add in earbuds that might be listening, malware buried in Steam wallpapers, and Google quietly going back on something it once called wrong, and you can see why keep on circling the same question all episode: who has your data, and how much of it is already gone.

All of that is in this weeks The Awareness Angle!


🎧 Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube

Listen Now

Podcast · Risky Creative

Fancy a free pass to the SANS Security Awareness & Culture Summit 2026?

Risky Creative is the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August and we will be giving away two passes to the summit. You still have to get yourself to Las Vegas, but we will get you in to the summit.

Ant will be there in person across both days - streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. Last year he did some interviews. This year it's going to be bigger. We want to hear from the people in the room - what they're working on, what's changing in their programmes, what they're taking away.

If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too. More details coming very soon.

Details on our free pass giveaway will be available next week!

More details on the SANS Summit is here

Breach of the Week

137,000 school staff exposed in the Infinite Campus hack

Watch | Read

ShinyHunters didn't break into a school. They found a side door through the cloud software schools use to run everything, from staff contracts to student records. The system was Infinite Campus, one of the biggest school management platforms in the US, used across more than 3,200 districts in 46 states and holding records for 11 million students. The attackers got into its Salesforce account back in March, and it's only this week the full scale has come out. They took names, email addresses, phone numbers, home addresses, job titles and support tickets for 137,000 staff, posted a sample online, and Have I Been Pwned has confirmed it.

Ant's point was that staff data sounds less frightening than children's data until you notice it includes home addresses. He brought up a scene from Tiptoe, the new Channel 4 drama, where a teacher who DJs in drag at night clocks one of their students walking into the club and realises the kid now knows exactly where they live. Teachers already deal with enough, and a public list of where every one of them lives is a safety problem, not a spam problem. It's the same story the show keeps running into, with Oracle and ServiceNow last week and Infinite Campus this week: attackers going after the big platforms everyone depends on, so the fallout hits organisations that were never the target in the first place. We've been here before too, with the PowerSchool hack back in December 2024 that exposed 62 million students and ended with the culprit jailed for four years.

The Awareness Angle -

The target was the supplier, not the school - You can do everything right and still get caught by a breach at a company you've never heard of. The question isn't only whether your data is safe, it's who else is holding it.

Staff data still means home addresses - For anyone in a messy custody situation, a domestic situation, or just dealing with an angry parent, that's a real safety risk rather than junk mail.

This is industrial now - ShinyHunters have claimed Carnival, Panera Bread, CarGurus, Grafana and the Council of Europe, with hundreds more behind them. That's why a breach is starting to feel less like bad luck and more like a matter of time.


This Week's Stories...

Americans lost a record $3.5 billion to imposter scams

Watch | Read

The US Federal Trade Commission says Americans reported three and a half billion dollars lost to imposter scams last year, nearly three times the 2020 figure. These are the ones where someone pretends to be your bank, the taxman, a tech company, or even someone you know, and they work by manufacturing just enough panic that you act before you think. No clever hack required, just a phone, a script, and a good read on how fear switches off the bit of your brain that asks questions.

Ant flagged the nudge his own banking app gives him, where opening it mid call reminds him the bank will never ring, so if the caller claims to be the bank, they aren't. Luke raised the idea of a family safe word, now that voice cloning makes the "Mum, my phone's broken, can you send money" trick far more believable. Then Ant got onto Thelma, the film about a 93 year old who wires ten grand to a scammer posing as her grandson and then goes after them on a borrowed mobility scooter. It's a comedy, but it nails how often this happens, and the FTC reckons the real total is much higher because most people are too embarrassed to report it.

The Awareness Angle -

Build in a pause - Scams run on urgency, so anything pushing you to act this second should be a reason to slow down. A real company will happily wait while you call back on a number you've looked up yourself.

The reported figure is the floor - Most victims stay quiet, so the true number is far worse. If it happens to you there's nothing to be ashamed of, and reporting still helps. In the UK that's Action Fraud.

Voice cloning is already here - A few seconds of audio off social media is enough to fake a relative's voice, which is what makes a simple family safe word worth setting up.


The FBI built a fake town to train its agents

Watch | Read

This was the one Ant loved. In Huntsville, Alabama, the FBI has built a 22,000 square foot fake town called the Kinetic Cyber Range, with wired up houses, a hotel, a gas station, a shop, a courthouse, a hospital and a power company, all joined by working roads and traffic lights. Every building runs real kit that behaves like the real thing, so agents can train on ransomware hitting a hospital or an attack on the grid, and there's even a server room they've deliberately kept cold, cramped and grim to match the conditions investigators actually work in. More than 1,400 people have trained there since it opened.

What got Ant was the street names, because they've called the roads DeLorean 1985 Street and Commodore 64 Avenue, and somebody has clearly had the time of their life building the place. Luke called it a movie set that actually works, which is about right. Underneath the fun there's a real point they both made, which is that tabletop exercises only take you so far. You can't shut down a live business to see what breaks, something the two of them know from warehouse days when the only slack in the day was an hour at shift change, and almost nobody gets a spare town to practise on.

The Awareness Angle -

Hospitals are the scenario that matters - The drills include ransomware knocking hospital systems offline, where an outage stops being an IT ticket and becomes a patient safety emergency. Anyone who's ever been treated in one has a stake in that.

The gap is the whole point - The FBI had to build a physical town to teach a digital subject, which tells you how far cybercrime now reaches into roads, traffic lights and power.

Practice beats theory - You don't really get a ransomware attack on a power company until you're stood in one that's just gone dark, and for most organisations a proper rehearsal is the closest they'll come.


Your Bluetooth earbuds could let a stranger listen in

Watch | Read

Apple has patched a serious flaw in its Beats Studio Buds that let someone nearby pair with them silently, no warning and no pop up, and then listen through the microphone sitting in your ear. It's a proximity attack, so they have to be close, your coffee shop, your office, your train carriage, but that's not much comfort when you've got them in for calls all day, and there's no way of knowing whether anyone used it before the fix landed.

Ant looked into it live and found this isn't new. The chip comes from a firm called Airoha, and back in July 2025 similar chips turned up vulnerable in Bose, Jabra, JBL, Marshall and Sony, among others. His question was whether Apple is just late to a known problem and it's only news because it's Apple. The useful bit came up too: AirPods usually patch themselves the second you drop them in the case, but loads of other gear doesn't. Ant's Anker speaker only updates if he opens an app he never otherwise touches, and as Luke said, if you've turned notifications off you won't even know there's an update waiting.

The Awareness Angle -

Install the update - The fix is out, but the gap between a patch landing and people applying it is weeks, so doing it now is one of the simplest wins you've got.

It's not only Beats - That Airoha chip sits inside earbuds from plenty of big names, so it's worth checking whether yours need an update too.

You never open the app - Most Bluetooth gear only updates through an app you used once at setup, so anything with a microphone is worth a check now and then.

Also this week

Malware hidden in Steam wallpaper downloads Watch | Read

Criminals slipped booby trapped wallpaper packs onto Steam Workshop, the community hub millions of gamers treat as safe, and the wallpapers ran perfectly while quietly installing malware underneath. The lesson is an old one. An official platform isn't the same as checked content, and a new creator with no track record is worth a second look even somewhere you trust.

A new Android trojan targeting 217 banking and crypto apps Watch | Read

Researchers spotted a new Android banking trojan called Rokarolla, built to go after 217 different banking and crypto apps across Europe, the US and Asia. With 137 separate commands behind it, this is a serious operation, not a hobbyist. The saving grace is the way it spreads, through unofficial app sources rather than the official Play Store, so it stays preventable.

Your cheap streaming box has been working for criminals Watch | Read

A botnet called Popa has spent four years quietly taking over cheap Android TV boxes, the thirty to fifty quid kind off market stalls and online, and using them for ad fraud, account takeovers and scraping. Researchers have traced it to a residential proxy company run by a NASDAQ listed Israeli firm, which denies it, and millions of boxes are thought to be caught up in it, all while still streaming telly exactly as sold.

Google to use UK and EU IP addresses for ad targeting Watch | Read

From 3 August, Google starts using IP addresses from UK, EU and Swiss users for ad personalisation and measurement, with no explicit consent needed under the usual cookie rules. The annoying part is that Google once called using IP addresses this way wrong. It happens automatically unless you go into your account settings and opt out, and the UK's ICO is now looking at whether the consent rules need a rethink.

Security Socials

The fake virus pop up that's just a web page Watch | Read

Ant shared a post from r/phishing where an iPhone user got a full screen "your device is infected" warning in Firefox, complete with Apple's liquid glass look and the browser buttons greyed out until they force closed the app. It looks terrifying and does precisely nothing. As the thread pointed out, it's just a JavaScript alert box with no payload, the sort of thing that lurks on dodgy streaming sites, and it behaves the same in Safari and Chrome because every iOS browser runs the same engine underneath. Close the tab, tap nothing.

Claude age verification, and what the viral post got wrong Watch | Watch on Instagram

Ant pulled up an Instagram clip claiming that from 8 July, Claude would demand your face, your ID and your biometrics just to keep using it. Reading the comments, he found the panic was overblown. The policy had been reworded, not rewritten, and the checks only trigger if an account looks like it needs them, for instance if it might belong to a minor. He also pointed out the verification would be handled by outside firms rather than the AI company, Yoti in the UK and Persona in the US, and neither is spotless, with Yoti fined by the Spanish regulator earlier this year. It tied straight back into the thread running through the whole episode about how much of our data already sits with companies we never picked.

The "15 Seconds of Fish" guy who fell for a fake captcha Watch | Watch on TikTok

Luke shared a TikTok from a musician, the "15 Seconds of Fish" guy, who got done by a ClickFix style fake captcha, the copy and paste trick that ends with one command quietly handing over the lot. The pair's point was that he's clearly no technophobe, with a properly kitted out smart home, and that's exactly why these land. Ant added that this is where your password manager earns its keep, since a locked vault keeps the blast radius small, while passwords saved in the browser, Edge especially, get unlocked the moment the browser opens and leave you exposed.

And Finally...

A captcha made of whale song

Watch | Read

Walking through King's Cross, Ant came across a student showcase piece by an spatial designer called Carolina Manríquez and it was awesome. 

A captcha made not of fire hydrants and traffic lights but of whale song, with a pulsing purple display and a pair of headphones so you could listen. Her idea was an excellent one. Those everyday captchas quietly train commercial AI, so why not aim that same effort at something worthwhile, like sorting through whale sounds for research. 

It set Ant off on Cloudflare's wall of lava lamps, which the company uses to generate encryption randomness, and then SETI@home, the old screensaver that borrowed your idle computer to scan the skies for alien signals. Luke threw in Folding@home, which did the same for disease research and even pitched in on COVID. A nice few minutes about pointing the internet's spare effort at something good for once.

Recently uploaded