Jul 6, 2026
iPhone 18 Leaked, Aflac Hacked (Again) and a Bank Robber Who Just Asked Nicely

This week on The Awareness Angle...

A scammer didn't need to hack anything in Venezuela, they just needed a website that looked charitable enough for five minutes, while people were still being pulled from the rubble. A robber didn't need to break into a bank, he just needed an old uniform and enough confidence to ask for the cash collection like it was any other Tuesday. Hotel staff didn't get hacked because they were careless, they got hacked because a guest complaint is the most normal email in the world, right up until it isn't.

Even the good news this week fits the pattern. Opera built a browser feature to stop you pasting a command into your own computer, because the scariest thing about ClickFix has never been the malware, it's that you install it yourself, with your own hands, because something convinced you it was routine.

All of that and a whole bunch more on this week's The Awareness Angle

Watch or listen to the episode today - YouTube | Spotify | Apple Podcasts

Visit riskycreative.com for past episodes, our blog, and our merch.

Get 25% off you pass to the SANS Security Awareness and Culture Summit!

Article contentWill Ant see you in Vegas?

We are the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.

Ant will be there in person across both days, streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. We want to hear from the people in the room, what they're working on, what's changing in their programmes, and what they're taking away.

If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too.

We have an exclusive discount code for Awareness Angle listeners. Enter RISKY_SUMMIT_PASS at checkout for 25% off your pass.

Full details on the summit are here.

This Week's News

Scammers Raced to Cash In on the Venezuela Earthquake Before Rescuers Even Arrived

Watch | Read

Within a day of the earthquake hitting Venezuela, before rescue teams had even finished pulling people from the rubble, scammers were already registering donation websites. Researchers counted over 200 new domains referencing the disaster in less than a week, and almost all of them hid who was actually behind them. Some were asking for donations in Bitcoin only, which tells you most of what you need to know, since real charities want your donation traceable, not anonymous.

As Ant pointed out on the show, this isn't new behaviour. The same pattern showed up after Hurricane Harvey, during COVID, and even years after the 2011 Japan tsunami, when fraudsters were still inventing stories about deceased businessmen and unclaimed fortunes. Disasters create urgency, and urgency is exactly what scammers need people to feel instead of caution.

Speed is the tell - legitimate charities rarely spin up a brand new website within hours of a disaster, so a fresh domain is always worth a second look.

Crypto only is a red flag - real charities offer traceable, conventional ways to pay and are transparent about where the money goes.

Type it in yourself - going directly to a charity's known website, rather than clicking a link someone shared, removes most of the risk.

Hackers Hit Japanese Hotels With Fake Guest Complaints to Sneak In Malware

Watch | Read

Phishing emails posing as guest reviews and complaints have been targeting hotel staff who work with booking platforms, mostly in Japan but also hitting hotels in the UK, US and Australia. Clicking through leads to a malware implant called TONResolver, hidden using blockchain technology to make it harder to shut down. The malware doesn't steal anything right away, it just opens a hidden connection so attackers can strike later, whenever it suits them.

Hotel staff deal with guest complaints constantly, so an email about a stay review doesn't raise any flags, it just looks like another Tuesday. That's exactly why it works so well. Luke made a good point on the episode too, the victim usually doesn't see anything happen right away, so there's a real temptation to assume it was nothing. That's exactly the gap this attack is built to exploit.

Guest complaint pressure is real - Staff feel obligated to respond quickly to anything that looks like a customer complaint, and attackers count on that urgency.

Slow down on booking platform emails - A moment spent checking the sender's actual address catches most of these.

Delayed attacks are real - Malware that waits before acting is designed to slip past the instinct that a quiet aftermath means everything's fine.

Cyberattacks on UK Hospitals Have Shot Up Tenfold This Year

Watch | Read

Security firm SonicWall recorded 264,000 attack events against UK healthcare systems in the first five months of 2026, compared with 27,000 for all of 2025. Two in five of those attacks tried to exploit Log4Shell, a vulnerability that was discovered and patched back in 2021, and a third of sensors also picked up break-in attempts against F5 load balancers widely used across the NHS.

Ant made the point on the show that a year doing cybersecurity in healthcare is basically five years anywhere else. Hospital software often can't be updated on a normal patching schedule, because taking a critical clinical system offline even briefly can affect patient care, so old vulnerable systems stay running far longer than anyone would like. At the same time, the rush to digitise is opening brand new doors, with fresh vulnerabilities showing up in newly built patient portals.

Legacy tech is a patient safety issue - Old, unpatched software in hospitals isn't just an IT headache, it can affect care directly.

New digital tools bring new risk - Every convenient new patient portal is also a new door for attackers to test.

Hospitals can't simply switch things off - Unlike most businesses, healthcare systems can't take a critical service offline to patch it without risking patient care, which is part of why this keeps happening.

Also this week

Medtronic tells millions of customers their health data and Social Security numbers were stolen, though the actual medical devices are safe to use. Watch | Read

Aflac's Japan business gets breached for the third time in a few years, exposing bank details for 4.4 million customers. Watch | Read

630GB of unreleased iPhone 18 Pro design files get leaked from Apple supplier Tata Electronics. Watch | Read

Opera launches Paste Protect, a browser feature built to stop you hacking yourself with a clipboard paste. Watch | Read

Talking Points

PewDiePie tells his followers to ditch ChatGPT for a self hosted AI tool called Odysseus. Anyone downloading it should know what they're taking on. Watch | Read

A retro Commodore flip phone launches with no social media and no browser at all. Watch

A bank robber walks out with £117,000 just by wearing an old uniform and asking nicely. He got caught because he came back from Ghana. Watch

Someone built a reusable tamper evident jar for storing sensitive items, and it's a surprisingly clever piece of analogue security. Watch | Read

Blurring someone's face doesn't hide their identity the way you'd think. Watch

WhatsApp usernames are rolling out to keep your phone number private, but the amount of metadata WhatsApp still holds on you tells its own story. Watch

Thanks for reading! If you’ve spotted something interesting in the world of cyber this week, a breach, a tool, or just something a bit weird, let us know at hello@riskycreative.com. We’re always learning, and your input helps shape future episodes.

Ant Davis and Luke Pettigrew write this newsletter and podcast.

The Awareness Angle Podcast and Newsletter is a Risky Creative production.

All views and opinions are our own and do not reflect those of our employers.

Recently uploaded