Jul 13, 2026
7 Million Driver's Licenses Leaked, Sainsbury's Facial Recognition Fail, Google Sues Gemini Scammers

This week on The Awareness Angle...

One phishing email cost an entire company nearly 7 million customer records, a teenager proved you don't need real hacking skills anymore if you've got a chatbot and some patience, and Google ended up suing people for abusing its own AI. Luke and I get into all of it, plus the story that started as a class action lawsuit within a day of going public.

All of that and a whole bunch more on this week's The Awareness Angle

Watch or listen to the episode today - YouTube | Spotify | Apple Podcasts

Visit riskycreative.com for past episodes, our blog, and our merch.

Get 25% off you pass to the SANS Security Awareness and Culture Summit!

Article content

We are the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.

Ant will be there in person across both days, streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. We want to hear from the people in the room, what they're working on, what's changing in their programmes, and what they're taking away.

If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too.

We have an exclusive discount code for Awareness Angle listeners. Enter RISKY_SUMMIT_PASS at checkout for 25% off your pass.

Full details on the summit are here.

This Week's News

One phished employee's login exposed 6.9 million driver's license numbers

Watch | Read

AssuranceAmerica, a US auto insurance provider, confirmed a data breach this week exposing personal information for just under 7 million people. It's the largest driver's license data spill disclosed so far this year. The stolen data includes names, contact details, driver's license numbers, insurance policy and claims information, and Social Security numbers and Tax ID details for some customers.

It all started with a phishing attack that stole the login credentials of one single employee. This is the bread and butter stuff Luke and I talk about every week, and it's exactly why phishing training matters. One person's mistake ended up exposing millions of other people's most sensitive data.

What's almost as striking as the scale is the timeline. The company detected the breach on March 17, didn't finish investigating until June 15, and only started sending notification letters on July 10. Within a day of that becoming public, a class action lawsuit was already being investigated. Someone saw seven million potential claimants and knew exactly what that meant.

Luke raised a fair point too, that it's easy to assume the employee was careless, but there's no detail yet on how sophisticated the phishing attempt actually was. It could easily have involved social engineering that most people would have fallen for.

Awareness Angles

One person's mistake becomes everyone's problem - a single phished employee credential led to nearly 7 million people's data being exposed, which is why phishing training isn't just an individual responsibility

Breach timelines are often longer than they look - detection, investigation and notification can span months, so "we just found out" rarely means "this just happened"

Driver's license numbers are worth more to criminals than people think - paired with Social Security numbers, they're commonly used to open fraudulent accounts and file fake insurance claims

A 15-year-old taught himself to hack in fourth grade, then used ChatGPT to take down an anime streaming service

Watch | Read

Japanese police arrested a 15 year old high school student accused of repeatedly hacking Bandai Channel, Bandai Namco's anime and tokusatsu streaming service. He allegedly cancelled the subscriptions of more than 46,000 accounts, forcing Bandai Namco to temporarily suspend the service.

He taught himself to code around fourth grade, then found the vulnerability by analysing the service's network traffic while still in junior high. He used ChatGPT to help write the malware, then changed his IP address around 30 times to keep dodging Bandai Namco's attempts to block him. He told police he wasn't motivated by anger at the company, he just did it because he could.

Luke picked up on that point during the show, that teenage hackers are often doing this to one up people and show off rather than for any real financial or personal gain. I added that it's a shame there wasn't a way to channel that kind of talent somewhere useful before it went the other way. We both agreed that the barrier to causing serious damage has basically collapsed. It used to take real skill to pull something like this off. Now it takes curiosity, patience, and a chatbot willing to fill in the technical gaps.

I went a step further on the show and suggested the industry needs proper bug bounty programmes aimed at kids like this, even joking about turning white hat hacking into an esport with league tables and sponsorships. Only half joking, since Luke found a genuine example moments later, an event called Hacker Rivals happening at Northeastern University Toronto in August.

Awareness Angles

Curiosity plus AI tools is a new risk profile - the old idea of a "sophisticated attacker" doesn't hold up when a chatbot can handle the technical parts for you

Companies need to watch for low motive attackers - this wasn't revenge or profit, just boredom and opportunity, which is much harder to predict or prevent

Blocking access alone isn't enough - Bandai Namco tried repeatedly cutting off his access, and he simply rotated his IP address around 30 times to get back in

Scammers used Google's own AI to help steal $1.9 billion, so Google is suing them

Watch | Read

Google has filed its first lawsuit over abuse of its Gemini AI tools, targeting a Chinese network it calls Outsider Enterprise. The group used Gemini to help build over 9,000 fake websites impersonating Google, YouTube, the US Postal Service, and toll services like E-ZPass. The FBI estimates the operation stole nearly 4 million credit card numbers and caused $1.9 billion in losses since 2023.

What makes this one stand out is that Outsider Enterprise wasn't just running the scam themselves, they were selling the whole thing as a product. Phishing kits and Gemini instructions were sold to other criminals through Telegram, so anyone with zero technical skill could run the same scams. This has genuinely been productised in a commercial way, complete with instructions and a name.

Luke made a sharp connection back to the ChatGPT malware story earlier in the episode, that both of these AI tools are supposed to have guardrails against this kind of misuse, and yet here are two stories in one episode proving otherwise. I had my own frustrating brush with AI guardrails that same week too, being refused a well known twelve word quote from Jurassic Park for a script because it was copyrighted, while these scammers were apparently having no trouble at all getting an AI to help write convincing phishing pages at scale.

We also pointed out just how much of what we've covered on the show over the past year, fake USPS delivery notices, toll payment scams, impersonated Google Ads, could plausibly trace back to a single group with one well built product. When you think about the scale of just one actor, that's when the size of the problem really sinks in.

Awareness Angles

Toll and delivery texts remain a top scam category - if a message about a package or toll payment creates urgency, that urgency is the manipulation

AI lowers the skill floor for scammers - people who couldn't have built a convincing fake site two years ago can now buy the instructions

Scale doesn't mean sophistication - a billion dollar operation can still be stopped by an individual person just pausing before they click

Also this week

A hacker is selling 35GB of Accenture's stolen source code and access keys - Watch | Read

A Sainsbury's shopper was told to leave the store after facial recognition wrongly flagged him - Watch | Read

OnlyFans creators are accidentally cleaning up hacked government websites - Watch | Read

A hidden Windows ID number is what finally caught an alleged Scattered Spider hacker - Watch | Read

Security Socials

OSINT is dangerous, imagine being tracked by one picture - Watch | Watch

An Instagram post walked through exactly how much someone can be tracked down from a single photo. A window with a balcony grate, a street sign confirming the country, writing on a van, a postcode, road markings, and within a few steps the exact location was found. It's the same kind of skill you see in geoguessing communities, where a single lamppost style or road marking can pin down a location almost instantly. A good reminder of how much detail sits in the background of photos we post without thinking twice.

My phone update just installed 17 apps - Watch | Watch

A Reddit post showed a Samsung S25, not exactly a budget phone, suddenly loaded with games and bloatware after an update. Turns out this was down to Verizon installing apps directly onto the device, something the user likely agreed to somewhere in a contract they never read. It happened even on a flagship phone bought through a network rather than direct from the manufacturer, which is the detail that surprised most people in the comments.

Something connected to my vibration plate at 3am - Watch | Watch

A TikTok video showed someone hearing their neighbour's conversation through their vibration plate in the middle of the night, sparking every conspiracy theory going in the comments. The real explanation turned out to be far more mundane. Cheap Bluetooth earbuds and the vibration plate shared the same manufacturer's Bluetooth radio, and the two devices ended up close enough to cross-connect. Not spies, just budget hardware doing something nobody designed it to do.

A fake AI avatar is stealing a YouTuber's likeness to sell scam ebooks - Watch | Watch

Luke brought this one to the show. A YouTuber with nearly 800,000 subscribers found a fake channel running an AI avatar wearing his exact outfit, sat in front of a near identical background, using his likeness to sell ebooks. It wasn't a perfect copy, but close enough to fool anyone scrolling quickly. The tools to do this are getting easier to access by the day, and Luke pointed out this creator almost certainly isn't the only one it's happening to.

It led Luke and me into a wider chat about how easy this kind of thing has become. Face-swapping tools, faceless AI channels, "upload your face once and get a hosted documentary short" services are all being sold openly now. What struck me most is that the fix probably isn't better detection, it's leaning harder into what can't be copied. The authenticity, the quirks, the actual relationship an audience has with a real person. That's the thing AI still can't fake, even if it can fake the face.

Recently uploaded