Cybersecurity news for humans, not just IT people
Click the picture above to see us move and talk!
This week on The Awareness Angle...
...the internet came for your fridge, your laptop and your DNA, and it wasn't subtle about any of it. Hackers shut down Coca-Cola's US milk production with ransomware. Mac users got hit with two new malware strains in the same week. And 23andMe is paying $18 million for letting people's genetic data leak, which is the one breach you genuinely cannot fix by changing a password. We've also got fake e-cards hiding remote access tools, the TFL hackers heading to prison, Microsoft's biggest ever Patch Tuesday followed within hours by a researcher dropping a fresh unpatched bug, and a law firm that used one master password for everything.
All of that and a whole bunch more on this week's The Awareness Angle
Watch or listen to the episode today - YouTube | Spotify | Apple Podcasts
Visit riskycreative.com for past episodes, our blog, and our merch.
Get 25% off you pass to the SANS Security Awareness and Culture Summit!
Just 5 weeks to go!
We are the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.
Ant will be there in person across both days, streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. We want to hear from the people in the room, what they're working on, what's changing in their programmes, and what they're taking away.
If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too.
We have an exclusive discount code for Awareness Angle listeners. Enter RISKY_SUMMIT_PASS at checkout for 25% off your pass.
Full details on the summit are here.
This Week's News
Lidl is telling customers their data was caught up in a breach at one of its suppliers
Lidl has notified customers in the Netherlands, Belgium and Germany that their data was exposed in a breach, but here's the thing: Lidl itself wasn't hacked. A third-party supplier was. The data taken included names, phone numbers, email addresses, dates of birth and customer numbers. Passwords, payment details and billing addresses appear to be unaffected, though Lidl was careful to phrase it as "at this time we can rule it out," which leaves the door open for updates.
This is the supply chain problem in a form everyone understands. You hand your details to a shop you trust, that shop passes some of that data to a supplier you never agreed to and never even knew existed, and the leak happens over there. From where you're sitting as a customer, that feels deeply unfair, because you had no way to vet a company you didn't know was in the chain. As Luke and I discussed on the show, there's also a document handling question here. This doesn't look like a full system compromise. It looks like one exported file sitting somewhere it shouldn't have been. Simple mistakes, big consequences.
If you've got colleagues or people in your life in those three countries who shop at Lidl, it's worth flagging. Watch for phishing attempts that reference your Lidl account, because the stolen data is exactly what you'd use to make a scam call sound convincing.
Awareness Angles
Your data has subcontractors - The brands people trust pass data down a chain of suppliers. A breach can reach your people from a company they've never heard of, which is why "I only gave it to a reputable company" isn't the full picture.
Third-party risk is everyone's risk - For security teams, a vendor's failure becomes your customer notification and your reputation hit. This is the everyday version of that conversation.
Read the breach letter - Encourage people to actually read these notifications rather than dismiss them. The detail of what specifically leaked tells you what kind of scam to watch for next.
23andMe is paying $18m over the breach that exposed people's DNA, and the settlement forces it to actually protect the data
Forty-two US state attorneys general have reached an $18 million settlement with 23andMe over the 2023 breach that exposed ancestry data and genetic information belonging to more than six million people. This one is worth revisiting because it keeps developing. The company filed for bankruptcy, the data became an asset in that process, and it was eventually sold to TTAM Research, a non-profit created by 23andMe's own founder. The settlement isn't just a cheque either. Regulators are now mandating specific data protection requirements the company has to meet going forward.
Most breaches leak an email address or a card number and you move on. This one is different because what leaked is you. Your ancestry, your relatives, your genetic makeup. You cannot reset your DNA. That's why this story still lands even years after it first broke, and it's why Luke and I keep coming back to it. The attackers didn't even break in through some sophisticated exploit. They got into accounts that didn't have multi-factor authentication enabled and worked from there. The fanciest data in the world, protected by the most basic gap.
If you or anyone you know sent a sample off to 23andMe back when it was all the rage, now is a fair moment to ask where that data actually lives, who owns it now, and whether you've exercised any right to deletion.
Awareness Angles
Some data is permanent - This is a useful way to explain the difference between data you can change and data you can't. It reframes why certain services deserve more careful thought before you sign up.
Consent has a long tail - Data handed over years ago is still out there. Encourage people to go back through old accounts and delete what they no longer use or need.
Fines are becoming obligations - Point security teams to the trend of regulators mandating specific controls rather than just issuing penalties. That changes how you make the case for security spend internally.
New Mac malware locks you out of your own computer and won't stop until you type your password in
This one is called ClickLock, and it is a bit nasty. It runs what researchers call a kill loop, repeatedly shutting down your apps every fraction of a second so the machine becomes completely unusable. Finder, your dock, your browsers, your terminal, even Activity Monitor, the tool you'd use to kill a rogue process. All of it just slammed shut the moment you open it, for up to 83 hours. The only way to make it stop is to type in your password, which is exactly what it's harvesting. It also kills notification centre for around six hours to suppress Gatekeeper warnings, so Apple's own defences go quiet while this is happening.
It starts with a ClickFix-style trick: a webpage tells you there's a problem and walks you through steps to fix it, and those steps are what infect you. As I said on the show, if you've done that and you're now being asked to enter a password, don't. Hold down the power button. Force a shutdown. Solid-state drives handle sudden stops fine. When the machine comes back up, you should be clear. The dangerous moment is the paste, not the password prompt.
This has already hit at least a hundred victims across thirty-three countries in about two months. That sounds small, but once something like this proves it works, it gets replicated fast.
Awareness Angles
Macs get malware too - Kill the "Apple computers don't get viruses" myth directly, because that false confidence is exactly what makes Mac users click.
Friction as a weapon - Attackers deliberately make things annoying to push you into a rushed decision. Slowing down is a defence. If your computer is behaving strangely, that's a moment to stop, not to comply.
Never follow a webpage's repair steps - A website telling you to copy, paste or run something to fix your device is the attack, not the fix. That rule is absolute.
Also this week
Mac malware is dressing up as Apple's own crash reporter to steal your passwords. Researchers at Jamf Threat Labs detailed CrashStealer, which abuses a legitimate Apple Developer ID to look signed and trusted, then presents a fake installer to steal credentials, browser passwords, crypto wallets and Apple Keychain data. Paired with ClickLock, the theme of the week for Mac users is clear. Watch | Read
The pair behind the Transport for London hack got five and a half years each in prison. Both pleaded guilty under the Computer Misuse Act. The judge described the motivation as "selfish bravado," which is about as perfect a three-word summary of Scattered Spider as you'll find. As I said on the show, this is a rare story where you get to see the whole arc from the attack all the way through to consequences. Watch | Read
Scammers are hiding malware inside cheery online greeting cards. A campaign called Seasonal Invite ran for around six months, using Valentine's, Easter, Spring and Christmas lures to trick people into installing legitimate remote monitoring tools that then handed attackers full remote access to the machine. The clever bit is that the software itself isn't malware. It's the same remote access tools IT departments use, which is exactly why it sails past defences. Watch | Read
Microsoft had its biggest ever Patch Tuesday, somewhere between 570 and 622 patches depending on who's counting, then a researcher known as Nightmare Eclipse dropped a brand new unpatched Windows vulnerability called LegacyHive hours later, just to make a point. It's a privilege escalation bug, so it promotes an attacker already on a machine to full control. Nightmare Eclipse kept some details back to limit misuse, but the message was clear enough. The work is never done. Also inside this month's patches: a BitLocker bypass flaw that let someone with physical access to a device get around the encryption entirely. It's fixed now, but it's a good prompt to check your encryption is actually on. Watch | Read
Ransomware hit Coca-Cola's dairy brand fairlife and temporarily shut down US milk production. Canadian operations kept running and the company says product quality and safety weren't affected, but the production lines went dark while outside experts were brought in and law enforcement notified. No one has claimed responsibility yet. This one is worth watching as it develops. Watch | Read
Security Socials
ChatGPT sent someone on a wasted road trip to a bike shop
My local bike shop, Highway Cycles, posted a video about a customer who drove quite a distance to come and see them because ChatGPT had told them the shop had a specific rally bike in stock. They didn't have one. They hadn't had one for ages. The shop's message was simple: call us before you come, don't trust ChatGPT for bike hunting. I couldn't find the video in time for the newsletter but the story stuck with me because of the trust involved. Someone took an AI's word for it completely, didn't think to verify, and made a real-world trip based on a hallucination. That's the gap we're still closing. Watch
A ClickFix awareness video with half a million likes
Liam sent me this one, so hello Liam. It's a TikTok video called "Not a Deep Fake" that walks through a ClickFix attack. Standard stuff for anyone in security, but half a million people liked it. What got me was the comment section. Top comment: "how do you fall for that?" Right underneath it, someone called Milena replied with something along the lines of: me, I have a master's degree and I've worked in corporate my whole adult life, but computers do this stuff all the time and I could see myself falling for it on a busy day or when I'm sleep deprived. That is the whole show, right there in two comments. That's why we keep talking about this. Watch
AI facial recognition put an innocent grandmother in jail for five months
Police in Fargo, North Dakota used AI facial recognition to link a Tennessee woman to bank fraud cases in a state she says she's never visited. She was arrested, and spent more than five months in jail before the errors were acknowledged. The police have since prohibited use of the tool and admitted mistakes, but stopped short of an apology. The system used was ClearView AI, deployed by a partner agency without executive knowledge or approval. Five months. For something she didn't do, in a state she'd never been to, identified by a tool that got it wrong. That's the real-world cost of AI error at its most serious. Watch | Read
General Motors is removing authenticator app MFA in favour of SMS
A Reddit post from a GM OnStar account holder shared an email they'd received saying that third-party authenticator app support is being removed by the end of August, and that the recommended replacement is SMS. As I said on the show, SMS is the weakest form of MFA. I switched banks specifically because my old one only offered SMS. And here's GM, the company that also decided to drop CarPlay and Android Auto so they could own the data from their infotainment systems, now deciding to downgrade their own security in the same direction. Incredible. Watch | Read