Cybersecurity news for humans, not just IT people
This week on The Awareness Angle... it's Episode 100.
One hundred episodes. When Luke and I started this in November 2024, I don't think either of us believed we'd get here. But here we are, over a year and a half later, recorded in person for only the second time ever, and with some news of our own to share.
This is the last edition of The Awareness Angle as you know it. After this week, the show and this newsletter are taking a short break, and when the feed comes back to life towards the end of September it'll have a new name and a fresh look. It'll be the same mission, cyber news for humans, but just a bit different. So whatever you do, don't unsubscribe. There's more on that at the bottom of this newsletter.
All of that is in this week's The Awareness Angle!
Listen on your favourite podcast platform - Spotify, Apple Podcasts and YouTube
Listen Now
Podcast · Risky CreativeGet 25% off your pass to the SANS Security Awareness and Culture Summit until August 14th!
We are the official media partner of the SANS Workforce Security & Risk Training Security Awareness Summit in Las Vegas this August.
Ant will be there in person across both days, streaming live conversations, interviewing practitioners on the floor, and giving remote attendees access to what's happening at the summit in a way that hasn't really been done before. We want to hear from the people in the room, what they're working on, what's changing in their programmes, and what they're taking away.
If you're attending remotely and want to get your voice into the summit floor, there'll be an opportunity for that too.
We have an exclusive discount code for Awareness Angle listeners. Enter RISKY_SUMMIT_PASS at checkout for 25% off your pass.
Full details on the summit are here.
First, the news. Because even in a milestone week, the criminals didn't take one off.
This Week's Stories
The gang that hit the Department for Education just leaked 100,000 police staff
A group calling itself ExfilSquad has leaked the details of more than 100,000 UK police officers and criminal justice staff. The data came from the Police National Legal Database, first spotted on 26 July, and includes names, organisations and email addresses, all now posted on the dark web. If that name sounds familiar, it should. This is the same crew that turned over the Department for Education just last week.
Two arms of the British state in two weeks stops looking like bad luck and starts looking like a pattern. Is there a common system? Shared credentials? One third party supplier sitting behind both? We don't know yet, and we also don't know how long they'd been inside before anyone noticed. What we do know is that names, employers and email addresses are exactly the raw material you need for convincing phishing and impersonation. And if the police can't keep their own data safe, it's probably time to retire the assumption that anyone can.
Repeat offenders - When the same group hits multiple targets fast, they've usually found a repeatable weakness. Watch for the common thread rather than treating each breach as a one-off.
Contact data is ammunition - Names, employers and email addresses sound harmless, but they're the building blocks of convincing phishing and impersonation.
No institution is untouchable - Use this one to retire the "surely the police have this covered" assumption that lulls people into ignoring their own basic protections.
Scam factories were caught running their cons through ChatGPT
OpenAI has banned a batch of accounts tied to investment fraud run out of scam compounds in Cambodia. The operations targeted people in India with fake investment opportunities, the classic "your money is growing, just deposit a bit more" trap, and the crews were leaning on ChatGPT to write messages, keep multiple conversations going, and sound convincing across a language barrier. The same tool millions of us use to draft an email, used to make the con smoother.
The part that sticks with me is who was actually typing. Many of the people inside these compounds are victims themselves, lured with fake job ads and then held against their will and forced to scam strangers all day. If you were at the SANS Security Awareness Summit last year, you'll remember Erin West's jaw-dropping keynote on exactly this. Her work with Operation Shamrock is well worth your time, and she's just published a fresh expose that's equally shocking. There are two sets of victims in this story, the people losing money and the people being made to steal it.
Human cost - The person messaging your users may be a captive worker. That reframes the story without excusing the harm being done.
AI as an accelerator - AI didn't invent a new scam here. It makes old scams faster, cheaper, and much harder to spot by grammar alone.
Report the tip - This whole takedown started because someone flagged something on WhatsApp. Encourage people to report suspicious contacts rather than just deleting them.
That Roblox cheat your kid installed might have been malware
Fake versions of a popular Roblox tool called Xeno Executor are being passed around as free downloads. Install one and instead of a game booster you've got malware that steals saved passwords and hands remote control of the machine to an attacker. The lure works because young players actively hunt for these script tools to get an edge in games, and someone in a chat saying "download this, it's free" is all it takes.
As a parent whose kids play Roblox, this is close to home. As I was leaving the house to record this episode, my nine year old asked to go on my computer and I said yes without thinking. The family computer is rarely just the kid's. It's where the banking happens, where the work files live. A child chasing free in-game currency can end up exposing an adult's entire digital life. We've covered this pattern before, cheats, cracks and free stuff have always been the way in, and it's a conversation worth having at home this week.
Shared devices, shared risk - What one family member installs affects everyone who uses that machine. A useful frame for household security conversations.
Free tools, hidden price - Cheats, cracks and free add-ons are a classic malware delivery route, and kids are the prime audience.
Talk, don't just block - Rather than banning everything, have a calm chat about where downloads come from and why some are risky. If you're not sure it's genuine, don't download it.
Passkeys were meant to kill passwords, but malware found a way in
Researchers found three attacks, dubbed Pass-ta-key, targeting passkeys synced through Google Password Manager on Chrome for Windows. On an infected machine, the malware can hijack accounts, sidestep the usual identity checks, and even pull out the private keys behind a passkey. Not a great headline for the technology we've all been told is the phishing-proof future of logging in.
Here's the responsible way to tell it though. This is not passkeys being broken from the outside. The attack needs malware already running on your device, and once that's true, you're in a whole world of trouble regardless of how you log in. Passkeys are still a genuine upgrade over passwords, and I'm not letting this put me off. I spent yesterday setting my mum up with passkeys on her iPhone for her supermarket shopping, and I'd do it again. The truth is that no login method saves you if the device itself is compromised, which is exactly why keeping malware off it still matters.
Passkeys are still worth it - Don't let a scary headline scare people back to weak passwords. Passkeys remain a genuine improvement for most users.
Device health is the foundation - Almost every advanced attack assumes the device is already infected. Basic malware defence underpins everything else.
Nuance over panic - A good chance to model calm reporting. Explain the real limits of an attack rather than amplifying the worst case headline.
Security Socials
The fake police phone call
Luke brought a TikTok this week from a guy who got a call from someone claiming to be a police cybercrime unit. The caller ID matched the right police station, they had personal details, and the story was that his data had been recovered in a raid. It was believable enough that he nearly went along with it, until he asked an AI chatbot whether it sounded genuine and got told to hang up. The moment he pushed back, the caller went silent and gave up.
This is exactly what the breaches we cover week in, week out actually get used for. A name, a number and an employer is all it takes. The advice stands whoever's calling: if someone rings claiming authority and starts applying pressure, that pressure is the red flag. Hang up and call back on a number you trust. A genuine officer can give you a reference number to verify through 101. In the UK, Action Fraud is the place to report it.
The Polymarket hairdryer hack
My contribution this week is one of the most creative financial exploits I've ever seen. A crypto trader worked out that Polymarket was settling its Paris daily temperature bets using a single unguarded weather sensor near a runway at Charles de Gaulle. So he bought cheap long-shot shares predicting an unlikely temperature spike, walked up to the sensor from a public road, and blasted it with a battery powered hairdryer for four seconds. The recorded temperature spiked, the market settled in his favour, and he netted $34,000 across two visits before meteorologists spotted readings that contradicted every surrounding station. No code, no hacking, he just manipulated reality itself. It's been dubbed a physical oracle attack, and Meteo France was not amused. Unfortunately for him, CCTV caught the whole thing.
100 episodes of cyber news: what we've learned
We spent the back half of this episode digging through a hundred episodes of stories, and some patterns are hard to ignore.
The most recurring threat actor, no surprise, was ShinyHunters, linked to over 760 companies through the Salesforce campaign alone. The most common root cause we covered was third party vendor breaches, followed closely by weak, reused or guessed passwords, which I can't believe we're still talking about. The most common way in was social engineering the help desk. And ClickFix went from something nobody had heard of to being responsible for more than half of malware attacks in 2025.
The AI story arc might be the biggest shift of all. We started this show talking about ChatGPT phishing emails. We're ending it having covered AI agents running 90 percent of a nation state intrusion, Claude hacking three real companies on its own, and Gemini finding a thirteen year old Chrome vulnerability. AI is now both the attacker and the defender, and record breaking Patch Tuesdays are the proof.
And the stories I'll never forget: the IT worker who drilled holes in SSDs and missed the memory chips entirely. The Hungarian NATO infosec colonel whose password was Frank Lampard. The Louvre's CCTV password being Louvre. The ransomware gang that apologised and gave the data back after hacking a nursery. The FBI's fully working fake town. And the one that mattered most, the NHS Synnovis attack, the only breach we've covered that was directly tied to a patient's death. A reminder, if one was needed, that this stuff is never just data.
Talking Points
Some conversation starters for your team, your family, or the pub:
If a fake police call came from a number matching your local station, would you have hung up? What would it take to make you question a caller with authority?
Who else uses your family computer, and does everyone on it know what a dodgy download looks like?
After 100 episodes, weak passwords are still a leading cause of breaches. Why do we all know the fix and still not do it?
Goodbye for now
That's it. One hundred episodes. And before anything else, a thank you.
Luke, this show simply wouldn't exist without you. I would never have started The Awareness Angle on my own, and every week for over a year and a half you've helped make it what it is. When we come back, Luke won't be in the chair every week, but he'll be around, we've got more planned together, and nothing about this show's journey happens without him. Partner in cybercrime prevention doesn't really cover it.
And thank you to all of you. Because the numbers from 100 episodes tell a story which does make me warm and fuzzy, and still a little shocked sometimes.
Nearly 18,000 plays and downloads. Listeners in 103 countries, with the UK, US and Australia leading the pack. Over 2,100 hours of listening time on Spotify alone, which works out at about 88 solid days of cyber news. A peak of number 5 in the UK Tech News podcast charts, and a top 200 tech news podcast on Apple Podcasts in nearly thirty countries. Almost 1,600 of you now read this newsletter every week.
And for the curious, here's who's actually listening. Our biggest audience is 35 to 44 year olds, making up around 43 percent of you, followed by the 28 to 34s. Spotify just pips Apple Podcasts as your app of choice, 41 percent to 28, with the rest of you spread across Overcast, Pocket Casts and beyond. Not bad for two blokes who used to work together and thought it might be a laugh.
This isn't a goodbye, it's a see you soon. The feed goes quiet for a few weeks, I get my weekends back for a bit of the summer, and towards the end of September something new arrives in its place. More of the...similar is how I put it in this episode.
Don't unsubscribe. Follow me on TikTok, Instagram and LinkedIn for announcements, and I'll see you on the other side.