WEBVTT

1
00:00:02.112 --> 00:00:12.112
<v Unknown>Did she think of sending a Truth Social message to the winner of the inaugural FIFA Peace Prize? Because he's normally online, and I believe he probably has the mobile phone number of the FIFA president.</v>

2
00:00:12.112 --> 00:00:22.111
<v Unknown>Smashing Security, Episode 473: How a Hacker Could Have Rickrolled the Entire World. World Cup with Graham Cluley and special guest Danny Palmer.</v>

3
00:00:22.111 --> 00:00:32.112
<v Unknown>Hello, hello, and welcome to Smashing Security episode 473. My name's Graham Cluley.</v>

4
00:00:41.149 --> 00:00:42.191
<v Danny Palmer>And I'm Danny Palmer.</v>

5
00:00:42.191 --> 00:00:49.725
<v Graham Cluley>Danny, great to have you on the show again. As regular listeners know, you are a cybersecurity journalist. Busy month, isn't it?</v>

6
00:00:49.725 --> 00:00:57.259
<v Graham Cluley>I mean, there's lots of events going on and things like that. You must be going from event to event, writing story after story.</v>

7
00:00:57.259 --> 00:01:04.278
<v Danny Palmer>It has been busy, of course, as you well know as well. It was Infosecurity Europe this month and you were on stage hosting. I saw you on the stage. I didn't get to see you in person.</v>

8
00:01:04.278 --> 00:01:11.299
<v Danny Palmer>I did see you in person at one point, actually. Did you? But—</v>

9
00:01:11.299 --> 00:01:12.959
<v Graham Cluley>You should have given me a wave.</v>

10
00:01:12.959 --> 00:01:20.459
<v Danny Palmer>Well, this is from behind and you turned into the toilets. So I thought you wouldn't want a tap on the shoulder at that point. But no, I could have sprinted up, but I doubt it would have been welcomed.</v>

11
00:01:20.459 --> 00:01:27.959
<v Danny Palmer>But no, it was a good show. It's one of the biggest cybersecurity events in, well, Europe. But this time I was working at Infosecurity Magazine.</v>

12
00:01:27.959 --> 00:01:35.459
<v Danny Palmer>So I was covering it from that side. So it was very, very hands-on. Lots of people seem to enjoy the talks, good feedback from sessions.</v>

13
00:01:33.439 --> 00:01:40.165
<v Danny Palmer>So that's good.</v>

14
00:01:35.459 --> 00:01:42.959
<v Danny Palmer>People like you, obviously, there's always nice things said about you and feedback from the events.</v>

15
00:01:40.165 --> 00:01:46.891
<v Danny Palmer>But yeah, it was grand.</v>

16
00:01:44.042 --> 00:02:14.042
<v Graham Cluley>Oh, thank you.</v>

17
00:01:46.891 --> 00:01:54.391
<v Graham Cluley>Well, before we kick off, let's thank this week's wonderful sponsors, BlackKite, ProtonPass, and Vanta. We'll be hearing more about them later on in the podcast.</v>

18
00:01:54.391 --> 00:02:01.891
<v Graham Cluley>This week on Smashing Security. We won't be talking about how Brazil suspended its mobile phone emergency alert system after a hacker sent false warnings to phones across the country.</v>

19
00:02:01.891 --> 00:02:09.391
<v Graham Cluley>You'll hear no discussion of how tech site Gizmodo has been caught hitting readers with click-fix malware prompts. And we won't even mention how two men have pled guilty to the £39 million cyberattack on Transport for London, which impacted 10 million commuters.</v>

20
00:02:09.391 --> 00:02:16.891
<v Graham Cluley>So Danny, what are you going to be talking about this week?</v>

21
00:02:31.930 --> 00:02:36.721
<v Danny Palmer>I'm going to be talking about a security issue at FIFA which could have got everyone rickrolled.</v>

22
00:02:36.721 --> 00:02:45.347
<v Graham Cluley>And I'm going to be talking about a devastating Dutch fraud epidemic that has forced police into a bold response involving motorway billboards.</v>

23
00:02:45.347 --> 00:02:53.972
<v Graham Cluley>Plus, don't miss our featured interview with Jeffrey Wheatman, where we'll be looking at BlackKite's report into ransomware and extortion attacks across Europe.</v>

24
00:02:53.972 --> 00:03:02.598
<v Graham Cluley>All this and much more coming up on this episode of Smashing Security.</v>

25
00:03:02.598 --> 00:03:05.941
<v Joe>Graham, what's this about a new report from one of our sponsors?</v>

26
00:03:05.941 --> 00:03:11.086
<v Graham Cluley>Yes, BlackKite have just put out their first ever European Cyber Risk Report.</v>

27
00:03:11.086 --> 00:03:16.231
<v Graham Cluley>And oh my goodness, they've been looking into ransomware attacks across Europe for the last year and a half or so.</v>

28
00:03:16.231 --> 00:03:20.020
<v Joe>And let me guess, everything is fine and we have nothing to worry about?</v>

29
00:03:20.020 --> 00:03:26.443
<v Graham Cluley>Well, ransomware is up 55% year on year in the first 4 months of 2026 alone.</v>

30
00:03:26.443 --> 00:03:27.807
<v Joe>So, not fine.</v>

31
00:03:27.807 --> 00:03:35.903
<v Graham Cluley>No, Joe, not fine at all. Nearly 70% of all European ransomware activity is concentrated in just 5 countries.</v>

32
00:03:35.903 --> 00:03:44.001
<v Graham Cluley>And this report from BlackKite breaks down exactly where the attacks are hitting hardest and which hacking groups are responsible.</v>

33
00:03:44.001 --> 00:03:46.903
<v Joe>So is there anything in there beyond the headline numbers?</v>

34
00:03:46.903 --> 00:03:53.192
<v Graham Cluley>The bit that really struck me is what they found about third-party risks. A lot of companies aren't being attacked directly.</v>

35
00:03:53.192 --> 00:03:59.479
<v Graham Cluley>Instead, they're being caught in the blast radius of an attack on one of their suppliers.</v>

36
00:03:59.479 --> 00:04:03.008
<v Joe>Right. You're only as secure as the weakest link in your supply chain.</v>

37
00:04:03.008 --> 00:04:10.490
<v Graham Cluley>And the report has some real-world examples that illustrate this perfectly.</v>

38
00:04:10.490 --> 00:04:17.973
<v Graham Cluley>For instance, there's a Swedish company, it has an unpronounceable name, they got hit and that ended up causing huge problems at hundreds of organisations, exposing the data of over a million people.</v>

39
00:04:17.973 --> 00:04:47.973
<v Joe>All from one incident.</v>

40
00:04:17.973 --> 00:04:23.548
<v Graham Cluley>All from one incident.</v>

41
00:04:23.548 --> 00:04:29.125
<v Graham Cluley>And the report also covers how regulations like NIS2 and DORA are forcing European businesses to get much more serious about all of this.</v>

42
00:04:29.125 --> 00:04:31.343
<v Joe>Sounds like essential reading, frankly.</v>

43
00:04:31.343 --> 00:04:41.343
<v Graham Cluley>It is, and it's free.</v>

44
00:04:41.343 --> 00:04:51.343
<v Graham Cluley>Get the full</v>

45
00:04:51.343 --> 00:05:01.343
<v Graham Cluley>report at blackkite.com/smashing.</v>

46
00:05:28.096 --> 00:05:36.672
<v Joe>That's Black Kite, B-L-A-C-K-I-T-E.com/smashing. And thanks to Black Kite for supporting the show.</v>

47
00:05:36.672 --> 00:05:43.156
<v Graham Cluley>Now, Danny, imagine you're at home. It's maybe a Tuesday afternoon, nothing unusual going on, and your phone rings and it's your bank.</v>

48
00:05:43.156 --> 00:05:49.639
<v Graham Cluley>Well, it's someone claiming to be from your bank.</v>

49
00:05:49.639 --> 00:06:02.384
<v Danny Palmer>I see.</v>

50
00:06:02.384 --> 00:06:07.807
<v Graham Cluley>And they're very polite, very professional, and they say, Danny, I'm afraid there's been some suspicious activity on your account. And they say, there's nothing to worry about, Danny.</v>

51
00:06:07.807 --> 00:06:13.228
<v Graham Cluley>We don't want you worrying, Danny.</v>

52
00:06:13.228 --> 00:06:43.228
<v Danny Palmer>Well, that's reassuring.</v>

53
00:06:34.230 --> 00:06:43.783
<v Danny Palmer>Panic.</v>

54
00:06:43.783 --> 00:06:50.653
<v Graham Cluley>They just want you to verify a few details. Now, your spider sense as a cybersecurity expert is tingling at this point. You think, oh, hang on, they're going to ask me for a password or they're going to ask me for something like that. They don't do anything like that. What they do is they say, look, we think you could be having some problems with your account.</v>

55
00:06:50.653 --> 00:06:57.526
<v Graham Cluley>We think maybe you're having some problems on your computer. There's lots of hackers about. Tell you what we're going to do, we're going to send someone round to help you. Now, you might be a little bit suspicious about that, knowing the evil corporations which are financial institutions and the likelihood that they would ever send anyone round.</v>

56
00:06:57.526 --> 00:07:04.115
<v Danny Palmer>They only send someone round when they want</v>

57
00:07:04.115 --> 00:07:10.702
<v Danny Palmer>something from you.</v>

58
00:07:04.427 --> 00:07:14.427
<v Graham Cluley>Well, it's not that reassuring, is</v>

59
00:07:10.702 --> 00:07:16.841
<v Graham Cluley>Right, right. But if you were, for instance, a little bit vulnerable or elderly or weren't too tech savvy, you might say, oh, would you do that? Would you come around? Because I just can't work out what I have to do here.</v>

60
00:07:14.427 --> 00:07:24.427
<v Graham Cluley>it? Whenever a company says, now,</v>

61
00:07:16.841 --> 00:07:22.980
<v Graham Cluley>Maybe you would be a little less suspicious. And because they've been polite, maybe you've been born in a different age where you're more trusting of people. I don't think you, Danny, would say, sure, come on round, would you?</v>

62
00:07:22.980 --> 00:07:32.980
<v Danny Palmer>No, no. It's one of those things where I've not had this particular thing happen</v>

63
00:07:24.427 --> 00:07:34.427
<v Graham Cluley>we don't want you to panic, but—</v>

64
00:07:32.980 --> 00:07:42.980
<v Danny Palmer>to me, but a few years ago, I had an alert from my bank saying</v>

65
00:07:42.980 --> 00:07:52.980
<v Danny Palmer>my bank card had been used elsewhere in the world.</v>

66
00:08:01.649 --> 00:08:11.649
<v Graham Cluley>Yes. Well, anyway, this particular scam, which has been called bank help desk fraud, has</v>

67
00:08:11.649 --> 00:08:21.649
<v Graham Cluley>been running rampant across the Netherlands. And the Netherlands, you just think it's a land</v>

68
00:08:21.649 --> 00:08:31.649
<v Graham Cluley>of bicycles and Edam cheese and just ostentatiously tall people.</v>

69
00:08:28.574 --> 00:08:34.673
<v Graham Cluley>It turns out it's also the home of help</v>

70
00:08:34.673 --> 00:08:40.774
<v Graham Cluley>desk fraud as well.</v>

71
00:08:40.774 --> 00:08:50.486
<v Danny Palmer>Well, it's a tech-savvy country, lots of startups there.</v>

72
00:08:50.486 --> 00:08:58.905
<v Graham Cluley>That's very true. And there certainly have been over the years many servers which have been run by the criminals. They've often been hosted in the Netherlands as well.</v>

73
00:08:58.905 --> 00:09:10.789
<v Danny Palmer>That is true, yeah.</v>

74
00:09:10.789 --> 00:09:18.711
<v Graham Cluley>Anyway, criminals apparently are calling victims pretending to be bank employees with all sorts of COVID stories. So they say, "We've detected unusual transactions," a bit like that call which you received, or "We need to increase your overdraft limit," or "We're trying to protect your account from some kind of problem." Whatever the script is saying, there's always some urgency. There's some authority in the voice which they're using. And because, you know, this is mainland Europe we're talking about, so they're still fairly civilised compared to us Brits.</v>

75
00:09:18.711 --> 00:09:29.453
<v Danny Palmer>Us all being painted on woad on our island here.</v>

76
00:09:28.580 --> 00:09:58.580
<v Graham Cluley>Right.</v>

77
00:09:29.453 --> 00:09:35.221
<v Graham Cluley>They will go so far as to offer hands-on help.</v>

78
00:09:35.221 --> 00:09:40.990
<v Graham Cluley>"If you're unsure what to do." So they're actually sending people to the victims' doors to collect their bank cards, their cash, whatever they can get.</v>

79
00:09:40.990 --> 00:09:47.316
<v Danny Palmer>I suppose the Netherlands isn't a huge country.</v>

80
00:09:47.316 --> 00:09:53.642
<v Danny Palmer>You can quite drive across it in a few hours.</v>

81
00:09:53.642 --> 00:10:23.642
<v Graham Cluley>I suppose so.</v>

82
00:10:17.438 --> 00:10:22.755
<v Graham Cluley>I bet the public transport's fantastic. Just this week, Dutch police raided an Amsterdam house. They found 6 people aged between 15 years old and 30, running a makeshift call centre, basically from someone's living room.</v>

83
00:10:22.755 --> 00:10:28.073
<v Graham Cluley>They were caught mid-call with a potential victim on the line when the police walked in. And this is apparently something which is happening a great deal and it's causing all sorts of problems. Now, there is a companion scam to this one where they send around the bank employee saying, "Oh, you know, we're worried about your money or whatever, so we'll come round, take your money." And put it somewhere safe for you because you can't look at it.</v>

84
00:10:28.073 --> 00:10:38.073
<v Danny Palmer>Yeah, we'll take that money from under your bed</v>

85
00:10:38.073 --> 00:10:48.073
<v Danny Palmer>and store it in a safety deposit box that</v>

86
00:10:48.073 --> 00:10:58.073
<v Danny Palmer>you don't know where it is.</v>

87
00:10:49.807 --> 00:10:59.807
<v Danny Palmer>Plus, it's difficult to be assertive when you've</v>

88
00:10:59.807 --> 00:11:09.807
<v Danny Palmer>got someone who says they're an expert on</v>

89
00:11:09.807 --> 00:11:19.807
<v Danny Palmer>the other end of the line.</v>

90
00:11:12.394 --> 00:11:22.394
<v Danny Palmer>Well, it's social engineering, isn't it? I suppose while you could</v>

91
00:11:22.394 --> 00:11:32.394
<v Danny Palmer>go on the phone, "Okay, I'm not doing that," if there's</v>

92
00:11:32.056 --> 00:11:40.693
<v Graham Cluley>So there is a companion scam running alongside this one. And it's perhaps even more brazen.</v>

93
00:11:32.394 --> 00:11:42.394
<v Danny Palmer>someone at your door asking something, it's harder.</v>

94
00:11:40.693 --> 00:11:49.331
<v Graham Cluley>It is called fake police officer fraud.</v>

95
00:11:47.729 --> 00:11:57.729
<v Danny Palmer>What I did then was</v>

96
00:11:49.331 --> 00:12:00.582
<v Danny Palmer>They've been thoughtful of these names, haven't they?</v>

97
00:11:57.729 --> 00:12:07.729
<v Danny Palmer>I called my actual bank</v>

98
00:12:00.582 --> 00:12:06.264
<v Graham Cluley>They have. It's a good name, but it requires a different fancy dress costume.</v>

99
00:12:06.264 --> 00:12:11.946
<v Graham Cluley>So rather than dressing up like someone who works at the bank, you know, with a bowler hat and an umbrella and that pinstripe suit, you turn up dressed as a policeman. Now—</v>

100
00:12:07.729 --> 00:12:17.729
<v Danny Palmer>and did it that way.</v>

101
00:12:11.946 --> 00:12:41.946
<v Danny Palmer>Yes.</v>

102
00:12:11.946 --> 00:12:26.946
<v Danny Palmer>Like some sort of</v>

103
00:12:21.158 --> 00:12:51.158
<v Danny Palmer>Yeah.</v>

104
00:12:26.946 --> 00:12:41.946
<v Danny Palmer>criminal Mr. Ben.</v>

105
00:12:35.578 --> 00:12:50.063
<v Danny Palmer>Oh no.</v>

106
00:12:39.970 --> 00:12:49.970
<v Graham Cluley>I mean, we're laughing, but if you are a nonagenarian — and I'm not saying all people who are elderly aren't tech savvy, because obviously some of them are very,</v>

107
00:12:49.970 --> 00:12:59.970
<v Graham Cluley>very tech savvy — but if you are someone who's maybe a little bit more trusting, a little bit more vulnerable, you might well fall for that kind of thing.</v>

108
00:12:50.063 --> 00:12:56.520
<v Graham Cluley>But don't worry, we're going to send one of our colleagues from the police force. We're going to get them to pop round and keep your valuables safe on your behalf because there's someone going around stealing stuff.</v>

109
00:12:56.520 --> 00:13:02.977
<v Graham Cluley>It's like, yes, there's someone going around stealing stuff because it's the person who's dressed up as a policeman pinching all your gear.</v>

110
00:12:59.970 --> 00:13:09.970
<v Graham Cluley>You know, it's people often towards the end of their lives who have a lot of assets. Which makes some rich pickings.</v>

111
00:13:02.977 --> 00:13:10.517
<v Danny Palmer>It's very old school, isn't it? It's almost like a Wild West element to it as well.</v>

112
00:13:10.517 --> 00:13:18.056
<v Danny Palmer>You'd have someone dressed up as a sheriff going around to do that to people, you know, 150 years ago.</v>

113
00:13:18.056 --> 00:13:24.730
<v Graham Cluley>Apparently they knock on your door, they flash a warrant card, because that's convincing, isn't it?</v>

114
00:13:24.730 --> 00:13:31.403
<v Graham Cluley>You also got to have a little laminated card and it's like, oh well, then you're clearly someone in authority.</v>

115
00:13:31.403 --> 00:13:46.488
<v Danny Palmer>Especially if it's laminated.</v>

116
00:13:46.488 --> 00:13:56.488
<v Graham Cluley>And they walk off with your jewellery and</v>

117
00:13:56.488 --> 00:14:06.488
<v Graham Cluley>your savings. In one case, they took the</v>

118
00:14:06.488 --> 00:14:16.488
<v Graham Cluley>wedding ring of one woman's deceased husband.</v>

119
00:14:13.104 --> 00:14:22.711
<v Graham Cluley>It's really horrible. In August last year, apparently an 80-year-old woman was killed during one of these fake police doorstep visits. So whether that particular woman got suspicious and put up some resistance or what, I mean, it is ghastly to think that these people are effectively being scammed on the phone, tricked into having someone come round, and who knows what's going to happen next.</v>

120
00:14:22.711 --> 00:14:27.980
<v Danny Palmer>So their details, I guess their phone number has been involved in</v>

121
00:14:27.980 --> 00:14:33.250
<v Danny Palmer>some sort of breach.</v>

122
00:14:33.250 --> 00:14:40.230
<v Graham Cluley>At the very least, their phone number. But let's think about it.</v>

123
00:14:40.230 --> 00:14:47.208
<v Graham Cluley>Many data breaches will not just contain your phone number, they will also contain your postal address as well.</v>

124
00:14:47.208 --> 00:14:52.225
<v Danny Palmer>Yes, I remember a few years back, I had an ethical hacker sort of do those things where, for an ask, let's see who you can find about me on the internet.</v>

125
00:14:52.225 --> 00:14:57.240
<v Danny Palmer>It was really freaky to hear.</v>

126
00:14:54.100 --> 00:15:24.100
<v Graham Cluley>Right.</v>

127
00:14:57.240 --> 00:15:03.241
<v Graham Cluley>Yeah, it is. Now, you might think, well, this seems rather far-fetched. How big a problem is this really? Well, apparently, last year, there were 13,000 reports of fake police officer scams in the Netherlands alone. 13,000.</v>

128
00:15:03.241 --> 00:15:09.243
<v Graham Cluley>So, I mean, it's not as though it's that rare. This is a small country, relatively, with a big problem. And police said that the impact on elderly victims, who are the most commonly targeted group, is devastating — not just financially, of course, but psychologically as well, because trust is gone. The Dutch police, Danny, they've decided to do something about all of this. And what they did was they launched a special operation called Game Over — in fact, it's called Game Over, question mark, exclamation mark.</v>

129
00:15:09.243 --> 00:15:39.243
<v Danny Palmer>So are they shouting at, or?</v>

130
00:15:30.336 --> 00:15:40.336
<v Danny Palmer>That's really interesting. It's almost applying — I'm not saying the</v>

131
00:15:40.336 --> 00:15:50.336
<v Danny Palmer>police are doing extortion, but it's the same sort of principle</v>

132
00:15:50.336 --> 00:16:00.336
<v Danny Palmer>as a lot of cybercrime, isn't it?</v>

133
00:15:51.198 --> 00:16:06.198
<v Danny Palmer>Yeah, do as</v>

134
00:16:06.198 --> 00:16:21.198
<v Danny Palmer>we say, otherwise we'll —</v>

135
00:16:15.745 --> 00:16:25.745
<v Danny Palmer>Come and —</v>

136
00:16:25.745 --> 00:16:35.745
<v Danny Palmer>come back and</v>

137
00:16:35.745 --> 00:16:45.745
<v Danny Palmer>get you big time.</v>

138
00:16:42.942 --> 00:16:50.453
<v Danny Palmer>You said they're all sort of between 15 and 30, the average demographic of a cybercriminal, young men.</v>

139
00:16:50.453 --> 00:16:57.965
<v Danny Palmer>I'd say there's a lot of hubris in there, and it's not going to be that many that turn themselves in because they'll think, "Oh, they'll never get me." Am I on the right track?</v>

140
00:16:57.965 --> 00:17:05.112
<v Graham Cluley>Well, I don't know if you'll consider this a small number or a large number.</v>

141
00:17:05.112 --> 00:17:12.259
<v Graham Cluley>Apparently 21 came forward.</v>

142
00:17:12.259 --> 00:17:42.259
<v Danny Palmer>One in five, yeah.</v>

143
00:17:35.277 --> 00:17:40.969
<v Danny Palmer>Well, they'll have taller doors though, won't they, to</v>

144
00:17:40.969 --> 00:17:46.661
<v Danny Palmer>make up for it?</v>

145
00:17:41.761 --> 00:18:11.761
<v Joe>Yes.</v>

146
00:17:46.661 --> 00:17:52.925
<v Graham Cluley>You would think so.</v>

147
00:17:52.925 --> 00:17:59.190
<v Graham Cluley>That would make sense really, wouldn't it?</v>

148
00:17:59.190 --> 00:18:04.858
<v Danny Palmer>I wouldn't know about that.</v>

149
00:18:04.858 --> 00:18:10.527
<v Danny Palmer>I'm 5 foot 7, so it's—</v>

150
00:18:10.527 --> 00:18:16.217
<v Graham Cluley>If there's any listeners out there in the Netherlands, we do have a fair few actually, maybe you can confirm whether</v>

151
00:18:16.217 --> 00:18:21.907
<v Graham Cluley>your average door height is higher than—</v>

152
00:18:21.907 --> 00:18:27.141
<v Danny Palmer>I'm off to the Netherlands in a couple of months, as discussed previously, so I</v>

153
00:18:27.141 --> 00:18:32.374
<v Danny Palmer>can report back and check.</v>

154
00:18:32.374 --> 00:18:39.609
<v Graham Cluley>Take a tape measure with you, Danny. Please find out for us. Anyway, once the photos were unblurred, and the public got involved because this is high profile.</v>

155
00:18:39.609 --> 00:18:46.846
<v Graham Cluley>This is on motorway billboards, these pictures. Over 500 tips came in.</v>

156
00:18:46.846 --> 00:18:53.913
<v Danny Palmer>I suppose you see it, you go, oh, I</v>

157
00:18:53.913 --> 00:19:00.980
<v Danny Palmer>recognise that guy.</v>

158
00:19:00.980 --> 00:19:07.073
<v Graham Cluley>Yeah, exactly.</v>

159
00:19:03.642 --> 00:19:13.642
<v Graham Cluley>You know, I love that analogy, Danny. I'm not sure everyone internationally is going to get it.</v>

160
00:19:07.073 --> 00:19:13.166
<v Graham Cluley>Oh, hang on, that's my nephew Bertrand or whatever who is over there.</v>

161
00:19:13.166 --> 00:19:43.166
<v Danny Palmer>Yeah.</v>

162
00:19:13.166 --> 00:19:23.542
<v Danny Palmer>Yeah, trying to think of Dutch names now.</v>

163
00:19:13.642 --> 00:19:23.642
<v Graham Cluley>I'm now going to have to link to Mr. Ben in the show notes so people can understand what that was about.</v>

164
00:19:23.542 --> 00:19:32.163
<v Joe>Dirk.</v>

165
00:19:23.642 --> 00:19:33.642
<v Graham Cluley>But, so if a policeman turns up on my door, I obviously will think, "Oh crumbs, maybe there's some speeding ticket I haven't paid or something." It's going to be that or it's going to be a strippogram. You don't expect it normally, but apparently they are calling people up, claiming to be a detective, and they say, "Look, there's been a burglary nearby and your valuables could be at risk."</v>

166
00:19:32.163 --> 00:19:43.539
<v Graham Cluley>Oh gosh. Joost. Marcel.</v>

167
00:19:43.539 --> 00:19:52.047
<v Danny Palmer>I should know this because me and some friends played a multiplayer Football Manager recently and we were in the Belgian and Dutch leagues. But all the information is gone from me now, unfortunately.</v>

168
00:19:52.047 --> 00:19:57.309
<v Graham Cluley>Anyway, the Game Over website has received more than 2 million visits.</v>

169
00:19:57.309 --> 00:20:02.573
<v Graham Cluley>The ads on social media have racked up 54 million views.</v>

170
00:20:02.573 --> 00:20:11.451
<v Joe>Wow.</v>

171
00:20:11.451 --> 00:20:18.797
<v Graham Cluley>And apparently some detectives had to work overtime just to handle all the tips that are coming in. By last month, 74 of the 100 suspects had been identified. 34 have handed themselves in.</v>

172
00:20:18.797 --> 00:20:26.142
<v Graham Cluley>40 were recognised by members of the public, you know, neighbours and school friends, I imagine, possibly family as well. And 6 have been arrested. And the youngest person identified was just 14 years old.</v>

173
00:20:26.142 --> 00:20:38.740
<v Joe>Wow.</v>

174
00:20:38.740 --> 00:20:45.250
<v Graham Cluley>Now, the thing is, Dutch police have said, look, even though there's lots of young people who are involved in this, they are not the masterminds behind this scheme. They are not the Mr. Big. What's happening apparently is young kids are basically acting as errand runners.</v>

175
00:20:45.250 --> 00:20:51.759
<v Graham Cluley>They're doing this for a little bit of pocket money. They are getting some cash. So they're being sent off to knock on doors and collect the bank cards and take the jewellery, that kind of thing.</v>

176
00:20:51.759 --> 00:21:04.586
<v Danny Palmer>The 2026 equivalent of a paper round.</v>

177
00:21:04.586 --> 00:21:10.500
<v Graham Cluley>I suppose so. This is the problem.</v>

178
00:21:10.500 --> 00:21:16.413
<v Graham Cluley>People don't get newspapers delivered anymore. So the kids are having to turn to crime instead.</v>

179
00:21:12.549 --> 00:21:22.549
<v Graham Cluley>It's not all in capitals. What they did was they collected CCTV images of these ne'er-do-wells who were engaged in this kind of thing. They took video footage from smart doorbells.</v>

180
00:21:16.413 --> 00:21:24.862
<v Danny Palmer>Newspapers.</v>

181
00:21:22.549 --> 00:21:32.549
<v Graham Cluley>They took video taken at ATMs when money was being taken there as well. They got photographs of 100 different suspects, and they published them. What was unusual about it was they blurred the images.</v>

182
00:21:24.862 --> 00:21:33.310
<v Danny Palmer>You established last week you don't have a milkman, so—</v>

183
00:21:32.549 --> 00:21:42.549
<v Graham Cluley>And they said, here is 100 people, and they put them up on motorway billboards, in supermarkets, at petrol stations, on TikTok, on TV, Instagram, all of that. But what they did was they said, in two weeks, we're going to unblur the images. So if you want to hand yourself in now, if you want to go to your local cop shop and say, maybe we should have a little chat about what I've been doing, now is your chance.</v>

184
00:21:33.310 --> 00:21:41.880
<v Graham Cluley>Yes. So they're handing everything up the chain. They're pocketing a little slice for themselves for being the face on the camera. And the organisers, the people actually behind all this criminality, they're the ones making serious money. And they are largely escaping appearing on the billboards.</v>

185
00:21:41.880 --> 00:21:50.450
<v Graham Cluley>So the police are keen to get the Mr. Bigs, as it were. So Dutch police are calling this a social problem that requires a social solution. I think that's probably true of a lot of things to do with our world, isn't it?</v>

186
00:21:50.450 --> 00:22:00.846
<v Danny Palmer>Yeah. You can't just stamp down on, let's say,</v>

187
00:22:00.846 --> 00:22:11.242
<v Danny Palmer>technologies, for example, and sort of hope things will get better.</v>

188
00:22:11.242 --> 00:22:17.182
<v Graham Cluley>You could almost draw an analogy with how we're trying to clean up the world of social media by preventing</v>

189
00:22:17.182 --> 00:22:23.121
<v Graham Cluley>kids from getting on social media.</v>

190
00:22:23.121 --> 00:22:34.672
<v Danny Palmer>Indeed, yes.</v>

191
00:22:34.672 --> 00:22:39.876
<v Graham Cluley>Rather than why don't we just clean up the social media</v>

192
00:22:39.050 --> 00:22:54.050
<v Graham Cluley>It's a bit of</v>

193
00:22:39.876 --> 00:22:45.082
<v Graham Cluley>sites or fine them?</v>

194
00:22:45.082 --> 00:22:50.278
<v Danny Palmer>Oh no, that's far too complicated. Children will, if you tell them not to do something, they'll just not do it.</v>

195
00:22:50.278 --> 00:22:55.476
<v Danny Palmer>Of course, they won't try to do it.</v>

196
00:22:54.050 --> 00:23:09.050
<v Graham Cluley>leverage, isn't it?</v>

197
00:22:55.476 --> 00:23:00.897
<v Graham Cluley>They're very obedient. Anyway, this public shaming campaign, it's been quite clever because it's not just caught 74 people.</v>

198
00:23:00.897 --> 00:23:06.319
<v Graham Cluley>It's also made the whole criminal ecosystem feel less safe for everyone involved. So I think if you are a 17-year-old, and you've been recruited to knock on doors for €50 a time, and you know there's a chance that you might have your photo taken by the doorbell and then appear on a motorway billboard, maybe you'll think twice about what you're doing.</v>

199
00:23:06.319 --> 00:23:12.059
<v Danny Palmer>Yeah, it's gonna put you off.</v>

200
00:23:12.059 --> 00:23:17.799
<v Danny Palmer>It's gonna sort of make the pool of potential, for want of a better word, employees smaller if they think, okay, what if my friends, family, what if my mum sees I've been part of a criminal group?</v>

201
00:23:17.799 --> 00:23:23.390
<v Graham Cluley>Oh yeah, that's always the biggest deterrent of all, isn't it? If your mum finds out what you've been up to.</v>

202
00:23:23.390 --> 00:23:28.980
<v Graham Cluley>Now, listeners, as you've already suggested, Danny, there are sensible steps to take if you do get a call which claims to be from your bank. Obviously, a genuine bank is never going to call you and offer to send someone to your house.</v>

203
00:23:28.980 --> 00:23:39.520
<v Danny Palmer>No, I mean, the bank keeps doing the opposite these days. They want everything to go online. So, yes.</v>

204
00:23:39.520 --> 00:23:46.287
<v Graham Cluley>And real police aren't going to knock on your door and ask to take all your valuables away for safekeeping. That doesn't really happen either. So if anything like that is offered to you, put your phone down, find the number yourself, just like you did, Danny. I imagine, you know, look on the back of your bank card or something like that for a contact phone number. Don't use the one that's been given to you on the phone and call the bank back directly.</v>

205
00:23:46.287 --> 00:23:53.053
<v Graham Cluley>And if you've got elderly relatives or neighbours, you know, have that kind of conversation with them because these operations, these criminal schemes, they are targeting people who grew up trusting institutions, like the banks, like the police, you know, those institutions that we've learned to be a little bit more suspicious of over the years. Modern-day cybercriminals can be very, very convincing indeed. Well, we've got time now to talk about one of today's sponsors, Vanta. Joe, what keeps you up at 2 o'clock in the morning?</v>

206
00:23:53.053 --> 00:24:06.611
<v Joe>The dog next door, mostly.</v>

207
00:24:06.611 --> 00:24:12.747
<v Graham Cluley>Oh, right. Well, yeah, but I'm talking professionally.</v>

208
00:24:12.747 --> 00:24:18.884
<v Graham Cluley>What keeps you up?</v>

209
00:24:18.884 --> 00:24:26.782
<v Joe>Oh, whether we've got the right security controls in place, whether our vendors are secure, how to escape the nightmare of outdated tools and endless manual processes.</v>

210
00:24:26.782 --> 00:24:37.213
<v Graham Cluley>Exactly. Which is where today's sponsor comes in. It's Vanta.</v>

211
00:24:37.213 --> 00:24:42.453
<v Joe>Fanta, the fizzy orange drink.</v>

212
00:24:42.453 --> 00:24:47.692
<v Joe>How can this possibly be true?</v>

213
00:24:47.692 --> 00:24:57.406
<v Graham Cluley>No, no, Joe. It's a Vanta with a V. It's a trust management platform. It's not a drink full of sugar. It automates all of that tedious manual compliance work so you can stop drowning in spreadsheets, chasing audit evidence, and filling out questionnaire after questionnaire.</v>

214
00:24:57.406 --> 00:25:10.573
<v Joe>Lush, I hate questionnaires.</v>

215
00:25:10.573 --> 00:25:17.346
<v Graham Cluley>Well, who doesn't? Vanta continuously monitors your systems. It centralises your security data.</v>

216
00:25:14.426 --> 00:25:44.426
<v Joe>Yes.</v>

217
00:25:17.346 --> 00:25:24.119
<v Graham Cluley>It keeps your program audit ready all of the time. It also uses AI to streamline evidence collection and flag risks. It automates compliance for SOC 2, ISO 27001, HIPAA, GDPR, and more.</v>

218
00:25:24.119 --> 00:25:29.848
<v Joe>So basically it handles the boring stuff so we can focus</v>

219
00:25:29.848 --> 00:25:35.576
<v Joe>on the interesting stuff.</v>

220
00:25:30.064 --> 00:25:40.064
<v Graham Cluley>It's a little bit like one of those data extortion attacks, which</v>

221
00:25:35.576 --> 00:25:41.834
<v Graham Cluley>Exactly. Precisely that. And for a limited time, new customers can get $1,000 off. $1,000?</v>

222
00:25:40.064 --> 00:25:50.064
<v Graham Cluley>we see all the time. So how many of those 100 suspects</v>

223
00:25:41.834 --> 00:25:48.092
<v Graham Cluley>Yep. $1,000. Head to vanta.com/smashing — that's vanta.com/smashing — and get started today.</v>

224
00:25:48.092 --> 00:25:53.939
<v Joe>And maybe get a decent night's sleep for once. Oh, and unlike fizzy drinks, Vanta isn't bad for you.</v>

225
00:25:50.064 --> 00:26:00.064
<v Graham Cluley>do you reckon turned themselves in before the countdown was gone?</v>

226
00:25:53.939 --> 00:25:59.785
<v Joe>That was a fruit twist.</v>

227
00:25:59.785 --> 00:26:12.792
<v Graham Cluley>Danny, what's your story for us this week?</v>

228
00:26:12.792 --> 00:26:18.763
<v Danny Palmer>Well, Graham, even if you don't follow football, you might have noticed there's quite a big event going on right now. That is the World Cup.</v>

229
00:26:18.763 --> 00:26:24.733
<v Danny Palmer>Ah! You're familiar with it, I take it?</v>

230
00:26:24.733 --> 00:26:30.761
<v Graham Cluley>I am familiar with the World Cup.</v>

231
00:26:30.761 --> 00:26:36.789
<v Graham Cluley>I think I've heard of it.</v>

232
00:26:36.789 --> 00:26:49.616
<v Danny Palmer>Yeah.</v>

233
00:26:49.616 --> 00:27:04.099
<v Graham Cluley>This is a football thing, I believe.</v>

234
00:27:04.099 --> 00:27:14.099
<v Danny Palmer>It's a football thing. Yeah. Quite a big deal.</v>

235
00:27:14.099 --> 00:27:24.099
<v Danny Palmer>So it started on June the 12th, and it runs all the way through to the final on July the 19th. So that's just over a month. It's the biggest World Cup ever, in fact, featuring 48 teams from around the world.</v>

236
00:27:24.099 --> 00:27:34.099
<v Danny Palmer>I'm a football fan. I'm aware of the World Cup. Wales aren't in it.</v>

237
00:27:34.823 --> 00:27:44.823
<v Graham Cluley>I thought that was quite a lot, considering, you know, their photo hadn't been published. It was just a blurred version.</v>

238
00:27:35.560 --> 00:27:44.367
<v Danny Palmer>I'm used to that over the years. We qualified for the 2021 World Cup. Before that, the previous World Cup was 1958. So it's a rare thing for us, but now I still get to sort of—</v>

239
00:27:44.367 --> 00:27:53.584
<v Graham Cluley>Hang on, Danny. There can't have been a 2021 World Cup. Isn't it every 4 years?</v>

240
00:27:44.823 --> 00:27:54.823
<v Graham Cluley>But they came forward before the deadline, before the images were unblurred. They cycled over to the police station.</v>

241
00:27:53.584 --> 00:27:59.561
<v Danny Palmer>It's 2020, but there was something, something happened during 2020, which made them postpone</v>

242
00:27:54.823 --> 00:28:04.823
<v Graham Cluley>They probably leant over a bit as they went through the doorway, because they were ostentatiously tall.</v>

243
00:27:59.561 --> 00:28:05.540
<v Danny Palmer>it for a year.</v>

244
00:28:05.540 --> 00:28:35.540
<v Graham Cluley>Okay, got it.</v>

245
00:28:26.643 --> 00:28:32.065
<v Graham Cluley>So, okay, there's 2 things I'm aware of, the World Cup and that pandemic thing.</v>

246
00:28:32.065 --> 00:28:37.487
<v Graham Cluley>I remember that.</v>

247
00:28:37.487 --> 00:29:07.487
<v Danny Palmer>All right.</v>

248
00:29:03.094 --> 00:29:09.159
<v Danny Palmer>Anyway, main point, Wales not good at football. I am just watching as a general fan. So, right. This biggest World Cup ever happens to be happening in the country that likes to do things big. It's in the United States of America, which is hosting the tournament alongside Mexico and Canada.</v>

249
00:29:09.159 --> 00:29:15.222
<v Danny Palmer>So this was decided about a decade ago, right? When things were a bit smoother diplomatically between those countries, let's say. And admittedly, this hasn't gone without controversy. There've been accusations of price gouging by FIFA and its official partners. Fans, a referee, and even players from certain countries were told they weren't allowed into the Land of the Free due to visa issues and restrictions.</v>

250
00:29:15.222 --> 00:29:21.311
<v Graham Cluley>Which does prove a bit of a challenge, doesn't it, in having a football game if you're</v>

251
00:29:21.311 --> 00:29:27.400
<v Graham Cluley>not allowed into the country?</v>

252
00:29:27.400 --> 00:29:37.400
<v Danny Palmer>Yeah, it's a bit tricky. I mean, I think some of the teams that are playing in Canada and Mexico are not having these problems there, but in the US, they're having these problems.</v>

253
00:29:37.400 --> 00:29:47.400
<v Danny Palmer>And then there's the whole kerfuffle with the winner of the inaugural FIFA Peace Prize, the President of the United States of America, not being that peaceful in his approach to international diplomacy in the run-up to the tournament. And on top of all that, obviously the key thing for us here is if you're watching it from the UK or Europe, the games are often late at night.</v>

254
00:29:47.400 --> 00:29:57.400
<v Danny Palmer>So weird times for us, but despite all that, the World Cup itself appears to be running rather smoothly. And there's already been a bunch of excellent matches and moments on the pitch.</v>

255
00:29:50.134 --> 00:30:00.134
<v Danny Palmer>Ultimately, hundreds of millions of people, and maybe billions, are tuning in to watch</v>

256
00:30:00.134 --> 00:30:10.134
<v Danny Palmer>these matches. So you'd expect FIFA to have strong, robust protections in place to</v>

257
00:30:09.133 --> 00:30:39.133
<v Graham Cluley>Oh.</v>

258
00:30:10.134 --> 00:30:20.134
<v Danny Palmer>ensure that nothing untoward can happen to the live broadcasts.</v>

259
00:30:15.306 --> 00:30:20.325
<v Danny Palmer>Well, it turns out that may not have</v>

260
00:30:20.325 --> 00:30:25.343
<v Danny Palmer>been the case.</v>

261
00:30:25.343 --> 00:30:37.907
<v Graham Cluley>Oh dear.</v>

262
00:30:37.907 --> 00:30:47.523
<v Danny Palmer>Because this week, a security researcher who goes by the name of Bob de Hacker. You might have heard of her older brother, who is a builder.</v>

263
00:30:47.523 --> 00:30:53.179
<v Graham Cluley>Yes.</v>

264
00:30:53.179 --> 00:30:58.834
<v Graham Cluley>But it's a bit strange for siblings to have the same first name.</v>

265
00:30:58.834 --> 00:31:13.582
<v Danny Palmer>That is true, yeah.</v>

266
00:31:13.582 --> 00:31:18.892
<v Graham Cluley>But anyway, Bob de Hacker, yeah.</v>

267
00:31:18.892 --> 00:31:24.201
<v Graham Cluley>What's she been up to?</v>

268
00:31:24.201 --> 00:31:29.569
<v Danny Palmer>Well, she published a blog post where she claimed she could have hijacked live match feeds and Rickrolled millions of people watching games. Oh boy. And despite this being the biggest World Cup ever and all that, it appears it was rather trivial for her to gain access because all she needed to start this process was some ID. So, as detailed on her blog, Bob started with the FIFA agent platform. So that's a public portal where football agents, that is the managers and advisors of football players, register that they are indeed football agents. I don't know what paperwork you need to say you are a football agent, I imagine you just need a big fur coat and a huge cigar. Exactly.</v>

269
00:31:29.569 --> 00:31:34.939
<v Danny Palmer>Yeah. So to register, she had to upload some personal data and some ID, and there she was in. She was part of the FIFA agent platform, which runs on Microsoft Entra, which is, I believe, used to be part of Azure previously. So while she was initially blocked from accessing the FIFA football data platform, she was able to bypass some of the guardrails on this. I mean, these haven't been specified. And we'll shortly see why, but basically Bob found herself with access to the FIFA streaming management panel, partly hosted by a third-party provider called MediaKind. And Bob said what she saw made her jaw, and I quote, "hit the floor."</v>

270
00:31:34.939 --> 00:31:44.489
<v Graham Cluley>Was she as sick as a parrot?</v>

271
00:31:44.489 --> 00:31:50.316
<v Danny Palmer>Hahaha. Well, let's assume yes. For in front of her eyes was the live production streaming management panel for the FIFA World Cup 2026. She could, through this panel, gain access to every match, every camera angle, every stream.</v>

272
00:31:50.316 --> 00:31:56.142
<v Danny Palmer>Ultimately, that is live video streams for live matches. And this wasn't just read-only. She could have played around with the live broadcast.</v>

273
00:31:56.142 --> 00:32:05.773
<v Graham Cluley>I thought you were going to say that she could just watch all of these for free, but what you're saying is she could actually alter them as well.</v>

274
00:32:00.236 --> 00:32:10.236
<v Danny Palmer>That would be a certain pandemic</v>

275
00:32:05.773 --> 00:32:11.904
<v Danny Palmer>Yes, she could sort of control the feeds, as it were.</v>

276
00:32:10.236 --> 00:32:20.236
<v Danny Palmer>that sort of caused some problems</v>

277
00:32:11.904 --> 00:32:18.036
<v Danny Palmer>What would you do if you stumbled upon that sort of power?</v>

278
00:32:18.036 --> 00:32:24.724
<v Graham Cluley>If I had that kind of power, what I would do is I would take my phone to the local park where there's a bunch of 7-year-olds having a kick around with a football. And I would— I would maybe get them to dress up. We'd have one side dressed up in the Portuguese football kit and the other side as Cape Verde. No, I'd have the US versus Iran.</v>

279
00:32:20.236 --> 00:32:30.236
<v Danny Palmer>and shenanigans around the world, let's say.</v>

280
00:32:24.724 --> 00:32:31.413
<v Graham Cluley>That's what I'd do. I'd get them to dress up in the Iranian football kit and the American football kit, and I would broadcast it. How brilliant would that be?</v>

281
00:32:29.763 --> 00:32:59.763
<v Unknown>Okay.</v>

282
00:32:31.413 --> 00:32:38.913
<v Danny Palmer>I thought you'd say you'd go into the park, you can turn it into a Springwatch type of thing. But no, that is a good idea. Well, what Bob said is that with the access she had, she could have just gone for what she described as the nuclear option and Rickrolled the entire world, which seems like a hacker thing to do, doesn't it? It does. Because Bob is a responsible ethical hacker, nothing happened.</v>

283
00:32:38.913 --> 00:32:46.413
<v Danny Palmer>But it's not hard to imagine that if someone with nefarious intentions had found this lapse in cybersecurity, they could have done something much worse. They could have shut down the live broadcast of one of the biggest sporting events in the world. People notice that sort of thing. They could have taken advantage of the ability to choose what to broadcast by unleashing unsavoury content. An attacker could have got hold of or messed around with data and broadcasts.</v>

284
00:32:46.413 --> 00:32:53.913
<v Danny Palmer>Then of course there's all the websites that rely on this platform for, even if they're not showing the actual match itself, updating scores. If you go to the BBC Live Football page, it'll be through that. There's implications, this security vulnerability, for an event watched by hundreds of millions of people. But as an ethical hacker, Bob wanted to disclose what she has found. It seems this was more difficult than gaining access to FIFA's live streaming platforms themselves.</v>

285
00:32:52.409 --> 00:32:57.904
<v Danny Palmer>These messages either bounced or received no response. Or as she described it, disappeared into the void.</v>

286
00:32:53.913 --> 00:33:01.413
<v Danny Palmer>She's listed on her blog post, which I'm sure we'll link to in the notes, the 10 steps she had to go through to actually get someone to apparently listen to her. So prepare yourself. Step 1: First, she tried to disclose the vulnerability directly to FIFA by several publicly available email addresses.</v>

287
00:32:57.904 --> 00:33:03.401
<v Danny Palmer>Second attempt, she reached out to a person. She found the LinkedIn account for the Head of Football Technology and Data at FIFA and tried to reach out to him.</v>

288
00:33:03.401 --> 00:33:14.232
<v Graham Cluley>Okay.</v>

289
00:33:12.386 --> 00:33:42.386
<v Graham Cluley>Right.</v>

290
00:33:14.232 --> 00:33:27.952
<v Danny Palmer>No response.</v>

291
00:33:27.952 --> 00:33:41.112
<v Graham Cluley>Oh dear.</v>

292
00:33:41.112 --> 00:33:48.518
<v Danny Palmer>Her third go, she tried to contact the FIFA headquarters in Zurich directly. She didn't receive a response there. She also tried calling the FIFA media line.</v>

293
00:33:48.518 --> 00:33:55.923
<v Danny Palmer>Same result. No one was there. In her now, what we on now, fifth attempt to get through to someone, Bob called the Dallas Convention Center, which for the World Cup is home to the temporary International Broadcast Centre, which is basically where all the media involved in covering the event are based for the duration.</v>

294
00:33:55.923 --> 00:34:09.487
<v Joe>Okay.</v>

295
00:34:09.487 --> 00:34:19.487
<v Danny Palmer>Nobody picked up and Bob left a voicemail</v>

296
00:34:14.481 --> 00:34:44.481
<v Unknown>Yes.</v>

297
00:34:19.487 --> 00:34:29.487
<v Danny Palmer>message. So that's quite a few attempts now</v>

298
00:34:29.291 --> 00:34:38.489
<v Danny Palmer>She phoned then MediaKind, the hosting partner for the streaming, and she got through to someone. She said that person understood immediately what the issue was and asked her to email details as proof, which she did.</v>

299
00:34:29.487 --> 00:34:39.487
<v Danny Palmer>just to tell someone about this.</v>

300
00:34:38.489 --> 00:34:47.688
<v Danny Palmer>But she isn't sure if action got taken immediately at that point. So she tried contacting Host Broadcasting Services, a specialist media organisation which helps to broadcast major events like this.</v>

301
00:34:47.688 --> 00:34:53.577
<v Graham Cluley>Did she think of sending a Truth Social message to the winner of the inaugural FIFA Peace Prize? Because he's normally online, and I believe he probably has the mobile phone number of the FIFA president.</v>

302
00:34:53.577 --> 00:34:59.467
<v Graham Cluley>I'm just thinking, go to—</v>

303
00:34:59.467 --> 00:35:09.467
<v Danny Palmer>You're right, yeah. Unfortunately, I don't</v>

304
00:35:09.467 --> 00:35:19.467
<v Danny Palmer>think she thought of that.</v>

305
00:35:19.467 --> 00:35:29.467
<v Danny Palmer>But lessons to be learned there.</v>

306
00:35:27.056 --> 00:35:37.056
<v Danny Palmer>But this 7th attempt, calling this host broadcasting services, she got through</v>

307
00:35:37.056 --> 00:35:47.056
<v Danny Palmer>to someone, but they said on the phone they didn't have anyone</v>

308
00:35:47.056 --> 00:35:57.056
<v Danny Palmer>there who could help, and they hung up on her.</v>

309
00:36:03.853 --> 00:36:33.853
<v Graham Cluley>Right.</v>

310
00:36:13.318 --> 00:36:18.472
<v Graham Cluley>Bob de Haka has shown remarkable patience by this point.</v>

311
00:36:18.472 --> 00:36:23.626
<v Graham Cluley>I would be tempted to think, why don't I just take over one of the streams and put up my email address on the screen and say, if you want this fixed, contact me and I'll tell you what the problem is.</v>

312
00:36:23.626 --> 00:36:29.663
<v Danny Palmer>That would have been eye-catching. I imagine she would have gotten a bit of trouble for doing that though.</v>

313
00:36:29.663 --> 00:36:38.335
<v Graham Cluley>Probably would. But you can understand why someone might feel so frustrated they would do that.</v>

314
00:36:38.335 --> 00:36:48.106
<v Danny Palmer>Definitely. So at this point, she's clearly getting a bit fed up that the situation hasn't been fully resolved. So she contacted CISA, the critical infrastructure agency in the United States.</v>

315
00:36:48.106 --> 00:37:00.795
<v Graham Cluley>Oh yeah.</v>

316
00:36:52.454 --> 00:37:22.454
<v Graham Cluley>Yes.</v>

317
00:37:00.795 --> 00:37:06.518
<v Danny Palmer>Holds the official title of federal lead on cybersecurity for the FIFA World Cup</v>

318
00:37:06.518 --> 00:37:12.242
<v Danny Palmer>2026, including broadcast services.</v>

319
00:37:12.242 --> 00:37:20.195
<v Graham Cluley>Okay. I was wondering why on earth CISA would be involved in the World Cup. Was that really critical infrastructure? But okay, they have somehow allied themselves with the World Cup, maybe for a few cheapo tickets in order for giving some cybersecurity advice.</v>

320
00:37:14.007 --> 00:37:44.007
<v Graham Cluley>Yeah.</v>

321
00:37:20.195 --> 00:37:31.338
<v Danny Palmer>Well, I suppose the stadiums are infrastructure.</v>

322
00:37:31.338 --> 00:37:46.338
<v Graham Cluley>I suppose they're—</v>

323
00:37:46.338 --> 00:38:01.338
<v Graham Cluley>okay, I suppose they are.</v>

324
00:37:53.228 --> 00:38:00.041
<v Graham Cluley>Fair enough.</v>

325
00:38:00.041 --> 00:38:06.853
<v Graham Cluley>Okay, so CISA now are going to fix this problem.</v>

326
00:38:06.853 --> 00:38:12.110
<v Danny Palmer>Well, they listened and asked for more information, which she sent across. And it seems that they responded positively.</v>

327
00:38:12.110 --> 00:38:17.367
<v Danny Palmer>And then she made a final attempt because, you know, she had contact at the FBI from some previous work she'd done.</v>

328
00:38:12.126 --> 00:38:30.637
<v Graham Cluley>Right.</v>

329
00:38:17.367 --> 00:38:28.554
<v Graham Cluley>I bet she does.</v>

330
00:38:28.554 --> 00:38:37.005
<v Danny Palmer>Yeah, who said they'd look into the disclosure right away. So it seems that after all this effort, the vulnerability was fixed. So all of this effort was for something.</v>

331
00:38:30.637 --> 00:38:40.637
<v Danny Palmer>And then didn't answer any further calls. You wouldn't want that if</v>

332
00:38:37.005 --> 00:38:45.458
<v Danny Palmer>But as has been reported by various media outlets and Bob themselves, FIFA haven't acknowledged that this was a thing which was a problem. They haven't acknowledged that Bob tipped them off.</v>

333
00:38:40.251 --> 00:38:50.251
<v Danny Palmer>You don't want those getting ransomwared and fans</v>

334
00:38:40.637 --> 00:38:50.637
<v Danny Palmer>you're calling, say, the police, and they went, "Ah, nah, sorry, mate.</v>

335
00:38:45.458 --> 00:38:50.697
<v Graham Cluley>Yeah.</v>

336
00:38:50.251 --> 00:39:00.251
<v Danny Palmer>not being able to get in.</v>

337
00:38:50.637 --> 00:39:00.637
<v Danny Palmer>Nothing to do with us," and hung up.</v>

338
00:38:50.697 --> 00:38:59.655
<v Danny Palmer>Maybe they were too busy hobnobbing with celebrities and world leaders, perhaps.</v>

339
00:38:59.655 --> 00:39:09.418
<v Graham Cluley>If you've got the choice of answering a message from some vulnerability researcher, some security bod on the internet or hanging out with Shakira, which are you gonna do?</v>

340
00:39:00.251 --> 00:39:10.251
<v Danny Palmer>That would be embarrassing, I imagine.</v>

341
00:39:09.418 --> 00:39:19.213
<v Danny Palmer>You're probably right, I imagine. You don't get to meet celebrities very often, I suppose.</v>

342
00:39:19.213 --> 00:39:31.474
<v Graham Cluley>No.</v>

343
00:39:31.474 --> 00:39:31.795
<v Danny Palmer>In any case, it feels like it should not have taken this much effort to get the issue, which boiled down to a simple client-side authorisation issue with no server-side enforcement, sorted. And FIFA might consider themselves lucky that it wasn't someone more nefarious who was trying to do something of this.</v>

344
00:39:31.795 --> 00:39:55.494
<v Graham Cluley>Yes.</v>

345
00:39:55.494 --> 00:40:02.315
<v Danny Palmer>Bob concluded the write-up with some advice for FIFA, which was, "When a researcher has to call CISA and the FBI to reach you, something is wrong." And she recommended that they might want to start some sort of bug bounty programme before signing off with the</v>

346
00:40:02.315 --> 00:40:09.135
<v Danny Palmer>phrase, "So long and thanks for all the fish." This episode is sponsored by ProtonPass.</v>

347
00:40:09.135 --> 00:40:18.657
<v Joe>ProtonPass, the password manager from the team behind ProtonMail, the world's largest end-to-end encrypted email service.</v>

348
00:40:18.657 --> 00:40:23.827
<v Graham Cluley>Now, Joe, you and I both know the grubby little secret of how a lot</v>

349
00:40:23.827 --> 00:40:28.996
<v Graham Cluley>of businesses actually share passwords.</v>

350
00:40:28.996 --> 00:40:38.291
<v Joe>A spreadsheet, a Post-it note, sending it to a colleague via Slack and hoping for the best.</v>

351
00:40:38.291 --> 00:40:44.467
<v Graham Cluley>That's pretty much it. All of the above.</v>

352
00:40:44.467 --> 00:40:50.646
<v Graham Cluley>And every one of them is a breach waiting to happen. ProtonPass is built to fix exactly that, letting teams store and share credentials securely, with end-to-end encryption baked into every feature.</v>

353
00:40:50.646 --> 00:40:55.704
<v Joe>It's open source and fully auditable. It runs on Swiss infrastructure, so your data sits outside US jurisdiction, and it's backed by a nonprofit.</v>

354
00:40:55.704 --> 00:41:00.764
<v Joe>No venture capitalists, no pressure to chase a quick exit.</v>

355
00:41:00.764 --> 00:41:10.599
<v Graham Cluley>Which is the bit I like. You know, it's built to serve you, not investors. So it will never be pressured to cut security corners or rush towards a liquidity event that could change ownership, pricing or priorities overnight. It's trusted by over 100 million people, ISO 27001 certified, SOC 2 audited, and it helps you tick the boxes for NIST 2, DORA, and the UK's Cybersecurity and Resilience Bill.</v>

356
00:41:10.599 --> 00:41:16.860
<v Joe>And crucially, people actually use it. One Swiss customer told Proton, and I quote, "It works.</v>

357
00:41:16.860 --> 00:41:23.119
<v Joe>It works perfectly." High praise indeed.</v>

358
00:41:23.119 --> 00:41:29.445
<v Graham Cluley>So why not start your business's free trial right</v>

359
00:41:29.445 --> 00:41:35.771
<v Graham Cluley>now at proton.me/smashingsecurity.</v>

360
00:41:35.771 --> 00:41:41.079
<v Joe>And thanks to Proton Pass for</v>

361
00:41:41.079 --> 00:41:46.389
<v Joe>supporting the show.</v>

362
00:41:46.389 --> 00:41:54.713
<v Graham Cluley>And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week.</v>

363
00:41:54.713 --> 00:42:09.713
<v Danny Palmer>Pick of the</v>

364
00:41:54.713 --> 00:42:04.713
<v Graham Cluley>Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app.</v>

365
00:42:04.713 --> 00:42:14.713
<v Graham Cluley>Whatever they wish. It doesn't have to be security related necessarily.</v>

366
00:42:09.713 --> 00:42:24.713
<v Danny Palmer>Week. Pick of the Week.</v>

367
00:42:14.713 --> 00:42:24.713
<v Graham Cluley>Now, my pick of the week this week is not security related. My pick of the week this week may take you back to your geography classroom, Danny.</v>

368
00:42:29.016 --> 00:42:34.097
<v Danny Palmer>Remember them well.</v>

369
00:42:34.097 --> 00:42:39.177
<v Danny Palmer>I was one of those people who enjoyed geography, I will say.</v>

370
00:42:39.177 --> 00:42:45.998
<v Graham Cluley>Yeah, geography's all right, isn't it?</v>

371
00:42:45.998 --> 00:42:52.818
<v Graham Cluley>I mean, basically you learn how an oxbow lake is made.</v>

372
00:42:52.818 --> 00:43:22.818
<v Danny Palmer>Very important information, isn't it?</v>

373
00:43:16.695 --> 00:43:26.221
<v Danny Palmer>Erosion.</v>

374
00:43:26.221 --> 00:43:36.163
<v Graham Cluley>A bit of erosion. Yes, that was good.</v>

375
00:43:36.163 --> 00:43:42.443
<v Danny Palmer>Stuff that sticks with you, even if it's not particularly useful for</v>

376
00:43:42.443 --> 00:43:48.724
<v Danny Palmer>everyday life these days.</v>

377
00:43:48.724 --> 00:43:54.958
<v Graham Cluley>Well, I wonder whether the image of an iceberg has stuck with you.</v>

378
00:43:54.958 --> 00:44:01.193
<v Graham Cluley>That picture, the sort of cross-sectional image of the part of the iceberg which is above water and the part of the iceberg which is beneath the water.</v>

379
00:44:01.193 --> 00:44:10.981
<v Danny Palmer>Now you mention it, I think it does. Yeah, they're quite large, these things, I believe.</v>

380
00:44:10.981 --> 00:44:16.842
<v Graham Cluley>Well, this is the whole thing, isn't it? Is that you get a little bit above the water and then you get this huge mass underneath and it's always like, oh, that's not the— that's the bit which isn't visible. It's like a mountain underneath the much smaller hill above the water.</v>

381
00:44:16.842 --> 00:44:22.704
<v Graham Cluley>So we've all seen that. But have you ever asked yourself, is that really true?</v>

382
00:44:22.704 --> 00:44:27.724
<v Danny Palmer>Well, I've not really thought about that in depth, as I assumed it was true because an expert in geography and</v>

383
00:44:27.724 --> 00:44:32.744
<v Danny Palmer>icebergs was telling me it was true.</v>

384
00:44:32.744 --> 00:44:38.427
<v Graham Cluley>Well, I am going to question this because although it is true that only about 10% of an iceberg is above water, I don't think it necessarily matches that image that we've been given. And this astonishing truth has been revealed to me by a website which I have visited.</v>

385
00:44:38.427 --> 00:44:44.112
<v Graham Cluley>A website created by a chap called Joshua Torbera, where he actually invites you to examine the physics of all of this.</v>

386
00:44:44.112 --> 00:44:49.233
<v Danny Palmer>Does sound very interesting. And that's not being sarcastic either.</v>

387
00:44:49.233 --> 00:44:54.355
<v Danny Palmer>That does sound interesting to me.</v>

388
00:44:54.355 --> 00:44:59.724
<v Graham Cluley>Right. So this is a site which allows you to draw an iceberg. So it has the waterline. You draw the shape of an iceberg.</v>

389
00:44:59.724 --> 00:45:05.094
<v Graham Cluley>So imagine that one, which you can see from that image with just a little bit on top and the huge massive mountain underneath. Draw that, and then it shows you how it would actually float. And what you find is that the iceberg will sort of adjust itself and change its position. So you don't end up with Everest underneath.</v>

390
00:45:00.862 --> 00:45:30.862
<v Joe>Yeah.</v>

391
00:45:05.094 --> 00:45:16.166
<v Danny Palmer>No, and it doesn't just sink, I presume.</v>

392
00:45:16.166 --> 00:45:23.731
<v Graham Cluley>Yeah. I'll put a link in the show notes, but why don't you go and try it for yourself right now? Cool. I'm looking at one here which someone else has drawn, which is an image of something which appears to be like a unicorn's head.</v>

393
00:45:23.731 --> 00:45:33.353
<v Danny Palmer>I see it, yes.</v>

394
00:45:33.353 --> 00:45:40.097
<v Graham Cluley>Well, why would it have to be a particular shape?</v>

395
00:45:40.097 --> 00:45:46.840
<v Graham Cluley>Anyway, you draw your own little iceberg and see what happens.</v>

396
00:45:46.840 --> 00:45:58.175
<v Danny Palmer>Huh, I can't think what to draw now.</v>

397
00:45:58.175 --> 00:46:03.552
<v Graham Cluley>Draw a traditional iceberg, how you imagine it</v>

398
00:46:03.552 --> 00:46:08.927
<v Graham Cluley>would be underneath.</v>

399
00:46:08.927 --> 00:46:14.338
<v Danny Palmer>I was just talking about football. I'm just going to draw a ball. Draw more something that looks like a rugby ball there.</v>

400
00:46:14.338 --> 00:46:19.748
<v Danny Palmer>Oh, it's sunk and most of it is underwater. Drawing a circle is a difficult thing, but I like how it bobs up and down. That's cool.</v>

401
00:46:19.748 --> 00:46:25.438
<v Graham Cluley>Anyway, check out the show notes. I think this will be a revelation to you that we've been lied to by geography teachers as to how icebergs actually float. Yes, they only have a little bit above the water, a little bit of their mass.</v>

402
00:46:25.438 --> 00:46:31.130
<v Graham Cluley>We agree on that. But you're not going to have this colossal mountain shape underneath.</v>

403
00:46:31.130 --> 00:46:40.186
<v Danny Palmer>Huh.</v>

404
00:46:40.186 --> 00:46:49.273
<v Graham Cluley>And so this revelation is my pick of the week. Danny, what's your pick of the week?</v>

405
00:46:49.273 --> 00:46:54.699
<v Danny Palmer>So my pick for the week is a video game I've recently started playing. It's a modification for the video game Fallout 4. So, first things first, Fallout video game series — it's a popular video game series which is set in a post-apocalyptic nuclear world. Sounds quite dark, but it tends to take quite a sideways, sort of funny look at things. So in this dark world, there's elements of humour.</v>

406
00:46:54.699 --> 00:47:00.125
<v Danny Palmer>I'll give you an example. In the game Fallout 4, based in Boston, you can go down into a bar and the skeletons at the bar, which have been nuked in this war, they look suspiciously like people who might frequent the bar Cheers. There's a postman at the bar, or a photo guy, kind of thing, so yeah — they've always had quite tongue-in-cheek humour in the games. That Fallout 4 came out 10 years ago now, which is mad to think about. And a couple of years ago, about a year ago, a mod came out, so a fan-made modification of the game.</v>

407
00:47:00.125 --> 00:47:12.483
<v Graham Cluley>Yes.</v>

408
00:47:12.483 --> 00:47:19.416
<v Danny Palmer>It's Fallout London, so they've taken this world and placed it in London, which is very impressive, especially for a fully fan-made project. And, you know, as someone who lives in London, I'd say the map is generally quite accurate.</v>

409
00:47:19.416 --> 00:47:26.349
<v Danny Palmer>Basically, when you start the game, it dumps you near New Cross Gate, which isn't that far away from me.</v>

410
00:47:26.349 --> 00:47:36.210
<v Graham Cluley>Right.</v>

411
00:47:36.210 --> 00:47:41.945
<v Danny Palmer>The fun thing is though, that the people who made it, they know London because the exact shopping centre that I've visited in Bromley is in the game. Wow.</v>

412
00:47:41.945 --> 00:47:47.679
<v Danny Palmer>There's even a thing where there's an equivalent of Boots exactly where that should be. There's an equivalent of a Games Workshop exactly where that should be.</v>

413
00:47:47.679 --> 00:47:57.769
<v Graham Cluley>And this is a post-apocalyptic London, right?</v>

414
00:47:57.769 --> 00:48:13.599
<v Danny Palmer>It is. Yeah.</v>

415
00:48:13.599 --> 00:48:27.507
<v Graham Cluley>So this is based on London after the Brexit vote.</v>

416
00:48:27.507 --> 00:48:36.722
<v Danny Palmer>Yes. And the nuclear Brexit.</v>

417
00:48:36.722 --> 00:48:50.106
<v Joe>Yes.</v>

418
00:48:50.106 --> 00:48:55.577
<v Danny Palmer>A lot of effort has gone into this and it also has some surprise celebrity cameos. I'm not that far into it, but it's a lot of fun.</v>

419
00:48:55.577 --> 00:49:01.045
<v Danny Palmer>A lot of love and effort has gone into this game. And if you own Fallout 4, it's completely free.</v>

420
00:49:01.045 --> 00:49:10.632
<v Graham Cluley>Right.</v>

421
00:49:10.632 --> 00:49:17.085
<v Danny Palmer>That's my pick of the week.</v>

422
00:49:17.085 --> 00:49:23.536
<v Danny Palmer>Come visit post-apocalyptic London, it's great.</v>

423
00:49:23.536 --> 00:49:28.706
<v Graham Cluley>And go and visit Danny in</v>

424
00:49:28.706 --> 00:49:33.876
<v Graham Cluley>his local Boots.</v>

425
00:49:33.876 --> 00:49:42.934
<v Danny Palmer>Fantastic.</v>

426
00:49:42.934 --> 00:49:50.398
<v Graham Cluley>Great pick of the week. Now, Black Kite has just released its first report focused specifically on Europe, covering ransomware and data extortion across 31 countries between January of 2025 and April of this year. And the findings of that report paint a pretty clear picture of how attacks are accelerating. It's not just about a growing number of victims who are being reached directly.</v>

427
00:49:50.398 --> 00:49:57.860
<v Graham Cluley>There's also, of course, a lot of companies who are being hit through their suppliers. So to dig into this report and walk me through the research, I'm really delighted to have on the show Jeffrey Wheatman, who is senior VP at Black Kite. Jeffrey, welcome to the show.</v>

428
00:49:57.860 --> 00:50:05.360
<v Jeffrey Wheatman>Graham, it is a pleasure and an honour to</v>

429
00:50:05.360 --> 00:50:12.860
<v Jeffrey Wheatman>be here with you.</v>

430
00:50:12.860 --> 00:50:19.164
<v Graham Cluley>Oh, steady on, old chap. Enough of the mutual backslapping.</v>

431
00:50:19.164 --> 00:50:25.469
<v Graham Cluley>This is Black Kite's first report specifically focused on Europe. So my question to start off with is what made now the right time to really look at what's going on in Europe?</v>

432
00:50:25.469 --> 00:50:30.835
<v Jeffrey Wheatman>That's a great question. And I'll sort of look back on my whole career — I feel like many American technology companies are very focused on America, North America. And I think that we live in a global economy and the reality is there are some different drivers and different approaches that take place in the EU, in the UK, in the whole region. And we just saw some interesting trends, because we have a ton of data.</v>

433
00:50:30.835 --> 00:50:36.199
<v Jeffrey Wheatman>We saw these interesting trends and we decided it was worthwhile maybe doing a focus on some of the countries in the region. And it turned out we found some really interesting things. And I think really the answer to your question is, why did it take so long for people to start focusing in Europe?</v>

434
00:50:36.199 --> 00:50:43.717
<v Graham Cluley>Right, right. Well, I think some of the things which you've dug up in this report are interesting. It's worth digging through these.</v>

435
00:50:43.717 --> 00:50:51.235
<v Graham Cluley>So the headline number is this big rise in ransomware attacks in early 2026. So you're saying there's been a 55% year-on-year rise in those attacks, which is quite a big jump, isn't it? Is that genuinely more attacks or are we just getting better at counting ransomware incidents?</v>

436
00:50:51.235 --> 00:50:56.768
<v Jeffrey Wheatman>So I think there are a few parts to that. I think there are definitely more attacks. We saw a huge number of CVEs last year and with Mythos and the Frontier models, we think that's going to continue to spike. So it's definitely more attacks. We are also getting better at counting them, in large part because of the regulatory environment. Companies are being required to make announcements when they have breaches. In the US, for example, if you're publicly traded and you have a material breach, you have to make an announcement.</v>

437
00:50:56.768 --> 00:51:02.302
<v Jeffrey Wheatman>The EU, we know, has very similar things. DORA for financial services, NIST too — all of these things are requiring organisations to be much more open. So I think it's really a combination of both of those things. There's more of them and we're being forced to talk about them more. And the other thing that I think is important is it used to be very much about data. It's still about data, but now it's much more about resilience.</v>

438
00:51:02.302 --> 00:51:11.440
<v Joe>Okay.</v>

439
00:51:11.440 --> 00:51:17.974
<v Jeffrey Wheatman>Right.</v>

440
00:51:17.974 --> 00:51:24.507
<v Jeffrey Wheatman>Can you keep your business up and running even if something bad happens to your partners who you don't directly control?</v>

441
00:51:24.507 --> 00:51:30.556
<v Graham Cluley>Yeah. Which is the scary thing, isn't it?</v>

442
00:51:30.556 --> 00:51:36.605
<v Graham Cluley>You may have your own house in order, but the problem is that you're letting in all these other people or you're letting other people's code into your organisation. And potentially that's a route through which you can suffer a ransomware incident.</v>

443
00:51:36.605 --> 00:51:46.460
<v Jeffrey Wheatman>Yeah, I present all over the world and I always get up on stage and say, look, you're all perfect at defending against ransomware. You're not, but I'm gonna give you the benefit of the doubt. But what I can tell you for sure is your partners, they're not.</v>

444
00:51:46.460 --> 00:51:58.382
<v Graham Cluley>Right.</v>

445
00:51:58.382 --> 00:52:08.159
<v Jeffrey Wheatman>And that kind of opens people's eyes up a little bit.</v>

446
00:52:08.159 --> 00:52:14.253
<v Graham Cluley>This problem of ransomware, it's not hitting everywhere equally, is it? The geographic picture around this, it's really quite striking.</v>

447
00:52:14.253 --> 00:52:20.346
<v Graham Cluley>You're reporting nearly 70% of the incidents landed in just 5 countries. So you've got the UK, Germany, France, Italy, Spain.</v>

448
00:52:20.346 --> 00:52:34.313
<v Danny Palmer>Yep.</v>

449
00:52:34.313 --> 00:52:41.217
<v Graham Cluley>Is that just because they're the biggest economies in Europe, or is something else going on?</v>

450
00:52:41.217 --> 00:52:48.119
<v Graham Cluley>Germany in particular seems to be having a really rough time.</v>

451
00:52:48.119 --> 00:52:53.141
<v Jeffrey Wheatman>Yeah, I think it's again a combination. I think it's because their economies are bigger, there are more targets there. Infamous US bank robber Willie Sutton, when they asked him why he robbed banks, he said, 'Cause that's where the money is.' And that's definitely the case. We also think that in part some of it is related to the regulatory environment. People are gonna be quicker to pay, I think, because of the potential financial impact if they don't. And then the other thing too, I think for global companies, they're more likely to have a presence in these 5 nations than others. As an example, it's because the economies are big, but really the targets are just bigger.</v>

452
00:52:53.141 --> 00:52:58.161
<v Jeffrey Wheatman>So that's what the bad actors are gonna go at, right? It's a magnification game for them. And I always say bad actors are like water. They take the easiest pathway. And frequently the easiest pathway is going to be where you have the most opportunities and the most targets and the most concentration. And that's why we think that these particular countries are getting nailed so badly.</v>

453
00:52:58.161 --> 00:53:07.610
<v Graham Cluley>And when you're talking about bad actors, you're not talking about Nicolas Cage, you are talking about—</v>

454
00:53:07.610 --> 00:53:17.655
<v Danny Palmer>Don't—</v>

455
00:53:17.655 --> 00:53:23.842
<v Jeffrey Wheatman>Hold on, hold on, Graham. Do not badmouth Nicolas Cage. Nicolas Cage is one of the finest actors of our generation.</v>

456
00:53:23.842 --> 00:53:30.030
<v Jeffrey Wheatman>He's not always good at picking scripts, but he is a terrific, terrific actor. We just watched Spider Noir and he was fabulous in that.</v>

457
00:53:30.030 --> 00:53:39.485
<v Graham Cluley>I haven't seen that one yet. Now, talking about these threat actors, though, Qilin, Q-I-L-I-N, pronounced Qilin, I believe. They pop up in 26 of the 31 countries you looked at. What's made them so prolific as a ransomware gang?</v>

458
00:53:39.485 --> 00:53:45.101
<v Jeffrey Wheatman>The short answer, they run this thing like a company. They don't run it like a ransomware gang. They run it like a criminal enterprise. They provide ransomware as a service. So if I want to go after a company with ransomware and I don't have the tools, they'll do it on my behalf. So that's a magnification. They are using what we call double extortion, which is they exfiltrate the data and then they encrypt it. So even if you have really good backups, that's not enough because they have your data and they're going to send it out. And there are a couple of examples around that. They're also always improving.</v>

459
00:53:45.101 --> 00:53:50.719
<v Jeffrey Wheatman>They're paying attention to the software market. They are updating their software. They're testing everything against all of the detection tools. They're also focusing in a very opportunistic way in areas where downtime is significantly impactful from a dollar, pound, euro perspective. It's not haphazard. They're going after companies that they know cannot afford to have any downtime. The bottom line is they operate like a company and not like a gang, like these organisations used to do. And if I'm a bad actor and I do business with them and it works and they support me, I'm going to continue to do business with them just like any company. And that's why we think their presence is so high.</v>

460
00:53:50.719 --> 00:53:56.858
<v Graham Cluley>So another thing which caught my attention were the most hit sectors. Now, what types of industry are getting hit? Manufacturing — nearly 28% of all incidents.</v>

461
00:53:56.858 --> 00:54:02.994
<v Graham Cluley>But it's IT services which is the single most targeted subsector. Why does that matter, do you think?</v>

462
00:54:02.994 --> 00:54:08.652
<v Jeffrey Wheatman>So I'll talk about manufacturing very briefly, and then I think the IT services is really interesting. So manufacturing traditionally, they haven't put a lot of time and effort into cyber because that's not what they're in business for. They're not about moving ones and zeros.</v>

463
00:54:08.652 --> 00:54:14.311
<v Jeffrey Wheatman>They're about making physical things. What we've seen in the last 18 to 24 months, very visibly, is that these organisations are getting hit with ransomware and it's causing downtime.</v>

464
00:54:14.311 --> 00:54:23.985
<v Graham Cluley>Yeah.</v>

465
00:54:23.985 --> 00:54:33.273
<v Jeffrey Wheatman>And that is very, very painful for them. And we have some great examples — K&P Logistics, which is in your neck of the woods. LastPass, two years ago they got hit with ransomware. They were out of business in 125 days — a 156-year-old shipping and logistics company. We saw Jaguar Land Rover last year got hit with an attack. It had an impact on the GDP of the UK, one of the biggest economies in the world. This is big money now.</v>

466
00:54:33.273 --> 00:54:42.766
<v Danny Palmer>Yeah.</v>

467
00:54:42.766 --> 00:54:50.646
<v Jeffrey Wheatman>IT services is a slightly different target. They are going after those organisations — why? Because they're connected into multiple organisations. So the blast radius of these IT service providers is really, really big. And, you know, as an example, we saw a breach last year that went after Royal Mail.</v>

468
00:54:50.646 --> 00:54:59.697
<v Graham Cluley>Yes.</v>

469
00:54:59.697 --> 00:55:09.117
<v Jeffrey Wheatman>And they got breached through a German data collector called Spectos. Well, Spectos provides data collection for a bunch of different organisations in a bunch of different sectors. So it was this magnification thing. We also saw Milja Data in Sweden, which is an HR company. Most people have never heard of them — I never heard of them until they showed up in the report. Well, the bad actors went after them and they compromised 200 entities — governments, universities, et cetera, and Volvo, a big car company. And they compromised one company and had access into hundreds of organisations. So IT service providers tend to be that single repository. They have their fingers everywhere. And we run up against the shoemaker's children problem — they generally are not focusing enough on locking down their own stuff, even though they're providing these services in a lot of cases for customers.</v>

470
00:55:09.117 --> 00:55:19.050
<v Graham Cluley>So it's the whole supply chain problem once again, isn't it?</v>

471
00:55:19.050 --> 00:55:31.166
<v Jeffrey Wheatman>Yeah.</v>

472
00:55:31.166 --> 00:55:39.574
<v Graham Cluley>Yeah. Which is what the bad guys are exploiting here. You can have all kinds of different businesses out there, but if they're reliant upon some kind of IT service provider and the IT service provider gets hit.</v>

473
00:55:39.574 --> 00:55:49.547
<v Jeffrey Wheatman>Yeah. And then you're in. And the reality is most of these IT service providers are considered trusted entities.</v>

474
00:55:49.547 --> 00:55:59.411
<v Graham Cluley>Yes.</v>

475
00:55:59.411 --> 00:56:06.112
<v Jeffrey Wheatman>And therefore, once you compromise them, get their credentials, you're inside and you're trusted. And once you're inside, the monitoring is gonna change. What they're looking for is gonna change. And I don't think people look enough at sort of data exfiltration in bulk and those kinds of things. So it's definitely an ongoing challenge. And I think we need to hold these folks to higher standards. And I don't think a lot of organisations out there recognise that.</v>

476
00:56:06.112 --> 00:56:12.813
<v Jeffrey Wheatman>You know, I always badly paraphrase Animal Farm by George Orwell. All partners are equal, but some partners are more equal than others. And we see organisations struggle with prioritisation. This is not unique to the EU or the UK. This is a global problem. But in these cases, we're seeing some specific examples that are regional in nature.</v>

477
00:56:12.813 --> 00:56:18.222
<v Graham Cluley>And I think one of the takeaways I took from your report, and it makes really clear, is that this is now a legal question as much as a security one, because European regulation has fundamentally shifted where the accountability sits. We've got the likes of NIS2 and DORA, which you've mentioned.</v>

478
00:56:18.222 --> 00:56:23.632
<v Graham Cluley>The message is quite plainly that now you are legally accountable for your suppliers' security, not just your own. But has that message got through to organisations yet?</v>

479
00:56:23.632 --> 00:56:33.025
<v Jeffrey Wheatman>I think a little bit. I've always said that the EU and the UK has definitely been more risk-aligned in the way security and information security and cybersecurity have been practised. So I think historically that's the case. I think it is still the case. And I think a byproduct of that is the regulations tend to be more risk-based and therefore they make much more sense within a business context. So that being said, I think until we see people see these big financial impacts like JLR, like nights of the old KMP, I mean, I told that story in our customer advisory board and one of my customers in manufacturing put their hand up and said, yeah, that cost us $50 million 'cause the truck didn't show up with raw materials.</v>

480
00:56:33.025 --> 00:56:43.637
<v Joe>Right?</v>

481
00:56:43.637 --> 00:56:53.599
<v Graham Cluley>Right.</v>

482
00:56:53.599 --> 00:57:00.362
<v Jeffrey Wheatman>So the regulatory environment I think is definitely shifting. I think one of the things that we at Black Kite focus on as a really, really important objective is collaboration is the key to success. The bad actors are collaborating. They do it really well. They do it through affiliate networks. This is some stuff that shows up in the report. We are bad at collaborating. We are way too competitive. We don't want to put out there what's going on because they don't want anybody pointing a finger and blaming. And that again is a global problem. But I think that slowly but surely organisations are starting to realise, and if you look at attack surface management or continuous threat and exposure management, whatever the analyst firms call it these days, what we're starting to see is that security operations centres, the SOCs, are starting to realise that their perimeter is not the perimeter they need to focus on. It's really about the perimeter that includes third parties. And as you mature, fourth, fifth, and sixth. So I think from an operational perspective, I think we're seeing that from a regulatory perspective, we're seeing that, but it's always very slow. I mean, you've been around a while. It is very hard to get the board to shift focus, to get the CEO and the CFO and the COO to shift focus because they're focused on money coming in, money going out, and if something goes bad, who gets in trouble?</v>

483
00:57:00.362 --> 00:57:07.512
<v Danny Palmer>Yep.</v>

484
00:57:07.512 --> 00:57:13.277
<v Jeffrey Wheatman>So we need to start more aligning our talk tracks and our conversations with money coming in, money going out, and who gets in trouble. And I think it's happening and I do think it's accelerating. And I think a few years down the road, I think there will be much more focus on it.</v>

485
00:57:13.277 --> 00:57:19.043
<v Jeffrey Wheatman>I mean, the market we're in is growing like crazy. We are seeing a lot more interest now than we were last year and more last year than two, three years ago. And I think that is a reflection of the focus there and the fact that people need to pay more attention to this.</v>

486
00:57:19.043 --> 00:57:28.985
<v Graham Cluley>Now, this podcast, we're lucky enough to have listeners around the world, not just in Europe. And I think this report is actually relevant to folks outside of Europe as well. I think there's a lot we can learn from this.</v>

487
00:57:28.985 --> 00:57:40.608
<v Jeffrey Wheatman>Yeah.</v>

488
00:57:40.608 --> 00:57:48.715
<v Graham Cluley>For anyone who's listening who runs security, what's the single most important thing your report tells them to go and do? You know, tomorrow when you arrive at your desk, what should you be doing?</v>

489
00:57:48.715 --> 00:57:55.659
<v Jeffrey Wheatman>I'm gonna cheat and I'm gonna give you a three-part answer.</v>

490
00:57:55.659 --> 00:58:05.461
<v Graham Cluley>Okay.</v>

491
00:58:05.461 --> 00:58:11.646
<v Jeffrey Wheatman>So the first part, Graham, is you need to inventory your suppliers. I talk to so many people and I say, how many vendors do you have? And they go, 50? I go, there's no way. My wife runs a business out of our kitchen. She's got 36 suppliers. You have way more than 50, and it's not just IT suppliers, it's all of your suppliers. So that's the first. The second thing is a follow-up to that. You need to prioritise them. You need to tier them.</v>

492
00:58:11.646 --> 00:58:17.831
<v Jeffrey Wheatman>Not all of them are going to lead to the same exposure. And then the third piece of that is you need to identify single points of failure. A friend of mine was the chief security officer for a global manufacturer, and they had one supplier that manufactured a screw. That screw was only manufactured by that company. That screw went into a module that went into an aerospace guidance system that went into military hardware all around the world. That small company was terrible at cyber. And the CISO went to the board and said, "Look, I need $5 million. I gotta go buy a bunch of screws." And the board said, "What?" And he articulated that story. They gave him the money and lo and behold, Graham, two weeks later, that screw supplier got hit with ransomware. They were down for three weeks and this company didn't lose a minute of production.</v>

493
00:58:17.831 --> 00:58:28.081
<v Danny Palmer>Right?</v>

494
00:58:28.081 --> 00:58:36.708
<v Jeffrey Wheatman>So if you don't have alternatives, you need to understand what your fallback is and can you be proactive? So I think those are really the key things, right? So inventory, tiering, and identifying your critical points of failure. And I think that gets people closer to where they need to go. There's obviously a bunch of stuff you need to do after that, but if you don't know who your partners are, how do you get them to change?</v>

495
00:58:36.708 --> 00:58:45.335
<v Jeffrey Wheatman>How do you get them to be more aligned with what we want them to do? And the answer is you can't. Because you're not engaged with them. And that's a problem. And with AI, I don't know if anyone out there has heard it.</v>

496
00:58:45.335 --> 00:58:53.961
<v Jeffrey Wheatman>It's this new technology, artificial intelligence. It's crazy, apparently. And we're seeing more and more of that in organisations and agentic workflows and MCP servers and all of this stuff. You're connecting to a bunch of people you don't know and never agreed to do business with.</v>

497
00:58:53.961 --> 00:59:00.675
<v Graham Cluley>Well, it's been really fascinating chatting with you today. And listeners, if you want to learn more, you can find the 2026 European Cyber Risk Report — download your own copy at blackkite.com/smashing.</v>

498
00:59:00.675 --> 00:59:07.387
<v Graham Cluley>We'll put a link in the show notes as well. Jeffrey Wheatman of Black Kite, thank you so much for joining us today.</v>

499
00:59:07.387 --> 00:59:16.780
<v Jeffrey Wheatman>Graham, it has been an absolute pleasure. You have a great rest of the day, my friend.</v>

500
00:59:16.780 --> 00:59:32.541
<v Joe>Thank you.</v>

501
00:59:32.541 --> 00:59:39.342
<v Graham Cluley>Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us.</v>

502
00:59:39.342 --> 00:59:46.143
<v Graham Cluley>I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way for them to do that?</v>

503
00:59:46.143 --> 00:59:54.318
<v Danny Palmer>Thank you for having me, first of all, and you can follow me on LinkedIn, Bluesky, trying to get back into using Mastodon more. Got my website as well, which I should update far more regularly than I do.</v>

504
00:59:54.318 --> 01:00:02.494
<v Danny Palmer>And of course, for the next sort of 6 weeks or so, you can catch my articles on infosecuritymagazine.com. I'm still there until my contract is up, and then I'll be off to explore the world on my own again.</v>

505
01:00:02.494 --> 01:00:08.190
<v Graham Cluley>Terrific stuff. And you can find me, Graham Cluley, on LinkedIn or follow Smashing Security on Bluesky and Mastodon, and even Reddit. And don't forget to ensure you never miss another episode — follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Pocket Casts, and Spotify.</v>

506
01:00:08.190 --> 01:00:13.885
<v Graham Cluley>Episodes, show notes, sponsorship info, guest lists, and the entire back catalog of 473 episodes — check out smashingsecurity.com. Until next time, cheerio. Bye-bye.</v>

507
01:00:13.885 --> 01:00:25.688
<v Danny Palmer>Bye-bye.</v>

508
01:00:25.688 --> 01:00:31.405
<v Graham Cluley>You've been listening to Smashing Security with me, Graham Cluley, and huge thanks, of course, to Danny Palmer for joining us this week and to this episode's sponsors, ProtonPass, BlackKite, and Banta. And you know what? We've also got to thank the patrons, haven't we? Yes, those people who've signed up for Smashing Security Plus, because we're going to pick a few of their names out of the hat right now to thank them. Thank them specifically. We've got Daniel Kromeck, sounds like a dab hand at opening a jar of pickles.</v>

509
01:00:31.405 --> 01:00:37.121
<v Graham Cluley>Jack Unverfurth. Orborus, which is, could be a person, maybe a snake with an appetite for its own tail. Dan H, who perhaps wisely thought twice about sharing his surname. Billy loves the podcast, but is even more privacy conscious than Dan, and so can't even tell us a single letter of his surname. MJ Lee. Well, we know their surname, but we're just getting initials for the forenames now.</v>

510
01:00:37.121 --> 01:00:49.001
<v Joe>Who else?</v>

511
01:00:49.001 --> 01:00:49.358
<v Graham Cluley>Saital, Mark Norman. Could be— sounds like should probably be presenting the 7 o'clock news. And the utterly delicious Sammy Doza. Those are just a few of the members of Smashing Security Plus. And because they are members, they get their episodes ad-free and earlier than the general public, and they can have their details pulled out at random and mercilessly mocked at the end of the show. If you'd like to join Smashing Security Plus, just head over to smashingsecurity.com/plus, because it puts a few shekels in my pocket, and I'm always grateful for that. Keeps the servers running. But you don't have to support us financially. You can also support us in other ways. You can subscribe, leave a 5-star review, or maybe tell your friends about the show. Simply spread the word. Why not? Because every little bit helps and it makes all the effort worthwhile. Until next week, where I hope you'll be tuning in again. Cheerio. Bye-bye.</v>
