Graham Cluely Security Blog

Subscribe to Graham Cluely Security Blog feed Graham Cluely Security Blog
Cybersecurity keynote speaker
Updated: 44 min 32 sec ago

How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down

Fri, 03/06/2026 - 12:58pm
In a co-ordinated public-private operation between law enforcement agencies and cybersecurity industry partners, Tycoon 2FA - one of the world's most prolific phishing-as-a-service platforms - has been dismantled. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #457: How a cybersecurity boss framed his own employee

Wed, 03/04/2026 - 7:33pm
When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker... who promptly sent an innocent colleague into a career-ending ambush. In this episode, we unravel the jaw-dropping tale of a defence contractor caught selling zero-day exploits to a Russia-linked broker. Plus: are nation states quietly poisoning AI models to bend reality itself? We explore how “foreign information manipulation interference” could target not just social media users, but the large language models we increasingly trust for answers — and what that might mean for truth, trust, and the future of online influence. All this, and much more, in episode 457 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Carl Miller.
Categories: Graham Cluely

They seized $4.8m in crypto… then gave the master key to the internet

Tue, 03/03/2026 - 11:09am
South Korea's National Tax Service (NTS) has found itself in the middle of a deeply embarrassing - and costly - blunder after accidentally handing thieves the master key to a seized cryptocurrency wallet. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Your staff are your biggest security risk: AI is making it worse

Thu, 02/26/2026 - 4:21pm
A new report claims that the cost of insider security incidents has surged 20% in two years, reaching an average of US $19.5 million per organization annually, with no sign that the alarming figure is flattening. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Notorious ransomware gang allegedly blackmailed by fake FSB officer

Thu, 02/26/2026 - 8:40am
There is a certain poetic justice in a cybersecurity-related story that has emerged from Moscow this week: A man has been accused of trying to extort money... from a notorious Russian ransomware gang. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #456: How to lose friends and DDoS people

Wed, 02/25/2026 - 7:16pm
When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email - they allegedly weaponised their own CAPTCHA page to launch a DDoS attack, threatened to invent an entirely new genre of AI porn, and tampered with parts of their own archive to smear the blogger's name. In this episode, we unravel how a website designed to preserve history may have trashed its own credibility - and how Wikipedia responded when trust went out the window. Plus a ransomware gang shoots itself in the foot with a classic case of buffoonery, accidentally corrupting the very keys victims would need to decrypt their data. When even the criminals can’t unlock your files, what happens next? All this, a surprisingly zen Pick of the Week, and a gloriously splenetic rant against web forms, on episode 456 of the award-winning "Smashing Security" podcast, with cybersecurity veteran Graham Cluley and special guest Paul Ducklin.
Categories: Graham Cluely

$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon

Wed, 02/25/2026 - 4:38am
Amid a privacy backlash, a US $10,000 reward has been offered for anyone who can find a way to run Ring doorbell cameras locally, cutting off the flow of video data to Amazon's servers. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent

Fri, 02/20/2026 - 5:54pm
Spain's police force has announced that it has arrested a 20-year-old man who they claim managed to book luxury hotel rooms worth up to €1,000 a night for just one euro cent. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #455: Face off: Meta’s Glasses and America’s internet kill switch

Wed, 02/18/2026 - 7:30pm
Could America turn off Europe's internet? That’s one of the questions that Graham and special guest James Ball will be exploring as they discuss tech sovereignty. Could Gmail, cloud services, and critical infrastructure really become geopolitical leverage? And is anyone actually building a Plan B? Plus we explore if Meta is quietly plotting to turn its smart glasses into face-recognising surveillance specs? With reports of internal memos suggesting they plan to launch controversial features while everyone’s distracted by political chaos, we ask: is this innovation really wanted by the public... or something far creepier? All of this, and much more, in episode 455 of the award-winning "Smashing Security" podcast with cybersecurity veteran Graham Cluley, joined this week by journalist and author James Ball.
Categories: Graham Cluely

Dutch police arrest man for “hacking” after accidentally sending him confidential files

Wed, 02/18/2026 - 5:52am
Police in The Netherlands say they have arrested a 40-year-old man on suspicion of hacking... after police officers accidentally sent him a link granting him access to their own confidential documents Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Urgent warnings from UK and US cyber agencies after Polish energy grid attack

Thu, 02/12/2026 - 1:47pm
A coordinated cyberattack that targeted Poland's energy infrastructure in late December 2025 has prompted cybersecurity agencies to issue urgent warnings to critical national infrastructure operators on both sides of the Atlantic. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Polish hacker charged seven years after massive Morele.net data breach

Thu, 02/12/2026 - 3:04am
A 29-year-old Polish man has been charged in connection with a data breach that exposed the personal details of around 2.5 million customers of the popular Polish e-commerce website Morele.net. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

Smashing Security podcast #454: AI was not plotting humanity’s demise. Humans were

Wed, 02/11/2026 - 7:30pm
AI bots are having existential crises, inventing religions, and allegedly plotting against humanity... or so the internet would have you believe. We dig into Moltbook, the “AI-only” social network that sent Twitter into a meltdown, attracted breathless talk of the singularity, and turned out to be far less Terminator and far more humans role-playing as bots. Plus we discuss why "vibe coding" your app might be a catastrophically bad idea, when security researchers can easily peek inside rifle through your private messages, API keys, and databases. Also this week we learn that pro-Russian hackers are circling the Winter Olympics - or is it the Jamaican Bobsleigh team? All this and more is discussed in episode 454 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Iain Thomson.
Categories: Graham Cluely

Fake Dubai Crown Prince tracked to Nigerian mansion after $2.5M romance scam

Sat, 02/07/2026 - 8:19am
When a Romanian businesswoman fell for a fake Dubai Crown Prince in a $2.5 million romance scam, investigators tracked the fraudster to his Nigerian mansion - only to discover he was masquerading as a campaigning philanthropist. Read more in my article on the Hot for Security blog.
Categories: Graham Cluely