Sign in

Graham Cluley

@grahamcluley.com
8.9K followers 1.7K following 1.7K posts

Award-winning #cybersecurity keynote speaker, writer, podcaster | Host of multi-award-winning @smashingsecurity.com podcast. ❤️ #DoctorWho, #Beatles, #Chess He/him 🌐 grahamcluley.com 🎙️ www.smashingsecurity.com

PostsRepliesMedia
Graham Cluley @grahamcluley.com · 8h
Nine months of undetected access, unencrypted files, and Social Security numbers for over three million military personnel. Learn what is known about The Pentagon's latest data breach in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Pentagon personnel database breach exposes personal data of millions
The US Department of Defense has confirmed a breach at one of its main repositories of personnel information, the Defense Manpower Data Center (DMDC), that has exposed the sensitive details of just ov...
052
Reposted by Graham Cluley
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 29/09/2026
Huh, who knew the jackasses behind Shiny Hunters ransomware group were not good people. “The 24-year-old Pepijn van der S., who was arrested on suspicion of involvement in the hacker group ShinyHunters on 15 September, is also suspected of an attempted provocation of two murders.”
rtl.nl
ShinyHunters-verdachte Pepijn van der S. ook verdacht van opdracht geven tot moorden
De 24-jarige Pepijn van der S. die 15 september was aangehouden op verdenking van betrokkenheid bij hackersgroep ShinyHunters, wordt ook verdacht van een poging van uitlokking van twee moorden.
22010
Graham Cluley @grahamcluley.com · 25/09/2026
Always a treat to have cybersecurity podcast legend Dave Bittner join "Smashing Security" as a guest! Hear us discuss how Flock security cameras are being hacked, how a vibe-coded website came a cropper, as well as Dave's love for Mrs Mills' piano-playing and my love for La La Land...
grahamcluley.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand’s national parks.
173
Graham Cluley @grahamcluley.com · 25/09/2026
Another one bites the dust. A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing the LockerGoga ransomware. www.bitdefender.com/en-us/blog/h...
bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the wo...
092
Graham Cluley @grahamcluley.com · 22/09/2026
Delighted to be giving the keynote at the Richmond Cybersecurity Forum in Davos today. The subject? How AI has changed cybersecurity, and how AI could be the biggest insider threat your firm has ever faced. And no, there isn't any snow this time of year. Even AI can't make that happen.
AspenGold Hotel
260
Graham Cluley @grahamcluley.com · 18/09/2026
If, like me, you were a teenage boy in the mid-1980s you quite possibly remember Kelly LeBrock in the movie "Weird Science"... How could we resist getting into computers after that!? Anyway, this and much more discussed in episode 485 of "Smashing Security" podcast with special guest Lianne Potter
262
Graham Cluley @grahamcluley.com · 17/09/2026
A supertanker carrying 2.3 million barrels of crude oil crossed the Atlantic. Hackers allegedly slipped past its defences - messing with fuel systems, engine speed, and knocking out communications for 30 hours. Read more in my article on the Bitdefender blog. www.bitdefender.com/en-us/blog/h...
bitdefender.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.
154
Graham Cluley @grahamcluley.com · 15/09/2026
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to help a SIM swap gang in their attempt to steal over half a million dollars.
bitdefender.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.
152
Reposted by Graham Cluley
Joseph Cox @josephcox.bsky.social · 14/09/2026
Here is the setting you need to turn off if you don't want a human potentially reading through your ChatGPT conversations. I've seen some of the prompts; these ChatGPT users clearly have no idea a human is reading www.404media.co/inside-proje...
719059
Reposted by Graham Cluley
Hassinator @hassinator.bsky.social · 13/09/2026
a great letter in the times today. perhaps worth sharing in these troubled times. #RNLI #heroes
4059742380
Reposted by Graham Cluley
Lou Morgan @lmorgan.bsky.social · 12/09/2026
Just for once, I’d like to see one of these super-rich crypto bros handing over £36 million to Great Ormond Street, or cancer research, or food banks and housing charities, because they want to make the world a better place and help its most vulnerable people. But instead…?
1153
Reposted by Graham Cluley
Brandy Zadrozny @brandyzadrozny.bsky.social · 11/09/2026
Get in, folks: a new Russian disinfo campaign is targeting the midterms, specifically Democrats, in what seems to be the first attempt by the Kremlin-backed op to meddle in this year’s U.S. elections. They're faking celebrity videos attacking Dems and are...very stupid. www.ms.now/news/russia-...
ms.now
A Russian disinformation campaign is doctoring celebrity videos to meddle in the midterms
The Kremlin-backed operation, known as Matryoshka, has Hollywood actors telling voters to disavow the Democratic Party and vote Republican.
8824581549
Reposted by Graham Cluley
evacide @evacide.bsky.social · 10/09/2026
I'm sure lots of other people have said this, but if I worked for a company on a product that I thought had a >10% chance of killing all humans within the next decade and we had no plan for how to stop it, I would quit and devote myself full time to destroying this product.
28475105
Graham Cluley @grahamcluley.com · 10/09/2026
In the latest "Smashing Security" podcast, "Five Eyes" intelligence agencies (not Five Guys 🍔) have published fresh advice on how firms should talk to the public after a breach. Their message in short? "please, for the love of God, stop calling every hack 'sophisticated'"
151
Graham Cluley @grahamcluley.com · 10/09/2026
Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub....
bitdefender.com
'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here's a tip for any budding cybercriminals out there.
020
Graham Cluley @grahamcluley.com · 10/09/2026
Excited to announce that I will be delivering the keynote at CYBER ROOT in Malta , discussing how your AI employee could be your biggest risk... Other great speakers on the line-up include BBC News's @joetidy.bsky.social and people hacker @jennyradcliffe.bsky.social. → ncc-mita.gov.mt/cyberroot/
120
Graham Cluley @grahamcluley.com · 09/09/2026
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Find out what you need to know about it in my article on the Fortra blog.
fortra.com
CRPx0 Ransomware: What You Need to Know | Fortra
Learn how CRPx0 ransomware works, how it spreads through ClickFix attacks, and what organizations can do to defend against ransomware threats.
060
Graham Cluley @grahamcluley.com · 08/09/2026
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
The US military just turned off ad tracking on its phones. Maybe you should too
Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target America...
285
Graham Cluley @grahamcluley.com · 07/09/2026
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts. Read all about it in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.
030
Graham Cluley @grahamcluley.com · 03/09/2026
On the latest episode of the "Smashing Security" podcast I was joined by @jamesrball.com who took a step back from the stories of AI "going rogue" and and asked the awkward question: is this really an emergent AI apocalypse, or were AI firms just lousy at security?
253
Graham Cluley @grahamcluley.com · 02/09/2026
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls... Cver a single four-week period, 75% of all scam crime reports police have received have involved Revolut accounts... www.bitdefender.com/en-us/blog/h...
bitdefender.com
Revolut scam steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.
022
Graham Cluley @grahamcluley.com · 28/08/2026
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm... Two men are now facing charges over TeamPCP's global supply-chain hacking spree. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more
Police have charged two men from Western Australia over their alleged involvement in TeamPCP, a cybercriminal gang that has been blamed for a massive software supply-chain hacking campaign.
081
Graham Cluley @grahamcluley.com · 27/08/2026
On the latest episode of "Smashing Security", Paul Ducklin and I take an extended look at the GTA 6 CyberLeek debacle... and the scourge of residential proxies. Find it in all good podcast apps, or at grahamcluley.com/smashing-sec...
grahamcluley.com
Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead…
051
Graham Cluley @grahamcluley.com · 27/08/2026
The US Navy has told sailors and their families to scrub their social media, as adversaries are watching... Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be usin...
010
Graham Cluley @grahamcluley.com · 24/08/2026
"Offside Wallet Theft Factory", a campaign involving scores of malicious Firefox browser extensions, has been running under the radar since at least March 2026 - stealing cryptocurrency seed keys and login credentials. More details: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sp...
062
Graham Cluley @grahamcluley.com · 24/08/2026
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog: www.fortra.com/blog/gunra-r...
fortra.com
Gunra Ransomware: What You Need to Know |Fortra
Gunra ransomware exploits unpatched VPNs and firewalls to steal and encrypt sensitive data. Learn how it attacks, whom it targets, and how to reduce risk.
031
Graham Cluley @grahamcluley.com · 20/08/2026
A group of security researchers took a robot dog, and jailbroke it by telling it that it was a Pokemon. And that wasn't the worst of it... Hear Jenny Radcliffe join me on the "Smashing Security" podcast to discuss this, the theft of Mozart statuettes, and Andy Burnham being socially-engineered.
pod.link
Never say this to a robot dog
Listen to Never say this to a robot dog from Smashing Security wherever you get your podcasts!
1154
Graham Cluley @grahamcluley.com · 19/08/2026
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume... But what he did instead was turn to extortion. www.bitdefender.com/en-us/blog/h...
bitdefender.com
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.
050
Graham Cluley @grahamcluley.com · 17/08/2026
A security researcher wrapped a car in an AI-generated pattern and drove it past a surveillance camera. The detection software logged nothing. Learn more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate...
2173
Graham Cluley @grahamcluley.com · 16/08/2026
A growing number of UK venues have decided to act against privacy-busting smart glasses. Hear that? It's the sound of the world's smallest violin playing for people who wear Meta Smart Glasses... www.bitdefender.com/en-us/blog/h...
bitdefender.com
Meta's Ray-Bans are being banned from pubs, restaurants, and theatres
I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.
3121
Graham Cluley @grahamcluley.com · 14/08/2026
Join me and the experts at Proofpoint in a webinar, looking at some of the real-world incidents every CISO should know about and what they tell us about protecting data in the age of AI. 📅 Monday 14th September ⏰ 11:00 BST Register here: grahamcluley.com/proofpoint
120
Graham Cluley @grahamcluley.com · 13/08/2026
Poison Claude!!! Would you trust it? Was great to have self-confessed skinflint Northerner Lianne Potter join me on the latest "Smashing Security" podcast. Hear more in episode 480 of the "Smashing Security" podcast. Find it in all good podcast apps, or at link in comments...
282
Graham Cluley @grahamcluley.com · 07/08/2026
Would you accept 90% off the cost of accessing Anthropic's AI? With "Poison Claude" you pay with cryptocurrency, get a cheap API key, and off you go. But there's a catch: every prompt you type, every document you share, every API key or password you paste in, goes through their servers first.
fortra.com
Beware Cut-Price AI Services that Read Your Every Word | Fortra
Learn how cut-price AI services like Poison Claude exploit cloud credits, expose sensitive prompts, and create serious data security risks for businesses.
151
Graham Cluley @grahamcluley.com · 06/08/2026
Watch out!! I almost fell for it when a "fake policeman" rang me up to talk about my cryptocurrency wallet. Huge thanks to @dannypalmer.bsky.social palmer for joining me on episode 479 of the "Smashing Security" podcast! #cybersecurity #podcast #crypto #cryptocurrency
2154
Graham Cluley @grahamcluley.com · 06/08/2026
Apple is so flooded with AI-generated bug reports that it accidentally locked out a firm that had just found a critical macOS zero-day. Is the cure is becoming as dangerous as the disease? www.bitdefender.com/en-us/blog/h...
bitdefender.com
Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing ...
1143
Graham Cluley @grahamcluley.com · 04/08/2026
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Bitdefender blog.
bitdefender.com
Fake IRS letters target cryptocurrency holders
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sound...
043
Graham Cluley @grahamcluley.com · 31/07/2026
Paul Ducklin shares a LinkedIn post he found with the audience of the "Smashing Security" podcast, discussing the recent news about AI models breaking out of their supposedly-secure environments... Hear more in episode 478 of the "Smashing Security" podcast! pod.link/1195001633/e...
053
Graham Cluley @grahamcluley.com · 31/07/2026
Anthropic not wanting to be left behind by OpenAI, I see... No doubt someone in their marketing department was crying into their coffee that OpenAI got there first...
BBC News headline: Anthropic's Claude AI escapes to hack into three organisations
911731
Graham Cluley @grahamcluley.com · 31/07/2026
The $5 million threat: AI Is supercharging phishing attacks. www.fortra.com/blog/5-milli...
fortra.com
The $5 Million Threat: AI Is Supercharging Phishing Attacks| Fortra
IBM's Cost of a Data Breach Report reveals how AI-powered phishing drives higher breach costs. Learn why layered defenses are critical in 2026.
040
Reposted by Graham Cluley
Rob Manuel @robmanuel.b3ta.com · 30/07/2026
If your vote is undecided in the Clacton by-election this might be the clincher for you
I don’t usually discuss politics on here, it’s rarely worth the grief in our increasingly polarised country. However, I feel compelled to draw attention to point 17 of Count Binface’s newly released 20-point manifesto:
“The hand dryer in the gents’ toilet at the Great Himalayas restaurant, Southport, to be moved to a more sensible position.”
As it happens, the Great Himalayas is my favourite restaurant in Southport, and Natasha and I have eaten there many times.
Having investigated the matter with our friends in the local community, I can confirm that Binface really knows what he’s talking about. At last, a politician addressing the issues that affect ordinary people.
Photographic evidence of the thoughtlessly positioned appliance taken yesterday:
4366114
Graham Cluley @grahamcluley.com · 30/07/2026
In what some would describe as a "bold move", a group of North Korean hackers have decided to hack... North Korea's central bank! You won't be surprised to hear that NK has not taken kindly to this... Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
North Korea's elite hackers turned on their own government — and got caught
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocu...
142
Graham Cluley @grahamcluley.com · 29/07/2026
Possibly my favourite TV programme of all time…. Yes, better than Bagpuss.
210
Graham Cluley @grahamcluley.com · 27/07/2026
Russian disinformation is being designed to be invisible to humans - but highly visible to AI. A sanctioned Russian propaganda operation deliberately crafted websites to *avoid* appearing prominently in search results, but maximised the chances of ChatGPT, Gemini and Claude parroting out their text
demos.co.uk
GEO for Geopolitics: What happens when AI and information warfare collide
Demos is Britain’s leading cross-party think-tank. We produce original research, publish innovative thinkers and host thought-provoking events.
0911
Graham Cluley @grahamcluley.com · 24/07/2026
Worst companion since Bonnie Langford?
Charles and Camilla arrive at the Commonwealth Games
050
Graham Cluley @grahamcluley.com · 23/07/2026
𝗕𝗥𝗘𝗔𝗞𝗜𝗡𝗚 𝗡𝗘𝗪𝗦: Microsoft has accidentally invented the weekend... on a Thursday.
Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services
081
Graham Cluley @grahamcluley.com · 23/07/2026
Great to have @jamesrball.com join me on the latest episode of the "Smashing Security" podcast where he explains how Suno was hacked, revealing awkward details of how it taught its AI to generate music. Plus the hacker suspected of links to the Kremlin, and his love of McDonald's McNuggets...
pod.link
How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Listen to How 14 orders of chicken McNuggets helped nail a suspected Russian hacker from Smashing Security wherever you get your podcasts!
293
Graham Cluley @grahamcluley.com · 23/07/2026
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the newspaper headlines suggest?
bitdefender.com
OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know
You can't have failed to hear the news headlines: "AI agent went rogue and hacked startup by itself, OpenAI reveals", "Firm hacked by rogue OpenAI models says it is 'a wake-up call'", a...
051
Graham Cluley @grahamcluley.com · 22/07/2026
"Grok, generate a historically accurate adaptation of a 2,800-year-old poem about a one-eyed giant, a six-headed sea monster, and a witch who turns men into pigs."
Elon Musk says Grok will make a full-length movie of The Odyssey before the year is out.
1120
Graham Cluley @grahamcluley.com · 22/07/2026
Hugging Face tried to use an American AI to defend against OpenAI's rogue AI, but its safety guardrails got in the way. They had to use a Chinese open-source model instead. This is fine... www.theguardian.com/technology/2...
theguardian.com
AI agent went rogue and hacked startup by itself, OpenAI reveals
Company behind ChatGPT says agent ‘cheated’ an evaluation by attacking a Hugging Face database
083
Graham Cluley @grahamcluley.com · 21/07/2026
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is using fake CAPTCHA checks to trick people into compromising their own PCs. www.bitdefender.com/en-us/blog/h...
bitdefender.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.
031