Sign in

Graham Cluley

@grahamcluley.com
8.9K followers 1.7K following 1.7K posts

Award-winning #cybersecurity keynote speaker, writer, podcaster | Host of multi-award-winning @smashingsecurity.com podcast. ❤️ #DoctorWho, #Beatles, #Chess He/him 🌐 grahamcluley.com 🎙️ www.smashingsecurity.com

PostsRepliesMedia
Graham Cluley @grahamcluley.com · 30/09/2026
Nine months of undetected access, unencrypted files, and Social Security numbers for over three million military personnel. Learn what is known about The Pentagon's latest data breach in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Pentagon personnel database breach exposes personal data of millions
The US Department of Defense has confirmed a breach at one of its main repositories of personnel information, the Defense Manpower Data Center (DMDC), that has exposed the sensitive details of just ov...
052
Reposted by Graham Cluley
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 29/09/2026
Huh, who knew the jackasses behind Shiny Hunters ransomware group were not good people. “The 24-year-old Pepijn van der S., who was arrested on suspicion of involvement in the hacker group ShinyHunters on 15 September, is also suspected of an attempted provocation of two murders.”
rtl.nl
ShinyHunters-verdachte Pepijn van der S. ook verdacht van opdracht geven tot moorden
De 24-jarige Pepijn van der S. die 15 september was aangehouden op verdenking van betrokkenheid bij hackersgroep ShinyHunters, wordt ook verdacht van een poging van uitlokking van twee moorden.
22010
Graham Cluley @grahamcluley.com · 25/09/2026
Always a treat to have cybersecurity podcast legend Dave Bittner join "Smashing Security" as a guest! Hear us discuss how Flock security cameras are being hacked, how a vibe-coded website came a cropper, as well as Dave's love for Mrs Mills' piano-playing and my love for La La Land...
grahamcluley.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand’s national parks.
173
Graham Cluley @grahamcluley.com · 25/09/2026
Another one bites the dust. A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing the LockerGoga ransomware. www.bitdefender.com/en-us/blog/h...
bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the wo...
092
Graham Cluley @grahamcluley.com · 22/09/2026
Lovely to see you too Brian. A shame I had to dash to the airport. Enjoy the rest of the conference!
010
Graham Cluley @grahamcluley.com · 22/09/2026
You know what? I'm going to mention that! Thanks!
010
Graham Cluley @grahamcluley.com · 22/09/2026
Don't worry, it hasn't gone to my head just yet. A fair few of the slides are dedicated to slagging off the billionaire bosses of AI firms...
SlideSlide
000
Graham Cluley @grahamcluley.com · 22/09/2026
Delighted to be giving the keynote at the Richmond Cybersecurity Forum in Davos today. The subject? How AI has changed cybersecurity, and how AI could be the biggest insider threat your firm has ever faced. And no, there isn't any snow this time of year. Even AI can't make that happen.
AspenGold Hotel
260
Graham Cluley @grahamcluley.com · 18/09/2026
Listen to the full show in your favourite podcast app, or at www.smashingsecurity.com/485
smashingsecurity.com
485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plaste...
051
Graham Cluley @grahamcluley.com · 18/09/2026
If, like me, you were a teenage boy in the mid-1980s you quite possibly remember Kelly LeBrock in the movie "Weird Science"... How could we resist getting into computers after that!? Anyway, this and much more discussed in episode 485 of "Smashing Security" podcast with special guest Lianne Potter
262
Graham Cluley @grahamcluley.com · 18/09/2026
Put your feet up, and I'll join you for a custard cream biscuit. It's almost the weekend. Thanks for listening!
110
Graham Cluley @grahamcluley.com · 17/09/2026
A supertanker carrying 2.3 million barrels of crude oil crossed the Atlantic. Hackers allegedly slipped past its defences - messing with fuel systems, engine speed, and knocking out communications for 30 hours. Read more in my article on the Bitdefender blog. www.bitdefender.com/en-us/blog/h...
bitdefender.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.
154
Graham Cluley @grahamcluley.com · 15/09/2026
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to help a SIM swap gang in their attempt to steal over half a million dollars.
bitdefender.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.
152
Reposted by Graham Cluley
Joseph Cox @josephcox.bsky.social · 14/09/2026
Here is the setting you need to turn off if you don't want a human potentially reading through your ChatGPT conversations. I've seen some of the prompts; these ChatGPT users clearly have no idea a human is reading www.404media.co/inside-proje...
719059
Reposted by Graham Cluley
Hassinator @hassinator.bsky.social · 13/09/2026
a great letter in the times today. perhaps worth sharing in these troubled times. #RNLI #heroes
4059762393
Reposted by Graham Cluley
Lou Morgan @lmorgan.bsky.social · 12/09/2026
Just for once, I’d like to see one of these super-rich crypto bros handing over £36 million to Great Ormond Street, or cancer research, or food banks and housing charities, because they want to make the world a better place and help its most vulnerable people. But instead…?
1153
Reposted by Graham Cluley
Brandy Zadrozny @brandyzadrozny.bsky.social · 11/09/2026
Get in, folks: a new Russian disinfo campaign is targeting the midterms, specifically Democrats, in what seems to be the first attempt by the Kremlin-backed op to meddle in this year’s U.S. elections. They're faking celebrity videos attacking Dems and are...very stupid. www.ms.now/news/russia-...
ms.now
A Russian disinformation campaign is doctoring celebrity videos to meddle in the midterms
The Kremlin-backed operation, known as Matryoshka, has Hollywood actors telling voters to disavow the Democratic Party and vote Republican.
8824591550
Reposted by Graham Cluley
evacide @evacide.bsky.social · 10/09/2026
I'm sure lots of other people have said this, but if I worked for a company on a product that I thought had a >10% chance of killing all humans within the next decade and we had no plan for how to stop it, I would quit and devote myself full time to destroying this product.
28475106
Graham Cluley @grahamcluley.com · 10/09/2026
All this and more on episode 484 of the "Smashing Security" podcast, with special guest @dannypalmer.bsky.social Find it in all good podcast apps, or at: pod.link/1195001633/e...
pod.link
How websites are tracking you with silence
Listen to How websites are tracking you with silence from Smashing Security wherever you get your podcasts!
010
Graham Cluley @grahamcluley.com · 10/09/2026
Plus - ever had your Bluetooth headphones refuse to switch over to your phone... because of a browser tab? One guy found a single AliExpress webpage, playing *nothing* at zero volume. Somehow his headphones could still "hear" it. This is audio fingerprinting - a sneaky tracking trick.
Smashing Security episode 484 cover art
121
Graham Cluley @grahamcluley.com · 10/09/2026
In the latest "Smashing Security" podcast, "Five Eyes" intelligence agencies (not Five Guys 🍔) have published fresh advice on how firms should talk to the public after a breach. Their message in short? "please, for the love of God, stop calling every hack 'sophisticated'"
151
Graham Cluley @grahamcluley.com · 10/09/2026
Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub....
bitdefender.com
'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here's a tip for any budding cybercriminals out there.
020
Graham Cluley @grahamcluley.com · 10/09/2026
Excited to announce that I will be delivering the keynote at CYBER ROOT in Malta , discussing how your AI employee could be your biggest risk... Other great speakers on the line-up include BBC News's @joetidy.bsky.social and people hacker @jennyradcliffe.bsky.social. → ncc-mita.gov.mt/cyberroot/
120
Graham Cluley @grahamcluley.com · 09/09/2026
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Find out what you need to know about it in my article on the Fortra blog.
fortra.com
CRPx0 Ransomware: What You Need to Know | Fortra
Learn how CRPx0 ransomware works, how it spreads through ClickFix attacks, and what organizations can do to defend against ransomware threats.
060
Graham Cluley @grahamcluley.com · 08/09/2026
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
The US military just turned off ad tracking on its phones. Maybe you should too
Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target America...
285
Graham Cluley @grahamcluley.com · 07/09/2026
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts. Read all about it in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.
030
Graham Cluley @grahamcluley.com · 03/09/2026
Also, with the foldable iPhone Ultra widely expected to be announced this week, we look at a sophisticated way AI is being used to help thieves steal your phone. Find "Smashing Security" episode 483 in all good podcast apps, or at www.smashingsecurity.com/483
010
Graham Cluley @grahamcluley.com · 03/09/2026
On the latest episode of the "Smashing Security" podcast I was joined by @jamesrball.com who took a step back from the stories of AI "going rogue" and and asked the awkward question: is this really an emergent AI apocalypse, or were AI firms just lousy at security?
253
Graham Cluley @grahamcluley.com · 02/09/2026
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls... Cver a single four-week period, 75% of all scam crime reports police have received have involved Revolut accounts... www.bitdefender.com/en-us/blog/h...
bitdefender.com
Revolut scam steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.
022
Graham Cluley @grahamcluley.com · 28/08/2026
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm... Two men are now facing charges over TeamPCP's global supply-chain hacking spree. Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more
Police have charged two men from Western Australia over their alleged involvement in TeamPCP, a cybercriminal gang that has been blamed for a massive software supply-chain hacking campaign.
081
Graham Cluley @grahamcluley.com · 27/08/2026
On the latest episode of "Smashing Security", Paul Ducklin and I take an extended look at the GTA 6 CyberLeek debacle... and the scourge of residential proxies. Find it in all good podcast apps, or at grahamcluley.com/smashing-sec...
grahamcluley.com
Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead…
051
Graham Cluley @grahamcluley.com · 27/08/2026
The US Navy has told sailors and their families to scrub their social media, as adversaries are watching... Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be usin...
010
Graham Cluley @grahamcluley.com · 26/08/2026
Thanks for being a great supporter of the podcast Zoē!
010
Graham Cluley @grahamcluley.com · 24/08/2026
"Offside Wallet Theft Factory", a campaign involving scores of malicious Firefox browser extensions, has been running under the radar since at least March 2026 - stealing cryptocurrency seed keys and login credentials. More details: www.bitdefender.com/en-us/blog/h...
bitdefender.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sp...
062
Graham Cluley @grahamcluley.com · 24/08/2026
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog: www.fortra.com/blog/gunra-r...
fortra.com
Gunra Ransomware: What You Need to Know |Fortra
Gunra ransomware exploits unpatched VPNs and firewalls to steal and encrypt sensitive data. Learn how it attacks, whom it targets, and how to reduce risk.
031
Graham Cluley @grahamcluley.com · 20/08/2026
Ahh. I was looking at YouTube. You seem to be looking at YouTube Music. I have no explanation for it, but what I can say is that both YouTube and Spotify are bloody awful ways to listen to podcasts!
110
Graham Cluley @grahamcluley.com · 20/08/2026
This is what I see when I go to the episode page on YouTube...
Show transcript button on YouTube
200
Graham Cluley @grahamcluley.com · 20/08/2026
You can find a full transcript alongside each episode. For instance, at www.smashingsecurity.com/481 In fact, if you use the player there it will even show you what is being said in real-time alongside the recording. :)
140
Graham Cluley @grahamcluley.com · 20/08/2026
A group of security researchers took a robot dog, and jailbroke it by telling it that it was a Pokemon. And that wasn't the worst of it... Hear Jenny Radcliffe join me on the "Smashing Security" podcast to discuss this, the theft of Mozart statuettes, and Andy Burnham being socially-engineered.
pod.link
Never say this to a robot dog
Listen to Never say this to a robot dog from Smashing Security wherever you get your podcasts!
1154
Graham Cluley @grahamcluley.com · 19/08/2026
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume... But what he did instead was turn to extortion. www.bitdefender.com/en-us/blog/h...
bitdefender.com
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.
050
Graham Cluley @grahamcluley.com · 18/08/2026
Wild horses couldn’t drag me back to Twitter…
180
Graham Cluley @grahamcluley.com · 17/08/2026
A security researcher wrapped a car in an AI-generated pattern and drove it past a surveillance camera. The detection software logged nothing. Learn more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
bitdefender.com
An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate...
2173
Graham Cluley @grahamcluley.com · 17/08/2026
Nice one!
000
Graham Cluley @grahamcluley.com · 16/08/2026
A growing number of UK venues have decided to act against privacy-busting smart glasses. Hear that? It's the sound of the world's smallest violin playing for people who wear Meta Smart Glasses... www.bitdefender.com/en-us/blog/h...
bitdefender.com
Meta's Ray-Bans are being banned from pubs, restaurants, and theatres
I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.
3121
Graham Cluley @grahamcluley.com · 14/08/2026
Thanks - looks interesting!
000
Graham Cluley @grahamcluley.com · 14/08/2026
Join me and the experts at Proofpoint in a webinar, looking at some of the real-world incidents every CISO should know about and what they tell us about protecting data in the age of AI. 📅 Monday 14th September ⏰ 11:00 BST Register here: grahamcluley.com/proofpoint
120
Graham Cluley @grahamcluley.com · 13/08/2026
Listen to the full podcast at www.smashingsecurity.com/480
011
Graham Cluley @grahamcluley.com · 13/08/2026
Poison Claude!!! Would you trust it? Was great to have self-confessed skinflint Northerner Lianne Potter join me on the latest "Smashing Security" podcast. Hear more in episode 480 of the "Smashing Security" podcast. Find it in all good podcast apps, or at link in comments...
282
Graham Cluley @grahamcluley.com · 07/08/2026
@majnouna.com is the breakout star of Hamster! A fascinating listen. Can she be on every week? :)
130
Graham Cluley @grahamcluley.com · 07/08/2026
Would you accept 90% off the cost of accessing Anthropic's AI? With "Poison Claude" you pay with cryptocurrency, get a cheap API key, and off you go. But there's a catch: every prompt you type, every document you share, every API key or password you paste in, goes through their servers first.
fortra.com
Beware Cut-Price AI Services that Read Your Every Word | Fortra
Learn how cut-price AI services like Poison Claude exploit cloud credits, expose sensitive prompts, and create serious data security risks for businesses.
151