Graham Cluley
banner
grahamcluley.com
Graham Cluley
@grahamcluley.com
Award-winning #cybersecurity keynote speaker, writer, podcaster | Host of multi-award-winning @smashingsecurity.com podcast.

❤️ #DoctorWho, #Beatles, #Chess

He/him

🌐 https://grahamcluley.com
🎙️ https://www.smashingsecurity.com
If, like me, you were a teenage boy in the mid-1980s you quite possibly remember Kelly LeBrock in the movie "Weird Science"...

How could we resist getting into computers after that!?

Anyway, this and much more discussed in episode 485 of "Smashing Security" podcast with special guest Lianne Potter
September 18, 2026 at 3:07 PM
A supertanker carrying 2.3 million barrels of crude oil crossed the Atlantic. Hackers allegedly slipped past its defences - messing with fuel systems, engine speed, and knocking out communications for 30 hours.

Read more in my article on the Bitdefender blog. www.bitdefender.com/en-us/blog/h...
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.
www.bitdefender.com
September 17, 2026 at 2:47 PM
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison.

That should be plenty of time for him to rue the day he agreed to help a SIM swap gang in their attempt to steal over half a million dollars.
Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.
www.bitdefender.com
September 15, 2026 at 9:46 AM
Reposted by Graham Cluley
Here is the setting you need to turn off if you don't want a human potentially reading through your ChatGPT conversations. I've seen some of the prompts; these ChatGPT users clearly have no idea a human is reading www.404media.co/inside-proje...
September 14, 2026 at 4:24 PM
Reposted by Graham Cluley
a great letter in the times today.

perhaps worth sharing in these troubled times.

#RNLI #heroes
September 13, 2026 at 2:01 PM
Reposted by Graham Cluley
Just for once, I’d like to see one of these super-rich crypto bros handing over £36 million to Great Ormond Street, or cancer research, or food banks and housing charities, because they want to make the world a better place and help its most vulnerable people. But instead…?
September 12, 2026 at 4:38 PM
Reposted by Graham Cluley
Get in, folks: a new Russian disinfo campaign is targeting the midterms, specifically Democrats, in what seems to be the first attempt by the Kremlin-backed op to meddle in this year’s U.S. elections. They're faking celebrity videos attacking Dems and are...very stupid.

www.ms.now/news/russia-...
A Russian disinformation campaign is doctoring celebrity videos to meddle in the midterms
The Kremlin-backed operation, known as Matryoshka, has Hollywood actors telling voters to disavow the Democratic Party and vote Republican.
www.ms.now
September 11, 2026 at 8:06 PM
Reposted by Graham Cluley
I'm sure lots of other people have said this, but if I worked for a company on a product that I thought had a >10% chance of killing all humans within the next decade and we had no plan for how to stop it, I would quit and devote myself full time to destroying this product.
Meanwhile on X, from Evan Hubinger, who leads the Alignment Science team at Anthropic.
September 10, 2026 at 10:40 PM
In the latest "Smashing Security" podcast, "Five Eyes" intelligence agencies (not Five Guys 🍔) have published fresh advice on how firms should talk to the public after a breach.

Their message in short? "please, for the love of God, stop calling every hack 'sophisticated'"
September 10, 2026 at 6:12 PM
Here's a tip for any budding cybercriminals out there.

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub....
'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here's a tip for any budding cybercriminals out there.
www.bitdefender.com
September 10, 2026 at 1:45 PM
Excited to announce that I will be delivering the keynote at CYBER ROOT in Malta , discussing how your AI employee could be your biggest risk...

Other great speakers on the line-up include BBC News's @joetidy.bsky.social and people hacker @jennyradcliffe.bsky.social.

ncc-mita.gov.mt/cyberroot/
September 10, 2026 at 1:21 PM
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.

Find out what you need to know about it in my article on the Fortra blog.
CRPx0 Ransomware: What You Need to Know | Fortra
Learn how CRPx0 ransomware works, how it spreads through ClickFix attacks, and what organizations can do to defend against ransomware threats.
www.fortra.com
September 9, 2026 at 8:44 AM
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours.

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
The US military just turned off ad tracking on its phones. Maybe you should too
Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target America...
www.bitdefender.com
September 8, 2026 at 3:35 PM
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts.

Read all about it in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.
www.bitdefender.com
September 7, 2026 at 10:36 AM
On the latest episode of the "Smashing Security" podcast I was joined by @jamesrball.com who took a step back from the stories of AI "going rogue" and and asked the awkward question: is this really an emergent AI apocalypse, or were AI firms just lousy at security?
September 3, 2026 at 4:57 PM
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls...

Cver a single four-week period, 75% of all scam crime reports police have received have involved Revolut accounts...

www.bitdefender.com/en-us/blog/h...
Revolut scam steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.
www.bitdefender.com
September 2, 2026 at 4:32 PM
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm... Two men are now facing charges over TeamPCP's global supply-chain hacking spree.

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more
Police have charged two men from Western Australia over their alleged involvement in TeamPCP, a cybercriminal gang that has been blamed for a massive software supply-chain hacking campaign.
www.bitdefender.com
August 28, 2026 at 10:26 AM
On the latest episode of "Smashing Security", Paul Ducklin and I take an extended look at the GTA 6 CyberLeek debacle... and the scourge of residential proxies.

Find it in all good podcast apps, or at grahamcluley.com/smashing-sec...
Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead…
grahamcluley.com
August 27, 2026 at 8:46 PM
The US Navy has told sailors and their families to scrub their social media, as adversaries are watching...

Read more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be usin...
www.bitdefender.com
August 27, 2026 at 12:46 PM
"Offside Wallet Theft Factory", a campaign involving scores of malicious Firefox browser extensions, has been running under the radar since at least March 2026 - stealing cryptocurrency seed keys and login credentials.

More details:
www.bitdefender.com/en-us/blog/h...
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sp...
www.bitdefender.com
August 24, 2026 at 3:16 PM
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more.

Read more in my article on the Fortra blog: www.fortra.com/blog/gunra-r...
Gunra Ransomware: What You Need to Know |Fortra
Gunra ransomware exploits unpatched VPNs and firewalls to steal and encrypt sensitive data. Learn how it attacks, whom it targets, and how to reduce risk.
www.fortra.com
August 24, 2026 at 12:57 PM
A group of security researchers took a robot dog, and jailbroke it by telling it that it was a Pokemon. And that wasn't the worst of it...

Hear Jenny Radcliffe join me on the "Smashing Security" podcast to discuss this, the theft of Mozart statuettes, and Andy Burnham being socially-engineered.
Never say this to a robot dog
Listen to Never say this to a robot dog from Smashing Security wherever you get your podcasts!
pod.link
August 20, 2026 at 3:47 PM
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume...

But what he did instead was turn to extortion.

www.bitdefender.com/en-us/blog/h...
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.
www.bitdefender.com
August 19, 2026 at 7:29 AM
A security researcher wrapped a car in an AI-generated pattern and drove it past a surveillance camera.

The detection software logged nothing.

Learn more in my article on the Bitdefender blog: www.bitdefender.com/en-us/blog/h...
An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate...
www.bitdefender.com
August 17, 2026 at 2:13 PM
A growing number of UK venues have decided to act against privacy-busting smart glasses.

Hear that? It's the sound of the world's smallest violin playing for people who wear Meta Smart Glasses...

www.bitdefender.com/en-us/blog/h...
Meta's Ray-Bans are being banned from pubs, restaurants, and theatres
I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.
www.bitdefender.com
August 16, 2026 at 7:36 PM