Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
GRAHAM CLULEY
You can access their cryptocurrency if you know those 24 words. They said, is it possible that the hackers have managed to get that for you?
And I said, I think that's really unlikely because I haven't been dumb enough to paste it in anywhere. I have it securely. No, it's not tattooed on my buttocks or anything like that.
DANNY PALMER
Yeah, it's just on the bottom of your website.
Unknown
Smashing Security, episode 479. How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.
Hello, hello, and welcome to Smashing Security, episode 479. My name's Graham Cluley.
DANNY PALMER
And I'm Danny Palmer.
GRAHAM CLULEY
Now, Danny, I've had a little bit of a run-in with, well, maybe with cybercriminals. I'm not sure. Let me tell you something which happened to me just a few days ago.
DANNY PALMER
Pray tell.
GRAHAM CLULEY
I got a phone call from somebody out of the blue, and I thought, I know that phone number. It said 0800 555 111, which is the number of Crimestoppers, of course.
Not that I'm regularly calling up.
DANNY PALMER
Not that you're regularly involved with crime or crime stopping, pans on anyway.
GRAHAM CLULEY
Not that I'm regularly the victim of crime. But anyway, this call came through and it said Crimestoppers. Oh, okay.
So anyway, I took the call and this chap started speaking to me who sounded very much like he could work for the law.
He could be a — and he introduced himself and said he was some sort of detective or something.
DANNY PALMER
Did he sound like Gene Hunt or someone like that?
GRAHAM CLULEY
No, not as obvious as that. No sort of Ashes to Ashes or Life on Mars connection. But no, he said his name was Dave Pullen.
Hello, this is Detective David Pullen here at the Crime Stoppers organisation. And he said he was working on a computer crime case.
And he says, don't be alarmed, he says, you haven't done anything wrong, he said. And he put me at my ease that I wasn't in any trouble myself.
But he said, maybe you can help me with an investigation.
And I thought, well, maybe I can, you know, because I have helped the police before with some computer crime cases investigating various hacking groups.
And I thought, well, it's a little bit unorthodox, but okay, all right. So he wants to talk to me. And he said that they had arrested someone on suspicion of some cybercrimes.
And during the investigation of the digital evidence, they had found some information about me.
Unknown
Huh.
GRAHAM CLULEY
They had got my phone number and they'd got my personal email address. And he told me what that was and that was correct.
And he said, and we've also found a scan of your passport and other information as well. And I said, oh, that sounds bad. I said, tell me more.
DANNY PALMER
Yeah. You said, oh, this sounds not great.
GRAHAM CLULEY
No, it doesn't sound great, does it? And he told me the name of the chap who they'd arrested.
And I'm not going to name him here on the podcast because it's quite possible this person is completely innocent.
But he gave me the name of somebody and they said, do you know this person? I said, no, I don't know him.
He said, do you have any reason to think that he might have a vendetta against you? And I said, well, it is possible.
I said, without being big-headed, it is possible he knows me, but I don't know him.
DANNY PALMER
Don't you know who I am? You said—
GRAHAM CLULEY
I said, I didn't quite say, do you know who I am? But I've got a podcast, you know.
But I said, I've been working in cybersecurity for 35 years or whatever and, you know, have a certain prominence. So it is possible.
And I have received threats in the past from criminals. And so it is possible there's been some kind of breach.
And he said, well, have you shared your passport information with anyone?
And I said, well, you know how it is sometimes, you know, I go and give talks around the world and sometimes people are booking me flights and sometimes people do ask for your passport.
So much as I groan about it and grumble and how bloody hell, can this be allowed? And it shouldn't be. And I tried to ensure that they delete it afterwards.
It is possible that a scan of my passport is out there being held by somebody. So I said, yeah, well, it is possible they've got my passport. And they said, okay, all right.
And they said, well, he said you sent it to him because you were booking an Airbnb in Manchester. And I said, no, that's not true. I haven't booked an Airbnb in Manchester.
DANNY PALMER
Well-known tourist destination, Manchester.
GRAHAM CLULEY
Well, you know, I mean, I imagine some people might want an Airbnb. Anyway, I don't have a need for an Airbnb in Manchester.
DANNY PALMER
I believe our Prime Minister is from there.
GRAHAM CLULEY
He is?
DANNY PALMER
There's rumours of that I've heard anyway.
GRAHAM CLULEY
Likes to describe himself as King of the North, which I imagine is actually rather upsetting to all the people for whom Manchester is considerably south of.
Unknown
Yeah.
GRAHAM CLULEY
Anyway, he likes to say that. So they said, okay, well, that's interesting.
They said, now, the other thing is that we have found some evidence that he had collected some information on people who own Trezor hardware wallets, which you can use to store your cryptocurrency on.
And hands up, I think I've spoken about it on the podcast before. I do have one of these hardware wallets for cryptocurrency. I bought it years and years and years ago.
I've only got a very small amount of cryptocurrency. If that weren't the case, then I wouldn't be doing a podcast.
Unknown
Yeah.
GRAHAM CLULEY
But, you know, I do have one of these wallet things and cybercriminals have found out that I've got one of these. I think at some point the Trezor mailing list was compromised.
Maybe they were using a third party for their newsletters or something.
Maybe it was like Mailchimp or something like that, because they know my email address because practically every day I get a phishing email claiming to come from Trezor, right?
Asking me to do things. And it's like, oh, here we go again.
Unknown
You know.
DANNY PALMER
Persistent, I suppose. There's that at least they've got going for them.
GRAHAM CLULEY
Right. So I thought, okay, it is quite possible that criminals know that I have one of these wallets.
And so he said to me, not only do they know that you have one of these wallets, they also have a 24-word seed key, which of course is the magic combination of words required to unlock someone's wallet so you can access their cryptocurrency if you know those 24 words, right?
They said, is it possible that the hackers have managed to get that for you? Because he appears to have a document which suggests that he's got it.
And I said, I think that's really unlikely, because I haven't been dumb enough to paste it in anywhere. You know, I have it securely.
No, it's not tattooed on my buttocks or anything like that.
Unknown
Yeah.
DANNY PALMER
It's just on the bottom of your website.
GRAHAM CLULEY
No, no, it's not. Right. So it's a secret. And he said, okay, okay. He said, but if your cryptocurrency were compromised, would that make you suffer a significant financial loss?
Unknown
Hmm.
GRAHAM CLULEY
And I said, no, it wouldn't because I've hardly got any cryptocurrency. You know, it's really not very much at all. And he sounded a bit disappointed at that point.
And then he said, well, do you have any other cryptocurrency? And I thought, this is all getting a bit strange.
DANNY PALMER
Yeah, this policeman's very interested in the contents of your wallet.
GRAHAM CLULEY
And particularly how much I might have in my cryptocurrency wallet. And so I said to him, I said, can you give me your name again?
And he gave me his name and I quickly had a little look, and sure enough, there he was on LinkedIn and he does appear to work for the police. Thought, interesting.
And I thought, he wouldn't be ringing from Crime Stoppers, would he?
And he said, can you go to a police station within the next 24 hours and take a look at the photograph of the person we've taken into custody to see if you recognise him for any reason?
Unknown
Hmm.
GRAHAM CLULEY
I said, all right, okay, I could do that. And he said, just head to the main reception desk. And he gave me a crime reference number. And I said, oh, I can go somewhere tomorrow.
I said, I can go to a particular place.
DANNY PALMER
Did they know which police station you'd have to go to?
GRAHAM CLULEY
And this was curious. So he said, is there a police station near you that you can go to? And I thought, I don't want to reveal where I live precisely.
So I gave the name of a town where I didn't live, where I knew there wasn't an open police office or department. And he says, okay. He says, I've just booked you in.
So you can go there, go up to the reception desk, quote this number. And he didn't ask me what county I lived in, for instance.
I just named a place and I thought, wouldn't you ask for some more information?
Anyway, so I began to ask him some questions, whereupon the phone cut off and I thought, that's strange.
And I looked in my email and there was an email claiming to come from the Metropolitan Police telling me that if I did not act upon their email, then potentially action could be taken against me because they said, you have to help us with this criminal.
So there's the email saying you've potentially been a victim of crime.
DANNY PALMER
If you don't help us investigate this crime, you are a criminal as well.
GRAHAM CLULEY
Potentially, yes. They could take action against me. And I looked in the headers of the email and although it had forged the headers, there was information in there.
If you look in the raw header information, it was clear it had come from somewhere else. And I thought, ooh, this is getting quite juicy.
And by this point, of course, I'm really kicking myself because I wish I had said, I've got 4 million quid in my cryptocurrency wallet and wait for them to try and inveigle out of me my 24-word seed key, which surely was the thing that they're gonna do.
So they're gonna say, well, can you read it out to us and we'll compare that to the one we have on our records? I think that was the plan.
I tried to call Crime Stoppers because I thought, well, their phone number's been forged. Couldn't get through to them. Just disaster.
Contacted Action Fraud, which is the thing you are told to do. I don't know what your experience has been reporting crimes to Action Fraud.
They've rather blotted their copybook over the years. They're not the most efficient.
Anyway, utterly unimpressed by their response, which was unhelpful because I shared all the email information and so forth and they just said, well, there's nothing here for us to investigate.
Unknown
Oh.
GRAHAM CLULEY
There is stuff here because presumably this person is going through a list of people who they know has Trezor cryptocurrency wallets on the phone, claiming to be the police and trying, I imagine, to get their seed keys out of them.
I did my best, Danny. I did my best. So that has been my unusual experience over the last few days. Once again, I've failed to become a victim of cybercrime.
DANNY PALMER
Whoever the individual or group behind this is, they're putting a lot of effort into this with the time it takes to do the phone calls, the research, that sort of thing.
I mean, they've left some holes in their plan, but yeah, this doesn't sound like it's some sort of amateur operation.
This is a group which seems to have a targeted goal to get this particular account using the information of this particular provider.
So they've got access to that and they're basically going down the list to try and get what they can from people.
GRAHAM CLULEY
It's possible they could — maybe they thought that would be a scalp, which would cause them some amusement.
It felt a little bit like Scattered Spider's tactics of ringing up customer service desks.
DANNY PALMER
Yes.
GRAHAM CLULEY
I mean, this guy did sound — you know how policemen have a certain timbre? I mean, it sounded like that. You know, it wasn't like, hello, yeah, I am Chief Inspector Morse.
It wasn't like that. You know, it was—
DANNY PALMER
It wasn't 3 12-year-olds in a big coat, no.
GRAHAM CLULEY
Anyway, before we kick off, let's thank this week's wonderful sponsors. Arctic Wolf, NordLayer, and Vanta. We'll be hearing more about them later on in the podcast.
This week on Smashing Security. We won't be talking about how people's Claude chats are turning up in Google search results.
You'll hear no discussion of how Iranian hackers are being blamed for a multi-state cyberattack on US water systems, although Donald Trump is blaming the Democrats.
And we won't even mention how Google Maps allowed anyone for one whole day to fake satellite images of nuclear plants and floods before quietly pulling the feature.
So Danny, what are you going to be talking about this week?
DANNY PALMER
I'm going to be talking a bit about quite a major attack on the Department for Education and how this relates to schools and universities and why they've become prime targets for hackers.
GRAHAM CLULEY
And I'm gonna be checking into a hotel where I'll be having rats with my cornflakes.
Unknown
Charming.
GRAHAM CLULEY
All this and much more coming up in this episode of Smashing Security.
Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.
Unknown
We've got a question for you. What's the thing that keeps you staring at the ceiling at 2 AM when it comes to your company security?
GRAHAM CLULEY
Is it wondering whether you've actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?
Why on earth are we still running our entire security programme out of a spreadsheet?
Unknown
If any of that hit a little too close to home, that's where Vanta comes in.
Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.
GRAHAM CLULEY
Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place, and keeps your security programme audit-ready around the clock.
Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.
The upshot of this is you move faster, scale without the usual headaches, and maybe, just, just maybe, actually get a decent night's sleep.
Unknown
Sounds lush. Find out more and get started at vanta.com/smashing.
GRAHAM CLULEY
That's Vanta.com/smashing. And a big thank you to Vanta for supporting the show. So, chums, you're travelling for work. We've all done it, right? Travel for work. You've had a long day.
Maybe it's been a lengthy trip and you finally made it to your hotel and you dump your bag on the bed, you kick off your shoes, you've opened your laptop.
First thing you're doing, priority number one, connect to the Wi-Fi. And you know how it is connecting to a hotel network.
Normally a little page will pop up asking you, can you confirm your room number? And sometimes they'd ask you for your surname as well.
And you accept their terms and conditions that you're not gonna do anything naughty on the Wi-Fi. And hopefully you're then online. It's fairly painless these days.
I think most hotels have made it a lot easier than it used to be maybe 10 or 15 years ago.
DANNY PALMER
Yeah, we're long past the point of where you have to go through about 5 different websites to get online and pay £20 for the privilege of an hour of internet, as it used to be back then.
GRAHAM CLULEY
So, you know, the job's done.
Except according to security boffins who say for the last few months at least, there is a chance that something else has been happening to travellers logging into their hotel Wi-Fi.
Russia's Foreign Intelligence Service, the SVR, they run a hacking group variously known as APT29, Midnight Blizzard, or Cozy Bear.
They are behind some of the biggest hacks of the last 10 years, including the SolarWinds supply chain attack, the hack of Microsoft's own corporate email, the breach at Hewlett-Packard Enterprise.
So these aren't script kiddies. These are serious cybercriminals with the backing of the Kremlin, professional spies funded by the Russian state.
And apparently they have gone on holiday. Apparently they could be at your local hostel.
DANNY PALMER
Interesting.
GRAHAM CLULEY
Microsoft researchers have called this campaign Captive Crunch. And I have to say, that really tickled me. Why would Captive Crunch tickle me, Danny?
What's your hacking history knowledge?
DANNY PALMER
Sounds very similar to a well-known breakfast cereal.
Unknown
Yes.
GRAHAM CLULEY
So in America, I don't know if it's sold here in the UK as well, there is of course the Captain Crunch breakfast cereal. And famously, it was the name of a hacker.
Who I think took the name because he used to freak the phone system by—
DANNY PALMER
Of course, yes.
GRAHAM CLULEY
Using the little whistle they gave away as a giveaway in a packet of Captain Crunch. That's way back when, decades and decades ago.
DANNY PALMER
Yeah.
GRAHAM CLULEY
Frankly, I'm very impressed at Microsoft. This is probably the best piece of branding their marketing department has done in years, calling this Captive Crunch.
Someone definitely deserves a pay rise. This attack takes advantage of captive portals, which are the pages that help you to log into hotel Wi-Fi.
So when your laptop joins a hotel network via Wi-Fi, it asks the network, where is everything, right? I've joined.
DANNY PALMER
Yeah.
GRAHAM CLULEY
Where can I find stuff? Because I want to go to Google, I want to go to Netflix or iPlayer or whatever it is you want to do.
And one of the things that the network provides is a phone book for the internet, which is the DNS, the Domain Name System, right?
Unknown
Yes.
DANNY PALMER
And it's not quite as hefty as Yellow Pages, but—
GRAHAM CLULEY
Right. And this is the thing which translates your entry into your browser of microsoft.com into a sequence of numbers. Websites are actually at numbers, IP addresses.
You don't remember those, so you remember names instead. So you go to microsoft.com or smashingsecurity.com instead.
The point is though, if you connect to someone else's Wi-Fi network, your computer or phone trusts that network's DNS to give it the right answer, not to transmogrify microsoft.com, for instance, into the wrong sequence of numbers.
Because if that were to happen, your browser would be taken to a website and in the browser bar it would still say microsoft.com.
Unknown
Yeah.
GRAHAM CLULEY
But it would actually be on a different server instead, because you could be phished, malware could be downloaded, you may hand over important credentials.
DANNY PALMER
Yeah, I presume anyone doing this isn't doing it for no particular reason. They have malicious, nefarious goals for doing this.
GRAHAM CLULEY
Yes, it's absolute mischief-making. And so what these Russian hackers have done in this case is they've got into systems that run the hotel or conference centre Wi-Fi networks.
And once they're in there, they mess with the DNS for every single guest simultaneously. So there's no need to touch anyone's individual devices.
There's no need to send any phishing emails. You, the guest, connect to the hotel Wi-Fi.
Your laptop gets pointed at servers controlled by the hackers rather than the one which you intended to actually access instead.
DANNY PALMER
That seems very economical of them. Phishing can be a lot of effort if you go around individuals.
Well, you're saying here, by doing what they're doing, they can get everyone within the hotel, which could be hundreds or maybe thousands of people depending on the size of it.
So are they doing this remotely or is there someone looking suspicious in the cafe on a laptop?
GRAHAM CLULEY
I think this is being done on such a scale that there isn't someone lurking in the ice cream parlour of the hotel.
The boffins at ReliaQuest, they say they have found this at hotels in multiple US cities.
Unknown
Mm-hmm.
GRAHAM CLULEY
And internationally in Saudi Arabia and India, collecting information from diplomats, government employees, people who work in financial services, legal firms, healthcare, energy, all kinds of people, anyone who travels for work.
DANNY PALMER
So they're not just after holidaymakers, they're going specifically for venues and hotels around them, which are known to be hubs for particularly large events and conferences.
GRAHAM CLULEY
I think so. I think they're thinking that's where the juicy information is rather than the flea pit.
DANNY PALMER
Hmm, interesting.
GRAHAM CLULEY
On the dark side of town. They're looking for people who either have money or they have information which would be useful.
Now you might think, well, this is fine, that's not a problem. I'll just hardcode Google's DNS server, which is 8.8.8.8, into my device.
I will bypass whatever DNS the hotel gives me.
But because your DNS request from your phone or from your laptop still leaves your computer as plain readable traffic, the Wi-Fi gateway can intercept it.
Unknown
Yeah.
GRAHAM CLULEY
Never will go anywhere near Google's DNS. So you ask for Google's opinion, but in fact you get the hacker's answer instead.
Unknown
Huh.
GRAHAM CLULEY
So this is really bad.
DANNY PALMER
It does sound bad. I'll be honest, Graham. It does.
Unknown
Yeah.
GRAHAM CLULEY
Because you can type in the correct URL of a website, you can choose it from your bookmarks and you'll be taken to a phishing site instead, or your software will be downloading a malicious update maybe.
And it will still look like in the URL bar that you're on the real site. So that would be bad enough, but there's worse.
Oh, because it turns out some of the victims have also been hit by ClickFix attacks. Now, we talked a little bit about ClickFix last week.
DANNY PALMER
Yes, our friend ClickFix.
GRAHAM CLULEY
There's such a wave of these ClickFix things, aren't there?
Anyone who hasn't already heard, just to very quickly describe it, it's where you have a popup or something asking you maybe to confirm that you're a human or to fix a technical problem.
Will you press this sequence of keys, which normally involves Windows+R on your Windows computer. Yeah.
DANNY PALMER
Can you open this on your desktop and paste this code we've conveniently placed in here? Don't ask us what the code is, but just paste it in.
GRAHAM CLULEY
Because you're effectively hacking your computer on behalf of the hackers by running a malicious piece of script.
DANNY PALMER
But because you are doing it, your computer isn't gonna go, oh, hang on, what's going on here? So, oh, it's the operator, the usual user doing this.
So there's no need to question that. Carry on.
GRAHAM CLULEY
And if you fall for that, you've just installed something called Cornflake. Another great name.
DANNY PALMER
Another cereal, then.
GRAHAM CLULEY
This is a Windows remote access Trojan that logs your keystrokes, which means they've got your passwords. It takes screenshots, records your microphone, your webcam.
I mean, what could possibly go wrong in the privacy of your hotel room if your webcam and your microphone are being recorded?
Steals passwords from your browser as well, exfiltrates files. Gives hackers remote access to your computer. And it does all this while disguising itself.
It claims to be a Windows service called Cloud Sync Service. Very sort of generic.
DANNY PALMER
Well, that sounds suitably boring for me to not care about what that is doing on my laptop.
GRAHAM CLULEY
Yeah, it just claims to be a service which is needed to synchronise files with your cloud storage provider.
So people are going to run that, particularly if they're working remotely. They probably want to connect to their cloud storage provider.
Many people think that's innocuous, and so they think there can't be anything dodgy with that. And you might think, well, wouldn't my antivirus spot that? Well, it might.
DANNY PALMER
Yes.
GRAHAM CLULEY
But this Cornflake thing is very good at maintaining persistence. It's a little bit like a dried cornflake on the bottom of your crockery, right?
You can't necessarily easily get rid of it. So if your antivirus removes it, or you try to remove it manually, it puts itself back.
DANNY PALMER
That's always the tricksy thing with these. I always find interesting about malware and Trojans.
Some of them are so clever, you do everything you want to get rid of it, then it's still — you close your front door, then you turn around and it's there standing right behind you again.
GRAHAM CLULEY
And it doesn't stop there. Running alongside Cornflake is a PowerShell info stealer. Do you want to have any guesses, Danny, as to what this one is called?
DANNY PALMER
Oh, Rice Krispies, Weetos, Red Brick, Shredded Wheat.
GRAHAM CLULEY
This is ChocoShell, apparently. ChocoShell steals your —
DANNY PALMER
That sounds like one of those off-brand ones you get at the discount supermarkets.
Unknown
That's it.
GRAHAM CLULEY
It's not Coco Pops.
It's ChocoShell, which steals your Microsoft 365 session tokens, which means if you've got multifactor authentication in place, as you should do, on your Microsoft 365 account, the hackers can still access it using your session token.
And all of this is overseen by a control panel, another piece of software, Fruitstone. Frankly, that doesn't sound that appetising to me.
DANNY PALMER
I think they're running out of ideas now in terms of — so the people who've named these, is it Microsoft who've named these or is it the criminals who've named these this way?
GRAHAM CLULEY
I think it's Microsoft again.
DANNY PALMER
I think it's the engineers there and at Reliant. It's what they get for breakfast when they turn up in the mornings at Redmond.
GRAHAM CLULEY
I think they can't be offering a decent breakfast to the technicians working at these security companies. That is my only explanation.
Fruitstone claims to be something called Cloud Sync Console by a fictional company called Acuity Systems Inc. It's designed to look utterly boring.
DANNY PALMER
As I said, yeah, you can see the offices of this fake company now because I'm seeing a lot of grey. A lot of beige. I'm getting very 1990s vibes from it.
GRAHAM CLULEY
So they don't want to draw attention to themselves. So what can you, dear listener, do about this?
Well, the single most effective thing, if you are a business, if you manage corporate devices, is to enforce the use of a full tunnel VPN.
So it's not the kind of VPN where DNS can sort of sneak out round the edges, but it's properly full tunnel.
All traffic, including DNS requests, goes through your corporate network before it goes anywhere else. Okay. So you're not paying any attention to what the hotel is saying to you.
DANNY PALMER
Hmm.
GRAHAM CLULEY
So if you can do that, that's a great defence.
DANNY PALMER
Okay. For businesses, yes. I struggle to get people I know to even use 2FA or a password that isn't the word password.
Well, maybe not to that extent, but sometimes solutions, because they can be perceived as so complex, people go, ooh, that sounds too complicated.
And they're unfortunately left open to things like this, I suppose.
GRAHAM CLULEY
So there is some advice for individuals as well. You maybe don't have that business solution. What you can do, of course, is you could use your mobile phone as a hotspot.
You could treat hotel Wi-Fi as something to be avoided. If you must use hotel Wi-Fi, you can use a VPN that will give you some protection.
Using a VPN is better than not using a VPN, but don't install anything.
Or if you get one of those click fix messages, if the captive portal asks you to install a driver or if it asks you to cut and paste something, you know, run to the hills effectively.
If there's anything like that.
DANNY PALMER
I don't think my hotels tend to ask me to install something on my computer when I get there.
GRAHAM CLULEY
No.
DANNY PALMER
That's some sound advice.
GRAHAM CLULEY
So next time you're sitting in the hotel room hooking up to the Wi-Fi, just bear in mind you might not be the only one. Getting connected, it could be the hackers as well.
Unknown
This week's episode is supported by NordLayer.
GRAHAM CLULEY
NordLayer. And before anyone says anything, no, it's not NordVPN.
Unknown
I wasn't gonna say that.
GRAHAM CLULEY
You were absolutely going to say that, Joe. They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals.
NordLayer is a network security platform built for businesses.
Unknown
Right, so what does NordLayer actually do?
GRAHAM CLULEY
Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.
Unknown
From a sun lounger, hopefully.
GRAHAM CLULEY
You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem. Credentials intercepted, phishing attacks, unauthorised access.
It's a scary world out there for travelling workers.
Unknown
So NordLayer fixes that.
GRAHAM CLULEY
It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second with zero additional hardware required.
But it goes well beyond just encrypting the connection.
You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.
And if someone leaves the company, you revoke their access immediately.
Unknown
No more ex-employees still wandering around your systems 6 months later.
GRAHAM CLULEY
No more of that. And it will block malicious sites, risky downloads, dangerous domains. And it can even detect shadow apps.
So if someone on your team has started using some AI tool that your security team hasn't approved—
Unknown
I'd never do that.
GRAHAM CLULEY
Yeah, well, whatever. NordLayer can spot that too. And there's no complex infrastructure to set up. Apparently, you can be up and running in just about 10 minutes.
Unknown
10 minutes?
GRAHAM CLULEY
10 minutes. Plans start from just $8 per user per month. And right now, there is a summer sale. New customers get up to 20% off annual plans until the end of August 2026.
Use the code NLSUMMER26 at checkout.
Unknown
Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.
GRAHAM CLULEY
Yep, go ahead, write it down.
Unknown
What's the code again? I forgot.
GRAHAM CLULEY
Oh, Joe, NLSUMMER26.
Unknown
Got it. Off to nordlayer.com/smashing I go.
GRAHAM CLULEY
And thanks to NordLayer for supporting the show. Danny, what's your story for us this week?
DANNY PALMER
Well, Graham, it's been a long time since I was at school, and I dunno how much has changed for sure, though I'm pretty sure that laptops and other internet-connected devices are much more commonplace than they were back when I was at school, when the computers were restricted to basically one room in the entire building.
So this was, oh yeah, late '90s, early noughties. Just pre-internet age. The only sort of connected devices, if you can call them that, we had back then was a Tamagotchi.
That was about the most virtual distraction you could get in class pre-smartphone, which not astounds me, but kids these days, he says, sounding like a very old man, they grow up with, you know, internet-connected devices, smartphones, that sort of thing, which we'll get onto in a moment.
But back to school, as it were.
Unknown
Yeah.
DANNY PALMER
I'm sure that even the best, most student-friendly teacher now or back then would prefer to keep their students at arm's length.
As far as I know, you don't call your teacher by your first name.
GRAHAM CLULEY
I thought you meant like a personal hygiene issue.
DANNY PALMER
Well, that's also bad. But anyway, I digress. But they'll be Mr. Smith or Ms. Jones. You won't really know your teacher's first name. And I suppose Mr. Smith or Ms.
Jones would like to keep it that way. They would not want their information out there for nosy students to find out, 'cause, you know, it's the summer holidays right now.
Kids need stuff to do, and, you know, kids like to find mischief, as far as I understand.
GRAHAM CLULEY
Yes.
DANNY PALMER
Well, unfortunately for thousands of teachers and headteachers, they have had their names, job titles, and email addresses, and in some cases, phone numbers stolen in a hack, and the crooks behind it have threatened to leak it.
So imagine, for most people, having your personal data stolen is an annoyance, but for a teacher to have their contact details leaked, there's probably some pranksters, ne'er-do-wells who might be tempted to use that for the wrong reasons.
GRAHAM CLULEY
You can imagine.
DANNY PALMER
Some kids don't like being taught by teachers, I believe.
But anyway, this is all potential worry, comes back to the UK government's Department for Education, for England specifically, 'cause I believe, you know, Scotland, Wales, Northern Ireland devolved out, which according to the Times revealed recently that hackers had obtained over 600,000 records in a cyberattack.
Now, the use of the word records is important here. It isn't the number of individuals which have been affected by the incident.
No, there aren't hundreds of thousands of teachers which have been affected by that. So I imagine if it was, that's basically every teacher in the country.
Unknown
Yeah.
DANNY PALMER
But the lines of data which have been stolen in a hack against the Department for Education's help desk portal.
The information on how this attack occurred is still not fully publicly out there, but there seem to be suggestions that it is like you experienced, Graham, sort of social engineering to try and get sort of usernames, passwords, that sort of thing for this help desk portal.
But fortunately for those affected, the theft isn't thought to include bank details or sensitive personal information. So there is that at least.
I don't imagine you want little Jimmy Scrackett, let's say, getting their hands on teachers' bank details, because I'm sure that would be pretty bad. So that's good at least.
So that might be a result of the Department for Education, which said the attack was contained quickly.
So whatever action it had taken, it reduced the amount of data which was accessed and stolen. So thumbs up there. It seems like this attack was spotted fairly swiftly.
It hasn't been going on for a long, long time, we think.
So as any organisation which falls victim to a cyber incident would do, they have got the likes of the National Cyber Security Centre and the National Crime Agency involved.
GRAHAM CLULEY
So those are other arms of the government essentially helping this one investigate.
Are you saying the resources of those investigatory bodies were more preoccupied with 600,000 records of teachers being stolen than they were in me receiving a funny phone call from someone claiming to be a copper?
DANNY PALMER
That's a good point, Graham. Maybe they were.
GRAHAM CLULEY
Have they got their priorities right? I have to ask.
DANNY PALMER
I suppose they might be closer to each other than they are to your house because they ought to be in Whitehall.
They can just walk around the corner to go have a chat, while with you, they'd have to sort of go somewhere else. If it's closer, we'll deal with it. If it isn't, nah, maybe not.
Interestingly though, as a side note, as well as the teachers, there are reports that this incident has also involved details of some police as well, which have been involved as well.
So whole different thing here, but all related to the same incident, which for the government, for the Department for Education, it's likely to be considered something of an embarrassment because it is a major part of the government.
It's been hit by a cyberattack, which is, you know, considering the government, as previously mentioned, government bodies very vocal about the threat of cyberattacks and cyber risk, for them to be targeted by one is, well, probably not unexpected because governments are likely a big scalp, but having been hit by one takes a little bit of explaining, I imagine.
So who is behind this attack?
Well, it's been reported that the culprit is a previously unknown hacking group, which calls itself Exfil Squad, which have been posting snippets of stolen data on their leak site.
There's, again, information about these is patchy, but they sound kind of similar to your Scattered Spider type operation where it seems they've got together to do this, to make money, to cause trouble.
And make money is what they want to do here because according to the Guardian newspaper, these hackers have demanded a payment from the Department of Education not to publish the whole vast swathes of the 600,000 bits of data they have stolen.
GRAHAM CLULEY
It's a familiar story of pay the ransom, otherwise we're going to publish the data which we've stolen from your servers.
DANNY PALMER
Exactly. You know, it's essentially like ransomware tactics, but as appears to be increasingly common for extortion groups, they cut out the middleman, middle software.
The ransomware element of it. They don't encrypt your files. They just go in, steal it, and say, we have it, now pay us.
Which I guess for the attackers takes less time because you're not having to sort of slowly move your way around the network to encrypt everything you need, and probably a bit less effort on their part.
Reproduced in full under licence from Graham Cluley. © Graham Cluley. Written by Graham Cluley.
Coverage
One outlet has carried this so far.
2026-08-05 23:10 UTC
Related stories
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- The true cost of a ransomware attack, with and without BCDR
BleepingComputer · 2026-09-16
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News · 2026-09-16
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
The Hacker News · 2026-09-15
- Hackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer · 2026-09-15