Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

LowGraham Cluley · Graham Cluley·

At a glance

Severity
Low
Used in attacks
No flaws named
Reported by
1 outlet

GRAHAM CLULEY

He takes his gun and he sort of shoots the word leek, L-E-E-K. I apologise to any English teachers who are listening to this, into a wall as if to prove it really is him.

PAUL DUCKLIN

Leek is a legitimate word. I mean, it's a type of onion. What's wrong with that?

GRAHAM CLULEY

Well, I suppose so.

PAUL DUCKLIN

I mean, Cyber Onion wouldn't sound great, but Cyber Leek—

GRAHAM CLULEY

It wouldn't be so good.

PAUL DUCKLIN

It is a pun, Graham, whether you approve of it or not.

Unknown

Smashing Security, episode 482.

PAUL DUCKLIN

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

Unknown

Hello, hello, and welcome to Smashing Security, episode 482. My name's Graham Cluley.

PAUL DUCKLIN

And I am Paul Ducklin. Hello, Duck.

GRAHAM CLULEY

Great to have you back on the show again.

PAUL DUCKLIN

Thank you, Graham.

GRAHAM CLULEY

We parachuted you in this week actually, 'cause that person we were intending to come on hasn't managed. Not that you are by any means a pale substitute.

PAUL DUCKLIN

I'm not pale at all these days. We've had so much sunshine.

GRAHAM CLULEY

No, that's true.

PAUL DUCKLIN

As you can see, I've had a bit too much lately, if those of us who can see me on video.

GRAHAM CLULEY

Well, it's always great to have you here. Before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, BlackKite, and Vanta.

We'll be hearing more about them later on in the podcast. This week on Smashing Security. We're not gonna be talking about how Iranian hackers managed to shut down a UK power plant.

PAUL DUCKLIN

You'll hear no discussion of—

GRAHAM CLULEY

How a ransomware crook silently ripped off his own gang by posing as a recovery firm and pocketed the victims' payments for himself.

And we won't even mention how the Toxic Panda Trojan is quietly taking over Android phones to steal banking PINs and passwords.

Now, Duck, what are you going to be talking about this week?

PAUL DUCKLIN

Well, Graham, if your smart TV isn't spying on you, what else might it be doing behind your back?

GRAHAM CLULEY

And the tyres are going to be hitting the tarmac as I enter the world of Grand Theft Auto 6. All this and much more coming up in this episode of Smashing Security.

JOE

This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.

GRAHAM CLULEY

That's right. We've seen research into autonomous ransomware, adaptive AI worms, and agents chaining tools without waiting for a human operator.

JOE

Which is all very interesting, just so long as it isn't your network they're experimenting on.

GRAHAM CLULEY

When enumeration, exploitation, and lateral movement happen at machine speed, relying on somebody to notice an alert and respond quickly begins to look rather optimistic.

Well, ThreatLocker puts default deny and least privilege between the agent and its next action.

So application allowlisting controls execution, ring-fencing restricts what trusted applications can access or launch, and privileged access management removes unnecessary elevation.

JOE

The attacker may be moving faster, but the controls are already in place. Agentic AI doesn't make established security principles obsolete.

It makes getting them right considerably more urgent.

GRAHAM CLULEY

So make sure that you are prepared for machine speed attacks with ThreatLocker. Visit threatlocker.com/smashing today to learn more and schedule your free demo.

JOE

That's threatlocker.com/smashing. And thanks to ThreatLocker for supporting the show.

GRAHAM CLULEY

Now, chums, Grand Theft Auto. It's one of the most successful entertainment products ever made. Duck, have you ever played Grand Theft Auto?

PAUL DUCKLIN

No, because when I had my own grand theft bicycle from outside my own flat—

GRAHAM CLULEY

Yes.

PAUL DUCKLIN

That was enough to convince me that this is not a laughing matter, Graham.

GRAHAM CLULEY

No, no, not a laughing matter.

PAUL DUCKLIN

I mean, it's more than a year ago. I'm almost over it now.

GRAHAM CLULEY

I've never played Grand Theft Auto.

PAUL DUCKLIN

I've seen it.

GRAHAM CLULEY

Yes, exactly. I've seen it. I've looked over people's shoulders while they're playing it, and it does seem very impressive. It's a huge, open-world game.

It's all about a life of crime. It has earned over $8 billion — billion with a B — since it launched in 2013. It's made more cash than any Hollywood movie.

It's still being played by millions of people more than a decade later. And that's really a testament to how much people love this game.

And also, it really, I think, underlines how desperate people are now, some 13 years later, for a sneak peek of its sequel, which is GTA 6.

It is gonna be finally released, they promise, this November.

Well, Thursday this week — actually the day that this episode airs at 3:00 PM Eastern time — amongst much hoopla, Netflix will be exclusively premiering a first look of GTA 6's gameplay ahead of its official release.

So I think the preview will be up for about 24 hours or something.

PAUL DUCKLIN

Will you be able to play it or will you just be able to watch players zooming around?

GRAHAM CLULEY

I really don't know, because I do believe it is possible these days to play games via Netflix.

Maybe younger listeners would be able to educate us as to whether that's possible or not. At the very least, I'm sure there'll be videos to watch of it.

And people are very excited about this because it'll be their first chance to see GTA 6. No, it won't. No, it won't, because someone has beaten them to it.

A hacker or a group, no one's quite sure. A hacker called Cyberleek has started to drop—

PAUL DUCKLIN

Cyberleek. I bet that name took months to think up.

GRAHAM CLULEY

Well, you may laugh, Duck, at their particular moniker, but they're going to be putting out clips of what is one of the world's most closely guarded pieces of software.

So they've been putting out video clips of game characters driving around the streets of Grand Theft Auto.

They've been swimming, they've been visiting strip clubs, they've been tasering each other.

Unknown

Swimming?

GRAHAM CLULEY

Yes, you can swim in these games.

PAUL DUCKLIN

It's aquatic car.

GRAHAM CLULEY

Not everything happens in a car. You really haven't played this, have you?

PAUL DUCKLIN

I said I hadn't.

GRAHAM CLULEY

You can fly planes and helicopters. You can go down zip wires. You can walk around. You can go into buildings. There's a lot of effing and jeffing as well.

There's a lot of very bad language.

PAUL DUCKLIN

So how did they get hold of this if it's so $8 billion worth protected?

GRAHAM CLULEY

Well, we don't know. We don't know how this has happened. Some people have been questioning, well, is it really footage of the game because the game hasn't come out yet?

Or is it someone who's taken some other footage which may have leaked out in the past? Because there have been other leaks which have come from GTA and Rockstar Games before.

At one point, what Cyberleek actually does in this clip which he shows, he shows himself, or rather his in-game character, evading the police.

And then he takes his gun and he sort of shoots the word leek, L-E-E-K — I apologise to any English teachers who are listening to this — into a wall as if to prove it really is him playing it.

PAUL DUCKLIN

Leek is a legitimate word. I mean, it's a type of onion. What's wrong with that?

GRAHAM CLULEY

Well, I suppose so.

PAUL DUCKLIN

I mean, CyberOnion wouldn't sound great, but Cyberleek—

GRAHAM CLULEY

It wouldn't be so good.

PAUL DUCKLIN

It is a pun, Graham. Whether you approve of it or not.

GRAHAM CLULEY

Okay, that's true. That is true.

Now, this would normally be a story of a hacker breaking into a company and the company, you know, sort of saying, oh, that's terribly embarrassing, and scrambling around to sort of fix the damage afterwards.

PAUL DUCKLIN

We take your security seriously, blah, blah, blah.

GRAHAM CLULEY

Exactly that kind of thing. And that's obviously part of the story, but there is more to it because Cyberleeks didn't just want attention.

It appears that they also wanted cash, but not through extortion, which you would expect, you know, Grand Theft Auto and Rockstar Games wallowing around in cash.

PAUL DUCKLIN

Oh, you mean saying Rockstar, pay us money and we'll shut the whole leak down?

GRAHAM CLULEY

There's that. But what they have done in this particular case is the hacker has launched their own cryptocurrency, which they have dubbed rather unimaginatively—

PAUL DUCKLIN

Let me guess.

GRAHAM CLULEY

Cyberleek.

Unknown

Yes. Oh.

GRAHAM CLULEY

Yes. Sorry, I ruined your fun.

So they created their own cryptocurrency called Cyberleek, and they announced that every time someone buys or sells some Cyberleek cryptocurrency, obviously Cyberleek, the hacker, they're gonna get a cut of the trading fees because of how they've set it up, right?

So they've set it up on Solana, I think is where they've got it.

And to incentivise you to buy and sell Cyberleek cryptocurrency, they've said that if the market capital of the Cyberleeks cryptocurrency hits $3 million, they will release a clip from inside the Grand Theft Auto strip club.

Unknown

Oh dear.

GRAHAM CLULEY

Sure enough, within 24 hours, the market capital did hit $3 million and the clip was released from that part of the game.

And this was all to the hackers' financial advantage because they're getting some of the money.

They're not only getting a cut of the trading fees, but apparently they also have something like 27% of all of the Cyberleek cryptocurrency themselves anyway.

So if the price of Cyberleek, the crypto, goes up, that's more money in their pocket.

PAUL DUCKLIN

So how did they prove that it really is a leak from the game and not just some blurry AI-generated variant of something that was in a previous issue?

GRAHAM CLULEY

It's difficult to prove when no one has really seen it. But what has happened is Rockstar Games have launched DMCA takedown requests.

They're subpoenaing, if I could say that, subpoenaing. Am I saying that correctly? It's too difficult for me.

Unknown

Yes.

PAUL DUCKLIN

Subpoena means under penalty if you don't do it, literally.

Unknown

Right.

GRAHAM CLULEY

Okay. They're doing that, Duck, to Microsoft and Discord.

They're trying to get this information taken down and they're trying to grab the information as to who the hacker is as well, because there's an Xbox link.

I think there's also been some email addresses. There's been setting up of websites as well.

The hacker claims, they said, look, 'cause some people online, you can imagine what a fervent community there is who are really into Grand Theft Auto.

PAUL DUCKLIN

We're talking about people who spent $3 million in 24 hours to see a virtual strip club?

GRAHAM CLULEY

Yes. And so to defend themselves, Cyberleek, the hacker, has said that they've spent about $29,000 setting up their website.

Well, I mean, for goodness' sake, they could have done it more cheap than that, but also the cryptocurrency in the first place.

And they said that within a couple of days they made about $50,000 just from the trading fees. So they have been making money.

PAUL DUCKLIN

That's without the 27% of the holdings, right, getting boosted.

GRAHAM CLULEY

So people have been looking at this cryptocurrency. It turns out the hacker hasn't sold any of their cryptocurrency themselves.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

And many people are speculating that they've done this because the heat was rising in the community and maybe from law enforcement as well.

And they're sort of worried that, hang on, maybe what I did wasn't quite as cool and groovy as I imagined.

PAUL DUCKLIN

Oh, so they're worried that their own fans may turn on them for pump and dump slash rug pulling.

GRAHAM CLULEY

Oh, exactly. Because the price went up. And of course, if they did actually sell their cryptocurrency, such a big chunk of it, the price is gonna go down.

These videos, by the way, they all contain the QR code, which will take you to Cyberleek's website where you can go and get the cryptocurrency.

So they appear to have destroyed — that's their word, at least — their entire stake worth something like $1.4 million of Cyberleek crypto.

I mean, frankly, is there anything legitimate which is ever happening with cryptocurrency? It does appear that the default is either crime or just some extreme shadiness.

PAUL DUCKLIN

Well, I suppose that fits the whole Grand Theft Auto theme, right? You know, lighting cigars with $1,000 bills. Stuff like that.

GRAHAM CLULEY

So the question is, why have they done this? And so, as I said, there's been lots of accusations that the whole Cyberleek thing was some kind of marketing scheme.

This was all about boosting the price of the cryptocurrency. According to the hacker, they weren't in it for the money.

And instead what they said was they were trying to lobby for Rockstar Games to release GTA on a physical disc rather than making it only available via download.

PAUL DUCKLIN

It seems that ripping it off before it's released, while it's supposedly vigorously protected online but isn't, is not a good way to convince the company.

Now also put it on a CD where I can take it away and study it infinitely at my leisure. That seems to be more specious than I didn't intend to make money.

I mean, okay, apart from the fact that they've done the breach.

GRAHAM CLULEY

Yes.

PAUL DUCKLIN

If you've got this thing like it's fallen into your hands, plenty of journalists use leaked data to write stories and then take payment for it.

GRAHAM CLULEY

Yep.

PAUL DUCKLIN

And the websites they write for take paid ads on those pages. Is it actually fraudulent to say, here's what the game looks like. I'm not saying how I got this.

I'm not saying I got it illegally. Like, if you like it, pay me a fee.

I mean, I don't like the sound of it, but is it actually as devious as selling someone a VPN they don't need that won't work? Yeah, it's an open question, isn't it?

GRAHAM CLULEY

I see your point. I mean, the breach, clearly that is quite clear. Computer Misuse Act legislation is being broken in order to steal the data, maybe passing it on.

PAUL DUCKLIN

But no one knows how it happened yet, right?

GRAHAM CLULEY

No, no.

And inevitably you've got to wonder, I don't think this is the case, but you have to wonder, is this to the benefit of Grand Theft Auto overall because it gives them even more headlines?

I'm sure they'd want to manage properly their launch, but—

PAUL DUCKLIN

We're engrossed in the story now. We don't even play the game. So you've always got to ask that, haven't you?

GRAHAM CLULEY

It's a strange world. Anyway, it does seem to me, I'm pretty convinced that the hacker was interested in making some money out of this cryptocurrency.

And certainly they were launching and they were promoting the cryptocurrency before they released any of the images, before they started talking about the physical disc, which they wanted Rockstar Games to distribute the game on.

PAUL DUCKLIN

Oh, you think that might be a story they had up their sleeve just in case?

GRAHAM CLULEY

Another way in which they appear to have tried to monetise the leaks was their website had a contact page which offered paid advertising slots, so you could actually advertise on their website.

And you could also request specific clips of gameplay footage.

They were saying, for instance, if you pay them 400 Monero, which is a type of cryptocurrency worth about $160,000, you would have, I don't know, images of the submarines or strippers on the submarines or whatever it is that would be your particular niche.

PAUL DUCKLIN

I guess that's a bit worrying because there, they're openly offering, we've got this stuff which we know we are not supposed to have 'cause it's covered by copyright.

We're offering to sell it to you privately.

Advertising on their site, that's one thing, but hey, we'll sell you somebody else's intellectual property is, well, you're going up against Rockstar North, right?

GRAHAM CLULEY

One of the things I found funny was on the website where they were saying that you can buy ads and things.

They said, look, they're perfectly happy with gambling ads and they're perfectly happy with adult content, but they didn't want any scam ads.

So if you were a scammer, you weren't allowed to advertise on their site. He's got some standards. I think you'll agree with that. Clearly Rockstar Games aren't happy.

They are asking for information from some internet companies, trying to identify who may be responsible. And also there's the cryptocurrency lead as well.

So to set up his cryptocurrency little operation, Cyberleeks had to use a vendor that requested a government-issued ID.

Unknown

Hmm.

GRAHAM CLULEY

Normally, if you create yourself an account on one of these sites, they'll ask you for a scan of your passport or your driving licence or something like that.

But it does mean that sometimes law enforcement can be successful. They don't necessarily need to break encryption.

They don't need to necessarily deanonymise a cryptocurrency wallet in order to get information about you. They may just have to go to a company and get your ID.

PAUL DUCKLIN

And as we know from recent leaks and busts, there are often things embedded in your data and your traffic, say if you're using a Windows computer, that will reasonably well identify you, even if you're going through 17 different VPNs to try and anonymise yourself.

GRAHAM CLULEY

And you have to bear in mind as well that many criminals, of course, if they're faced with a website which says you have to confirm your ID, they'll use a stolen or forged ID.

PAUL DUCKLIN

There is that.

GRAHAM CLULEY

But, you know, hackers screw up. Don't they sometimes, and accidentally reveal their true identities? Poor old Rockstar Games.

It's sort of put a little bit of a blemish on the announcement which they're making this week with their trailer launch on Netflix.

It's not the first time, of course, they've had trouble with the Grand Theft Auto games.

PAUL DUCKLIN

Yes, they've been breached before, haven't they?

GRAHAM CLULEY

They have.

PAUL DUCKLIN

So maybe they actually figure, you know what, how bad was it last time? It's so bad that everyone's been excited about this new game for four years.

It's almost as though they can't lose.

GRAHAM CLULEY

I mean, they've spent so long writing this game. It's been going on for like 13 years or whatever. It's absolutely astonishing.

PAUL DUCKLIN

Imagine if you'd spent that long on Jacaranda Jim, Graham. Jacaranda Jim version 42 by now.

GRAHAM CLULEY

It is practically at version 42, the number of bug fixes I had to do with that.

But yeah, back in 2022, a teenager who was a member of the Lapsus$ hacking group broke into Rockstar Games and leaked 90 videos of Grand Theft Auto 6, obviously an early development version of the game.

He was caught by the cops and they obviously didn't want him to do any hacking while he was on bail.

And they shoved him into a hotel and said, look, you're not allowed to go on the internet.

It later turned out that he did manage to get on the internet, and even though he didn't have a computer or anything like that, he managed to exploit the Amazon Fire TV stick plugged into the back of a TV in order to get online.

In that particular breach, Rockstar claimed that they had lost $5 million to that particular individual, who I think is still being held.

PAUL DUCKLIN

Yes, they were found unfit to stand trial, I think. Yes.

GRAHAM CLULEY

So what is clear is that GTA 6 is enormously anticipated by people. It's an enormously valuable piece of intellectual property as well.

But it's a company which doesn't seem to really know how people are breaking in. I mean, that's actually the most important thing of all, isn't it?

What is being done to prevent these hacks from happening and to make sure that it doesn't happen again?

JOE

Graham, what's this about a new report from one of our sponsors?

GRAHAM CLULEY

Yes, BlackKite have just put out their first ever European Cyber Risk Report.

And oh my goodness, they've been looking into ransomware attacks across Europe for the last year and a half or so.

JOE

And let me guess, everything is fine and we have nothing to worry about?

GRAHAM CLULEY

Well, ransomware is up 55% year on year in the first 4 months of 2026 alone.

JOE

So not fine.

GRAHAM CLULEY

No, Joe, not fine at all. Nearly 70% of all European ransomware activity is concentrated in just 5 countries.

And this report from BlackKite breaks down exactly where the attacks are hitting hardest and which hacking groups are responsible.

JOE

So is there anything in there beyond the headline numbers?

GRAHAM CLULEY

The bit that really struck me is what they found about third-party risks. A lot of companies aren't being attacked directly.

Instead, they're being caught in the blast radius of an attack on one of their suppliers.

JOE

Right. You're only as secure as the weakest link in your supply chain.

GRAHAM CLULEY

And the report has some real-world examples that illustrate this perfectly. For instance, there's a Swedish company, it has an unpronounceable name.

They got hit and that ended up causing huge problems at hundreds of organisations, exposing the data of over a million people.

JOE

All from one incident.

GRAHAM CLULEY

All from one incident. And the report also covers how regulations like NIS2 and DORA are forcing European businesses to get much more serious about all of this.

JOE

Sounds like essential reading, frankly.

GRAHAM CLULEY

It is, and it's free. Get the full report at blackkite.com/smashing.

JOE

That's BlackKite, B-L-A-C-K-K-I-T-E.com/smashing. And thanks to BlackKite for supporting the show.

GRAHAM CLULEY

Duck, what's your story for us this week?

PAUL DUCKLIN

Well, I thought that I would talk about residential proxies.

Unknown

Okay.

PAUL DUCKLIN

Because I suspect that many Smashing Security listeners have probably seen it in the context of the cybersecurity media writing up terrible malware stories.

And it seems that we've adopted that word even though it sounds fairly neutral and it's not actually clear what it means.

And therefore it can't possibly be clear how you'd know whether you had one of these. And if you did, was it good, bad, or indifferent?

And if it was bad, what on earth would you do about it?

GRAHAM CLULEY

Okay, let's get back to basics. So what is a residential proxy?

PAUL DUCKLIN

Well, I guess we have to start by digging into what do we understand by the word proxy?

Unknown

Okay.

PAUL DUCKLIN

It's something that does something lawfully on your behalf. Quite a neutral idea.

So in network terms, that term was borrowed as a metaphor to refer to a computer service, like say a web server, that instead of actually being the web server you want to visit, you visit the proxy and you tell the proxy what you want to access.

And the proxy goes and fetches the content and gives it back to you.

And originally the idea of that was all supposed to be a great idea to have a gateway proxy or a company proxy, because it means that firstly, the company can limit the sites that you go to, if they're legally obliged to protect you from gambling sites or porn sites in work hours by forcing you to use a proxy, it means the proxy can go, no, you can't go there.

You can't go there. Oh, that site's got malware on it. You can't go there.

GRAHAM CLULEY

Okay.

PAUL DUCKLIN

Also, it can speed things up because if 72 people want to go and look at the cricket score, wouldn't it be nice if the proxy had already got that and it figured, oh, I'll speed things up, I'll feed it back to the other 71 people.

GRAHAM CLULEY

Right.

PAUL DUCKLIN

So the idea of having a proxy to do network services was that it was good for performance, good for security, good for bandwidth limiting, and something that companies would routinely do.

So obviously you could use it for bad.

If you had a proxy that you snuck onto a company network that people didn't know was there, they might go to one search engine and end up being fed results from another.

So you can use proxies for bad as well. But in general, as a term, it's neutral. So that leads us to the point, well, what do we mean by a residential proxy?

GRAHAM CLULEY

Yes.

PAUL DUCKLIN

And the answer is loosely, when we say a residential proxy, it's exactly the same technology that happens to be on a home network.

And then that leads to the question, why on earth would anyone install one of those? Well, I have what I would call a residential proxy at home.

GRAHAM CLULEY

Okay.

PAUL DUCKLIN

I've set it up for myself on a small server of my own.

And the idea is then when I'm on the road, whether I'm out of the country or just in the coffee shop, let's say I want to do something like online banking or I want to pay an electricity bill and I want them to see that I'm coming from my usual location.

I can connect securely using SSH back to my home network and then I can go out on the internet.

And in fact, in browsers like Firefox and Chromium, you can go in and say, use a proxy, and you can explicitly say, I want to use this particular proxy.

So obviously Google and Firefox think it's a good idea to have proxies.

GRAHAM CLULEY

Yeah.

PAUL DUCKLIN

And there's no legal reason why you're not allowed to run one at home. So why has residential proxy become conflated with, oh, terrible malware attack?

And that, Graham, is where the story gets both devious and interesting at the same time.

GRAHAM CLULEY

All right. Okay. So explain it.

PAUL DUCKLIN

Well, obviously people might want to install a residential proxy like the one I have that they chose to install, where they chose the software and they decide who gets to use it and when it runs and when it doesn't.

But what if you could be lured into installing exactly the same sort of software, not on your laptop, where if it goes rogue, your antivirus or your EDR software might detect it and block it.

GRAHAM CLULEY

Yeah.

PAUL DUCKLIN

But on something that you generally don't really think of as a general purpose computer, even though secretly internally it is, like your smart TV or even your home router or a home thermostat or some Internet of Things device that's inside your network.

GRAHAM CLULEY

And it's not only inside your network, it may also be plugged in permanently.

So it may be constantly connected to the internet, whereas your laptop, you know, you shut it, you turn it off, and it can't be abused in that way.

PAUL DUCKLIN

Well, generally, if it's your smart TV, even when it goes into sort of suspend mode, it's still there.

And you'd expect it to go online to download updates and security patches and notifications for the TV programs coming up that you're interested in.

So you kind of expect your smart TV to be online.

And especially if we move away from smart TVs for a moment, the thing that really is on all the time and in theory has all the bandwidth it can possibly have is your home router.

The thing that sits between you and the internet.

GRAHAM CLULEY

Yes.

PAUL DUCKLIN

And even worse for many people, that home router is not theirs.

GRAHAM CLULEY

No.

PAUL DUCKLIN

When they sign up with the ISP, it arrives in the mail and it just says, plug it in. But it is not your router. It belongs to the ISP. You can't modify it. You can't reflash it.

You can't run your own software. Even if there were such a thing, you would not be allowed to install an antivirus on it to scan for rogue software.

And the one thing you can be sure with your router, it has all the bandwidth at its disposal all the time because that is its job.

GRAHAM CLULEY

You're absolutely right. They don't want you meddling too much with your router because that's going to create tech support problems for them, isn't it?

For their customer service department.

PAUL DUCKLIN

Yeah. The router that I got from my ISP, untouchable. I understand why.

They want to try and make it resilient to things like rogue, unexpected residential proxies and other malware being injected onto it.

And they want it to stop you messing with it and authorising access in ways that they don't like. So you're right.

Not only is it difficult to meddle with it, the idea is that you cannot. And even if you were to find a way to hack it, it's probably against the terms and conditions of service.

And if they find that out, A, they can cut you off, or B, they'll just push out a firmware update and undo all your changes.

GRAHAM CLULEY

Now, Doug, I can understand why you might want to install a residential proxy on a Raspberry Pi or on a router or something like that, but why would you want to put one on your smart TV?

If you were a regular homeowner, what would be the thinking behind that?

PAUL DUCKLIN

Well, that is the $64 question, isn't it? And there are lots of different answers to that.

One is that there is allegedly a legitimate market for these so-called residential proxies where you agree to install this software, maybe in return for free content, maybe in return for some modest discount against some other service.

Maybe even in return for money that gets paid to you in some way for installing this on your smart TV.

GRAHAM CLULEY

Right.

PAUL DUCKLIN

And in return, you allow this basically VPN for other people outside your network to borrow your internet connection while you're asleep.

But you don't get to choose who those people are, and you don't necessarily know that much about the company you've entered into this agreement with for installing the software.

You're getting some nebulous benefit. Oh, you get free games or you get access to some TV channel or other.

GRAHAM CLULEY

Yeah, I know some people, not me. I know I'm saying friends of mine, but it really isn't me.

I know people who have got these dodgy sticks plugged into their TVs, which give them, for instance, access to Premier Football matches or something without paying a subscription.

Or maybe it gives them access, I don't know, to some of the streaming services.

PAUL DUCKLIN

Oh, so it's a USB stick with an app on it and you plug it in.

GRAHAM CLULEY

Yeah.

PAUL DUCKLIN

And some of these TVs, they'll come with their own application store.

And even Apple's much-vaunted App Store and Google Play, if you have an Android-based smart TV, even they get poisoned by malware, even though they're supposed to have protection on.

Right?

Unknown

Right.

PAUL DUCKLIN

So you get someone offering, oh, well, you don't need to burn this onto a USB stick and then plug it in.

Basically, you just install our app and it will provide fun games that your kids can play free, or it's got these fantastic games that your kids can play. It's $3 a month.

But if you turn on this super special option that allows us to share your internet connection when you are not using it, unquote, then you won't have to pay the $3 a month, something like that.

GRAHAM CLULEY

So it could be the case that you're installing an app onto, for instance, a smart TV which has terms and conditions.

Maybe this is mentioned in the terms and conditions, maybe it's not.

It could be that you are buying from some dodgy website, something to circumvent Netflix or Apple TV in order to give you access to the latest streaming TV shows.

And you may be unknowingly opening a residential proxy. So who wants to use a residential proxy?

I can understand that people may have them, may even not know that they are operating inside their home, but who are the people actually exploiting it and using it?

What are they doing with them?

PAUL DUCKLIN

Well, if you look at the very many, at least claiming to be legitimate residential proxies, and there are non-dark websites that actually help you choose the best residential proxy provider, you know, top 24 residential proxy services of 2026.

And they really do list 24 of them. It's not just clickbait. Well, it is clickbait, but they list all these services.

And one of the things that I think that supposedly legitimate companies claim they want to do with this is things like online surveys, web scraping.

So they want to maybe look through competitors' websites, and maybe they want to be able to do it from 20 different people in a night and see if they get different results.

GRAHAM CLULEY

Hmm.

PAUL DUCKLIN

Maybe they don't want to get caught out.

Maybe they want to see, hey, this competitor of mine, what are their special offers of the day in England, Scotland, Wales, Ireland, Netherlands, Belgium, etc., etc.

So there are all sorts of quasi-legitimate reasons why you might just want to buy service from somebody else, right? In the same way that you buy a VPN service. Yes.

Which we can come back to in a minute. Yes. Because that's the dodgy side of how you might get one of these.

GRAHAM CLULEY

Let's talk about that in just a moment. So the parallel which I would draw to this is it's a bit like a botnet.

Where a botnet, which is launching maybe a distributed denial of service attack—

PAUL DUCKLIN

You could, if you like, leave the word "a bit" out of that sentence if you really wanted.

GRAHAM CLULEY

Yes. It's like a botnet.

PAUL DUCKLIN

You could leave the word "like" out of that sentence if you really like.

GRAHAM CLULEY

It's a botnet because you end up with lots of computers which aren't yours. Whether they be on TVs or routers or fridges or thermostats or who knows what.

PAUL DUCKLIN

That somebody else is selling to somebody else who's selling to somebody else to do whatever they want with off your network, with your IP number, from your household, in your name, basically.

GRAHAM CLULEY

Yes. So this is the thing. It's distributed because normally they would have to do that from their own computers, which would maybe be easy to block or maybe be easy to identify.

But suddenly this is happening from lots and lots of people's home addresses. Absolutely.

PAUL DUCKLIN

And just think how much money you can make in ad click fraud if you are paying somebody else for access to 1,000, 10,000, 100,000.

And some of these residential proxy networks apparently number into the millions.

Unknown

Wow.

PAUL DUCKLIN

Believe it or not, imagine that you can make 1 million ad clicks in a legitimate way from computers all over one particular country, all over the world, that are coming effectively from residential networks.

So as far as the person receiving the ad click, it couldn't look more legit.

Unknown

Hmm.

PAUL DUCKLIN

It's not like 1,000, 10,000, 1 million clicks coming from one massive ISP site. It's not a special private server that they set up yesterday in the cloud.

It's basically just, hey, look at this.

And you could time the clicks so that they seem legitimate and you could follow them up with visits that look as though the person then clicked through from the ad to further action and all sorts of stuff.

And that's before you've actually stolen anything.

GRAHAM CLULEY

So where do VPNs come into all of this?

PAUL DUCKLIN

Well, in one famous case, the residential proxy, essentially cybercrime VPN, the one that the provider rented out to cybercriminals around the world, was actually embedded in, irony of ironies, a VPN that they were selling.

Unknown

Oh.

PAUL DUCKLIN

So they provided an actual VPN. It was an open source VPN that they'd taken the source code and just modified it. And it had all these super extra cool features.

And you paid a fee so they actually earned money and it did actually work.

And irony of ironies, if you use this VPN on all of the computers on your home network, all of your traffic, wherever you did, whether you were a crook or not, would appear to come from somewhere else.

And the only traffic that did come from your home network would be traffic that had come from crooks who'd bought the service the other way around.

And from the person who sold you the VPN in the first place, if you don't mind. Put that in your pipe of irony and smoke it. Absolutely crazy.

GRAHAM CLULEY

Should our listeners be worried about this?

Reproduced in full under licence from Graham Cluley. © Graham Cluley. Written by Graham Cluley.

Coverage

One outlet has carried this so far.

  1. Graham CluleyEstablished SourceFirst reported

    2026-08-26 23:10 UTC

Related stories