Smashing Security
Episodes
Russian heists and Ring wrongs
29 Jan 2020
Contributed by Lukas
Should possessing malware be illegal in itself? How did a Russian cryptocurrency exchange millionaire lose his fortune? And what on earth are Amazon R...
Robocalls, health hacks, and facial recognition fears
22 Jan 2020
Contributed by Lukas
A hospital gets hacked because of an ex-employee's grudge, robocalls are on the rise, and we share a scary story about the future of facial recogn...
Love, lucky dips, and 23andMe
15 Jan 2020
Contributed by Lukas
The man who hacked the UK National Lottery didn't end up a winner, Japanese Love hotel booking tool suffers a data breach, and just what is 23andM...
SNAFUs! MS Word, Amazon Ring, and TikTok
08 Jan 2020
Contributed by Lukas
We discuss how Microsoft Word helped trap a multi-million dollar fraudster, how Amazon Ring may be recording more than you're comfortable with, an...
Rap, robbery, and IoT holiday hell
18 Dec 2019
Contributed by Lukas
A rapping bank worker is accused of stealing from the vault, the devices that can hide your car's true mileage, and why it may be a case of "N...
The man behind The Missing Cryptoqueen
11 Dec 2019
Contributed by Lukas
We're joined by special guest Jamie Bartlett, of the chart-topping "The Missing Cryptoqueen" podcast, in this bumper episode where we disc...
A biometric knuckle duster
04 Dec 2019
Contributed by Lukas
What is Kaspersky's ugly ring for? Is there something suspicious about how NordVPN lets you stream Disney+? And why did a hacker impersonate a mu...
Better safe than Sony
27 Nov 2019
Contributed by Lukas
In this clip from a special bonus episode produced for our Patreon supporters, Graham Cluley and Carole Theriault discuss the 2014 hack of Sony Pictur...
Juice jacking, YouTube hacking, password slacking
20 Nov 2019
Contributed by Lukas
A bank has some of the worst password advice ever, travellers are told to be wary when USB charging their smartphones and laptops, and a gamer has his...
A buttock of biometrics
13 Nov 2019
Contributed by Lukas
The UK's Labour Party kicks off its election campaign with claims that it has suffered a sophisticated cyber-attack, Apple's credit card is a...
Cybercrime doesn’t pay (but Uber does)
06 Nov 2019
Contributed by Lukas
The cybercrime lovebirds who hijacked Washington DC's CCTV cameras in the run-up to Donald Trump's inauguration, the truffle-snuffling bankers...
Cats, hoodies, and rent
30 Oct 2019
Contributed by Lukas
What's the problem with IoT-enabled pet feeders? Can hacking ever be illustrated without a hoodie? And just how are landlords using smart home tec...
Frankly, sometimes paying the ransom is a good idea
23 Oct 2019
Contributed by Lukas
Remember how the City of Baltimore was badly hit by ransomware earlier this year? Turns out that wasn't the end of their problems. Also, Carole t...
Liverpool WAGs, Facebook politics, and a selfie stalker
16 Oct 2019
Contributed by Lukas
Footballers' wives go to war over Instagram leaks, it turns out fake news is fine on Facebook (just so long as it's in a political ad), and th...
Falling in love with fraudsters
09 Oct 2019
Contributed by Lukas
We take a trip to Staten Island, New York, to hear how a case of cyberstalking resulted in the arrest of 20 alleged mobsters, learn about the nude pho...
Billboard boobs, face forensics, and Alexa gets way too personal
02 Oct 2019
Contributed by Lukas
Drivers are distracted by a hacked billboard, we take a deeper look at how the deepfake problem has... uh... deepened, and Carole is less than happy a...
Don't Snapchat and drive
25 Sep 2019
Contributed by Lukas
How is private medical data leaking onto the streets of Milton Keynes, what is widening the cybersecurity skills gap, and how is Australia controversi...
Password secrets and baking brownies
18 Sep 2019
Contributed by Lukas
In the latest edition of the "Smashing Security" podcast, hosted by computer security veterans Graham Cluley and Carole Theriault, Carole has ...
Apple and Google willy wave while home assistants spy - DoH!
11 Sep 2019
Contributed by Lukas
Apple is furious with Google over iPhone hacking attacks against Uyghur Muslims in China, DNS-over-HTTPS is good for privacy but makes ISPs angry, and...
Google helps the FBI, Twitter Jack’s hijack, and car data woes
04 Sep 2019
Contributed by Lukas
Should Google really be helping the FBI with a bank robbery? What's the story behind the Twitter CEO claiming there's a bomb in their offices?...
Hacking from outer space, Ukrainian cryptomining, and deepfaked Canadians
28 Aug 2019
Contributed by Lukas
Was a cybercrime committed on the International Space Station? What on earth were Ukrainian scientists thinking when they plugged a nuclear power stat...
Mercedes secret sensors, smart cities, and ransomware runs riot
21 Aug 2019
Contributed by Lukas
Darknet Diaries host Jack Rhysider joins us to discuss how cities in Texas are being hit by a wave of ransomware, how Mercedes Benz has installed a tr...
Black Hat and Bridezillas
14 Aug 2019
Contributed by Lukas
Say cheese to ransomware on your camera! A sponsored speech at Black Hat causes uproar, and should you trust that Lightning cable you're about to ...
Love, PINs, and 8chan
07 Aug 2019
Contributed by Lukas
Is the PIN you use for your bank card secure? How did one woman get duped into giving a romance scammer $200,000? And Cloudflare and other online serv...
Capital One hacked, iMessage flaws, and anonymity my ass!
31 Jul 2019
Contributed by Lukas
Capital One gets hacked, critical vulnerabilities are found in iMessage, and data anonymization may not be as good as we hope. But listen up, we also...
Logic bombs, brain data exploitation, and Digga D tweets
24 Jul 2019
Contributed by Lukas
Logic bombs in Excel spreadsheets, how should we protect our brain data from big companies, and how did bizarre messages about Drill rap end up on the...
Porn trolling lawyers, Insta hacking, and Ctrl-Alt-LED
17 Jul 2019
Contributed by Lukas
Erection your honour! Lawyers find themselves behind bars after they make porn movies in an attempt to scam internet users, boffins in Israel detail a...
Oops, we created Iran's hacking exploit
10 Jul 2019
Contributed by Lukas
Mac users of the Zoom video conferencing app are warned their webcams could be hijacked, security firms warn of how scammers are deepfaking audio to s...
Zombie grannies and unintended leaks
03 Jul 2019
Contributed by Lukas
We take a bloodied baseball bat to Android malware, and debate the merits of a social media strike, as one of the team bites the bullet and buys a sma...
Sextortion, silicone face masks, and a DDoS doofus
26 Jun 2019
Contributed by Lukas
Scammers steal millions by impersonating a French politician, we offer fashion tips for DDoS attackers, and hear how a small town fought a sextortioni...
Cookie cock-ups, Hong Kong protests, and smart TV virus scans
19 Jun 2019
Contributed by Lukas
We head to Hong Kong to look at how technology has helped anti-government protesters (and how China has tried to disrupt it), Samsung is skittish over...
CBP cyber attack, an iPhone privacy boost, and Twitter list abuse
12 Jun 2019
Contributed by Lukas
United States Customs and Border Protection had sensitive data stolen, but the hackers didn't have to breach its network. Apple has ambitious plan...
Zap yourself from the net, and patch now against BlueKeep
05 Jun 2019
Contributed by Lukas
Microsoft issues warning to unpatched Windows users about worm risk, and how do you delete all traces of yourself off the internet after you murder yo...
Doctored videos, Bcc blunders, and a diva
30 May 2019
Contributed by Lukas
You won't believe who had to report themselves to the data protection agency for a breach, or who has been sharing doctored videos of political ri...
Too Long; Didn't Listen
22 May 2019
Contributed by Lukas
Don't hire a hacker, they might scam you! What works and what doesn't when it comes to protecting your email account? And China's controve...
Shackled ankles, photo scrapes, and SIM card swaps
15 May 2019
Contributed by Lukas
A bad software update causes big headaches for Dutch police, but brings temporary freedom to criminals. SIM swaps are in the news again as fraudsters...
I do love the Dutch
08 May 2019
Contributed by Lukas
Israel strikes back at Hamas's hacking HQ, a new sextortion email comes with a twist, and Carole saves the world with some help from hacked Roomba...
Zombie chickens and fast-food victims
01 May 2019
Contributed by Lukas
What's the worst that can happen if you join a Hollywood hard man's Facebook page? What drove a man to hijack a website's name at gunpoin...
Pick of the thief!
24 Apr 2019
Contributed by Lukas
WannaCry's "accidental hero" pleads guilty to malware charges, Samsung and Nokia have fingerprint fumbles, the NCSC publishes a list of 10...
Poisoned porn ads, the A word, and why why why Wipro?
17 Apr 2019
Contributed by Lukas
The hacker who lived the high life after spreading malware via porn sites, Wipro demonstrates how to turn a cybersecurity crisis into a PR disaster, a...
Backups - a necessary evil? (replay)
10 Apr 2019
Contributed by Lukas
With Graham incapacitated, we drag an episode out from the archives. In this special "splinter" episode of the "Smashing Security" po...
The big fat con at Office Depot
03 Apr 2019
Contributed by Lukas
Office Depot and OfficeMax are fined millions for tricking customers into thinking their computers were infected with malware, car alarms can make you...
Hijacked motel rooms, ASUS PCs, and leaky apps
27 Mar 2019
Contributed by Lukas
An app leaking private conversations and intimate photographs is ignoring requests to fix the problem, hackers poison a security update sent to ASUS P...
Silk Road with Deliveroo
20 Mar 2019
Contributed by Lukas
Online drug dealers get busted due to poor OPSEC! People are still failing to wipe their USB sticks properly! A potential presidential candidate is ou...
Hijacked homes, porn passports, and ransomware regret
13 Mar 2019
Contributed by Lukas
A $150 million mansion is hijacked online, Brits will soon have to scan their passport to watch internet porn, and are organisations right to pay up w...
The 's' in IoT stands for security
06 Mar 2019
Contributed by Lukas
Twerking robot assistants, an app from Saudi Arabia that lets men track women, and a gnarly skiing security snarl-up!Oh, and find out how a didgeridoo...
SWATs on a plane
27 Feb 2019
Contributed by Lukas
Why is Tampa's mayor tweeting about blowing up the airport? Are hackers trying to connect with you via LinkedIn? And has Maria succeeded in her at...
Stalking debtors, Facebook farce, and a cyber insurance snag
20 Feb 2019
Contributed by Lukas
How would you track someone who owed you money? What was the colossal flaw Facebook left on its website for anyone to exploit and hijack accounts? And...
Love, Nests, and is 2FA destroying the world?
13 Feb 2019
Contributed by Lukas
Is two factor authentication such a pain in the rear end that it's costing the economy millions? Do you feel safe having a Google Nest in your hom...
Darknet Diaries, death, and beauty apps
06 Feb 2019
Contributed by Lukas
Jack Rhysider from the "Darknet Diaries" podcast joins us to chat about his interview with the elusive Hacker Giraffe, how a death is preventi...
FaceTime, Facebook, faceplant
30 Jan 2019
Contributed by Lukas
A FaceTime bug allows callers to see and hear you before you answer the phone, Facebook's Nick Clegg tries to convince us the social network is ch...
Payroll scams, gold coin heists, web giants spanked
23 Jan 2019
Contributed by Lukas
Business email compromise evolves to target your company's payroll, how the world's largest gold coin was stolen from a Berlin museum, and are...
When rivals hack, and "extreme" baby monitors
16 Jan 2019
Contributed by Lukas
Why a business spat resulted in Liberia falling off the internet, how the US Government shutdown is impacting website security, and the perplexing wor...
What? You can get paid to leave Facebook?
09 Jan 2019
Contributed by Lukas
Twitter and the not-so-ethical hacking of celebrity accounts, study discovers how you can pay someone to quit Facebook for a year, and the millions of...
Grinches target Amazon and Reddit, stealing Christmas from the poor
19 Dec 2018
Contributed by Lukas
Join us for our special Christmas episode as we tell tales of printer hacking, website defacement, Grinches, and how Google is snooping on your privat...
Hoaxes, Huawei and chatbots - with Mikko Hyppönen
12 Dec 2018
Contributed by Lukas
The curious case of George Duke-Cohan, Huawei's CFO finds herself in hot water, and the crazy world of mobile phone mental health apps.All this an...
Sextorting the US army, and a Touch ID scam
05 Dec 2018
Contributed by Lukas
Fitness apps exploit TouchID through a sneaky user interface trick, tech giants claim to have a plan to banish passwords, and you won't believe wh...
Google Maps, Fed phishing, and Grinch bots
28 Nov 2018
Contributed by Lukas
How are scammers stealing your money through Google Maps? Why did the FBI create a fake FedEx website? And how are US senators hoping to stop Grinch b...
Facebook, Nietzsche, Tesla, and Nicole
21 Nov 2018
Contributed by Lukas
Tesla takes customer service a step too far, is it a romantic gesture or stalking when you email 246 women called Nicole, and Carole finds herself in ...
The world's most evil phishing test, and cyborgs in the workplace
14 Nov 2018
Contributed by Lukas
Does your employer want to turn you into a cyborg? Was this phishing test devised by an evil genius? And how did a cinema chain get scammed out of mil...
An Instagram nightmare, crazy iPhone deaths, and election hack claims
07 Nov 2018
Contributed by Lukas
One travel blogger finds you don't have to be Kylie Jenner to be targeted by an Instagram hacker. When 40 iPhones at a hospital mysteriously die, ...
Ethical dilemmas, Girl Scouts, and porn-loving US officials
31 Oct 2018
Contributed by Lukas
Who deserves to die in a driverless car crash? Who has been sniffing around the Girl Scouts' email account? And just how long would it take for a ...
Rule 34, Twitter scams, and Facebook fails
24 Oct 2018
Contributed by Lukas
A Facebook friend request leads to arrest, Twitter scams ride again via promoted ads, and adult websites expose their members. Oh, and Graham finds ou...
IoT failures, and Donald Trump dating disaster
17 Oct 2018
Contributed by Lukas
Yes, Smashing Security has reached its 100th episode!Despite our celebratory mood, we don't forget to take a look at the security stories of the l...
099: Passwords - A Smashing Security splinter (replay)
10 Oct 2018
Contributed by Lukas
With Carole in the wilds of Canada, and Graham knee-deep in a security conference in Glasgow, we drag an episode out from the archives of February 201...
098: A Facebook omnishambles
03 Oct 2018
Contributed by Lukas
Millions of Facebook user accounts put at risk after hack! The UK Conservative party's conference app causes a privacy omnishambles! And Facebook ...
097: Dash cam surveillance, robocall plague, and Zoho woe
26 Sep 2018
Contributed by Lukas
Why was Zoho's website taken offline by its own domain registrar? How are dash cams making you less secure? And why are robocalls on the rise in t...
096: Bribing Amazon staff, and blinking deepfakes
19 Sep 2018
Contributed by Lukas
Amazon staff are being bribed to delete negative reviews and leak data, deepfakes are getting more dangerous, an update on John McAfee's bitcoin b...
095: British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked
12 Sep 2018
Contributed by Lukas
Malicious script is being blamed for the British Airways hack, Trend Micro's apps are booted out of the Mac App Store for snaffling private data, ...
094: Rogue browser extensions, Twitter presence, and how to cheat in exams
05 Sep 2018
Contributed by Lukas
What's the danger when browser extensions go bad? Is Twitter sharing your online status a boon for stalkers? And which of the show's hosts is ...
093: Abandoned domains and dating app dangers
29 Aug 2018
Contributed by Lukas
How do fraudsters exploit abandoned domains to steal your company's secrets? How can you better protect your privacy when looking for love online?...
092: Hacky sack hack hack
22 Aug 2018
Contributed by Lukas
Is your used car still connected to its old owner? Just how did Apple manage to identify the teenager hacker who stole 90GB of the firm's files? A...
091: Sextortion, Las Vegas hotels, and Alex Jones
15 Aug 2018
Contributed by Lukas
Just how did sextortionists get (some) of the digits in your phone number? Why are some hackers saying they won't be going to DEF CON in Las Vegas...
090: Fortnite for Android, and the FCC's DDoS BS
08 Aug 2018
Contributed by Lukas
Fortnite players are told they'll have to disable a security setting on Android, the FCC finally admits that it wasn't hit by a DDoS attack, a...
089: Data breaches, ransomware, Bitcoin robberies, and typewriters
01 Aug 2018
Contributed by Lukas
Ransomware rears its head again, Dixons Carphone reveals its data breach was almost 1000% worse than they previously thought, a man is accused of stea...
088: PayPal’s Venmo app even makes your drug purchases public
25 Jul 2018
Contributed by Lukas
Websites still using HTTP are marked as "not secure" by Chrome, 85,000 Google employees haven't been phished for a year, and if you're...
087: How Russia hacked the US election
18 Jul 2018
Contributed by Lukas
Regardless of whether Donald Trump believes Russia hacked the Democrats in the run-up to the US Presidential election or not, we explain how they did ...
086: Elon Musk submarine scams and 2FA bypass
11 Jul 2018
Contributed by Lukas
The world has been gripped with the story of that soccer team, those poor boys... but enough about England's World Cup hopes being dashed, it'...
085: Doctor Who, Facebook patents, and Bob's Burgers
04 Jul 2018
Contributed by Lukas
Doctor Who's TARDIS has sprung a data leak, Facebook's creepy patents are unmasked, and an app to keep women safe on dates has surprising orig...
084: No! My voice is not my password
27 Jun 2018
Contributed by Lukas
Who's been collecting the voice prints of millions of people saying "My voice is my password"? Why has it become tougher for law enforceme...
083: Fake email derails clarinetist's dream
20 Jun 2018
Contributed by Lukas
Hell hath no fury like a jealous clarinetist's girlfriend! Your Google ChromeCast could be letting stalkers find out where you live! And why on ea...
082: World Cup cybersecurity, crypto crashes, and a bang of a password fail
13 Jun 2018
Contributed by Lukas
Coinrail cryptocurrency exchange goes offline after hack, Russia appears to be 'live testing' cyber attacks, and Florida stopped running backg...
081: Hacker no-hopers, Wessex Water has a word, and we win an award
06 Jun 2018
Contributed by Lukas
The mastermind behind the Owari botnet doesn't seem to have learnt anything from his victims, and someone at Wessex Water forgets to remove an emb...
080: Country bans Facebook, eavesdropping Alexa, and PornHub VPN
30 May 2018
Contributed by Lukas
The country of Papua New Guinea is planning a month-long nationwide ban of Facebook, PornHub wants to keep your online activities more private, and Am...
079: Mugshots, mobile mania, and backend gurus
23 May 2018
Contributed by Lukas
A website which demands money if you want your police mugshot removed, could "sharenting" lead to a rise in fraud and identity theft, and how ...
078: Hounds hunt hackers, too-human Google AI, and ethnic recognition tech - WTF?
16 May 2018
Contributed by Lukas
Dogs are trained to sniff out hackers' hard drives, facial recognition takes an ugly turn, and do you trust Google to book your hair appointment?A...
077: Why Paris Hilton doesn’t use iCloud, lottery hacking, and Facebook dating
09 May 2018
Contributed by Lukas
The tricky-to-pronounce Paytsar Bkhchadzhyan is jailed for hacking Paris Hilton, we hear the story of the man who hacked the lottery and almost got aw...
076: Spying phones, hacked ski lifts, and World Password Day
02 May 2018
Contributed by Lukas
Cheap Android smartphones sold on Amazon have been sending customers' full text messages to a Chinese server, ski lifts are found to be the latest...
075: Quitting Facebook
25 Apr 2018
Contributed by Lukas
Should you quit Facebook? How do you delete your Facebook account? What do you need to consider before leaving Facebook for good? And what's the e...
074: Smashing Security isn't bullsh*t
18 Apr 2018
Contributed by Lukas
Crime forums on Facebook, fraudsters pose as anti-fraud hotlines, and how big advertising companies are in bed with the rampant data collection of int...
073: Rick Astley: Never gonna hack you up...
11 Apr 2018
Contributed by Lukas
Politician admits to hacking a rival's website, T-Mobile Austria ends up in a Twitter security storm, and siren systems are hit by a Rick Astley a...
072: Why are firms so cr*p with our private data?
04 Apr 2018
Contributed by Lukas
Grindr, MyFitnessPal, and Panera Bread. They've all had data breach scares of varying degrees this week. Some handled the security breaches well, ...
071: Pony-tailed pundit ponders privacy problems - with Mikko Hyppönen
28 Mar 2018
Contributed by Lukas
Endangering your friends online, the fibs told by VPN vendors, developments from the world of cryptomining, and Carole shares an animated GIF with Mik...
070: Facebook and Cambridge Diabolica
21 Mar 2018
Contributed by Lukas
It’s not fair to describe what happened at Facebook and Cambridge Analytica as a data breach - it’s much worse than that. An autonomous Uber vehi...
069: Cryptomining, China, and Bob Ross
14 Mar 2018
Contributed by Lukas
How come Apple's Mac App Store authorised a buggy app that mined for cryptocurrency in the background? How can a Mosquito attack steal data from a...
068: Malware from outer space!
07 Mar 2018
Contributed by Lukas
If aliens did contact us would it be safe to open the email? Why would MoviePass track film lovers after they leave the cinema? Would you know how to...
067: Cyber stalking and gun control
01 Mar 2018
Contributed by Lukas
Incognito mode on your browser not as private as you think, consumer spyware companies get hacked, Graham is accused of "multitasking" in his ...
066: Passwords, pirates, and postcards
21 Feb 2018
Contributed by Lukas
Flight simulators packed with password-grabbing malware, Facebook fighting Russian trolls, and how vulnerability researchers fear being sued.All this ...
065: Cryptominomania, Poppy, and your Amazon Alexa
15 Feb 2018
Contributed by Lukas
Cryptomining goes nuclear, YouTube for Kids gets scary, and TV ads have been given the green light to mess with your Amazon Alexa.All this and much m...
064: So just a "teeny tiny" security issue then?
07 Feb 2018
Contributed by Lukas
A Namecheap vulnerability allows strangers to make subdomains for your website, Troy Hunt examines password length, and ex-Google and Facebook employe...