
Smashing Security
A helpful and hilarious take on the week's tech SNAFUs.
Computer security industry veterans Graham Cluley and Carole Theriault chat with guests about cybercrime, hacking, and online privacy. It's not your typical cybersecurity podcast...
Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Rory Cellan-Jones.
Follow the podcast on Twitter at @smashinsecurity, and subscribe for free in your favourite podcast app. New episodes released at 7pm EST every Wednesday (midnight UK).
This podcast uses the following third-party services for analysis:
OP3 - https://op3.dev/privacy
Latest episodes

Feb 28, 2024 • 54min
Wireless charging woe, AI romance apps, and ransomware revisited
Your smartphone may be toast - if you use a hacked wireless charger, we take a closer look at the latest developments in the unfolding LockBit ransomware drama, and Carole dips her toe into online AI romance apps.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:VoltSchemer: Use Voltage Noise to Manipulate Your Wireless Charger - ArXiv.FBI offers free decryption help for LockBit ransomware victims - Paul Ducklin.LockBitsupp unmasked!!? Graham’s reaction to the FBI and NCA’s LockBit ransomware revelation - YouTube.Dating Statistics And Facts In 2024 – Forbes Health.Romantic AI Chatbots Don't Have Your Privacy at Heart - Mozilla Privacy Not Included.Promptsmart.Solving a celestial mystery: the Sun, Earth and Moon model - Museum of Natural History, Oxford.Lotus Bud.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:BlackBerry – BlackBerry helps keeps you one step ahead. Cylance AI stops more attacks, earlier and with less effort than other solutions in the market todayKolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Feb 21, 2024 • 53min
LockBit locked out, and funeral Facebook scams
Scammers exploit online funerals, Law enforcement takes down LockBit ransomware group, Fake funeral live stream scams on Facebook, Podcast features interview with BlackBerry on AI defense against threats

Feb 14, 2024 • 51min
Declaring war on ransomware gangs, mobile muddles, and AI religion
Allan Liska, a ransomware expert, joins cybersecurity veterans Graham Cluley and Carole Theriault as they discuss AI in religion, the vulnerability of phone numbers as login credentials, and a bizarre case of unauthorized Instagram access after a mobile number change. They also touch on the revival of the character The Saint and recommend the feel-good series 'God's Favorite Idiot'.

Feb 7, 2024 • 51min
Hong Kong hijinks, pig butchers, and poor ransomware gangs
In this episode, cybersecurity experts Graham Cluley and Carole Theriault are joined by Lianne Potter from the 'Compromising Positions' podcast. They discuss a sophisticated deepfake scam in Hong Kong, the rise of pig butchering scams, and the decreasing trend of ransomware payments. They also share tips on approaching someone romantically, talk about their love for Sudoku puzzles, and recommend improv comedy courses.

Jan 31, 2024 • 59min
Interview with an iPhone thief, anti-AI, and have we gone too far?
The iPhone security setting that you should enable right now, the worrying way that AI is predicting what criminals look like, and we play a game of face fake or real...All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Mobile phone stolen every six minutes in London, says Met Police - BBC News.iPhone Thief Explains How He Breaks Into Your Phone - YouTube.About Stolen Device Protection for iPhone - Apple.Cops Used DNA to Predict a Suspect’s Face—and Tried to Run Facial Recognition on It - Wired.Will ChatGPT write ransomware? Yes - Malwarebytes.AI chatbots are making scams more convincing than ever, warn spy chiefs - The Telegraph.Test yourself: which faces were made by AI? - New York Times.AI vs. Human Writing: Experts Fooled Almost 62% of the Time- Neuroscience News.I know that I know nothing - Wikipedia.Yours truly, Johnny Dollar - Comic book.I Heart Umami.Libby.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Jan 24, 2024 • 46min
Big dumpers, AI defamation, and the slug that slurped
This week the podcast is more lavatorial than usual, as we explore how privacy may have gone to sh*t on Google Maps, our guest drives hands-free on Britain's motorways (and is defamed by AI), and ransomware attacks an airplane-leasing firm.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by BBC Technology Editor Zoe Kleinman.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:The Great British Public Toilet Map.How one man’s pay-to-use toilet gag revealed Google Maps can be used to track people - Crikey.Please Rob Me site exposes danger of sharing too much information online - Graham Cluley.Artist creates a virtual traffic jam in Google Maps - YouTube.How to Get Google to Quit Tracking Your Location - PC Magazine.Grieving With Google Street View - Slate.Zoe describes her curious tangle with AI - Twitter.What happens when you think AI is lying about you? - BBC News.Aercap confirms cyber threat involving ransomware - Air Finance.Ransomware crims slime AerCap, claim to have stolen 1TB - The Register.AerCap discloses cybersecurity incident - Reuters.BBC staffers warned of payroll data breach. BA and Boots also affected by MOVEit vulnerability - Graham Cluley.Randy Rainbow - YouTube.Donald in the John With Boxes - A Randy Rainbow Song Parody - YouTube.Zoe drives hands-free on a British motorway - Twitter.How to Play Taco Cat Goat Cheese Pizza - Wikihow.Asmodee Taco Cat Card Game - John Lewis.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Jan 17, 2024 • 47min
Fishy Rishi, 23andMe, and the labour of love
Has the British Prime Minister been caught secretly profiting from a cryptocurrency app? Were 23andMe right to blame their users after a data breach? And Indian men have hard feelings after falling for a money-for-sex scam.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:What Rishi Sunak gets up to over Christmas… - YouTube.Boris Johnson's Love Actually parody (Conservative Party election broadcast) - YouTube.UK's Rishi Sunak becomes richest ever occupant of Number 10 - Reuters.Over 100 Deep-Faked Rishi Sunak Ads Found on Meta’s Platform - Fenimore Harper Communications.Slew of deepfake video adverts of Sunak on Facebook raises alarm over AI risk to election - The Guardian.23andMe Blames User “Negligence” for Data Breach - Infosecurity Magazine.All India Pregnant Job service: Indian men conned by 'impregnating women' scam - BBC News.World War II: From the Frontlines - Netflix.Spintronics - Upper Story.Reacher - Amazon Prime.The Trust - Netflix.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Jan 10, 2024 • 49min
Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam
Chuck Norris gives a helping hand to a mysterious cryptocurrency CEO who may have separated investors from over a billion dollars, generative AI creates a nightmare for those wanting to Know Their Customer, and a determined journalist finally gets their revenge on a sneaky Airbnb scammer.All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, who are joined this week by special guest Maria Varmazis.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Chief executive of collapsed crypto fund HyperVerse does not appear to exist - The Guardian.Crypto hedge fund CEO may not exist; probe finds no record of identity - Ars Technica.BUSTED: Fake HyperVerse CEO Who Stole $1.3 Billion Unmasked! - YouTube.Hyperverse’s Steven Reece Lewis outed as Steve Harrison - Behind MLM.HyperVerse crypto promoter ‘Bitcoin Rodney’ arrested and charged in US - The Guardian.GenAI could make KYC effectively useless - TechCrunch.Airbnb Grifter Busted for $7.5 Million 'Bait-and-Switch' Scam, Feds Say - The Daily Beast.I Accidentally Uncovered a Nationwide Scam Run by Fake Hosts on Airbnb - Vice.Percentage Point vs. Percent Difference - Macroption.“Is Math Real?” - Book by Eugenia Cheng.“Julia” trailer - YouTube.Watch Before We Die - Channel 4.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Dec 20, 2023 • 45min
Phone hacking, Piers Morgan, and Carole’s Christmas cockup
Piers Morgan is less than happy after a judgement that there is "no doubt" he knew phone hacking was going on at the Daily Mirror, and a shopper comes a-cropper just before Christmas.All this and more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Piers Morgan denies knowing of phone hacking after judge rules he did - The Guardian.I've never told anyone to hack a phone - Piers Morgan tells Laura Kuenssberg - BBC News.Piers Morgan interviewed by BBC’s Amol Rajan about phone hacking at Daily Mirror - BBC News.Piers Morgan will find many ways to deny phone hacking – but how long before his number is up? - Archie Bland’s article in The Guardian.Piers Morgan tells Charlotte Church how to stop her mobile phone from being hacked - YouTube.I'm sorry, Macca, for introducing you to this monster - Piers Morgan describes in the Daily Mail a voicemail he heard between Paul McCartney and Heather Mills.The human cost of phone hacking - Graham Cluley.Eudesignhouse.shop Review – Unmasking the Store Closing Scam - MyAntiSpyware.Whois Domain Lookup.Myth Maker: The Lost Legacy of Donald Cotton - SoundCloud.15 virtual Christmas party games to play this festive season - Country Living.21 Virtual Christmas Games To Play On Zoom With Adults - Team Building.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get 10% off!SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!FOLLOW US:Follow us on Twitter at @SmashinSecurity, or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.This podcast uses the following third-party services for analysis: OP3 - https://op3.dev/privacy

Dec 13, 2023 • 57min
For research purposes only
Paul Ducklin, a cybersecurity expert and frequent contributor, joins the hosts for a lively discussion on everything from hackers targeting inflatable fetish communities to unpredictable celebrity involvement in geopolitical drama. They unpack a serious data breach at InflateVids, emphasizing the importance of user security. The group also delves into how President Zelensky leverages his Hollywood connections and explores the potentially manipulative nature of celebrity video messaging. Expect a mix of tech talk, humorous anecdotes, and insightful commentary!