<description>&lt;p&gt;In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you&amp;#39;re immune?&lt;/p&gt;&lt;p&gt;Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything.&lt;/p&gt;&lt;p&gt;And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor...&lt;/p&gt;&lt;p&gt;All this, and much more, in episode 459 of the &amp;#34;Smashing Security&amp;#34; podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;EPISODE LINKS:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://techcrunch.com/2026/03/10/doge-employee-stole-social-security-data-and-put-it-on-a-thumb-drive-report-says/" rel="nofollow"&gt;DOGE employee stole Social Security data and put it on a thumb drive, report says&lt;/a&gt;&lt;span&gt; - TechCrunch.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.reuters.com/world/us/foreign-hacker-2023-compromised-epstein-files-held-by-fbi-source-documents-show-2026-03-11/" rel="nofollow"&gt;Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show&lt;/a&gt;&lt;span&gt; - Reuters.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.bleepingcomputer.com/news/security/new-font-rendering-trick-hides-malicious-commands-from-ai-tools/" rel="nofollow"&gt;New font-rendering trick hides malicious commands from AI tools&lt;/a&gt;&lt;span&gt; - Bleeping Computer.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://support.apple.com/en-gb/105120" rel="nofollow"&gt;Lockdown Mode&lt;/a&gt;&lt;span&gt; - Apple support.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://ma.tt/2026/03/gone-almost-phishin/" rel="nofollow"&gt;Gone (Almost) Phishin’&lt;/a&gt;&lt;span&gt; - Matt Mullenweg.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=deeNAGzVOY0" rel="nofollow"&gt;Listen to the Live Scam Call Targeting Matt Mullenweg’s Apple Account&lt;/a&gt;&lt;span&gt; - YouTube.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.theguardian.com/science/2026/mar/14/confidential-health-records-exposed-online-uk-biobank" rel="nofollow"&gt;Confidential health records from UK BioBank project exposed online&lt;/a&gt;&lt;span&gt; - The Guardian.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.ukbiobank.ac.uk/news/a-message-to-our-participants-protecting-your-personal-information/" rel="nofollow"&gt;A message from Professor Sir Rory Collins, Chief Executive and Principal Investigator of UK Biobank&lt;/a&gt;&lt;span&gt; - UK BioBank.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://pducklin.com/2024/05/03/psychotherapy-data-breach-blackmailer-sent-to-prison/" rel="nofollow"&gt;Psychotherapy data breach blackmailer sent to prison&lt;/a&gt;&lt;span&gt; - Paul Ducklin.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://youraislopbores.me/" rel="nofollow"&gt;Your AI slop bores me&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.linkedin.com/posts/vaughan-shanks_a-judge-has-sentenced-a-ciso-to-8-consecutive-activity-7437743654838104065-TkxN/" rel="nofollow"&gt;Post by Vaughan Shanks&lt;/a&gt;&lt;span&gt; - LinkedIn.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.theexploit.co/articles/judge-sentences-ciso-to-8-consecutive-hours-on-rsa-expo-floor" rel="nofollow"&gt;Judge Sentences CISO to 8 Consecutive Hours on RSA Expo Floor as Formal Punishment for Security Breach&lt;/a&gt;&lt;span&gt; - The Exploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.smashingsecurity.com/store/" rel="nofollow"&gt;Smashing Security merchandise (t-shirts, mugs, stickers and stuff)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;SPONSORS:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://www.vanta.com/smashing" rel="nofollow"&gt;Vanta&lt;/a&gt; - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.smashingsecurity.com/adaptive" rel="nofollow"&gt;Adaptive Security&lt;/a&gt; - request a custom demo featuring a real CEO deepfake simulation.&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.meter.com/smashing" rel="nofollow"&gt;Meter&lt;/a&gt; - Network infrastructure for the enterprise. Get a free personalised demo.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;SUPPORT THE SHOW:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Tell your friends and colleagues about “Smashing Security”, and leave us a review on &lt;a href="https://www.smashingsecurity.com/applepodcasts" rel="nofollow"&gt;Apple Podcasts&lt;/a&gt; or &lt;a href="https://www.podchaser.com/podcasts/smashing-security-244729" rel="nofollow"&gt;Podchaser&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Become a supporter! Join Smashing Security PLUS via &lt;a href="https://www.patreon.com/smashingsecurity" rel="nofollow"&gt;Patreon&lt;/a&gt; or &lt;a href="https://www.smashingsecurity.com/applepodcasts" rel="nofollow"&gt;Apple Podcasts&lt;/a&gt; for ad-free episodes on our early-release feed!&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;FOLLOW THE SHOW:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Follow us on &lt;/span&gt;&lt;a href="https://bsky.app/profile/smashingsecurity.com" rel="nofollow"&gt;Bluesky&lt;/a&gt;&lt;span&gt; or &lt;/span&gt;&lt;a href="https://www.smashingsecurity.com/mastodon" rel="nofollow"&gt;Mastodon&lt;/a&gt;&lt;span&gt;, or on the &lt;/span&gt;&lt;a href="https://www.reddit.com/r/smashingsecurity" rel="nofollow"&gt;Smashing Security subreddit&lt;/a&gt;&lt;span&gt;, and &lt;/span&gt;&lt;a href="https://www.smashingsecurity.com/" rel="nofollow"&gt;visit our website&lt;/a&gt;&lt;span&gt; for more episodes.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;THANKS:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Theme tune: &amp;#34;Vinyl Memories&amp;#34; by Mikael Manvelyan.&lt;/p&gt;&lt;p&gt;Assorted sound effects: AudioBlocks.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;br/&gt;&lt;br/&gt;Privacy &amp; Opt-Out: &lt;a href='https://redcircle.com/privacy'&gt;https://redcircle.com/privacy&lt;/a&gt;</description>

Smashing Security

Graham Cluley

This clever scam nearly hijacked a tech CEO's Apple ID

MAR 19, 202654 MIN
Smashing Security

This clever scam nearly hijacked a tech CEO's Apple ID

MAR 19, 202654 MIN

Description

In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune?Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything.And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor...All this, and much more, in episode 459 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin.EPISODE LINKS:DOGE employee stole Social Security data and put it on a thumb drive, report says - TechCrunch.Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show - Reuters.New font-rendering trick hides malicious commands from AI tools - Bleeping Computer.Lockdown Mode - Apple support.Gone (Almost) Phishin’ - Matt Mullenweg.Listen to the Live Scam Call Targeting Matt Mullenweg’s Apple Account - YouTube.Confidential health records from UK BioBank project exposed online - The Guardian.A message from Professor Sir Rory Collins, Chief Executive and Principal Investigator of UK Biobank - UK BioBank.Psychotherapy data breach blackmailer sent to prison - Paul Ducklin.Your AI slop bores me.Post by Vaughan Shanks - LinkedIn.Judge Sentences CISO to 8 Consecutive Hours on RSA Expo Floor as Formal Punishment for Security Breach - The Exploit.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)SPONSORS:Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!Adaptive Security - request a custom demo featuring a real CEO deepfake simulation.Meter - Network infrastructure for the enterprise. Get a free personalised demo.SUPPORT THE SHOW:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!FOLLOW THE SHOW:Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.THANKS:Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Privacy & Opt-Out: https://redcircle.com/privacy