meta_pixel
Tapesearch Logo
Log in
Smashing Security

This clever scam nearly hijacked a tech CEO's Apple ID

Smashing Security

Graham Cluley

Technology, News, Tech News

4.7579 Ratings

🗓️ 19 March 2026

⏱️ 55 minutes

🧾️ Download transcript

Summary

In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune?

Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to reveal everything.

And! Human-powered “AI”, and a punishment worse than prison: eight hours on the RSA expo floor...

All this, and much more, in episode 459 of the "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Paul Ducklin.


EPISODE LINKS:




SPONSORS:

  • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • Adaptive Security - request a custom demo featuring a real CEO deepfake simulation.
  • Meter - Network infrastructure for the enterprise. Get a free personalised demo.


SUPPORT THE SHOW:

Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!


FOLLOW THE SHOW:

Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.


THANKS:

Theme tune: "Vinyl Memories" by Mikael Manvelyan.

Assorted sound effects: AudioBlocks.





Privacy & Opt-Out: https://redcircle.com/privacy

Transcript

Click on a timestamp to play from that location

0:00.0

A judge has sentenced a CISO to eight consecutive hours on the RSA conference floor.

0:10.4

His crime failing to disclose a breach to the Securities and Exchange Commission.

0:16.3

Legal experts at the SEC are calling the penalty proportionate and corrective. Former RSA attendees

0:23.9

are calling it barbaric.

0:36.4

Smashing Security, Episode 459.

0:40.5

This clever scam nearly hijacked a tech CEO's Apple ID, with Graham Cluley and special guest

0:46.2

Paul Ducklin.

0:47.5

Hello, hello, and welcome to Smashing Security episode 459.

0:50.8

My name's Graham Cluley.

0:52.3

And my name is Paul Duck.

0:54.0

Duck, great to have you back on the show once again. Thank you for joining us.

0:58.1

It's a great pleasure. So what fun stuff have you been up to lately? Well, as you know, Graham, for very many years,

1:05.0

I haven't owned a car because I kind of got into bicycling. Yes. So when I need a car, which is only very occasionally, I hire one and every time you seem to get a different model. Right. And the one thing you have to do, at least in Britain, when you hire a car, the rule is you get it full of fuel and you must return it full of fuel or they charge you some extortionate price to fill it back up. Yeah. And of course, because it's not your car, how do you know when you pull into the filling

1:30.9

station which side the filler cap is on?

1:33.5

Okay.

1:33.8

And although I've been doing this for years and years and years, I only very recently

1:38.6

discovered that if you look at the fuel gauge, digital or not, underneath it,

1:43.2

there's a little petrol pump icon, says this is the fuel gauge, digital or not, underneath it there's a little petrol pump icon,

1:45.2

says this is the fuel gauge, and at the bottom of the little petrol pump icon, there's an

1:50.5

arrow which is either on the left hand side or the right hand side. Guess what the arrow tells you.

1:57.0

I think bless you, Duck, for not knowing that. What? Well, I knew that.

2:01.2

Because in the cars I've driven, I've noticed that.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Graham Cluley, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Graham Cluley and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.