Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions

A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of organisations. All for some free in-game currency.
Meanwhile, there’s a 1980s phone protocol called SS7 that lets shadowy surveillance companies track anyone, anywhere, via their mobile phone. Governments know about it. Telecoms know about it. Nobody’s fixing it.
All this and more in episode 465 of the “Smashing Security” podcast with cybersecurity keynote speaker and industry veteran Graham Cluley, joined this week by special guest James Ball.
Plus! Don’t miss our featured interview with Rob Edmondson of CoreView, discussing how to lock down Microsoft 365 before it’s too late.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
This is like 4 layers of Swiss cheese lining up and just something dropping straight through, isn’t it?
It’s not staying contained at the moment. And so I’d like to put it on the record, I am the greatest victim of the world’s political situation right now.
You know, I had some feedback from a listener just in the last couple of days actually saying, you love the podcast, been listening to the podcast forever, but oh my God, Graham, can you stop talking about politics?
And my reaction was, look, thank you very much for listening and all the rest of it, but it feels to me that technology and politics are more intertwined than ever before.
You can’t really extract them from each other, can you?
I’ve sort of always gone, I wish people would pay more attention to this. This is transformative. I sort of came of age with the internet.
You’re kind of going, no, we need to look at this. This is really huge.
And now tech and politics have merged so much and are in the discourse so much and are crashing together in so many ways. It’s I was really stupid to want this.
Why can’t this go back to being in its nice own lovely corner where I can just think about how the technology works or, you know, the principles of it instead of what stupid way is this going to be used to upend our politics yet again?
How can you extricate them? I don’t know that you can.
It’s when the railway monopolies were there or the early oil monopolies, because the biggest companies and the biggest tech companies is synonymous.
9 of the world’s 10 biggest listed companies are tech companies. Essentially, this domination by one sector is pretty much unheard of in either of our lifetimes.
And so politics is going to be weird until tech is kind of normal again. And that might be bad for someone who reports on and covers tech, but might be good for the world.
It might be good for our blood pressure and it might be good for your listener. I promise I haven’t brought a load of political things this week.
Well, not very political, small p political.
Well, before we kick off, let’s thank this week’s wonderful sponsors, CoreView, Elastic, and Vanta. We’ll be hearing more about them later on in the podcast.
This week on Smashing Security, we won’t be talking about how home security firm ADT has been burgled by the Shiny Hunters gang.
You’ll hear no discussion of how ransomware negotiator has pleaded guilty to helping hackers by leaking victims’ insurance details.
And we won’t even mention how Elon Musk’s Grok chatbot told researchers pretending to be delusional that there was indeed a doppelganger in their mirror and they should drive an iron nail through the glass while reciting a psalm backwards.
So James, what are you going to be talking about this week?
He’ll be joining us as we take a look at how hackers have been turning essential tools like Microsoft 365 against their targets and what you can do to lock down your environments before it’s too late.
All this and much more coming up on this episode of Smashing Security.
If someone broke into your Microsoft 365 tenant right now and quietly disabled your conditional access policies, grabbed global admin rights, turned off Bitdefender, would you even notice?
One compromised account and an attacker can quietly reshape your entire tenant.
No alerts, no noise, just someone systematically dismantling your defenses while you’re none the wiser.
You could be rebuilding your tenant settings from scratch for weeks.
It’s actually a really practical read.
It covers how these attacks unfold step by step, where your existing tools are leaving gaps, and what it actually takes to recover control once it’s been lost.
You can learn more at smashingsecurity.com/coreview and maybe do it before someone else does something bad to your organization.
They are at the heart of all kinds of stuff which is going on on the internet. Hundreds of thousands of organizations use them because they’re a cloud company.
You know, they’re a properly grown-up company. And on the 19th of April, Vercel put out a security bulletin. I’ll summarize it.
They basically said, we’ve been hacked, customer data has gone missing.
We’d quite like to tell you about it before the Russian hackers selling it on a darkweb forum get there before us. So we’re going to get out there ahead of the bad news.
Now, normally at this point, I’ll be telling you about a clever zero-day vulnerability or sophisticated nation-state campaign or even a simple phishing email, right?
Normally, that’s the kind of thing which I’m— not this week, however. No, this week, James, the story really begins with someone wanting to play Roblox.
I am less terrible at Roblox than I am at Minecraft. I think really it’s not for adults, it’s for teenagers. It’s kind of even for tweens, really.
I’m sure there are adults who enjoy Roblox completely legitimately, but it has been slower to act on those concerns than almost any other platform as well.
I hear they have improved of late.
They’re not the Context AI which was acquired by OpenAI.
It’s a different Context AI, which I think really suggests that, you know, maybe people shouldn’t have relied upon AI to dream up their company name.
Clearly they were using an old version of a model there because that is quite important context, ironically.
So it’s something which plugs into your Google Workspace and you grant it sweeping permissions and it can go ahead and read your email and your documents, helpfully does all kinds of wonderful AI things to them.
It sounds absolutely gorgeous. You know the kind of thing, people get it all the time. A consent screen will pop up.
You know, a sensible person reading the terms and conditions go, ha ha ha ha ha, no way. Eh, eh, it’s a big fat no.
But many people will just hit the approve button instead in order to allow it to do that.
And apparently one of Context AI’s own employees, someone who works at the company, a company which has asked its customers to trust them with the keys to their corporate Google accounts, effectively, they, on apparently a work laptop, decided what they really needed in their life was a Roblox auto-farming script.
Are you familiar with auto?
I mean, just the fact anyone working in any tech-related sector would do this. Gaming add-ons are notorious. You know, approved add-ons, fine, great.
I’ve modded almost every game I’ve ever played. That’s the fun of it.
You know, Baldur’s Gate 3, absolute delight and amazing mods on that and some slightly horrifying ones involving Withers that I won’t get into. If you’ve played the game, you know.
But any mod that sort of claims to let you do something a bit against the rules tends to be incredibly dodgy because they never go through the official stores, which means—
Or, you know, trustworthy.exe from a Nigerian prince, Derby Dragons stuff.
But you’ll get the in-game currency so you can then buy things, you know, add-ons and so forth. And it’s dodgy software, as you said, James, downloaded from dodgy websites.
But people have already decided the rules don’t apply to them and they’re encouraging it.
I mean, it always sounds daft getting something to play the game for you, but any sort of massively multiplayer game has bits that basically involve grinding.
You know, it’s a bit if you could pay someone to go to the gym for you and you got the results, which, you know, the dream.
I mean, look, no company IT server setup should ever have let someone be able to install this, really, should they? I mean, this is a bit of a disaster.
You know, the user is stupid here, let us stress, but they shouldn’t have been able to make this mistake, should they?
And unfortunately, this particular script came bundled with the Lumma, I believe it’s pronounced, Info Stealer, which rifles through your browser, grabs your passwords, every cookie, every session token, every OAuth credential it can find.
Bundles it up, sends it to a complete stranger afterwards. So in February, this guy downloaded this Roblox cheat. He got infected.
Lumma quietly stealthed its way into the browser, grabbed the database of information, including Google Workspace credentials, including the keys to Context AI’s AWS environment, including— and this is the crucial part, really, I suppose— including the OAuth tokens belonging to Context AI’s customers.
Well, this certainly shouldn’t have been able to happen. Oh, oh, this is great.
I mean, this is sort of building an incredibly elaborate safe door with all of this sort of stuff and then just leaving the code on a Post-it on it, isn’t it?
Graham, this is not great.
So when you click allow, you are giving an app, for instance, access to your Google account. They don’t need your password. They don’t trigger your two-factor authentication.
And once a thief has your OAuth token, they don’t need to break in because as far as Google’s concerned, they are you.
And the scary thing, I think, for many people, and they don’t realize this, is if they actually check their Google account right now and have a look at what apps they have granted access to their account over the years, they’re probably going to be surprised.
There’s probably things in there that you don’t remember doing, or you may have just done on one particular day, and you’ve granted them access to stuff, and you should revoke it.
You know, I think there were several on Twitter, as it was back in the day, that would give you a score for your social standing or your clout.
But these old apps that you’d granted access to for one purpose would get bought by someone else or the domain would get taken over and they could hijack the thing.
And so even things that were completely sensible to grant access to, suddenly became terrible.
I remember back in the days of when I was on Twitter, as was, there was a third-party app or something or service which I think was doing some kind of ego-stroking examination of my followers, right?
So I could think I was doing really, really well in terms of Twitter followers.
And what happened was that particular service got hacked which means the hackers then had access to my Twitter account, not just me, but also Justin Bieber and whoever else.
And my account started posting Nazi spam to people. And you just think, oh no, no, no, I don’t, you know, I don’t want this. So it can happen to everyone.
You always need to look and revoke permissions wherever possible.
So one of Vercel’s employees had at some point signed up for the Context AI office suite using their Vercel Enterprise Google Workspace account.
And when the permission screen came up, they clicked on Allow All.
So now our hacker, our attacker, who started his day off poisoning Roblox hacks, is sitting on an OAuth token that gives him read access to a Vercel employee’s entire Enterprise Google Workspace.
So you’ve got different companies here, but it has cascaded through to grant a huge amount of permission to access data.
This is like 4 layers of Swiss cheese lining up and just something dropping straight through, isn’t it? Have you not come across this analogy? I didn’t just make it up. I haven’t.
And so you just get more and more of them on top of each other and you reduce the chance of them lining up. This is like a hole through 5 slices, just straight there. Bumpf.
Now, Vercel says that some of these were marked as sensitive and therefore protected, but the ones which weren’t marked as sensitive, which apparently were most of them, because that wasn’t the default, duh, once again, they’ve changed that default now, by the way, funny that.
