Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There’s just one small problem: what they really want is the 24-word seed key to Graham’s cryptocurrency wallet.
Meanwhile, if you’ve stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of “Captive Crunch” for a Russian intelligence-linked hacking group.
And a group calling itself the “ExFilSquad” has walked off with 600,000 records of the UK’s teachers and head teachers from the Department for Education – sending an unusually polite ransom demand.
All this and more in episode 479 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
0:00
0:00
Show full transcript
▼
This transcript was generated automatically, probably contains mistakes, and has not been manually verified.
And I said, I think that’s really unlikely because I haven’t been dumb enough to paste it in anywhere. I have it securely. No, it’s not tattooed on my buttocks or anything like that.
Hello, hello, and welcome to Smashing Security, episode 479. My name’s Graham Cluley.
Not that I’m regularly calling up.
So anyway, I took the call and this chap started speaking to me who sounded very much like he could work for the law.
He could be a — and he introduced himself and said he was some sort of detective or something.
Hello, this is Detective David Pullen here at the Crime Stoppers organisation. And he said he was working on a computer crime case.
And he says, don’t be alarmed, he says, you haven’t done anything wrong, he said. And he put me at my ease that I wasn’t in any trouble myself.
But he said, maybe you can help me with an investigation.
And I thought, well, maybe I can, you know, because I have helped the police before with some computer crime cases investigating various hacking groups.
And I thought, well, it’s a little bit unorthodox, but okay, all right. So he wants to talk to me. And he said that they had arrested someone on suspicion of some cybercrimes.
And during the investigation of the digital evidence, they had found some information about me.
And he said, and we’ve also found a scan of your passport and other information as well. And I said, oh, that sounds bad. I said, tell me more.
And I’m not going to name him here on the podcast because it’s quite possible this person is completely innocent.
But he gave me the name of somebody and they said, do you know this person? I said, no, I don’t know him.
He said, do you have any reason to think that he might have a vendetta against you? And I said, well, it is possible.
I said, without being big-headed, it is possible he knows me, but I don’t know him.
But I said, I’ve been working in cybersecurity for 35 years or whatever and, you know, have a certain prominence. So it is possible.
And I have received threats in the past from criminals. And so it is possible there’s been some kind of breach.
And he said, well, have you shared your passport information with anyone?
And I said, well, you know how it is sometimes, you know, I go and give talks around the world and sometimes people are booking me flights and sometimes people do ask for your passport.
So much as I groan about it and grumble and how bloody hell, can this be allowed? And it shouldn’t be. And I tried to ensure that they delete it afterwards.
It is possible that a scan of my passport is out there being held by somebody. So I said, yeah, well, it is possible they’ve got my passport. And they said, okay, all right.
And they said, well, he said you sent it to him because you were booking an Airbnb in Manchester. And I said, no, that’s not true. I haven’t booked an Airbnb in Manchester.
They said, now, the other thing is that we have found some evidence that he had collected some information on people who own Trezor hardware wallets, which you can use to store your cryptocurrency on.
And hands up, I think I’ve spoken about it on the podcast before. I do have one of these hardware wallets for cryptocurrency. I bought it years and years and years ago.
I’ve only got a very small amount of cryptocurrency. If that weren’t the case, then I wouldn’t be doing a podcast.
Maybe they were using a third party for their newsletters or something.
Maybe it was like Mailchimp or something like that, because they know my email address because practically every day I get a phishing email claiming to come from Trezor, right?
Asking me to do things. And it’s like, oh, here we go again.
And so he said to me, not only do they know that you have one of these wallets, they also have a 24-word seed key, which of course is the magic combination of words required to unlock someone’s wallet so you can access their cryptocurrency if you know those 24 words, right?
They said, is it possible that the hackers have managed to get that for you? Because he appears to have a document which suggests that he’s got it.
And I said, I think that’s really unlikely, because I haven’t been dumb enough to paste it in anywhere. You know, I have it securely.
No, it’s not tattooed on my buttocks or anything like that.
And then he said, well, do you have any other cryptocurrency? And I thought, this is all getting a bit strange.
And he gave me his name and I quickly had a little look, and sure enough, there he was on LinkedIn and he does appear to work for the police. Thought, interesting.
And I thought, he wouldn’t be ringing from Crime Stoppers, would he?
And he said, can you go to a police station within the next 24 hours and take a look at the photograph of the person we’ve taken into custody to see if you recognise him for any reason?
I said, I can go to a particular place.
So I gave the name of a town where I didn’t live, where I knew there wasn’t an open police office or department. And he says, okay. He says, I’ve just booked you in.
So you can go there, go up to the reception desk, quote this number. And he didn’t ask me what county I lived in, for instance.
I just named a place and I thought, wouldn’t you ask for some more information?
Anyway, so I began to ask him some questions, whereupon the phone cut off and I thought, that’s strange.
And I looked in my email and there was an email claiming to come from the Metropolitan Police telling me that if I did not act upon their email, then potentially action could be taken against me because they said, you have to help us with this criminal.
So there’s the email saying you’ve potentially been a victim of crime.
If you look in the raw header information, it was clear it had come from somewhere else. And I thought, ooh, this is getting quite juicy.
And by this point, of course, I’m really kicking myself because I wish I had said, I’ve got 4 million quid in my cryptocurrency wallet and wait for them to try and inveigle out of me my 24-word seed key, which surely was the thing that they’re gonna do.
So they’re gonna say, well, can you read it out to us and we’ll compare that to the one we have on our records? I think that was the plan.
I tried to call Crime Stoppers because I thought, well, their phone number’s been forged. Couldn’t get through to them. Just disaster.
Contacted Action Fraud, which is the thing you are told to do. I don’t know what your experience has been reporting crimes to Action Fraud.
They’ve rather blotted their copybook over the years. They’re not the most efficient.
Anyway, utterly unimpressed by their response, which was unhelpful because I shared all the email information and so forth and they just said, well, there’s nothing here for us to investigate.
I did my best, Danny. I did my best. So that has been my unusual experience over the last few days. Once again, I’ve failed to become a victim of cybercrime.
I mean, they’ve left some holes in their plan, but yeah, this doesn’t sound like it’s some sort of amateur operation.
This is a group which seems to have a targeted goal to get this particular account using the information of this particular provider.
So they’ve got access to that and they’re basically going down the list to try and get what they can from people.
It felt a little bit like Scattered Spider’s tactics of ringing up customer service desks.
It wasn’t like that. You know, it was—
This week on Smashing Security. We won’t be talking about how people’s Claude chats are turning up in Google search results.
You’ll hear no discussion of how Iranian hackers are being blamed for a multi-state cyberattack on US water systems, although Donald Trump is blaming the Democrats.
And we won’t even mention how Google Maps allowed anyone for one whole day to fake satellite images of nuclear plants and floods before quietly pulling the feature.
So Danny, what are you going to be talking about this week?
Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today’s sponsors, Vanta.
Why on earth are we still running our entire security programme out of a spreadsheet?
Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.
Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.
The upshot of this is you move faster, scale without the usual headaches, and maybe, just, just maybe, actually get a decent night’s sleep.
Maybe it’s been a lengthy trip and you finally made it to your hotel and you dump your bag on the bed, you kick off your shoes, you’ve opened your laptop.
First thing you’re doing, priority number one, connect to the Wi-Fi. And you know how it is connecting to a hotel network.
Normally a little page will pop up asking you, can you confirm your room number? And sometimes they’d ask you for your surname as well.
And you accept their terms and conditions that you’re not gonna do anything naughty on the Wi-Fi. And hopefully you’re then online. It’s fairly painless these days.
I think most hotels have made it a lot easier than it used to be maybe 10 or 15 years ago.
Except according to security boffins who say for the last few months at least, there is a chance that something else has been happening to travellers logging into their hotel Wi-Fi.
Russia’s Foreign Intelligence Service, the SVR, they run a hacking group variously known as APT29, Midnight Blizzard, or Cozy Bear.
They are behind some of the biggest hacks of the last 10 years, including the SolarWinds supply chain attack, the hack of Microsoft’s own corporate email, the breach at Hewlett-Packard Enterprise.
So these aren’t script kiddies. These are serious cybercriminals with the backing of the Kremlin, professional spies funded by the Russian state.
And apparently they have gone on holiday. Apparently they could be at your local hostel.
What’s your hacking history knowledge?
Who I think took the name because he used to freak the phone system by—
Someone definitely deserves a pay rise. This attack takes advantage of captive portals, which are the pages that help you to log into hotel Wi-Fi.
So when your laptop joins a hotel network via Wi-Fi, it asks the network, where is everything, right? I’ve joined.
And one of the things that the network provides is a phone book for the internet, which is the DNS, the Domain Name System, right?
You don’t remember those, so you remember names instead. So you go to microsoft.com or smashingsecurity.com instead.
The point is though, if you connect to someone else’s Wi-Fi network, your computer or phone trusts that network’s DNS to give it the right answer, not to transmogrify microsoft.com, for instance, into the wrong sequence of numbers.
Because if that were to happen, your browser would be taken to a website and in the browser bar it would still say microsoft.com.
And once they’re in there, they mess with the DNS for every single guest simultaneously. So there’s no need to touch anyone’s individual devices.
There’s no need to send any phishing emails. You, the guest, connect to the hotel Wi-Fi.
Your laptop gets pointed at servers controlled by the hackers rather than the one which you intended to actually access instead.
Well, you’re saying here, by doing what they’re doing, they can get everyone within the hotel, which could be hundreds or maybe thousands of people depending on the size of it.
So are they doing this remotely or is there someone looking suspicious in the cafe on a laptop?
The boffins at ReliaQuest, they say they have found this at hotels in multiple US cities.
Now you might think, well, this is fine, that’s not a problem. I’ll just hardcode Google’s DNS server, which is 8.8.8.8, into my device.
I will bypass whatever DNS the hotel gives me.
But because your DNS request from your phone or from your laptop still leaves your computer as plain readable traffic, the Wi-Fi gateway can intercept it.
And it will still look like in the URL bar that you’re on the real site. So that would be bad enough, but there’s worse.
Oh, because it turns out some of the victims have also been hit by ClickFix attacks. Now, we talked a little bit about ClickFix last week.
Anyone who hasn’t already heard, just to very quickly describe it, it’s where you have a popup or something asking you maybe to confirm that you’re a human or to fix a technical problem.
Will you press this sequence of keys, which normally involves Windows+R on your Windows computer. Yeah.
So there’s no need to question that. Carry on.
I mean, what could possibly go wrong in the privacy of your hotel room if your webcam and your microphone are being recorded?
Steals passwords from your browser as well, exfiltrates files. Gives hackers remote access to your computer. And it does all this while disguising itself.
It claims to be a Windows service called Cloud Sync Service. Very sort of generic.
So people are going to run that, particularly if they’re working remotely. They probably want to connect to their cloud storage provider.
Many people think that’s innocuous, and so they think there can’t be anything dodgy with that. And you might think, well, wouldn’t my antivirus spot that? Well, it might.
You can’t necessarily easily get rid of it. So if your antivirus removes it, or you try to remove it manually, it puts itself back.
Some of them are so clever, you do everything you want to get rid of it, then it’s still — you close your front door, then you turn around and it’s there standing right behind you again.
It’s ChocoShell, which steals your Microsoft 365 session tokens, which means if you’ve got multifactor authentication in place, as you should do, on your Microsoft 365 account, the hackers can still access it using your session token.
And all of this is overseen by a control panel, another piece of software, Fruitstone. Frankly, that doesn’t sound that appetising to me.
Fruitstone claims to be something called Cloud Sync Console by a fictional company called Acuity Systems Inc. It’s designed to look utterly boring.
Well, the single most effective thing, if you are a business, if you manage corporate devices, is to enforce the use of a full tunnel VPN.
So it’s not the kind of VPN where DNS can sort of sneak out round the edges, but it’s properly full tunnel.
All traffic, including DNS requests, goes through your corporate network before it goes anywhere else. Okay. So you’re not paying any attention to what the hotel is saying to you.
Well, maybe not to that extent, but sometimes solutions, because they can be perceived as so complex, people go, ooh, that sounds too complicated.
And they’re unfortunately left open to things like this, I suppose.
You could treat hotel Wi-Fi as something to be avoided. If you must use hotel Wi-Fi, you can use a VPN that will give you some protection.
Using a VPN is better than not using a VPN, but don’t install anything.
Or if you get one of those click fix messages, if the captive portal asks you to install a driver or if it asks you to cut and paste something, you know, run to the hills effectively.
If there’s anything like that.
NordLayer is a network security platform built for businesses.
It’s a scary world out there for travelling workers.
But it goes well beyond just encrypting the connection.
You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.
And if someone leaves the company, you revoke their access immediately.
So if someone on your team has started using some AI tool that your security team hasn’t approved—
Use the code NLSUMMER26 at checkout.
So this was, oh yeah, late ’90s, early noughties. Just pre-internet age. The only sort of connected devices, if you can call them that, we had back then was a Tamagotchi.
That was about the most virtual distraction you could get in class pre-smartphone, which not astounds me, but kids these days, he says, sounding like a very old man, they grow up with, you know, internet-connected devices, smartphones, that sort of thing, which we’ll get onto in a moment.
But back to school, as it were.
As far as I know, you don’t call your teacher by your first name.
Jones would like to keep it that way. They would not want their information out there for nosy students to find out, ’cause, you know, it’s the summer holidays right now.
Kids need stuff to do, and, you know, kids like to find mischief, as far as I understand.
So imagine, for most people, having your personal data stolen is an annoyance, but for a teacher to have their contact details leaked, there’s probably some pranksters, ne’er-do-wells who might be tempted to use that for the wrong reasons.
But anyway, this is all potential worry, comes back to the UK government’s Department for Education, for England specifically, ’cause I believe, you know, Scotland, Wales, Northern Ireland devolved out, which according to the Times revealed recently that hackers had obtained over 600,000 records in a cyberattack.
Now, the use of the word records is important here. It isn’t the number of individuals which have been affected by the incident.
No, there aren’t hundreds of thousands of teachers which have been affected by that. So I imagine if it was, that’s basically every teacher in the country.
The information on how this attack occurred is still not fully publicly out there, but there seem to be suggestions that it is like you experienced, Graham, sort of social engineering to try and get sort of usernames, passwords, that sort of thing for this help desk portal.
But fortunately for those affected, the theft isn’t thought to include bank details or sensitive personal information. So there is that at least.
I don’t imagine you want little Jimmy Scrackett, let’s say, getting their hands on teachers’ bank details, because I’m sure that would be pretty bad. So that’s good at least.
So that might be a result of the Department for Education, which said the attack was contained quickly.
So whatever action it had taken, it reduced the amount of data which was accessed and stolen. So thumbs up there. It seems like this attack was spotted fairly swiftly.
It hasn’t been going on for a long, long time, we think.
So as any organisation which falls victim to a cyber incident would do, they have got the likes of the National Cyber Security Centre and the National Crime Agency involved.
Are you saying the resources of those investigatory bodies were more preoccupied with 600,000 records of teachers being stolen than they were in me receiving a funny phone call from someone claiming to be a copper?
They can just walk around the corner to go have a chat, while with you, they’d have to sort of go somewhere else. If it’s closer, we’ll deal with it. If it isn’t, nah, maybe not.
Interestingly though, as a side note, as well as the teachers, there are reports that this incident has also involved details of some police as well, which have been involved as well.
So whole different thing here, but all related to the same incident, which for the government, for the Department for Education, it’s likely to be considered something of an embarrassment because it is a major part of the government.
It’s been hit by a cyberattack, which is, you know, considering the government, as previously mentioned, government bodies very vocal about the threat of cyberattacks and cyber risk, for them to be targeted by one is, well, probably not unexpected because governments are likely a big scalp, but having been hit by one takes a little bit of explaining, I imagine.
So who is behind this attack?
Well, it’s been reported that the culprit is a previously unknown hacking group, which calls itself Exfil Squad, which have been posting snippets of stolen data on their leak site.
There’s, again, information about these is patchy, but they sound kind of similar to your Scattered Spider type operation where it seems they’ve got together to do this, to make money, to cause trouble.
And make money is what they want to do here because according to the Guardian newspaper, these hackers have demanded a payment from the Department of Education not to publish the whole vast swathes of the 600,000 bits of data they have stolen.
The ransomware element of it. They don’t encrypt your files. They just go in, steal it, and say, we have it, now pay us.
Which I guess for the attackers takes less time because you’re not having to sort of slowly move your way around the network to encrypt everything you need, and probably a bit less effort on their part.
For ransomware, for example, you need to have some ransomware under your belt to sort of shove into the system you’re trying to compromise.
So it sounds like it’s part of an efficiency drive by the attackers here. Also, there is just the fact that you know many attackers are just lazy.
They want to do the least amount of work possible to make the most money they can, and in this case, just stealing the data is what they’re doing.
So they’ve gone in here and they’ve stolen this data and threatened to publish it.
The statement which has been posted in the media in articles about this is — the attackers say, and I quote, the payment we request of you is simply a rounding error compared to the litigation costs of your data leaking.
Be smart and just pay. Which is polite, isn’t it? I just find it fascinating, these cybercriminal groups, they always try to make it sound like they are doing you a favour.
Imagine going to the supermarket and a shop member of staff threatening you with a big stick if you don’t buy a certain product from the shelf.
But that’s what they’re doing here, essentially.
They’ve threatened to expose this information about teachers and headteachers, which, as established, isn’t the most sort of sensitive information out there, but it would be annoying for those people who are affected, not just because they could become targeted by scams, but also, yeah, there’s the potential for mischievous students playing pranks on them, as you imagine they might do.
But in addition to this, this leak has also contained information about members of staff at universities as well.
So they are under the remit of the Department for Education, but this is beyond a bit from your schools and your colleges.
And I’m sure listeners to Smashing Security are likely aware, the university has had something of a torrid time when it comes to cyberattacks this year.
There’ve been a range of high-profile incidents around the world. Here in the UK, the University of Nottingham received a significant cyberattack where a lot of data was breached.
And it all comes at a time when there’s lots of stories in the news about students not being very happy with the services they’re getting from university anyway, sometimes because it costs a lot of money.
And if you are not getting your education because someone’s ransomwared your university, that’s not good for anyone.
So why is this? Well, there’s a combination of reasons really. So back when I was at university, again, we’ve established a long time ago.
I couldn’t use a connection from my student room to play any online games, which I don’t think would go down well these days.
I don’t imagine you could tell teenagers getting into university that they can’t play Call of Duty or FIFA or whatever it is they play these days.
And we still accessed most resources in paper and book form, which again, suddenly makes me sound really ancient. So fast forward to 2026 and things are very different.
My contract at Security Magazine has recently ended and I’m back to being a freelancer now. But just before I left, I drafted an interview with Keith Joy.
He’s head of technology and digital at the University of Arts London, which is one of the most highly rated arts and creative universities in the world.
I couldn’t even imagine that back when I was at university. You had a laptop and that was it. Put simply, students these days, like many of us, expect to be online all the time.
However, unlike a corporate environment, those laptops that are being used by students — I don’t think they would react well saying, “Welcome to university, can we take your laptop?
Because we’re going to tell you what you can and can’t do on your personal laptop.”
Students are online a lot, so there’s a lot of risk for social engineering leading to increased risks of cyberattacks.
They know the students are very online and they know that because these students are paying a lot to attend universities, these universities also can’t be in a position where they can be locked down by ransomware or students feel like they’ve been let down by their data being breached and stolen, which is why unfortunately it remains extremely common for universities to pay ransom demands to cybercriminal groups.
It’s an interesting one. I feel like for all intents and purposes, a university does act quite like a corporate environment.
But as mentioned, you can’t have that entirely locked down thing going on, so it’s a bit of an open goal.
So you have to have all these new accounts, new setups. That sort of time is probably another big window for attackers as well.
You know, “Oh, welcome to university, click here to sign up” — oh, it’s a phishing email.
So yeah, unfortunately extortion, ransomware — these remain big issues for the university sector. Education is struggling with this and still is.
A lot of it comes down to resources. I imagine they’re not really thinking about cybersecurity until it’s too late. It feels like, as is often the case, this is ongoing.
As I said, there is a ransom demand, but I would be very, very, very, very surprised if the government paid a ransom to some cybercriminals.
They’ve just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.
Nobody added him, nobody removed him, and he’s been quietly in there for 11 years downloading maps of Paraguay.
That’s the path of least resistance.
And the report is free to download. Free!
Could be a funny story, a book that they’ve read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.
It doesn’t have to be security-related necessarily. Well, my pick of the week this week is not security-related.
In fact, my pick of the week this week may not actually be a pick of the week.
Look, I can say pick of the week and I can say nitpick of the week. Listen to that. Can you tell the difference?
Classic Doctor Who is what I like. That’s when Patrick Troughton, the 2nd Doctor, he was in charge of the TARDIS back then. And this book is written by a guy called Thom Dexter.
And I read a review of it and I thought, this book sounds great. ‘Cause I’m interested in all the behind-the-scenes stuff more than the actual programme.
I think I’m more interested in the production of Doctor Who. And I thought, oh, that’s really interesting. I hadn’t heard about that before.
And it was only after I ordered it that I found that maybe the wool had been pulled over my eyes a little.
And he just happens to use the name Thom Dexter now. And if I knew that Adrian Rigglesford had written the book, it’s probably quite likely I would have paused before buying it.
Six months later in the TV Times, which is not a publication I regularly purchase or indeed have ever purchased in my life, but six months just after the death of Stanley Kubrick, they ran what they called a world-exclusive last interview conducted with Kubrick by Adrian Rigglesford on the set of Eyes Wide Shut.
And this came out. And one of the people who read that interview was Kubrick’s personal assistant, who said, hang on a minute, this doesn’t seem right to me.
I would surely have known about this interview taking place on the set.
And so he challenged the magazine and the TV Times initially resisted and said, well, the interview was tape recorded, but they never provided a recording.
And eventually TV Times admitted that it had been conned by Rigglesford and they published an apology. It was a completely fantasised fake interview.
And it subsequently emerged because this assistant of Stanley Kubrick dug a little deeper. He obviously had the bit between his teeth.
But he wrote these articles up of like the long-lost interview with so-and-so, which he claimed to have done.
And then he was jailed for stealing 50,000 photos from the Daily Mail photo library and selling them to memorabilia shops in London.
And you would’ve thought after that run-in, he maybe would’ve chosen a different career. He would’ve become a landscape gardener. He would’ve become a bus conductor.
He would’ve done something else. But it turns out that he actually threw himself back into Doctor Who fandom, writing stuff but under a different name.
And it’s only just been found out. The link has been made. So hang on a minute. Now he’s writing books which claim again to be factual reports of Doctor Who in the 1960s.
And this mug here may not have lost his cryptocurrency, but he lost his 15 quid buying a book.
I’m very impressed by that, by Geoff Cummins. Nothing wrong with him.
And I have enjoyed reading the book, but my experience of the book is soured somewhat by not knowing if I can trust a word of it because of this guy’s reputation.
And I’m not saying people can’t be rehabilitated, but when it comes to producing something which is a historical document, if you want to be taken seriously for talking about something which happened 60, 70 years ago or more, then I think how you behaved in the past, how you have carried yourself, carries some weight.
And so I’m afraid this book, which is called When I Say Run, Run by Thom Dexter in quotes, has to be my nitpick of the week.
And I also, apparently the publisher knew his real identity.
And you just think, well, today, couldn’t you have given me the ability to make an informed decision before buying it? So I’m a bit annoyed about it.
And that is my nitpick of the week.
I mean, but no, that is a— that does sound like a really interesting read. It’s like yourself, you know, I have an interest in these older ones because I’m such a cool guy.
A few years ago when I got married, part of my stag party was going to Riverside Studios to watch on the big screen some episodes of The Tenth Planet.
And wow. That was your stag party.
Well, it also reminds me of — it’s not so much behind the scenes of scenes, but back when they had the 50th anniversary of Doctor Who, 13 years ago now, whatever it was, they had that drama, BBC drama about the making of Doctor Who.
He’s got a cigarette hanging out his mouth during a break in filming.
But it’s always good to see behind the scenes of how things are done, but maybe not so if those behind the scenes looks may or may not be true.
Half-Life is arguably the game that got me into PC gaming in the first place. So I’ve spent hours playing and replaying Half-Life and its expansions.
For those who might be thinking, Danny, what are you rabbiting on about?
An experiment basically goes wrong and it creates something called a resonance cascade, which floods the facility with aliens from another world.
This is where a game called Half-Life: Black Mesa comes in.
It’s a fan-made remake of Half-Life by a group called the Crowbar Collective, crowbar being sort of the iconic weapon of Gordon Freeman, which used the updated engine from Half-Life 2, which came along a few years later, and other later games from Valve that make it look more like a modern game.
I found it when I was a teenager, when I was coming of age. And it’s just been a lot, a lot of fun.
And unlike a lot of games these days, you have to spend hundreds of hours to get to the end. You could probably finish this in about 14, 15 hours maybe.
Trying to get back into Mastodon as well. Keep sort of kind of forgetting it’s there.
And don’t forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.
For episode show notes, sponsorship info, guest lists, and the entire back catalogue of 479 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
And to this episode’s sponsors, Arctic Wolf, NordLayer, and Vanta. Now, we all know what’s coming up.
It’s the bit where I pull out names at random from the hat of Smashing Security Plus supporters over on Patreon. And you know what?
I think this week I’m going to dig deep into the bottom of that. I’m going to pull out some of the very longest-serving supporters of the show.
Some of these fine fellows have been supporting the show for, oh, I don’t know, six years or more maybe. So who have we got? Thanks to Dimitri.
That name always arrives with a certain brooding intensity. Richard van Liesen, who I imagine owns a fine art gallery in the Netherlands.
Huge thanks to Dr_Herbalist, who always has his prescription pad open, has terrible handwriting, but knows where his Shift key is.
Scotia, and also the gloriously monikered Jonathan Haddock, who I think I met once. Who else?
Well, cheers to Lisa with an S and Jane with a Y, and also to the Scrabble master Robert Ødegard. He’s got vowels going in all directions.
And finally for this week, big love to Just Nate Please, Roy Tate, and Yuri Taraday, rounding things off in magnificent style. You know what, guys? I love you all.
Thank you so much for supporting the show. It means so much to me and it encourages me to make the podcast every week, so thank you for all of your support.
If you would like to be like them, you don’t only get the chance for me to make fun of your name and thank you at the end of the show; you also get the episodes ad-free, ooh, and you get them earlier than the general public.
So that’s pretty neat, isn’t it? If you’d like to join up, just head over to smashingsecurity.com/plus for all of the details. You can also support the show in other ways.
You can like, you can subscribe, you can leave a 5-star review. Let me say that again. You can leave a 5-star review.
Go on, leave a 5-star review wherever you listen, or simply spread the word. Every little bit helps. It makes all the effort worthwhile. And until next week, cheerio. Bye-bye.
Host:
Graham Cluley:
Guest:
Danny Palmer:
Episode links:
Sponsored by:
- Arctic Wolf – See why 1 in 3 IT assets is missing a critical security control. Download the 2026 State of the Cybersecurity Attack Surface report.
- NordLayer – the network security platform for modern teams across different work environments. Use code NLSUMMER26 for up to 20% off annual plans.
- Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
Support the show:
You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.
Join Smashing Security PLUS for ad-free episodes and our early-release feed!
Follow us:
Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.
Thanks:
Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.

