Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency

A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead, they’ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club…

Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of “residential proxies” – how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet connection.

All this and more in episode 482 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

0:00

0:00



Show full transcript


TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.

He takes his gun and he sort of shoots the word leek, L-E-E-K. I apologise to any English teachers who are listening to this, into a wall as if to prove it really is him.

Leek is a legitimate word. I mean, it’s a type of onion. What’s wrong with that?

Well, I suppose so.

I mean, Cyber Onion wouldn’t sound great, but Cyber Leek—

It wouldn’t be so good.

It is a pun, Graham, whether you approve of it or not.

Smashing Security, episode 482.

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

Hello, hello, and welcome to Smashing Security, episode 482. My name’s Graham Cluley.

And I am Paul Ducklin. Hello, Duck.

Great to have you back on the show again.

Thank you, Graham.

We parachuted you in this week actually, ’cause that person we were intending to come on hasn’t managed. Not that you are by any means a pale substitute.

I’m not pale at all these days. We’ve had so much sunshine.

No, that’s true.

As you can see, I’ve had a bit too much lately, if those of us who can see me on video.

Well, it’s always great to have you here. Before we kick off, let’s thank this week’s wonderful sponsors, ThreatLocker, BlackKite, and Vanta.

We’ll be hearing more about them later on in the podcast. This week on Smashing Security.

We’re not going to be talking about how Iranian hackers managed to shut down a UK power plant.

You’ll hear no discussion of—

How a ransomware crook silently ripped off his own gang by posing as a recovery firm and pocketed the victims’ payments for himself.

And we won’t even mention how the Toxic Panda Trojan is quietly taking over Android phones to steal banking PINs and passwords.

Now, Duck, what are you going to be talking about this week?

Well, Graham, if your smart TV isn’t spying on you, what else might it be doing behind your back?

And the tyres are going to be hitting the tarmac as I enter the world of Grand Theft Auto 6. All this and much more coming up in this episode of Smashing Security.

This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.

That’s right. We’ve seen research into autonomous ransomware, adaptive AI worms, and agents chaining tools without waiting for a human operator.

Which is all very interesting, just so long as it isn’t your network they’re experimenting on.

When enumeration, exploitation, and lateral movement happen at machine speed, relying on somebody to notice an alert and respond quickly begins to look rather optimistic.

Well, ThreatLocker puts default deny and least privilege between the agent and its next action.

So application allowlisting controls execution, ring-fencing restricts what trusted applications can access or launch, and privileged access management removes unnecessary elevation.

The attacker may be moving faster, but the controls are already in place. Agentic AI doesn’t make established security principles obsolete.

It makes getting them right considerably more urgent.

So make sure that you are prepared for machine speed attacks with ThreatLocker. Visit threatlocker.com/smashing today to learn more and schedule your free demo.

That’s threatlocker.com/smashing. And thanks to ThreatLocker for supporting the show.

Now, chums, chums, Grand Theft Auto. It’s one of the most successful entertainment products ever made. Duck, have you ever played Grand Theft Auto?

No, because when I had my own grand theft bicycle from outside my own flat—

That was enough to convince me that this is not a laughing matter, Graham.

No, no, not a laughing matter.

I mean, it’s more than a year ago. I’m almost over it now.

I’ve never played Grand Theft Auto.

I’ve seen it.

Yes, exactly. I’ve seen it. I’ve looked over people’s shoulders while they’re playing it, and it does seem very impressive. It’s a huge, open-world game.

It’s all about a life of crime. It has earned over $8 billion — billion with a B — since it launched in 2013. It’s made more cash than any Hollywood movie.

It’s still being played by millions of people more than a decade later. And that’s really a testament to how much people love this game.

And also, I think, it really underlines how desperate people are now, some 13 years later, for a sneak peek of its sequel, which is GTA 6.

It is gonna be finally released, they promise, this November.

Well, Thursday this week, actually the day that this episode airs at 3:00 PM Eastern time, amongst much hoopla, Netflix will be exclusively premiering a first look of GTA 6’s gameplay ahead of its official release.

So I think the preview will be up for about 24 hours or something.

Will you be able to play it or will you just be able to watch players zooming around?

I really don’t know, ’cause I do believe it is possible these days to play games via Netflix.

Maybe younger listeners would be able to educate us as to whether that’s possible or not. At the very least, I’m sure there’ll be videos to watch of it.

And people are very excited about this ’cause it’ll be their first chance to see GTA 6. No, it won’t. No, it won’t, because someone has beaten them to it.

A hacker or a group, no one’s quite sure. A hacker called CyberLeak has started to drop—

CyberLeak. I bet that name took months to think up.

Well, you may laugh, Duck, at their particular moniker, but they’re going to be putting out clips of what is one of the world’s most closely guarded pieces of software.

So they’ve been putting out video clips of game characters driving around the streets of Grand Theft Auto.

They’ve been swimming, they’ve been visiting strip clubs, they’ve been tasering each other.

Yes, you can swim in these games.

It’s aquatic car.

Not everything happens in a car. You really haven’t played this, have you?

I said I hadn’t.

You can fly planes and helicopters. You can go down zip wires. You can walk around. You can go into buildings. There’s a lot of effing and jeffing as well.

There’s a lot of very bad language.

So how did they get hold of this if it’s so $8 billion worth protected?

Well, we don’t know. We don’t know how this has happened. Some people have been questioning, well, is it really footage of the game because the game hasn’t come out yet?

Or is it someone who’s taken some other footage which may have leaked out in the past? Because there have been other leaks which have come from GTA and Rockstar Games before.

At one point, what CyberLeak actually does in this clip which he shows, he shows himself, or rather his in-game character, evading the police.

And then he takes his gun and he sort of shoots the word leak, L-E-A-K — I apologise to any English teachers who are listening to this — into a wall as if to prove it really is him playing it.

Leak is a legitimate word. I mean, it’s a type of onion. What’s wrong with that?

Well, I suppose so.

I mean, CyberOnion wouldn’t sound great, but CyberLeak—

It wouldn’t be so good.

It is a pun, Graham. Whether you approve of it or not.

Okay, that’s true. That is true.

Now, this would normally be a story of a hacker breaking into a company and the company, you know, sort of saying, oh, that’s terribly embarrassing, and scrambling around to sort of fix the damage afterwards.

We take your security seriously, blah, blah, blah.

Exactly that kind of thing. And that’s obviously part of the story, but there is more to it because CyberLeaks didn’t just want attention.

It appears that they also wanted cash, but not through extortion, which you would expect, you know, Grand Theft Auto and Rockstar Games wallowing around in cash.

Oh, you mean saying Rockstar, pay us money and we’ll shut the whole leak down?

There’s that. But what they have done in this particular case is the hacker has launched their own cryptocurrency, which they have dubbed rather unimaginatively—

Let me guess.

CyberLeak.

Yes. Sorry, I ruined your fun.

So they created their own cryptocurrency called CyberLeak, and they announced that every time someone buys or sells some CyberLeak cryptocurrency, obviously CyberLeak, the hacker, they’re gonna get a cut of the trading fees because of how they’ve set it up, right?

So they’ve set it up on Solana, I think is where they’ve got it.

And to incentivise you to buy and sell CyberLeak cryptocurrency, they’ve said that if the market capital of the CyberLeaks cryptocurrency hits $3 million, they will release a clip from inside the Grand Theft Auto strip club.

Sure enough, within 24 hours, the market capital did hit $3 million and the clip was released from that part of the game.

And this was all to the hackers’ financial advantage because they’re getting some of the money.

They’re not only getting a cut of the trading fees, but apparently they also have something like 27% of all of the CyberLeak cryptocurrency themselves anyway.

So if the price of CyberLeak, the crypto, goes up, that’s more money in their pocket.

So how did they prove that it really is a leak from the game and not just some blurry AI-generated variant of something that was in a previous issue?

It’s difficult to prove when no one has really seen it. But what has happened is Rockstar Games have launched DMCA takedown requests.

They’re subpoenaing, if I could say that, subpoenaing. Am I saying that correctly? It’s too difficult for me.

Subpoena means under penalty if you don’t do it, literally.

Okay. They’re doing that, Duck, to Microsoft and Discord.

They’re trying to get this information taken down and they’re trying to grab the information as to who the hacker is as well, because there’s an Xbox link.

I think there’s also been some email addresses. There’s been setting up of websites as well.

The hacker claims, they said, look, ’cause some people online, you can imagine what a fervent community there is who are really into Grand Theft Auto.

We’re talking about people who spent $3 million in 24 hours to see a virtual strip club?

Yes. And so to defend themselves, CyberLeak, the hacker, has said that they’ve spent about $29,000 setting up their website.

Well, I mean, for goodness’ sake, they could have done it more cheap than that, but also the cryptocurrency in the first place.

And they said that within a couple of days they made about $50,000 just from the trading fees. So they have been making money.

That’s without the 27% of the holdings, right, getting boosted.

So people have been looking at this cryptocurrency. It turns out the hacker hasn’t sold any of their cryptocurrency themselves.

It appears, although the value of their stash was being pumped up by all these other transactions, they’ve actually destroyed their entire stake.

And many people are speculating that they’ve done this because the heat was rising in the community and maybe from law enforcement as well.

And they’re sort of worried that, hang on, maybe what I did wasn’t quite as cool and groovy as I imagined.

Oh, so they’re worried that their own fans may turn on them for pump and dump slash rug pulling.

Oh, exactly. Because the price went up. And of course, if they did actually sell their cryptocurrency, such a big chunk of it, the price is gonna go down.

These videos, by the way, they all contain the QR code, which will take you to CyberLeak’s website where you can go and get the cryptocurrency.

So they appear to have destroyed — that’s their word, at least — their entire stake worth something like $1.4 million of CyberLeak crypto.

I mean, frankly, is there anything legitimate which is ever happening with cryptocurrency? It does appear that the default is either crime or just some extreme shadiness.

Well, I suppose that fits the whole Grand Theft Auto theme, right? You know, lighting cigars with $1,000 bills. Stuff like that.

So the question is, why have they done this? And so, as I said, there’s been lots of accusations that the whole CyberLeak thing was some kind of marketing scheme.

This was all about boosting the price of the cryptocurrency. According to the hacker, they weren’t in it for the money.

And instead what they said was they were trying to lobby for Rockstar Games to release GTA on a physical disc rather than making it only available via download.

It seems that ripping it off before it’s released, while it’s supposedly vigorously protected online but isn’t, is not a good way to convince the company.

Now also put it on a CD where I can take it away and study it infinitely at my leisure. That seems to be more specious than I didn’t intend to make money.

I mean, okay, apart from the fact that they’ve done the breach.

If you’ve got this thing like it’s fallen into your hands, plenty of journalists use leaked data to write stories and then take payment for it.

And the websites they write for take paid ads on those pages. Is it actually fraudulent to say, here’s what the game looks like. I’m not saying how I got this.

I’m not saying I got it illegally. If you like it, pay me a fee.

I mean, I don’t like the sound of it, but is it actually as devious as selling someone a VPN they don’t need that won’t work? Yeah, it’s an open question, isn’t it?

I see your point. I mean, the breach, clearly that is quite clear. Computer Misuse Act legislation is being broken in order to steal the data, maybe passing it on.

But no one knows how it happened yet, right?

No, no.

And inevitably you’ve got to wonder, I don’t think this is the case, but you have to wonder, is this to the benefit of Grand Theft Auto overall because it gives them even more headlines?

I’m sure they’d want to manage properly their launch, but—

We’re engrossed in the story now. We don’t even play the game. So you’ve always got to ask that, haven’t you?

It’s a strange world. Anyway, it does seem to me, I’m pretty convinced that the hacker was interested in making some money out of this cryptocurrency.

And certainly they were launching and they were promoting the cryptocurrency before they released any of the images, before they started talking about the physical disc, which they wanted Rockstar Games to distribute the game on.

Oh, you think that might be a story they had up their sleeve just in case?

Another way in which they appear to have tried to monetise the leaks was their website had a contact page which offered paid advertising slots, so you could actually advertise on their website.

And you could also request specific clips of gameplay footage.

They were saying, for instance, if you pay them 400 Monero, for instance, which is a type of cryptocurrency worth about $160,000, you would have, I don’t know, images of the submarines or strippers on the submarines or whatever it is that would be your particular niche.

I guess that’s a bit worrying because there, they’re openly offering, we’ve got this stuff which we know we are not supposed to have ’cause it’s covered by copyright.

We’re offering to sell it to you privately.

Advertising on their site, that’s one thing, but hey, we’ll sell you somebody else’s intellectual property is, well, you’re going up against Rockstar North, right?

One of the things I found funny was on the website where they were saying that you can buy ads and things.

They said, look, they’re perfectly happy with gambling ads and they’re perfectly happy with adult content, but they didn’t want any scam ads.

So if you were a scammer, you weren’t allowed to advertise on their site. He’s got some standards. I think you’ll agree with that. Clearly Rockstar Games aren’t happy.

They are asking for information from some internet companies, trying to identify who may be responsible. And also there’s the cryptocurrency lead as well.

So to set up his cryptocurrency little operation, CyberLeaks had to use a vendor that requested a government-issued ID.

Normally, if you create yourself an account on one of these sites, they’ll ask you for a scan of your passport or your driving licence or something like that.

But it does mean that sometimes law enforcement can be successful. They don’t necessarily need to break encryption.

They don’t need to necessarily deanonymise a cryptocurrency wallet in order to get information about you. They may just have to go to a company and get your ID.

And as we know from recent leaks and busts, there are often things embedded in your data and your traffic, say if you’re using a Windows computer, that will reasonably well identify you, even if you’re going through 17 different VPNs to try and anonymise yourself.

And you have to bear in mind as well that many criminals, of course, if they’re faced with a website which says you have to confirm your ID, they’ll use a stolen or forged ID.

There is that.

But, you know, hackers screw up. Don’t they sometimes, and accidentally reveal their true identities? Poor old Rockstar Games.

It’s sort of put a little bit of a blemish on the announcement which they’re making this week with their trailer launch on Netflix.

It’s not the first time, of course, they’ve had trouble with the Grand Theft Auto games.

Yes, they’ve been breached before, haven’t they?

They have.

So maybe they actually figure, you know what, how bad was it last time? It’s so bad that everyone’s been excited about this new game for four years.

It’s almost as though they can’t lose.

I mean, they’ve spent so long writing this game. It’s been going on for like 13 years or whatever. It’s absolutely astonishing.

Imagine if you’d spent that long on Jacaranda Jim, Graham. Jacaranda Jim version 42 by now.

It is practically at version 42, the number of bug fixes I had to do with that.

But yeah, back in 2022, a teenager who was a member of the Lapsus$ hacking group broke into Rockstar Games, leaked 90 videos of Grand Theft Auto 6, obviously an early development version of the game.

He was caught by the cops and they obviously didn’t want him to do any hacking while he was on bail.

They shoved him into a hotel and said, look, you’re not allowed to go on the internet.

It later turned out that he did manage to get on the internet, and even though he didn’t have a computer or anything like that, he managed to exploit the Amazon Fire TV stick plugged into the back of a TV in order to get online.

In that particular breach, Rockstar claimed that they had lost $5 million to that particular individual, who I think is still being held.

Yes, they were found unfit to stand trial, I think. Yes.

So what is clear is that GTA 6 is enormously anticipated by people. It’s an enormously valuable piece of intellectual property as well.

But it’s a company which doesn’t seem to really know how people are breaking in. I mean, that’s actually the most important thing of all, isn’t it?

What is being done to prevent these hacks from happening and to make sure that it doesn’t happen again?

Graham, what’s this about a new report from one of our sponsors?

Yes, Black Kite have just put out their first ever European Cyber Risk Report.

And oh my goodness, they’ve been looking into ransomware attacks across Europe for the last year and a half or so.

And let me guess, everything is fine and we have nothing to worry about?

Well, ransomware is up 55% year on year in the first 4 months of 2026 alone.

So not fine.

No, Joe, not fine at all. Nearly 70% of all European ransomware activity is concentrated in just 5 countries.

And this report from Black Kite breaks down exactly where the attacks are hitting hardest and which hacking groups are responsible.

So is there anything in there beyond the headline numbers?

The bit that really struck me is what they found about third-party risks. A lot of companies aren’t being attacked directly.

Instead, they’re being caught in the blast radius of an attack on one of their suppliers.

Right. You’re only as secure as the weakest link in your supply chain.

And the report has some real-world examples that illustrate this perfectly. For instance, there’s a Swedish company, it has an unpronounceable name.

They got hit and that ended up causing huge problems at hundreds of organisations, exposing the data of over a million people.

All from one incident.

All from one incident. And the report also covers how regulations like NIS2 and DORA are forcing European businesses to get much more serious about all of this.

Sounds like essential reading, frankly.

It is, and it’s free. Get the full report at blackkite.com/smashing.

That’s blackkite.com/smashing. And thanks to Black Kite for supporting the show.

Duck, what’s your story for us this week?

Well, I thought that I would talk about residential proxies.

Because I suspect that many Smashing Security listeners have probably seen it in the context of the cybersecurity media writing up terrible malware stories.

And it seems that we’ve adopted that word even though it sounds fairly neutral and it’s not actually clear what it means.

And therefore it can’t possibly be clear how you’d know whether you had one of these. And if you did, was it good, bad, or indifferent?

And if it was bad, what on earth would you do about it?

Okay, let’s get back to basics. So what is a residential proxy?

Well, I guess we have to start by digging into what do we understand by the word proxy?

It’s something that does something lawfully on your behalf. Quite a neutral idea.

So in network terms, that term was borrowed as a metaphor to refer to a computer service, like say a web server, that instead of actually being the web server you want to visit, you visit the proxy and you tell the proxy what you want to access.

And the proxy goes and fetches the content and gives it back to you.

And originally the idea of that was all supposed to be a great idea to have a gateway proxy or a company proxy, because it means that firstly, the company can limit the sites that you go to, if they’re legally obliged to protect you from gambling sites or porn sites in work hours by forcing you to use a proxy, it means the proxy can go, no, you can’t go there.

You can’t go there. Oh, that site’s got malware on it. You can’t go there.

Also, it can speed things up because if 72 people want to go and look at the cricket score, wouldn’t it be nice if the proxy had already got that and it figured, oh, I’ll speed things up, I’ll feed it back to the other 71 people.

So the idea of having a proxy to do network services was that it was good for performance, good for security, good for bandwidth limiting, and something that companies would routinely do.

So obviously you could use it for bad.

If you had a proxy that you snuck onto a company network that people didn’t know was there, they might go to one search engine and end up being fed results from another.

So you can use proxies for bad as well. But in general, as a term, it’s neutral. So that leads us to the point, well, what do we mean by a residential proxy?

And the answer is loosely, when we say a residential proxy, it’s exactly the same technology that happens to be on a home network.

And then that leads to the question, why on earth would anyone install one of those? Well, I have what I would call a residential proxy at home.

I’ve set it up for myself on a small server of my own.

And the idea is then when I’m on the road, whether I’m out of the country or just in the coffee shop, let’s say I want to do something like online banking or I want to pay an electricity bill and I want them to see that I’m coming from my usual location.

I can connect securely using SSH back to my home network and then I can go out on the internet.

And in fact, in browsers like Firefox and Chromium, you can go in and say, use a proxy, and you can explicitly say, I want to use this particular proxy.

So obviously Google and Firefox think it’s a good idea to have proxies.

And there’s no legal reason why you’re not allowed to run one at home. So why has residential proxy become conflated with, oh, terrible malware attack?

And that, Graham, is where the story gets both devious and interesting at the same time.

All right. Okay. So explain it.

Well, obviously people might want to install a residential proxy like the one I have that they chose to install, where they chose the software and they decide who gets to use it and when it runs and when it doesn’t.

But what if you could be lured into installing exactly the same sort of software, not on your laptop, where if it goes rogue, your antivirus or your EDR software might detect it and block it.

But on something that you generally don’t really think of as a general purpose computer, even though secretly internally it is, like your smart TV or even your home router or a home thermostat or some Internet of Things device that’s inside your network.

And it’s not only inside your network, it may also be plugged in permanently.

So it may be constantly connected to the internet, whereas your laptop, you know, you shut it, you turn it off, and it can’t be abused in that way.

Well, generally, if it’s your smart TV, even when it goes into sort of suspend mode, it’s still there.

And you’d expect it to go online to download updates and security patches and notifications for the TV programs coming up that you’re interested in.

So you kind of expect your smart TV to be online.

And especially if we move away from smart TVs for a moment, the thing that really is on all the time and in theory has all the bandwidth it can possibly have is your home router.

The thing that sits between you and the internet.

And even worse for many people, that home router is not theirs.

When they sign up with the ISP, it arrives in the mail and it just says, plug it in. But it is not your router. It belongs to the ISP. You can’t modify it. You can’t reflash it.

You can’t run your own software. Even if there were such a thing, you would not be allowed to install an antivirus on it to scan for rogue software.

And the one thing you can be sure with your router, it has all the bandwidth at its disposal all the time because that is its job.

You’re absolutely right. They don’t want you meddling too much with your router because that’s going to create tech support problems for them, isn’t it?

For their customer service department.

Yeah. The router that I got from my ISP, untouchable. I understand why.

They want to try and make it resilient to things like rogue, unexpected residential proxies and other malware being injected onto it.

And they want it to stop you messing with it and authorising access in ways that they don’t like. So you’re right.

Not only is it difficult to meddle with it, the idea is that you cannot. And even if you were to find a way to hack it, it’s probably against the terms and conditions of service.

And if they find that out, A, they can cut you off, or B, they’ll just push out a firmware update and undo all your changes.

Now, Doug, I can understand why you might want to install a residential proxy on a Raspberry Pi or on a router or something like that, but why would you want to put one on your smart TV?

If you were a regular homeowner, what would be the thinking behind that?

Well, that is the $64 question, isn’t it? And there are lots of different answers to that.

One is that there is allegedly a legitimate market for these so-called residential proxies where you agree to install this software, maybe in return for free content, maybe in return for some modest discount against some other service.

Maybe even in return for money that gets paid to you in some way for installing this on your smart TV.

And in return, you allow this basically VPN for other people outside your network to borrow your internet connection while you’re asleep.

But you don’t get to choose who those people are, and you don’t necessarily know that much about the company you’ve entered into this agreement with for installing the software.

You’re getting some nebulous benefit. Oh, you get free games or you get access to some TV channel or other.

Yeah, I know some people, not me. I know I’m saying friends of mine, but it really isn’t me.

I know people who have got these dodgy sticks plugged into their TVs, which give them, for instance, access to Premier Football matches or something without paying a subscription.

Or maybe it gives them access, I don’t know, to some of the streaming services.

Oh, so it’s a USB stick with an app on it and you plug it in.

And some of these TVs, they’ll come with their own application store.

And even Apple’s much-vaunted App Store and Google’s Google Play, if you have an Android-based smart TV, even they get poisoned by malware, even though they’re supposed to have protection on.

Right?

So you get someone offering, oh, well, you don’t need to burn this onto a USB stick and then plug it in.

Basically, you just install our app and it will provide fun games that your kids can play free, or it’s got these fantastic games that your kids can play. It’s $3 a month.

But if you turn on this super special option that allows us to share your internet connection when you are not using it, unquote, then you won’t have to pay the $3 a month, something like that.

So it could be the case that you’re installing an app onto, for instance, a smart TV which has terms and conditions.

Maybe this is mentioned in the terms and conditions, maybe it’s not.

It could be that you are buying from some dodgy website, something to circumvent Netflix or Apple TV in order to give you access to the latest streaming TV shows.

And you may be unknowingly opening a residential proxy. So who wants to use a residential proxy?

I can understand that people may have them, may even not know that they are operating inside their home, but who are the people actually exploiting it and using it?

What are they doing with them?

Well, if you look at the very many, at least claiming to be legitimate residential proxies, and there are non-dark websites that actually help you choose the best residential proxy provider, you know, top 24 residential proxy services of 2026.

And they really do list 24 of them. It’s not just clickbait. Well, it is clickbait, but they list all these services.

And one of the things that I think that supposedly legitimate companies claim they want to do with this is things like online surveys, web scraping.

So they want to maybe look through competitors’ websites, and maybe they want to be able to do it from 20 different people in a night and see if they get different results.

Maybe they don’t want to get caught out.

Maybe they want to see, hey, this competitor of mine, what are their special offers of the day in England, Scotland, Wales, Ireland, Netherlands, Belgium, etc., etc.

So there are all sorts of quasi-legitimate reasons why you might just want to buy service from somebody else, right? In the same way that you buy a VPN service. Yes.

Which we can come back to in a minute. Yes. Because that’s the dodgy side of how you might get one of these.

Let’s talk about that in just a moment. So the parallel which I would draw to this is it’s a bit like a botnet.

Where a botnet, which is launching maybe a distributed denial of service attack—

You could, if you like, leave the word “a bit” out of that sentence if you really wanted.

Yes. It’s like a botnet.

You could leave the word “like” out of that sentence if you really like.

It’s a botnet because you end up with lots of computers which aren’t yours. Whether they be on TVs or routers or fridges or thermostats or who knows what.

That somebody else is selling to somebody else who’s selling to somebody else to do whatever they want with off your network, with your IP number, from your household, in your name, basically.

Yes. So this is the thing. It’s distributed because normally they would have to do that from their own computers, which would maybe be easy to block or maybe be easy to identify.

But suddenly this is happening from lots and lots of people’s home addresses. Absolutely.

And just think how much money you can make in ad click fraud if you are paying somebody else for access to 1,000, 10,000, 100,000.

And some of these residential proxy networks apparently number into the millions.

Believe it or not, imagine that you can make 1 million ad clicks in a legitimate way from computers all over one particular country, all over the world, that are coming effectively from residential networks.

So as far as the person receiving the ad click, it couldn’t look more legit.

It’s not like 1,000, 10,000, 1 million clicks coming from one massive ISP site. It’s not a special private server that they set up yesterday in the cloud.

It’s basically just, hey, look at this.

And you could time the clicks so that they seem legitimate and you could follow them up with visits that look as though the person then clicked through from the ad to further action and all sorts of stuff.

And that’s before you’ve actually stolen anything.

So where do VPNs come into all of this?

Well, in one famous case, the residential proxy, essentially cybercrime VPN, the one that the provider rented out to cybercriminals around the world, was actually embedded in, irony of ironies, a VPN that they were selling.

So they provided an actual VPN. It was an open source VPN that they’d taken the source code and just modified it. And it had all these super extra cool features.

And you paid a fee so they actually earned money and it did actually work.

And irony of ironies, if you use this VPN on all of the computers on your home network, all of your traffic, wherever you did, whether you were a crook or not, would appear to come from somewhere else.

And the only traffic that did come from your home network would be traffic that had come from crooks who’d bought the service the other way around.

And from the person who sold you the VPN in the first place, if you don’t mind. Put that in your pipe of irony and smoke it. Absolutely crazy.

Should our listeners be worried about this?

I mean, from the legal point of view, if they’ve got a TV and if they install an app and it happens to have a residential proxy on it, which is used by people to commit ad fraud, it’s not the owner of the TV who’s committed the ad fraud.

I guess you could argue that they’ve somehow abetted the act of ad fraud, for instance? Yes.

I’m not a lawyer, Graham, thankfully, so I don’t really know the answer to that.

And I imagine it would be somewhat hard to prove that the user’s intention was to aid and abet cybercriminality.

But people still have a moral obligation, don’t they, to do something? It feels to me as a member of the internet community, we don’t want this kind of bad stuff happening.

And so you should be running a tight ship inside your home.

Yes, I think that’s perfectly reasonable to say. Try and be a nice person, basically have some ethics. But there is obviously an element of self-serving altruism here.

Like you should do it because you don’t want other people in your neighbourhood, in your country, on the internet, in your online TV community to get screwed over by people who are using your device to commit crimes.

But at the same time, you don’t want to be in the firing line on behalf of that crook.

Because after all, if somebody is criminal enough to want to sneak a residential proxy into an app you install and then sell it to other people for cybercrime purposes, it would be foolish not to assume that they might want also to spy on you, to stalk you, to do creepy things to you, to steal your cryptocurrency wallets, to monitor your browsing habits, et cetera.

So it’s almost as though the residential proxy thing is a kind of warning.

Well, we’ve got time right now to chat about one of our sponsors this week, Vanta.

Oh yes, my favorites. What do they do again?

They stop you running your entire security program out of a spreadsheet, Joe.

That seems aimed at me personally, Graham.

Well, it is a little bit, yes. But you know how most companies have to prove they’re secure to customers or auditors or regulators?

And the whole thing involves chasing down evidence, filling in questionnaires and forms, updating the same spreadsheet cells over and over again.

Over and over again. It sounds utterly soul-destroying.

Well, Vanta automates all of that.

Automates it? How?

Well, their trust management platform keeps a continuous eye on your systems. It pulls everything into one place and keeps you audit-ready around the clock.

So no more staring at the ceiling at 2 AM wondering whether you’ve got the right controls in place or whether one of your suppliers has been breached.

The stuff of nightmares.

Yeah, it would be, wouldn’t it?

But this Vanta solution uses AI as well, and it’s the useful kind, flagging risks, collecting evidence, slotting into the tools your team already uses.

So you move faster, scale without the headaches, and perhaps actually get some sleep. Go to vanta.com/smashing to find out more.

That’s vanta.com/smashing. And thanks to Vanta for supporting the show. And welcome back.

And you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week.

Pick of the Week. Pick of the Week.

Pick of the Week is the part of the show where—

And that’s week with 2 Es, Graham, not W-E-A-K.

You’re right.

There you go.

So part of the show where everyone chooses something they like — could be a funny story, a book that they’ve read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.

Doesn’t have to be security related necessarily. Well, my pick of the week this week is not security related.

My pick of the week this week is a little website which my darling wife found and she pointed me towards and she said, this is a bit of fun.

Why don’t you go and have a play with this? It is a website called timeguesser.com.

That is timeguesser with 2 Es, one at the end of time, one sort of halfway through guesser, but not just before the other. Anyway, this is a site where you can play a little game.

What it will do is it will show you a historic photograph taken at some point in history, one can assume since the invention of the camera, and somewhere in the world.

Well, I’ve got one, the daily challenge. It looks very much like it’s somewhere on what used to be the Iron Curtain filled with water.

Yes, I’ve done today’s one already. So you can change the year and then you can place your pin and hit guess.

And how close do you have to get? I’m going to— okay, so it’s—

Well, you can zoom in on the map if you want.

This is going to be tricky because it’s going to be—

It does look like it’s in Eastern Europe, doesn’t it? It looks like it’s on a very rainy day.

Serbia one way. And is that Slovenia the other way?

Yes, I think there’s a road sign suggesting maybe it’s that sort of part of the world. This is great radio, by the way.

Let’s see. And you’ve got to think of the year as well, Doug. Oh, I have to choose the year.

You have to choose the year.

I’m going to go that it’s going to be, and it’s black and white, I’m gonna go, it’s 19— I’m gonna guess 1964. And then how, where do you, where’s the pin? How do I find the pin?

I think you click. So you’ve changed the year, then you click with the mouse, I think.

Oh, oh no, I put the pin in the wrong place. I didn’t get it. I, you can see that I was drawn in.

You were really in the zone.

I was like, I don’t want to get this wrong.

So it will tell you how close you are, both in time and in miles.

Oh, I was away by quite a long way.

Yes. Well, that’s irritating. I was only one year off. I said 1965.

And it was actually 1964, wasn’t it?

Oh, I should have thought of that. It’s actually in Zagreb, in what’s now Croatia.

Yeah. So it actually gives you a little bit of text as well, describing the photograph.

So Duck was looking at a picture of some old cars in the flooded streets of Zagreb, which happened in 1964.

I think this is a bit of fun.

You can even see what it looks like now by going into Street View.

Now there’s no such sign because there’s a massive freeway, zooming elevated freeway. So boy, how times change, eh?

So it’s called timeguesser. Time, as you’d expect, guess, as you’d expect, and then just an R rather than an ER, dot com. And that is my pick of the week.

Duck, what’s your pick of the week?

My pick of the week is a book. It is not about cybersecurity, but it is what you would call a STEM book. It’s all about science.

And yeah, it was published about 20 years ago, but it’s dealing with stuff from ancient history until fairly recently.

And it is called Scientific Curiosity, by a chap called Cyril Aydon.

A-Y-D-O-N. And it’s a lot of little vignettes that take you through how facts that we now take for granted.

Like, what is the speed of light? How far away is the sun? What is the mass of the sun? How do we know what stars are made of? How did Newton figure out gravity? All of that stuff.

Obviously, there are scientists that everybody’s heard of. You know, there’s Aristotle and there’s Eratosthenes, and of course there’s Sir Isaac Newton.

But there are also lesser-known people like country vicars who just got into science during the Enlightenment, who came up with ideas that were way ahead of their time and were laughed at and then turned out to be correct, particularly on things like dinosaurs and stuff like that.

So, Duck, you described this book as being a series of vignettes.

I love a vignette. And yet it’s rather an old-fashioned word. It’s like the old-fashioned word for a YouTube Short or an Instagram Reel, isn’t it?

Is this something which you can sort of dip into and enjoy briefly? Is this something which is quite an accessible book with all its little tales?

It is. And I will actually read, if I may, from the book itself where the author describes the two ways that you can enjoy it.

So it’s called, as I said, Scientific Curiosity, but the subtitle is Everything you want to know about science but never had time to ask.

And then he has a little essay about what made him curious about science.

And it says, this book can be read straight through as an introduction to 2,000 years of scientific discovery, but readers who prefer to treat it as a lucky dip will, I hope, find interest wherever they open it.

The book does not assume any prior knowledge of science or of mathematics, and there is only one formula in the book. Can you guess what it is, Graham?

The most famous formula is E=mc², right?

Bingo. You got it in one. Thank goodness. So it does cover that. Obviously that’s when you get to the atomic age. Why are nuclear explosions so jolly powerful?

And that’s that a small amount of mass gets multiplied by a truly enormous — okay, so that’s Scientific Curiosity by Cyril Aden. Indeed.

Is your pick of the week. Well, that just about wraps up the show for this week. Thank you so much, Duck, for coming onto the show. I really appreciate it.

I’m sure lots of our listeners would love to find out what you’re up to and follow you online. What’s the best way to do that?

I write great content, explain things, do talks, make podcasts and short videos and all of that sort of stuff about cybersecurity. I do cybersecurity for a living.

So if you would like to hire me or just see some of the stuff I’ve done in the past, please find me at pducklin.com/about or go onto your favourite social media site, whether it’s Mastodon, Facebook, LinkedIn, and look for Paul Ducklin.

You will find me fairly easily.

Terrific. And of course, you can find me, Graham Cluley, on Bluesky, Mastodon. I’ve even got an Instagram and a TikTok account these days.

Oh, Graham.

I don’t know how to use it.

Do you do dances and ice bucket challenges and all of that stuff?

Oh dear. And you can follow Smashing Security on Bluesky, Mastodon, or Reddit as well. Don’t forget to ensure you never miss another episode.

Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.

For episode show notes, sponsorship info, guest lists, and the entire back catalogue of 482 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.

Bye, folks.

You’ve been listening to Smashing Security with me, Graham Cluley, and huge thanks, of course, to Duck for joining us this week, and also to this episode’s sponsors, ThreatLocker, BlackKite, and Vanta.

And we should also thank those brilliant people who are patrons of the podcast. So enormous thanks to them, including brand new sign-up Paul Davis, the mysterious L.

More power to them. Dan H, who’s keeping things admirably concise with just a nibble of four characters there. Cheers to Alex Tasker and Sharon and to S.K.

Very special thank you to Sabahatin Gukalukoglu. Oh my goodness! A name of such enormous complexity that I am genuinely in awe.

And after reading it out, I feel like I really need to lie down. Big love to William Sabados and to Ask Leo, who arrives with their own exclamation mark.

And finally for this week, Louis, who is rounding things off with characteristic one-name efficiency.

Those are just a few members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and they can have their names pulled out at random to be mocked at the end of the show.

If you’d like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details.

And even if you don’t do that, you can still do me a favour by leaving a five-star review, liking the podcast, subscribing to it, and tell your friends about it.

That really does help. Well, until next week, cheerio, bye bye.

Host:

Graham Cluley:






Guest:

Paul Ducklin:

Episode links:

Sponsored by:

  • ThreatLocker – Book a demo today and start securing your organisation.
  • Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • Black Kite – Read Black Kite’s 2026 European Cyber Risk Report to explore the latest ransomware trends, top threat actors, and how supplier breaches are reshaping cyber risk across Europe.

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Join Smashing Security PLUS for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.












About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.