Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Unknown 2026-7-22 23:10:22 Author: grahamcluley.com(查看原文) 阅读量:3 收藏

Unknown

I have to say, despite the fact that I have used it, I do feel completely dirty and appalled at myself for having used it. And my opinion on that has strengthened only over time.

So I do think it's completely reprehensible of me. Yes. Smashing Security, episode 477.

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

Hello, hello, and welcome to Smashing Security episode 477. My name's Graham Cluley.

JAMES BALL

And I'm James Ball.

GRAHAM CLULEY

James, welcome back to the show. Always a pleasure to have you.

Now, I was following you on Blue Sky and I saw that you had an unusual way of handling the extreme heat which we were experiencing a couple of weeks ago.

Many people have been caught out by those scam adverts on YouTube for things which claim to be able to air condition your room. But what did you do?

JAMES BALL

I mean, the good news is I didn't fall for any scams.

GRAHAM CLULEY

Good, well done.

JAMES BALL

The bad news is I went insane and booked myself flights right up to the Arctic Circle. And so I spent a week up in Tromsø in northern Norway. Norway goes a long way up.

JAMES BALL

And Tromsø is right at the top. It's the gateway to the Arctic. 24-hour sunshine this time of year, but crucially never got above 15 degrees. Truly delightful.

GRAHAM CLULEY

And was this an intentional reaction to the weather situation we were suffering from?

JAMES BALL

It was fully 100% a reaction to the heatwave. I booked the travel, I think, 30 hours before I got the plane.

JAMES BALL

And it was genuinely a result of Googling, where can I go that's cold?

And there were lots of sort of things where it's like, well, about £20, or this place is also in the heatwave. Northern Scotland was really expensive.

And it turned out that actually going up to the Arctic — I mean, I spent a week there and including the flights, it cost me less than £1,000.

GRAHAM CLULEY

And you got to see the England-Norway World Cup game as well, I think.

JAMES BALL

Yes, in Norway, they had screens up in the town square full of very drunk Norwegians who — yeah, I don't think they were cheering on England, you know.

Although the nice thing was the day after, I was sort of worried I'd have to try and put on a really terrible American accent or something.

And they did all sort of say, look, just beat Argentina. We don't want Argentina to win. And I heard that from 3 or 4 different people. So they were kind of okay with it.

They were cooler than they could have been. But strongly recommend it. Tromsø is great. Just don't get a curry there. Norway does not do spice.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

GRAHAM CLULEY

Well, before we kick off, let's thank this week's wonderful sponsors, Arctic Wolf, NordLayer, and Vanta. We'll be hearing about them later on in the podcast.

This week on Smashing Security, we won't be talking about how a man in India has been accused of using an AI chatbot to help him plan a triple murder.

You'll hear no discussion of how the July 2026 patch update from Microsoft comes with security updates for a record-breaking 570 vulnerabilities.

And we won't even mention how plugging in an LG monitor can automatically install adware on your Windows PC that bombards you with McAfee pop-ups without ever asking your permission.

So James, what are you going to be talking about this week?

JAMES BALL

I am going to be talking about the Suno hack because I think there's quite a lot in there.

GRAHAM CLULEY

And I'm going to be discussing why ordering McNuggets may not be good for your online privacy, particularly if you're a hacker.

All this and much more coming up in this episode of Smashing Security.

Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.

JOE

We've got a question for you. What's the thing that keeps you staring at the ceiling at 2 AM when it comes to your company's security?

GRAHAM CLULEY

Is it wondering whether you've actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?

Why on earth are we still running our entire security program out of a spreadsheet?

JOE

If any of that hit a little too close to home, that's where Vanta comes in.

Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.

GRAHAM CLULEY

Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place and keeps your security programme audit-ready around the clock.

Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.

The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night's sleep.

JOE

Sounds lush. Find out more and get started at vanta.com/smashing.

GRAHAM CLULEY

That's vanta.com/smashing, and a big thank you to Vanta for supporting the show. Now, chums, chums, imagine if you can that you are a spy working for the Russians, all right?

What's the worst thing that could possibly occur if you were actually working for the Russians?

Would your biggest threat be having your identity exposed, being found out by the FBI?

Would it be about Western intelligence agencies finding out where you're based, locating your identity and extraditing you?

Or would the biggest threat actually be about Chicken McNuggets? That is the thing we're going to be exploring. Do you stand anywhere in particular on Chicken McNuggets, James?

JAMES BALL

I'm actually a big fan of them. For a long time as a kid, I ate very little else.

And so I've travelled in many, many countries in the world and every single one that had a McDonald's, I've been to the McDonald's in that country.

GRAHAM CLULEY

Oh my goodness, James.

JAMES BALL

I've had McNuggets in India, in China, in Australia, and in Norway. Indian McNuggets are the best, by the way.

GRAHAM CLULEY

Oh, there's a difference, is there, between McNuggets? I can't believe we're having this conversation, but—

JAMES BALL

I should stress, I eat in normal, good restaurants as well. This isn't expensive.

GRAHAM CLULEY

Oh, good, okay. That's reassuring, at least.

JAMES BALL

So this would be bad news for me.

GRAHAM CLULEY

Well, back in September 2024, Dutch cybersecurity experts discovered that someone had burrowed into the computer systems of the Netherlands National Police Force and they had accessed the email account of a staff member there.

And via that account, they had then grabbed the data of tens of thousands — I think over 64,000 — officers in the force.

Officers' names, addresses, identities, also of their informants.

The Dutch intelligence agency at the time described it as the first time that the country had fallen victim to deliberate sabotage by a Russian-backed hacking group.

It caused a big furore in the press, as you can expect, and they didn't break in to plant ransomware or extort money — this was all about stealing intelligence, gathering intel in order to exploit it later.

So this was effectively a police force's entire contact database — you know who the police are, who they're talking to, who talks to them.

And Microsoft, working with Dutch intelligence, publicly named the hacking group responsible for this back in May 2025 as Void Blizzard.

I love the names which are sometimes given to these groups.

JAMES BALL

It sounds like a World of Warcraft patch, doesn't it?

GRAHAM CLULEY

Yes. I mean, they called it Void Blizzard. There was another group of researchers who I believe called them Laundry Bear.

JAMES BALL

Well, that would probably be the official US designation, wouldn't it? Because everything that's believed to be Russian state-linked is always given bear. So Fancy Bear is the GRU.

GRAHAM CLULEY

And we've got Crazy Bear.

JAMES BALL

Military Bear will be a different military intelligence unit.

GRAHAM CLULEY

Yeah, I know, but Laundry Bear — you'd almost be embarrassed to be a member of Laundry Bear compared to Fancy Bear, wouldn't you, I think?

JAMES BALL

It does suggest where you are in the pecking order, doesn't it?

Which, given this is a pretty good hack, actually getting 64,000 officers and the contact database, I think maybe they deserve a promotion — Laundry, maybe to Scullery, Scullery Bear.

GRAHAM CLULEY

I think they're being trolled, basically.

So anyway, Microsoft and the Dutch intelligence agency said that this attack hadn't just targeted the police, it turns out, but other sectors — defence, healthcare, government — not just the Netherlands as well, but also countries across NATO and Ukraine as well, of course.

So you can all kind of guess where this attack is likely to be coming from, and the typical attack would come in the form of a personal invitation via email.

You might get invited to a European Defence Summit, and if you click on the link or you scan the QR code sent in the PDF which you've been sent, you get taken to a login page.

Looks like Microsoft Teams you're logging into, and of course it's the usual story — they're grabbing your username and password so that they can then log into your account and steal your information.

So this was fairly standard state-sponsored cyber espionage directed at Western security infrastructure.

And at the heart of it, according to US prosecutors, is a chap called Denis Obrezhko.

He is a 36-year-old Russian IT nerd, and at the end of October 2025, he made possibly a worse mistake than you going up to the Arctic Circle — he chose to go to Phuket in Thailand.

He grabbed himself a ticket there, he fancied a little break, a little holiday, and less than a week later, Thai police were knocking on his door, seizing his laptop and his mobile phone and probably a digital wallet as well, and placing him under arrest, believing him to be a hacker involved in this attack.

And of course, the first rule, if you are a Russian hacker, is you shouldn't leave Russia. If you're in Russia and you're only attacking organisations outside, stay in Russia.

JAMES BALL

You'll get promoted, you'll get a nice home, you'll do great. I mean, I guess you could go on holiday to Belarus — that would probably be fine.

GRAHAM CLULEY

Yes, they'll probably be fine with you as well.

JAMES BALL

It's probably quite a short travel list, thinking about it.

Maybe bits of Central Africa, but I think anywhere with a US extradition treaty should probably not be on the destination list, right?

GRAHAM CLULEY

And Russia's foreign ministry, they instantly leapt into action.

They issued a warning to their citizens saying, do not travel to Thailand — there is a threat of you being arrested at the request of the United States.

They said, we strongly advise Russian citizens who have even the slightest reason to suspect they might be subject to criminal prosecution by US authorities to refrain from travelling to Thailand.

So this Denis chap, Denis Obrezhko, he has since been extradited to the United States.

This month he's appeared in a federal court in Boston, he's pled not guilty to hacking charges, and if he is found guilty, he could be facing, I don't know, 10 years in prison maybe.

And now the thing is about Denis Obrezhko — I tried to find him on LinkedIn, which is my standard.

JAMES BALL

Your research tool, you know, that's your spy intel, is it?

GRAHAM CLULEY

And to be honest, it is surprising just how many people will leave their dodgy past employments up on LinkedIn.

I couldn't find him, but he is alleged to have had quite an interesting job history. So according to the FBI, for 5 years between 2012 and 2017, he was working for the FSB.

And for anyone who doesn't know, the FSB is like New Labour to Old Labour — it's the rebranded version of the KGB.

JAMES BALL

The cuddly, kindly, non-Soviet KGB, yes. Yes.

GRAHAM CLULEY

And after the FSB, according to Reuters, who spoke to a former colleague and saw some documents, he spent 2 years as a senior member of staff at a well-known Russian company, which probably a lot of our listeners have heard of, called, hmm, let me just— Kaspersky.

GRAHAM CLULEY

Now Kaspersky, as I'm sure most of our listeners know, is of course a very well-known Russian antivirus company, cybersecurity company, who has had a rotten few years, quite frankly, particularly since the war in Ukraine began.

Because there've been so many stories about them being linked to the Kremlin and to the FSB, and they've had to shut down their operations.

JAMES BALL

Have you ever talked to anyone there about the whole Russia connection or this kind of thing? Have you ever had that chat?

GRAHAM CLULEY

I have, yes.

JAMES BALL

Because they get quite— I mean, there are some very, very good security researchers at Kaspersky. They've helped me out on stories before and sort of talked me through things.

You know, they have some real pros. And they get incredibly awkward about it because of course most people who work there just work and have a job, don't they?

JAMES BALL

Yeah. But when you start to look at Eugene Kaspersky and the realities of operating in Russia and all of that, it's hard not to wonder.

Even before everyone was saying it, people either very enthusiastically deny that they've ever seen anything or done anything with it, or try and move the conversation on, in my experience.

What's it been like for you?

GRAHAM CLULEY

So I have a close friend who has worked at Kaspersky for many— he doesn't work there any longer because effectively their UK operations are dead now.

They're only selling online, their offices are shut down, they've laid off their staff.

I think it's actually illegal to sell it at all in America now, even to consumers, not just to government organisations.

JAMES BALL

Yeah, I think you're right.

GRAHAM CLULEY

So I mean, it has been catastrophic for them business-wise.

My friend's a very nice chap and he's not a spy, and it happened that he got a job 25 years ago or whatever it was for an antivirus company which happened to be based in Russia.

And I've known Eugene for many, many years. I haven't seen him for quite a few years, to be honest, but I know him — seems like a very nice guy.

JAMES BALL

I think I've interviewed him. Yeah, he's very, very clever.

GRAHAM CLULEY

Yeah, extremely clever. Like many of these guys who've set up these antivirus companies.

But you do have to wonder, would it be possible to be a successful businessman — and he was an extremely successful businessman in Russia — without kowtowing to what the Russian authorities want?

Because they would make your life extremely difficult, if not impossible.

JAMES BALL

I mean, it isn't possible.

You have to at least be friendly and cooperative, and given the importance of hacking to Russia's soft power and how it conducts diplomacy and sort of information operations, I just don't think you could be in a job as sensitive as that and not do that.

I mean, let's be honest, the eight biggest cybersecurity companies that operate in the UK coordinate with NCSC and with the intelligence agencies.

There are certain companies, if you're on critical national infrastructure, there's an approved list. And I'm not saying anyone does anything out of line with the law.

We are a Western democracy. Everything is in the statute and above board to that level. But we cooperate with them in that way.

It's not weird to say, would a company with a similar stature and a similar reach and scope that's headquartered in Russia have a relationship with the Kremlin? Of course it would.

It'd be impossible for it not to.

GRAHAM CLULEY

Yeah.

I feel like Kaspersky found itself in an impossible position, and obviously there were accusations that maybe their software could be used to sabotage companies or to steal information from companies, with a malicious update at the behest of the Kremlin.

I don't think I've ever seen any evidence whatsoever that that was something which was planned to do, but obviously you only need a certain amount of doubt, a small amount of doubt, and that's enough to convince people, well, maybe we shouldn't use that product, maybe we should use this other one instead.

So unfortunately world events sort of overtook things, which is a shame because it was in many ways a good product. Yeah.

JAMES BALL

Geopolitics has always got a win in that one though, isn't it?

GRAHAM CLULEY

Yeah, absolutely. Anyway, the guys at Kaspersky, they say that whatever Abrezco is accused of now, had nothing to do with his time working for them.

They say that the alleged hacking activity didn't happen until after he had left. But it gets more interesting than that.

Five years ago in 2021, Abrezko gave a guest lecture at the Moscow Technical University of Communications and Informatics, and he was introduced as the Deputy Director of the Information and Analytical Center of Russia's Ministry of Emergency Situations.

Imagine working at the Ministry of Emergency Situations.

JAMES BALL

It's a great job title. I hope Andy Burnham sets that one up, a Ministry of Emergency Situations. It feels like we need one, doesn't it? I'd love that.

GRAHAM CLULEY

Anyway, so this is a Russian government institution which he was working for.

And the prosecutors then say he became a deputy director at a Russian tech firm called UTECH.NN, which is alleged to have been a cover organisation for Void Blizzard's hacking campaign.

So this isn't actually that unusual, in that companies will be set up appearing to do one thing — in this case, it was IT consultancy and project management, product development, all very dull.

But when you look into the public records, apparently they show that that company holds an FSB-issued licence for what is described as the covert acquisition of information.

So you get your licence from the Russian government saying, yes, you are allowed to secretly, without other people's knowledge, acquire information.

It seems a little bit unusual, but again, it makes you think, what does this company actually do?

JAMES BALL

It's sort of like a digital PI's licence, isn't it? You know, I sort of feel like it's your sort of hacking fedora or something. I kind of like this.

GRAHAM CLULEY

Anyway, this company, UTECHNN, their founder is a guy called Mikhail Dudin, and it turned out he was listed — there's a caller ID app called GetContact where you can find out what people's common nickname is, or they can set themselves a name.

He'd chosen the name Ethan Hunt, which is from a movie I've seen, Mission: Impossible, the Thom Cruise character.

JAMES BALL

I mean, how's that for cultural hegemony though? You know, the extent to which American culture is everywhere, that even the Russians are picking Ethan Hunt as their name.

GRAHAM CLULEY

Anyway, Microsoft published their report into Void Blizzard apparently on that very same day.

Obrezhko allegedly emailed Ethan Hunt in quotes, suggesting that they have a meeting to discuss developments.

So it's quite a tangled dark web, which the courts are obviously going to have to unknot to see if this guy is guilty or not. He obviously denies it.

But I was interested in knowing how the investigators have pieced this all together.

How had it come to the situation where the US had asked the Thai police to arrest this guy if he ever turned up in Phuket? And it's rather interesting.

So what happens, it seems, is he had reused the same username and his real Russian phone number across multiple email accounts and social media platforms and financial apps, things like that.

And he'd used the same Google account for cryptocurrency transactions as he'd used to create accounts on Twitter and Instagram and PayPal.

So same username, same avatar, same phone number, same date of birth over and over again.

It's like, guys, if you're going to be criminals, have in your back pocket a whole list of different dates of birth, of different names, of different email addresses — don't make it easy to triangulate who you are.

And the investigators say that they've traced cryptocurrency payments used to fund Void Blizzard, and they followed transactions back through an internet provider.

Eventually they found an email account registered in Obrezhko's own name.

And this is where it becomes really interesting, because independent threat intelligence firm Control Alt Intel took the email address and phone numbers that the FBI had published in their affidavit, and they cross-referenced them with Russian leak databases.

So these are databases of leaked information which have spilled out over time through criminal activity.

And it's not just the criminals who use these — sometimes the threat intel people use them as well.

And what they were able to find was, by going through this data, they got information from banks and social networks and courier companies, food delivery apps, anything like that, which is obviously horrendous from the point of view of if you're a Russian citizen, but great if you're a threat intel researcher.

They were able to search for Denis Obrezhko's email address and phone number, and they kept on popping up in these leak databases, including that he had ordered, on the 1st of March 2021, at half past 3 in the afternoon, a Lipton iced tea, 9 Chicken McNuggets, and a McChicken burger to be delivered to him at the Russian Ministry of Emergency Situations on that particular date.

And they found 13 other separate orders, all delivered to that ministry address, all on weekdays, early in the afternoon. Loved his Chicken McNuggets.

And it's tangled him even more into — yes, this is the ministry you were working in. You were working for the Russian government, despite any claims you may try and make later on.

JAMES BALL

I do find this stuff really interesting because listeners are probably aware that I was one of the reporters who worked on the Edward Snowden story.

JAMES BALL

And that meant 18 months of us knowing that we were under surveillance, sort of from the US, from the UK, but possibly also sort of hostile agencies.

We were flying between the US, the UK, Brazil.

We were sort of trying to communicate about classified documents all of the time, and we were trying to be quite sort of cautious about that. But you also have to live.

You're staying in hotels, you're trying to sort of spend on credit cards or company cards because my bank account was emptied by the first week.

I was sort of having to get prepaid Visa cards, not for OPSEC, but because I had no money.

But you know, you needed to get a McDonald's at 2 AM or you needed to get a taxi to get back and you were jet lagged.

And so you're trying to do good security, but if you can't remember a password at 2 AM when you haven't slept for 30 hours and you don't know what time zone you're in, there's no point having the password.

And so the compromise between where your kind of normal mundane accounts sort of reach and where your sort of uber ones reach are incredibly complicated to keep up.

And you know, maybe for a week someone can do it, but 3 months in, 6 months in, when it's your everyday life, the things that look very silly when you see them in an indictment or when you see them in a security research, it is that thing where it's like, well, how do you live otherwise?

How do you remember which date of birth you used for your Uber account versus which one you used for your other one?

So all of these details are there, and if you don't use as many real ones as possible, you mess it up.

You know, I remember LulzSec got caught because the leader, Sabu, turned on the other ones.

He got caught because he forgot to change one thing and needed to log back in, and it was about half 3 in the morning, and he'd done everything properly, and he logged in without his VPN once.

JAMES BALL

And from the fuzzed IP location, they then just basically manually surveilled that little block in New York until they worked out which flat it was and whose activity pattern it matched.

And they got him that way, from one failure to use his VPN. And so, you know, this looks shoddy. I mean, this is poor. For a sort of security professional, this is dismal.

But having lived like this, having tried to do it, I can say it is more difficult than you think.

GRAHAM CLULEY

I accept that, James, but was the canteen in the Ministry of Emergency Situations so poor that he was having to order Chicken McNuggets in instead?

I mean, that's an indictment in itself, isn't it?

JAMES BALL

Have you eaten in post-Soviet universities or public institutions? Because if you have, I suspect you might have more sympathy for the McDonald's orders.

JOE

Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?

GRAHAM CLULEY

You are right, Joe. They've just published a new report, 2026 State of the Cybersecurity Attack Surface.

They analysed over 800,000 real IT assets to find out how exposed organisations actually are.

JOE

And I'm guessing everything is hunky-dory.

GRAHAM CLULEY

Not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.

JOE

One in three. That's terrible.

GRAHAM CLULEY

Isn't it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.

JOE

So the tools don't even know those assets exist?

GRAHAM CLULEY

Right. Ghost assets wandering around your network, unprotected, unmonitored.

JOE

Like a retired geography teacher who's somehow still on the school network.

Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.

GRAHAM CLULEY

Yeah, yeah, yeah, I guess so, Joe. The point is, your attackers will find him before you do, because they are specifically looking for the forgotten, the unpatched, the invisible.

That's the path of least resistance.

JOE

So what does the report tell us to actually do about it?

GRAHAM CLULEY

Arctic Wolf's report covers how to prioritise the exposures that actually matter, cut through all that noise, and verify that when you fix something, it actually stays fixed.

And the report is free to download. Free.

JOE

I like that. Where do I get it?

GRAHAM CLULEY

SmashingSecurity.com/ArcticWolf.

JOE

That's SmashingSecurity.com/ArcticWolf. And thanks to Arctic Wolf for supporting the show.

GRAHAM CLULEY

James, what have you got for us this week?

JAMES BALL

So it's a real sort of who's the good guys, who's the bad guys here, but have you come across Suno, the AI music generator?

GRAHAM CLULEY

I have, and what's more, I'm ashamed to say I have used it to generate AI music.

JAMES BALL

What AI music did you generate?

GRAHAM CLULEY

Well, I generated the theme tune for The AI Fix, which was a podcast.

I'm no longer involved in The AI Fix, but it was a weekly podcast about AI developments, which I did for a couple of years. And it did it. I mean, it was a fantastic song.

The AI Fix, a digital zoo. Smart machines, bots with brains, what will they do? Fly us to Mars or bake a bad cake? World domination, a silly mistake.

JAMES BALL

Bots with brains.

GRAHAM CLULEY

It was very catchy. In fact, we had so many people who said they loved the song that we ended up putting it on Spotify.

And so far, I think I've made the sum total of 4 pence out of it.

JAMES BALL

I saw you in the top 10% of earners then. So yes, it is quite fun to play with. You can sort of give it pretty much any lyrics or any genre and ask it to mix things up.

It tends to make very middle-of-the-road, very sort of basic composition, but it's quite a fun thing to play with.

But inevitably quite contentious in the same way as if you post any AI art, people say, well, you've just taken a job from an illustrator.

If you use Suno music, people say, you know, you're killing music.

JAMES BALL

And in some cases, people absolutely are.

In others, if you would never go to pay a musician anyway, you know, if that budget wasn't there, it's just creating something that wouldn't otherwise exist.

There are all sorts of views on this, but—

GRAHAM CLULEY

I have to say, by the way, despite the fact that I have used it, I do feel completely dirty and appalled at myself for having used it.

And my opinion on that has strengthened only over time.

GRAHAM CLULEY

So I do think it's completely reprehensible of me. Like I said, I'm not involved in the podcast anymore, but I have made 4 pence out of it.

JAMES BALL

So, well, I hope that you donate that to an artist support charity or to someone campaigning for reforms to the copyright law for the AI era.

But it means essentially Suno is in the middle of very similar lawsuits to a lot of the other AI companies.

What it generates, there's always a bit of contention — is that original, et cetera?

But the real row is over how they were trained and have they improperly accessed the training material, have they sort of violated that?

I think the best known lawsuit over all of this at the moment is the Anthropic one.

JAMES BALL

Which essentially found that if they bought books secondhand, very cheaply ingested them and churned them through, that's fine. They could do it a dollar a pop, cheaper. That's okay.

But they didn't bother doing that. They just downloaded a load of pirated books. And so they've had to do an out-of-court settlement. I have to do a disclosure here.

Two of my books are in that settlement. If that goes through, Anthropic owe me, I think, about $5,000. I'm not a party to the case otherwise.

GRAHAM CLULEY

The irony is though that Anthropic themselves don't like the idea of, for instance, Chinese AI companies stealing their resources and their knowledge to better their own.

You know, they seem to have thought it was all right for them to take stuff without asking.

But if anyone takes anything from Anthropic without asking, they're not quite so pleased about that.

JAMES BALL

Yes, but you see, it's very different because when you take from one model to train your model, they call it distillation.

And because they give it a different name, it's obviously entirely different morally and legally. It is not.

They are really genuinely kicking off at the Chinese companies for exactly the conduct they did.

I mean, exactly right down to a lot of it ends up centring on whether it comes to terms of service violations mean that you accessed unlawfully, etc.

There's lots of very fine points of IP law in this. Now, Suno are right in the middle of all of this.

And to be honest, I think they're in a trickier position than Anthropic and OpenAI, not necessarily because their conduct's any different.

If you want to produce a lot of music, you need to ingest a lot of music. And they have more or less now admitted that they scraped off YouTube, Genius, Deezer, all of these things.

They took a lot of music. Their difficulty is that they're not really up against a bunch of authors who are, you know, generally pretty poor and not that well-resourced.

They're up against big music and big music basically fought this and won this once before.

You know, they beat Napster, they beat LimeWire, they beat all of those, they have a much smaller group who are much more aggressive pursuing them a lot more.

And so Anthropic has got off fairly cheaply for using pirated material.

The question is going to be, if you grab stuff off YouTube and use it to train an AI, that is not in line with how you're supposed to use YouTube. It is very, very dubious.

And they had been dancing around in discovery about whether they'd done this, and now Suno has been hacked and it's been hacked by someone who's put an awful lot of the material online.

And it pretty much categorically seems to show not just that they did train off YouTube, etc., which we kind of knew, but things like exactly how much they've ingested into different parts because it's annotated code.

JAMES BALL

So people can check the code and they can check the annotations, but there's things like 113,879 hours of YouTube Music, 12,287 hours of Deezer, 3,722 of Jamendo.

What I like is that there was one site that had some copyright-free sound and there's only 410 hours from that one. So it sort of tells you some issues.

You know, there is decades and decades and decades worth of original music.

And so if they were ever trying to go, well, prove it, or, you know, you have no evidence of that, this looks dubious.

They'd largely helped themselves to the back catalogue of every musician in the world, and now a hacker has helped themselves to their code.

Now, legally, they're not quite the same status, but morally, that's got to look very similar to a lot of people, isn't it? It's, on one level, a fairly basic hack.

They got in through one programmer using a 2025 worm, Shaihulud. I don't know much about Shai Hulud. Do you?

GRAHAM CLULEY

Yes, Shai Hulud was a worm that hit the npm JavaScript package registry. I think it was in late 2025. We spoke about it in an earlier episode of Smashing Security.

Basically, a developer inside your company would install a booby-trap package and the malware would quietly steal their credentials and then use them to infect other packages that they maintained.

So it would spread itself automatically across your ecosystem.

And to make matters worse, it also dumped all the things it had stolen into a public GitHub repository under the victim's own account, so sort of broadcasting credentials to the world.

So yeah, a real supply chain menace, that one. An unusual worm, but was affecting a large number of organisations potentially and causing quite a big problem.

But once they're in, of course, yeah, the data which can be extracted.

JAMES BALL

The hacker says they've got the customer list, the customer emails, phone numbers, Stripe payment details. They provided 404 a sample of those, which looked legitimate.

But what seems to have been used for the interesting stuff is this is all the GitHub submits and back and forth.

What I found particularly interesting here was I started all sorts of musing about whether this was a sort of Hacker Wars 2.0 and whether this was a sort of revenge for the creative industries type thing.

I also wondered if there was a bit of — it is known that corporates hack each other sometimes for various reasons, because it's useful if material can hit the public domain, and you can kind of launder it if you get a third-party hacker.

It's not legal, but a company could, in theory, get a third-party hacker to get some sensitive information, get that third party to disclose it to a journalist, and that journalist, if they run it in a major outlet, they can then use that journalist's reporting to subpoena the information that was hacked and use it in a court case or similar.

Now, I should stress this is illegal.

I'm using this as a general example of something that lawyers and others have talked me through and said, this is something that everyone thinks other people are doing, and everyone says they, of course, would never touch and never do.

Which is what phone hacking was like in journalism back in the day. Everyone said they didn't do it, but they knew people who did.

GRAHAM CLULEY

But even if it wasn't us, even if it wasn't a Suno rival who was behind this, it could be simply someone who doesn't like the slop which Suno is producing, is against the taking away of work from legitimate musicians and creative types, and wants to have an impact.

And I'm sure you, like myself, have been approached by hacking gangs in the past who've said, we've got this data, we've stolen this information, can you publicise this?

We think this is a good story. And there are many —

JAMES BALL

I've used it sometimes. I mean, essentially you test the public interest of the disclosure versus the fact you don't know the source and the source's motivations.

This was the thing I kind of thought, well, is this some corporate espionage? It doesn't look state to me. Is this exactly that kind of ideological hack? Supposedly not, though.

In a sort of fairly underwhelming line, buried quite deep in the story, the hacker told 404 Media they had no specific motivation for hacking Suno, and said, "I like to hack anything and everything." Now maybe that's true, or maybe that's cover, you know.

It is a clever hack, they've used their access, etc., but they've largely used something off the shelf that someone could grab and play with, you know.

There's not a reason that this has to be super sophisticated or a large number of people, but they're not claiming any ideological motivation here.

But I thought it was a particularly interesting one because it trod on several red buttons all at once.

So I think as well, whatever their motivation, it will end up pulled into the ongoing lawsuits because how could it not?

GRAHAM CLULEY

Well, that's the thing, isn't it? Is this going to be further bad news for Suno, this been released, do you think?

JAMES BALL

Yes, I mean, I assume that they have known that this kind of lawsuit will come from the get-go.

And it's all about fight the case to try and get the best terms you can and then use it to cut a deal for your future relationship. You know, do they take an ownership stake?

Do you come up with licensing terms? Because presumably your eventual model will be Suno Music getting distributed alongside traditional artists.

GRAHAM CLULEY

But this is a rubbish way to do business, isn't it?

Is to commit what some of us would consider to be a crime or to commit something which appears unethical, you know, which is grabbing someone else's music and using it to feed and create your own music.

And then, well, we'll do that now because in the future sometime we'll come to some business relationship or we'll come to some understanding which will make it acceptable.

But by that time we'll have built our business up enough.

JAMES BALL

Yeah, but it is how the entire AI industry has built itself. So, you know, we can say it's skeezy and it's unethical, but yeah, it's morally dubious.

There's maybe no good guys in this story.

JAMES BALL

Maybe the good guys are the big record companies. Everyone loves them. They've never done anything dodgy.

GRAHAM CLULEY

Oh yeah, they're great.

JOE

This week's episode is supported by NordLayer.

GRAHAM CLULEY

NordLayer. And before anyone says anything, no, it's not NordVPN.

JOE

I wasn't going to say that.

GRAHAM CLULEY

You were absolutely going to say that.

GRAHAM CLULEY

They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals. NordLayer is a network security platform built for businesses. Right.

JOE

So what does NordLayer actually do?

GRAHAM CLULEY

Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.

JOE

From a sun lounger, hopefully.

GRAHAM CLULEY

You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem. Credentials intercepted, phishing attacks, unauthorised access.

It's a scary world out there for travelling workers.

JOE

So NordLayer fixes that.

GRAHAM CLULEY

It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second, with zero additional hardware required.

But it goes well beyond just encrypting the connection.

You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.

And if someone leaves the company, you revoke their access immediately.

JOE

No more ex-employees still wandering around your systems 6 months later.

GRAHAM CLULEY

No more of that. And it will block malicious sites, risky downloads, dangerous domains, and it can even detect shadow apps.

So if someone on your team has started using some AI tool that your security team hasn't approved—

GRAHAM CLULEY

Yeah, well, whatever. NordLayer can spot that too. And there's no complex infrastructure to set up. Apparently you can be up and running in just about 10 minutes.

GRAHAM CLULEY

10 minutes. Plans start from just $8 per user per month. And right now there is a summer sale. New customers get up to 20% off annual plans until the end of August 2026.

Use the code NLSUMMER26 at checkout.

JOE

Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.

GRAHAM CLULEY

Yep, go ahead, write it down.

JOE

What's the code again? I forgot.

GRAHAM CLULEY

Oh, Joe. NLSUMMER26.

JOE

Got it. Off to nordlayer.com/smashingigo.

GRAHAM CLULEY

And thanks to NordLayer for supporting the show. And welcome back, and you join us for our favourite part of the show, the part of the show that we like to call Pick of the Week.

Pick of the Week.

JAMES BALL

Pick of the Week.

GRAHAM CLULEY

Pick of the Week is the part of the show where everyone chooses something they like.

Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.

It doesn't have to be security related necessarily. Well, my Pick of the Week this week is not security related.

This last weekend I had the chance to see a one-woman play at the Bristol Old Vic, and it so happens I am a big fan of Nina Simone, the music of Nina Simone.

I think she was incredible. Incredible, and her music continues to be. And the play I saw was a one-woman play called Black Is the Colour of My Voice.

And an American actor called Afia Campbell is the writer and performer of the show, which sees her as Nina Bordeaux. She's not Nina Simone.

She's Nina Bordeaux, possibly for legal reasons.

JAMES BALL

A legally distinct person, yes.

GRAHAM CLULEY

Yes, so it appears the performance was inspired by Nina Simone. It's about this woman who is very skilled at playing the piano from a young age.

It's a life shaped by racism and civil rights and Martin Luther King and all these things are crossing over into her life.

Anyway, Afia Campbell, she doesn't play the piano, but she sings, and there is a musical accompaniment as well during the performance.

She weaves in some of Nina Simone's really beautiful, haunting songs. I Loves You Porgy, Wild Is the Wind. They're all in the narrative as well. It's about an hour and a quarter long.

I really, really liked it. It was spellbinding. It got your attention. The music obviously was band-bloody-tastic. It's on tour.

And if that sounds like your kind of thing, go and check it out. Link in the show notes. So, Black Is the Colour of My Voice is my pick of the week.

JAMES BALL

That sounds rather wonderful. Mine's possibly a little more lowbrow. But I'm not ashamed of that.

Netflix have launched the second season of their live-action Avatar: The Last Airbender. Oh yes. Which has had very mixed reviews from fans.

There was famously a terrible Avatar movie about 10, 15 years ago that I think is one of the most panned movies of all time. The fandom hated it, the casuals hated it too.

GRAHAM CLULEY

This isn't the James Cameron Avatar movie. This is The Last Airbender. The Last Airbender.

JAMES BALL

Yes. Right. So it's based on this 3 seasons animated. It was kind of in the Pokémon era where everyone was very into anime.

And it was sort of widely regarded as one of the best sort of kids anime series of all time. So this live action season, everyone praises the actors.

You know, these are real children acting. And apparently the SFX are good, but, you know, it's different. It's live action. It's trying to be a bit more adult.

I think it's trying to get people who watched the cartoon as a kid. And so they've been fairly mixed.

Anyway, all of this made me realise I'd never watched the actual original series. Oh, okay. You know, I was a little bit old for it when it was out. But I love that kind of thing.

I was too old for the Pokémon cartoon. They were sort of fun background if you're working or whatever.

And so I've been working my way through these, the original animated Avatar: The Last Airbender.

And honestly, if you've got a sort of 8, 9, 10-year-old, sit down and watch it with them.

Or if you've just got the brain of a child like I do, have it on while you do something else. It is not emotionally taxing, but they are well plotted. They are well structured.

They are 20 minutes long an episode. You know that the story completes, it's 3 seasons and done. It's lovely. And I can see why people loved it. It's a really good show.

So Avatar: The Last Airbender, the latest recommendation anyone will give you for that, I'm sure.

GRAHAM CLULEY

Okay, but you are recommending the animated series, not the live action. Not the live action.

JAMES BALL

I will probably try the live action, but I thought, you know what, why don't I go to the one everyone agrees is good? And I'll make my own judgment about the live action later.

But yeah, I can see why people fell in love with the animated one.

GRAHAM CLULEY

Fantastic. Well, that just about wraps up the show for this week. Thank you so much, James, for coming along.

I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?

JAMES BALL

I am @jamesrball.com on Bluesky. I'm at the same web address. You can find me in the New World Magazine or the i Newspaper or about 6 other places.

GRAHAM CLULEY

And Smashing Security is on social media as well. You can follow it on Blue Sky, on Reddit, on Mastodon. You can also find me, Graham Cluley, on those places or on LinkedIn.

And don't forget to ensure you never miss another episode of Smashing Security. Find it in your favourite podcast apps such as Spotify, Pocket Casts, and Apple Podcasts.

For episode show notes, sponsorship info, guest list, and the entire back catalogue of 477 episodes, check out smashingsecurity.com. Until next time, cheerio, bye-bye, farewell.

You've been listening to Smashing Security with me, Graham Cluley.

A big, big thanks to James Ball for joining us this week and to this episode's sponsors, NordLayer, Vanta, and Arctic Wolf.

Go and check out their services and products, why don't you? And also to the following fine folks who are amongst our fantastic Smashing Security patrons.

So picking some out of the hat at random, we start with Matt H and Alvin. Also big thanks to Yuri Taraday and to the letter J, just the letter J, single letter.

Most efficient patron we have ever encountered. Extraordinary commitment to brevity there. Thank you, Jay.

Thank you also to Jessica Orth and Alboros, who remains as delightfully mysterious as ever. And to Lisa, who continues to prove that one name is more than sufficient.

Cheers also to Dan H, who got slightly further than a single letter like Jay, but also kept things admirably concise. And to David Smythe, or is it Smith? I don't know.

Either way, it's a solid sounding name if I ever heard one. And finally for this week, Marvin 71. Marvin, we are still wondering about the other 70 Marvins.

Maybe you can get them to sign up as well.

Those are just a few members of Smashing Security Plus, which means that they get their episodes ad-free and earlier than the general public.

And of course, they can have names pulled out at random to be mercilessly mocked at the end of the show.

If you would like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details. Now, you can also support the show in other ways.

You can like, you can subscribe, you can leave a 5-star review. All that is really appreciated. And do tell your friends about the podcast too.

Go on, go and bash them on the head with a balloon. That's pretty painless because every little bit helps, and you spreading the word really does help me.

Until next time, cheerio, bye-bye.


文章来源: https://grahamcluley.com/smashing-security-podcast-477/
如有侵权请联系:admin#unsafe.sh