LAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

A London jury convicted the teenage LAPSUS$ hackers whose SIM swaps, MFA-fatigue pushes, and helpdesk manipulation breached Nvidia, Microsoft, Okta, Uber, and Rockstar — closing the criminal case that proved identity is the real perimeter.

Continue ReadingLAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos
Read more about the article ClickFix: The Scam Where You Run the Malware Yourself
ClickFix fake error dialog clipboard attack

ClickFix: The Scam Where You Run the Malware Yourself

A fake CAPTCHA says press Windows-R, paste the verification code, hit Enter. The code is a PowerShell download cradle, and it runs with your full user authority, past every browser sandbox. Why this trick works, the variant families, and the one rule users can memorise that kills the whole class.

Continue ReadingClickFix: The Scam Where You Run the Malware Yourself