The Awareness Angle: Cyber Security Awareness and Human Risk
Aug 3, 2026 · 1 hr 7 min · 11 segments
This week, a $70 million Bitcoin heist that took just 41 minutes, a government helpdesk breach that leaked 600,000 school staff records, and an AI security story where Anthropic's Claude broke into…
Okay, the first story in Breach Watch today, hackers talk their way into a government helpdesk and dump 600,000 school and university staff records on the dark web.
So this is the UK's Department for Education was breached by a group calling itself Exfil Squad.
Which targeted an external helpdesk used by school and university staff and local authorities.
The attackers manipulated a person rather than breaking through using technology or a vulnerability or a hole in the system.
But as a result, more than 600,000 records were taken, including full names, work email addresses, and phone numbers of government and university staff and senior school leaders such as headteachers.
And The Times, the newspaper here in the UK, have verified the data, so it's all, it, it's been verified.
The records were posted on the dark, dark web and the department pulled systems offline and is working with the Information Commissioner's Office, the ICO, the National Crime Agency, and the NCSC.
This is all a bit more- You know, someone's contacted a support desk, they've sounded convincing, someone's basically given them access or given them a password reset probably, which is exactly all they needed to gain access.
And the person on the help desk is probably feeling quite guilty now if they know it was them, which isn't fair.
I guess it depends on the processes that were in place for, like, checking if they were legitimate and maybe, maybe they've bypassed it, maybe they were manipulated to bypass it.
One interesting thing is, so one expert has put it as criminals can piece together information like a jigsaw and send follow-up messages.
So a headteacher might get an email that looks like it came from the Department of Educ- for Education, but in fact it isn't.
Okay, the first story in Breach Watch today, hackers talk their way into a government helpdesk and dump 600,000 school and university staff records on the dark web.
So this is the UK's Department for Education was breached by a group calling itself Exfil Squad.
Which targeted an external helpdesk used by school and university staff and local authorities.
The attackers manipulated a person rather than breaking through using technology or a vulnerability or a hole in the system.
But as a result, more than 600,000 records were taken, including full names, work email addresses, and phone numbers of government and university staff and senior school leaders such as headteachers.
And The Times, the newspaper here in the UK, have verified the data, so it's all, it, it's been verified.
The records were posted on the dark, dark web and the department pulled systems offline and is working with the Information Commissioner's Office, the ICO, the National Crime Agency, and the NCSC.
This is all a bit more- You know, someone's contacted a support desk, they've sounded convincing, someone's basically given them access or given them a password reset probably, which is exactly all they needed to gain access.
And the person on the help desk is probably feeling quite guilty now if they know it was them, which isn't fair.
I guess it depends on the processes that were in place for, like, checking if they were legitimate and maybe, maybe they've bypassed it, maybe they were manipulated to bypass it.
One interesting thing is, so one expert has put it as criminals can piece together information like a jigsaw and send follow-up messages.
So a headteacher might get an email that looks like it came from the Department of Educ- for Education, but in fact it isn't.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.