news.mlab.sh
Back to the feed
threat-intel

Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

High
Summary

This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing the contact information of over 64,000 officers, including informants, as part of a broader intelligence-gathering operation. The episode highlights how the attack was not limited to the Netherlands but extended to other NATO countries and Ukraine, emphasizing the use of phishing emails to gain access to targets. The host and guest discuss the attack’s implications and the tactics employed by the group, referencing the use of personalized invitations and QR codes to bypass security measures.

This week on Smashing Security, we won't be talking about how a man in India has been accused of using an AI chatbot to help him plan a triple murder. You’ll hear no discussion of how the July 2026 patch update from Microsoft comes with security updates for a record-breaking 570 vulnerabilities. And we won’t even mention how plugging in an LG monitor can automatically install adware on your Windows PC that bombards you with McAfee pop-ups without ever asking your permission. So James, what are you going to be talking about this week?

I am going to be talking about the Suno hack because I think there’s quite a lot in there.

And I’m going to be discussing why ordering McNuggets may not be good for your online privacy, particularly if you’re a hacker.

All this and much more coming up in this episode of Smashing Security.

Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today’s sponsors, Vanta.

We’ve got a question for you. What’s the thing that keeps you staring at the ceiling at 2 AM when it comes to your company’s security?

Is it wondering whether you’ve actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?

Why on earth are we still running our entire security program out of a spreadsheet?

If any of that hit a little too close to home, that’s where Vanta comes in. Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.

Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place and keeps your security programme audit-ready around the clock.

Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on. The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night’s sleep.

Sounds lush. Find out more and get started at vanta.com/smashing, and a big thank you to Vanta for supporting the show. Now, chums, chums, imagine if you can that you are a spy working for the Russians, all right?

What’s the worst thing that could possibly occur if you were actually working for the Russians?

Would your biggest threat be having your identity exposed, being found out by the FBI?

Would it be about Western intelligence agencies finding out where you’re based, locating your identity and extraditing you?

Or would the biggest threat actually be about Chicken McNuggets? That is the thing we’re going to be exploring. Do you stand anywhere in particular on Chicken McNuggets, James?

I’m actually a big fan of them. For a long time as a kid, I ate very little else.

And so I’ve travelled in many, many countries in the world and every single one that had a McDonald’s, I’ve been to the McDonald’s in that country.

I’ve had McNuggets in India, in China, in Australia, and in Norway. Indian McNuggets are the best, by the way.

Oh, there’s a difference, is there, between McNuggets? I can’t believe we’re having this conversation, but—

I should stress, I eat in normal, good restaurants as well. This isn’t expensive.

Well, back in September 2024, Dutch cybersecurity experts discovered that someone had burrowed into the computer systems of the Netherlands National Police Force and they had accessed the email account of a staff member there.

And via that account, they had then grabbed the data of tens of thousands — I think over 64,000 — officers in the force.

Officers’ names, addresses, identities, also of their informants. The Dutch intelligence agency at the time described it as the first time that the country had fallen victim to deliberate sabotage by a Russian-backed hacking group.

It caused a big furore in the press, as you can expect, and they didn't break in to plant ransomware or extort money — this was all about stealing intelligence, gathering intel in order to exploit it later.

So this was effectively a police force’s entire contact database — you know who the police are, who they’re talking to, who talks to them.

And Microsoft, working with Dutch intelligence, publicly named the hacking group responsible for this back in May 2025 as Void Blizzard.

I love the names which are sometimes given to these groups.

It sounds like a World of Warcraft patch, doesn’t it?

Yes. I mean, they called it Void Blizzard. There was another group of researchers who I believe called them Laundry Bear.

Well, that would probably be the official US designation, wouldn't it? Because everything that’s believed to be Russian state-linked is always given bear. So Fancy Bear is the GRU.

And we’ve got Crazy Bear.

Military Bear will be a different military intelligence unit.

Yeah, I know, but Laundry Bear — you’d almost be embarrassed to be a member of Laundry Bear compared to Fancy Bear, wouldn't you, I think?

It does suggest where you are in the pecking order, doesn't it?

Which, given this is a pretty good hack, actually getting 64,000 officers and the contact database, I think maybe they deserve a promotion — Laundry, maybe to Scullery, Scullery Bear.

I think they’re being trolled, basically.

So anyway, Microsoft and the Dutch intelligence agency said that this attack hadn't just targeted the police, it turns out, but other sectors — defence, healthcare, government — not just the Netherlands as well, but also countries across NATO and Ukraine as well, of course.

So you can all kind of guess where this attack is likely to be coming from, and the typical attack would come in the form of a personal invitation via email. You might get invited to a European Defence Summit, and if you click on the link or you scan the QR code sent in the PDF which you’ve been sent, you get taken to a login page.

Looks like Microsoft Teams you’re logging into, and of course it’s the usual story — t

Read the full article at Graham Cluley