| ~7 MIN READ |
|
Two of today's biggest stories are about AI going rogue: one's a criminal gang faking a Claude download page, the other is OpenAI's own models cheating on a test by hacking a different company. Pick your nightmare. Meanwhile a Swiss train maker just told a ransomware gang to get lost for the second time in six years, so at least somebody's got a spine. This week the line between "attacker" and "AI behaving badly" got blurrier than ever, and the fallout landed on real people either way. Here's what changed, what got worse, and one habit that actually helps.
PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
Data Breach
🔌 Australia's Biggest Energy Company Got Hacked. Now Someone's Blackmailing 4.8 Million Customers.
Intro
Origin Energy just told 4.8 million Australians their personal data might be in a stranger's hands. And that stranger wants to talk.
What Happened
Origin, Australia's largest energy retailer, confirmed on July 23 that an unknown attacker breached systems holding customer names, addresses, birth dates, phone numbers, and partial financial details. A threat actor going by "John Doe" claims records on 2 million customers and gave the company two weeks to negotiate over Signal before going public.
Why It Matters
This is the exact playbook that made the Optus and Medibank breaches national news in Australia: a household-name utility, millions of affected people, and an attacker who knows exactly how much leverage that combination buys.
The Other Side
Origin says the exposed financial details are incomplete and can't be used to hijack accounts or make charges, and it's working with federal police and privacy regulators rather than negotiating.
TL;DR: A hacker claiming 2 million Origin Energy customer records is demanding negotiation within two weeks or the data goes public.
Further reading: BleepingComputer
|
|
The AI Agent You Can Trust
The best assistants don't multitask their attention across a hundred tools. Neither does Catch. It's an AI agent that focuses on one thing — the admin work you'd rather not touch — and does it exceptionally well.
Scheduling, flights, restaurants, follow-ups, vendors, clients. You hand it over; Catch handles the back-and-forth and comes back with it done.
No context-switching. No dropped balls. Just your admin, quietly cleared — so your focus stays on the work only you can do.
Meet the agent built for admin, and it'll be ready to work before your next meeting.
Get started at catchagent.ai — and give your attention back to what matters.
|
|
|
Making AI work day to day is becoming its own job. Hear from three people doing it, on demand. Watch now
Strange but real
🖥️ A Manager Tried to Learn Nmap for Fun. He Took Down the Whole Company Network Instead.
Intro
Roger, a manager at a mid-sized company, decided to spend a weekend teaching himself Nmap by scanning his employer's entire internal network. He did not tell IT.
What Happened
He kicked off the scan Friday and left for the weekend. By Monday the network had completely crashed: no VPN, no remote access, nothing. IT traced the outage to Roger's laptop, and disconnecting it brought everything back to life.
Why It Matters
Rather than admit what he'd done, Roger claimed he might have picked up a virus while traveling to the company's China office. IT spent nearly a week scanning his machine for malware that was never there.
The Other Side
Curiosity about how your own network is configured isn't a bad instinct; running an unannounced full scan against live production infrastructure is where it went wrong.
TL;DR: A manager crashed his company's entire network trying to learn Nmap, then blamed a nonexistent virus to cover it up.
Further reading: The Register
|
The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.

