How a hacker could have Rickrolled the entire World Cup artwork

How a hacker could have Rickrolled the entire World Cup

Smashing Security

June 24, 2026

A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe.
Speakers: Graham Cluley, Danny Palmer, Joe, Jeffrey Wheatman
**Graham Cluley** (0:02)
Did she think of sending a truth social message to the winner of the inaugural FIFA Peace Prize? Because he's normally online, and I believe he probably has the mobile phone number of the FIFA president.

**SPEAKER_3** (0:25)
Smashing Security, episode 473 How a hacker could have rickrolled the entire World Cup, with Graham Cluley and special guest Danny Palmer.

**Graham Cluley** (0:36)
Hello, hello, and welcome to Smashing Security, episode 473 My name's Graham Cluley.

**Danny Palmer** (0:41)
And I'm Danny Palmer.

**Graham Cluley** (0:42)
Danny, great to have you on the show again. As regular listeners know, you are a cyber security journalist. Busy month, isn't it? I mean, there's lots of events going on and things like that. You must be going from event to event, writing story after story.

**Danny Palmer** (0:57)
It has been busy, of course, as you well know as well. It was Info Security Europe this month. You were on stage hosting.

**Graham Cluley** (1:03)
I was.

**Danny Palmer** (1:04)
I saw you on the stage. I didn't get to see you in person. I did see you in person at one point, actually.

**Graham Cluley** (1:10)
Did you?

**Danny Palmer** (1:10)
But...

**Graham Cluley** (1:11)
You should have given me a wave.

**Danny Palmer** (1:12)
Well, this is from behind, and you turned into the toilets. So I thought you wouldn't want to tap on the shoulder at that point.
I could have sprinted up, but I doubt it would have been welcomed. But no, it was a good show. It's one of the biggest cybersecurity events in Europe. But this time, I was working at InfoSecurity magazine, so I was covering it from that side. So it was very hands on. Lots of people seem to enjoy the talks, good feedback from sessions, people like you, obviously. There's always nice things said about you and feedback from the event. Thank you. That's good. But yeah, it was grand.

**Graham Cluley** (1:46)
Well, before we kick off, let's thank this week's wonderful sponsors, Black Kite, Proton Pass, and Vanta. We'll be hearing more about them later on in the podcast.
This week on Smashing Security, we won't be talking about how Brazil suspended its mobile phone emergency alert system after a hacker sent warnings to phones across the country. You'll hear no discussion of how tech site Gizmodo has been caught hitting readers with ClickFix malware prompts. And we won't even mention how two men have pled guilty to the £39 million cyberattack on Transport for London, which impacted 10 million commuters. So Danny, what are you going to be talking about this week?

**Danny Palmer** (2:31)
I'm going to be talking about a security issue at FIFA, which could have got everyone rickrolled.

**Graham Cluley** (2:37)
And I'm going to be talking about a devastating Dutch fraud epidemic that has forced police into a bold response involving motorway billboards.
Plus don't miss our featured interview with Jeffrey Wheatman, where we'll be looking at Black Kite's report into ransomware and extortion attacks across Europe. All this and much more coming up on this episode of Smashing Security.

**Joe** (3:02)
Graham, what's this about a new report from one of our sponsors?

**Graham Cluley** (3:05)
Yes, Black Kite have just put out their first ever European cyber risk report. And oh my goodness, they've been looking into ransomware attacks across Europe for the last year and a half or so.

**Joe** (3:16)
And let me guess, everything is fine and we have nothing to worry about?

**Graham Cluley** (3:19)
Well, ransomware is up 55% year on year in the first four months of 2026 alone.

**Joe** (3:26)
So not fine?

**Graham Cluley** (3:27)
No, Joe, not fine at all. Nearly 70% of all European ransomware activity is concentrated in just five countries. And this report from Black Kite breaks down exactly where the attacks are hitting hardest and which hacking groups are responsible.

**Joe** (3:43)
So is there anything in there beyond the headline numbers?

**Graham Cluley** (3:46)
The bit that really struck me is what they found about third-party risks. A lot of companies aren't being attacked directly. Instead they're being caught in the blast radius of an attack on one of their suppliers.

**Joe** (3:59)
Right, you're only as secure as the weakest link in your supply chain.

**Graham Cluley** (4:02)
And the report has some real-world examples that illustrate this perfectly. For instance, there's a Swedish company, it has an unpronounceable name. They got hit and that ended up causing huge problems at hundreds of organisations exposing the data of over a million people.

**Joe** (4:17)
All from one incident?

**Graham Cluley** (4:19)
All from one incident. And the report also covers how regulations like NIST 2 and DORA are forcing European businesses to get much more serious about all of this.

55 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000773766849