Remote-control rickshaws and rogue book marketers artwork

Remote-control rickshaws and rogue book marketers

Smashing Security

July 15, 2026

An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed.
Speakers: Graham Cluley, Geoff White, Joe
**Graham Cluley** (0:03)
I didn't know that e-rickshaws existed.

**Geoff White** (0:06)
We've talked about some ewickshaw, but... It only gives wise to people called ewick. It's a tiny market, particularly in India.

**Graham Cluley** (0:13)
I suppose...

**Geoff White** (0:14)
I took an ewickshaw here. I took a Geoffshaw, but that's fine.

**SPEAKER_4** (0:27)
Smashing Security, Episode 476, Remote Control Rickshaws and Rogue Book Marketers, with Graham Cluley and special guest Geoff White.

**Graham Cluley** (0:38)
Hello, hello, and welcome to Smashing Security, Episode 476 My name's Graham Cluley.

**Geoff White** (0:42)
And I'm Geoff White.

**Graham Cluley** (0:44)
Geoff, welcome back to the show. Always a pleasure having you here. Now, you've been a busy chap, haven't you, in the last week or two, with your latest... Well, do you consider yourself a content creator, or does that gag slightly at the back of your throat?

**Geoff White** (0:56)
Oh, gags more than slightly.
It's technically true in that I create something and it is content.
But it's like describing yourself as a mouth-breathing food tube. It just sounds a bit clinical, a real person. But yes, I've been creating content, specifically a new series of what was the Lazarus Heist podcast, and has now been renamed Cyber Hack.
One season four of Cyber Hack now actually, so just published, which is all about a gang that will be very familiar to you, Graham and the Conti Ransomware gang. It's always irked me that there was this amazing leak of internal chats from Conti, all the things they typed to each other for two years, basically spilled all over the internet, for reasons that we go into in the podcast. I'd always wondered, I'd seen people like Brian Krebs had done articles and people had done things with it, but nobody seemed to really do something exciting with it and get to grips with it. So I thought, well, this is great. Podcasts have got an opportunity to go back to those leaks and really mine them. I instantly realized why no one had done anything with it, really impressive, is because it's horrible. It's all in Russian, it's hack a slang Russian. Instead of having the chats though, they chatted to each other. It's just all in one continuous order. It is honestly eye-bleedingly difficult to go through. I went through 47,000 of the messages before I gave up. It's like I've done enough, I've done my job. But what you get is amazing. You get the actual people talking themselves. As they were doing the crime, bitching, slagging each other off, talking about their wives, their girlfriends. It's amazing stuff. It's genuinely amazing.

**Graham Cluley** (2:25)
Fantastic. That's all in the latest episodes of the Cyber Hack right now which you can access via BBC Sounds, I imagine.

**Geoff White** (2:31)
Yeah, and Apple, podcasts, and Spotify, and other places like that.

**Joe** (2:34)
It's everywhere.

**Graham Cluley** (2:35)
Fabulous stuff. Well, before we kick off, let's thank this week's wonderful sponsors, Arctic Wolf, NordLayer, and Vanta. We'll be hearing about them some more later on in the podcast.

**Joe** (2:47)
This week on Smashing Security.

**Graham Cluley** (2:49)
We won't be talking about how a ransomware negotiator has been jailed after working with hackers to extort clients.
You'll hear no discussion of how users of LastPass and Bitwarden have been targeted with fake security alerts. And we won't even mention how a German textile firm has filed for insolvency, blaming a ransomware attack, which shut down production. So Geoff, what are you going to be talking about this week?

**Geoff White** (3:18)
I'm going to be talking about something quite personal, something quite close to home. Attempts, I should say failed attempts, to try and scam me and what I've been doing back to the scammers.

**Graham Cluley** (3:30)
And I'm going to be taking a journey to India and jumping on board an e-rickshaw. Find out what can happen there.
All this and much more coming up in this episode of Smashing Security.

**Joe** (3:44)
This week's episode is supported by NordLayer.

**Graham Cluley** (3:47)
NordLayer, and before anyone says anything, no, it's not NordVPN.

**Joe** (3:52)
I wasn't going to say that.

**Graham Cluley** (3:53)
You were absolutely going to say that, Joe. They are both from NordSecurity, but NordLayer is a completely different product. NordVPN is for individuals. NordLayer is a network security platform built for businesses.

**Joe** (4:07)
Right, so what does NordLayer actually do?

**Graham Cluley** (4:09)
Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.

**Joe** (4:18)
From a sun lounger, hopefully.

**Graham Cluley** (4:19)
You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem. Credentials intercepted, phishing attacks, unauthorised access. It's a scary world out there for travelling workers.

34 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000776790657