Don't Be A Sitting Duck Podcast

Don't Be A Sitting Duck Podcast

Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!

Episodes

August 1, 2025 2 mins
  • In this episode, we dig into the newly discovered FileFix attack—a clever and stealthy cyber trick that exploits how people use their clipboard. No malware. No download. Just voice‑less manipulation of Windows Explorer and the clipboard to execute hidden PowerShell commands. We’ll break down how it works, why it’s so dangerous, and what businesses should do today to stay protected.Click here for full Transcript, shownotes and resou...
  • Mark as Played

    Qantas has joined the long list of major companies hit by cybercrime — this time, through a third-party contact centre platform. In this special Don’t Be A Sitting Duck episode, Leigh Kefford unpacks how customer data was leaked, what it means for businesses, and why vendor risk can no longer be ignored.


    What You’ll Learn:

    • Which customer details were compromised
    • Why third-party platforms are your biggest hidden risk
    • Steps to au...
    Mark as Played

    Ransomware is more dangerous — and more accessible — than ever before. In this episode of Don’t Be A Sitting Duck, Leigh Kefford breaks down what’s really happening behind the scenes, how local businesses are being impacted, and the 5 non-negotiable actions your business must take to stay protected.

    In This Episode:

      • Why ransomware is exploding in 2025
      • The biggest risks for regional businesses
      • How phishing, pat...
    Mark as Played

    Is your business really ready for a cyberattack? If you’re in banking, insurance, or superannuation — APRA’s CPS 234 isn’t just a suggestion, it’s mandatory.

    In this extended episode, Leigh Kefford unpacks the what, why, and how of CPS 234 — Australia’s leading information security standard for regulated financial entities. But even if you’re not regulated, there’s a lot to learn here.

    • What CPS 234 requires from boards, managemen...
    Mark as Played

    From 30 May 2025, Australian businesses earning over $3 million per year must report any ransomware or cyber extortion payments to the government within 72 hours. In this episode, Leigh explores:

    • What qualifies as a reportable ransomware or cyber extortion payment

    • Who needs to report and how to calculate turnover thresholds

    • What’s included in the 72-hour reporting requirement

    • Why these reports matter for Australia’s national cyber ...

    Mark as Played

    Fatalities caused by cyberattacks in hospitals? That’s what healthcare leaders are bracing for—and that’s just the beginning. In this episode of the Don't Be A Sitting Duck Podcast, Leigh Kefford unpacks the critical cybersecurity threats facing Australia right now.

    We explore:

    • The growing belief that it’s only a matter of time before a cyberattack leads to death in healthcare.

    • New legislation requiring ransomware payment disc...

    Mark as Played

    In this episode, we delve into the pressing cybersecurity issues facing Australia today. From the dangers of unmanaged digital assets to the rise of AI-generated election misinformation, and the recent malware attacks on major banks, we uncover the vulnerabilities that businesses and individuals must address. Tune in to learn actionable steps to protect your digital environment.​

    👉 Full transcript and show notes available at ⁠sitt...

    Mark as Played

    Thousands of Australians have had their online banking passwords stolen by stealthy infostealer malware like RedLine and Raccoon Stealer. These credentials are now being sold on dark web marketplaces, putting businesses and individuals at risk. In this episode, I break down how infostealer malware works, why it's so dangerous, and the key steps you must take to protect your business.

    Episode Notes / Show Notes:

    • How inf...

    Mark as Played

    A coordinated cyberattack hit several Australian super funds—including AustralianSuper, Hostplus, and Rest—leading to major financial and data loss. This episode explores how the breach happened, the method known as credential stuffing, and steps businesses can take to avoid a similar fate.

    Main Stories Covered:

    • Credential stuffing attacks on super funds

    • $500,000 stolen from compromised AustralianSuper accounts

    • The role of weak pas...

    Mark as Played

    February 2025 saw ransomware attacks hit an all-time high, with cybercriminals exploiting software vulnerabilities to hold businesses hostage. At the same time, social engineering scams are becoming more deceptive, tricking victims into handing over sensitive information.

    In this episode, I break down:
    ✅ Why ransomware attacks skyrocketed and how businesses are being targeted
    ✅ The growing threat of social engineering scams and how to...

    Mark as Played

    In this episode, we delve into recent significant cybersecurity incidents: a massive data breach at Brydens Lawyers, ASIC's legal action against FIIG Securities for prolonged cybersecurity failures, and the emergence of the Ballista botnet exploiting vulnerabilities in TP-Link routers. These events highlight the critical need for robust cybersecurity measures across all sectors. For more insights and resources, visit sittingduc...

    Mark as Played

    Papua New Guinea is going digital—but is it secure?

    In this episode of Don't Be a Sitting Duck, we dive into the cybersecurity challenges facing PNG’s government, businesses, and critical infrastructure. We discuss real-life cyberattacks—including ransomware incidents affecting PNG’s Department of Finance and the Internal Revenue Commission—and explore what needs to change to protect the nation’s digital future.

    Key topics covere...

    Mark as Played

    A major cybersecurity breach has rocked Australia’s healthcare sector. Genea, a leading IVF provider, was hit by a cyberattack that compromised sensitive patient data, exposing medical histories, test results, and personal information on the dark web. In this episode, we break down how the attack happened, why it matters, and—most importantly—what businesses can do to prevent similar breaches.

    🔗 Show notes & resources: sittingd...

    Mark as Played
    In this episode of Don't Be A Sitting Duck, we unpack APRA’s latest regulatory updates: CPS 230 on Operational Risk Management and CPS 234 on Information Security. With CPS 230 set to take effect in July 2025, organizations must prepare for stronger risk management, business continuity, and third-party oversight—especially in cloud outsourcing. Plus, we break down CPS 234, which mandates strict cybersecurity controls, risk assessm...
    Mark as Played
    Cybercriminals are relentless, and this week’s stories prove just how high the stakes are. North Korea’s Lazarus Group Strikes Again: The notorious state-backed hacking group has pulled off another major crypto heist, stealing $21 million in Ethereum from the Bybit exchange. But how did they do it, and what does this mean for the future of cryptocurrency security? Australian IVF Data Breach: A major Australian fertility clinic ha...
    Mark as Played
    Papua New Guinea’s Tax Office Hacked – What You Need to Know! The Internal Revenue Commission (IRC) of Papua New Guinea has suffered a devastating ransomware attack, shutting down critical systems and exposing major cybersecurity weaknesses. With government agencies and businesses now on high alert, this breach raises urgent questions about cybersecurity in PNG and beyond. In this episode of the Don't Be A Sitting Duck Podcast, we...
    Mark as Played
    Is your favorite game a cybersecurity threat? In today’s episode of Don't Be A Sitting Duck, we dive into a shocking Steam malware case where a popular game turned into a digital trap. Plus, the Australian Federal Police have released a romance scam playbook used by criminals—learn how scammers manipulate victims with scripted deception. Lastly, we discuss four practical ways to bring cybersecurity awareness into your community and...
    Mark as Played
    In this episode of Don't Be A Sitting Duck, we’re breaking down three major cybersecurity threats that businesses need to be aware of: CommBank & Telstra’s Fraud Detection Partnership – A new fraud indicator system is set to improve identity theft detection by 25%. Learn how this technology works and what businesses can do to protect themselves from financial fraud. Valentine’s Day Phishing Scams – Cybercriminals are taking advanta...
    Mark as Played
    In today’s episode, we dive into three critical cybersecurity threats that businesses can’t afford to ignore. Apple has just released an urgent patch for a zero-day vulnerability affecting iPhones and iPads—find out why it matters and what you should do immediately. Meanwhile, cyber threats in the healthcare sector are escalating, pushing the need for stronger collaboration and proactive defense strategies. And in Australia, cyber ...
    Mark as Played
    Artificial Intelligence is evolving, but so are cyber threats. In this episode of Don't Be A Sitting Duck, we break down DeepSeek AI and how cybercriminals are leveraging it to supercharge phishing, malware, and business email compromise attacks. Learn how to defend against AI-driven threats and ensure your business isn’t an easy target. What is DeepSeek AI? How cybercriminals are weaponizing AI Why phishing attacks are getting ha...
    Mark as Played

    Popular Podcasts

      If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

      New Heights with Jason & Travis Kelce

      Football’s funniest family duo — Jason Kelce of the Philadelphia Eagles and Travis Kelce of the Kansas City Chiefs — team up to provide next-level access to life in the league as it unfolds. The two brothers and Super Bowl champions drop weekly insights about the weekly slate of games and share their INSIDE perspectives on trending NFL news and sports headlines. They also endlessly rag on each other as brothers do, chat the latest in pop culture and welcome some very popular and well-known friends to chat with them. Check out new episodes every Wednesday. Follow New Heights on the Wondery App, YouTube or wherever you get your podcasts. You can listen to new episodes early and ad-free, and get exclusive content on Wondery+. Join Wondery+ in the Wondery App, Apple Podcasts or Spotify. And join our new membership for a unique fan experience by going to the New Heights YouTube channel now!

      24/7 News: The Latest

      The latest news in 4 minutes updated every hour, every day.

      Dateline NBC

      Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

      NFL Daily with Gregg Rosenthal

      Gregg Rosenthal and a rotating crew of elite NFL Media co-hosts, including Patrick Claybon, Colleen Wolfe, Steve Wyche, Nick Shook and Jourdan Rodrigue of The Athletic get you caught up daily on all the NFL news and analysis you need to be smarter and funnier than your friends.

    Advertise With Us
    Music, radio and podcasts, all free. Listen online or download the iHeart App.

    Connect

    © 2025 iHeartMedia, Inc.