Graham Cluley, the veteran cybersecurity expert and co-host of the Smashing Security podcast, recently found himself on the receiving end of a sophisticated social engineering attack that came alarmingly close to succeeding. The scam, which involved a caller impersonating a police detective and spoofing the official Crimestoppers phone number, was designed with one clear objective: to pry loose the 24-word seed phrase for Cluley’s cryptocurrency wallet. That the attack ultimately failed owes less to any flaw in the scammers’ planning and more to Cluley’s professional instincts and a single, telling question that raised his suspicion.
The Call That Started It All: How a Fake Detective Targeted Graham Cluley
Cluley received an unexpected phone call from the number 0800 555 111 — the genuine, well-known contact number for Crimestoppers, the UK crime reporting charity. Number spoofing, a common tactic in which attackers falsify the caller ID information displayed on a victim’s phone, made the incoming call appear legitimate. When Cluley answered, the caller introduced himself as Detective David Pullen and claimed to be working on a computer crime case. The detective immediately put Cluley at ease, stating that he was not in any trouble himself but might be able to assist with an active investigation.
The caller explained that police had arrested a suspect on suspicion of cybercrimes and that, during the examination of digital evidence, they had found information relating to Cluley — specifically, his personal phone number, personal email address, and even a scanned copy of his passport. The detective asked Cluley if he knew the named suspect, and Cluley replied that he did not, though he conceded it was possible the individual knew of him given his three-decade career in cybersecurity and public profile.
The detective then raised a more specific concern: the suspect appeared to possess information suggesting that Cluley owned a Trezor hardware wallet for storing cryptocurrency. This was accurate. Cluley had purchased a Trezor device years earlier, and while he maintains the wallet contains only a modest amount of cryptocurrency, the fact that the scammers knew this detail was significant. Worse still, the caller claimed the suspect had obtained a document containing Cluley’s 24-word seed key — the master password required to restore and access any cryptocurrency wallet.
“They said, is it possible that the hackers have managed to get that for you? And I said, I think that’s really unlikely because I haven’t been dumb enough to paste it in anywhere. I have it securely. No, it’s not tattooed on my buttocks or anything like that.”
blockquoteblockquoteblockquoteblockquoteblockquoteblockquote
This exchange represented the core of the scam. The fake detective was laying groundwork: establishing credibility, building a narrative of imminent threat, and positioning himself as a helper. The natural next step, as Cluley later realised, would have been to ask him to read out his seed phrase so the police could compare it against the supposedly compromised version on their records.
A Question That Gave the Game Away
Several details began to trouble Cluley as the conversation progressed. The detective asked directly how much cryptocurrency he held and whether losing it would constitute a significant financial loss. When Cluley described his holdings as minimal, the caller sounded disappointed and pressed further — a reaction entirely inappropriate for a genuine law enforcement officer.
The detective instructed Cluley to visit a police station within 24 hours to view a photograph of the arrested suspect. Crucially, when Cluley named a town he did not live in — a town he knew had no operational police station — the caller accepted this without question and claimed to have booked him in. No genuine police investigator handling a computer crime case would fail to verify a witness’s location or accept a destination that had no working front desk.
The phone call then cut out abruptly. Shortly afterward, Cluley received an email purporting to come from the Metropolitan Police, warning that failure to cooperate with the investigation could result in legal action being taken against him. Analysis of the email headers revealed they had been forged, but the underlying routing information confirmed the message had originated from a source entirely unaffiliated with law enforcement.
Why This Was Not an Amateur Operation
Danny Palmer, Cluley’s co-host and a seasoned cybersecurity journalist, noted that the level of preparation evident in this attack pointed to a well-resourced group rather than a lone opportunist. The scammers had obtained Cluley’s phone number, email address, passport scan, and knowledge of his Trezor wallet ownership. This information likely came from a combination of data breaches — including the compromise of a mailing list used by Trezor for newsletter communications — and open-source intelligence gathering.
The use of Crimestoppers’ genuine phone number added legitimacy. The caller’s demeanour was measured and professional. He did not sound like a stereotypical scammer. He sounded, as Cluley put it, like someone who could plausibly work for law enforcement. The entire script was designed to build trust before making the ask.
That ask never came in this case because Cluley recognised the pattern in time. But the structure was clear: establish authority, create urgency, offer a path to safety, and request the one piece of information that would grant full control of the victim’s cryptocurrency. For a less technically experienced target, the outcome could easily have been devastating.
The Trezor Connection: Why Crypto Wallet Owners Are in the Crosshairs
Trezor hardware wallets store cryptocurrency offline, which makes them far more secure than software wallets connected to the internet. The vulnerability lies not in the device itself but in the 24-word recovery seed. Anyone who obtains those words can restore the wallet on any compatible device and drain its contents. The seed phrase is the single most sensitive piece of data a cryptocurrency holder possesses.
Cluley noted that he receives near-daily phishing emails claiming to come from Trezor, a direct consequence of the mailing list breach. The scammers behind this phone call appear to have taken that same stolen data and used it to identify high-value targets for direct social engineering. Rather than blasting out generic phishing emails that most recipients ignore, they invested time in researching individuals, crafting a credible backstory, and making voice calls — a higher-effort but vastly more effective technique.
A Wasted Opportunity: The Unhelpful Response from Action Fraud
After the call ended and Cluley confirmed the scam, he attempted to report it. He contacted Crimestoppers directly but could not get through. He then submitted a report to Action Fraud, the UK’s national reporting centre for fraud and cybercrime. The response was dismissive. Action Fraud stated there was nothing to investigate, despite Cluley providing full email headers, the spoofed phone number, and a detailed account of the interaction.
Cluley expressed frustration at this outcome, noting that the same scammers were likely working through a list of Trezor wallet owners, contacting them one by one, and that active intervention could prevent further victims. The lack of engagement from the reporting body highlights a persistent weakness in how law enforcement handles cyber-enabled fraud, particularly when no immediate financial loss has occurred.
Beyond the Phone Scam: The Broader Threat Landscape in 2026
The same episode of Smashing Security also covered two other significant cybersecurity developments that underscore the breadth of threats facing organisations and individuals alike.
Captive Crunch: Russian State Hackers Targeting Hotel Wi-Fi
Microsoft researchers have identified a campaign they named Captive Crunch, attributed to the Russian Foreign Intelligence Service (SVR) and conducted by the hacking group known variously as APT29, Midnight Blizzard, or Cozy Bear. This is the same group responsible for the SolarWinds supply chain attack, the breach of Microsoft’s corporate email, and the compromise of Hewlett-Packard Enterprise.
The attack targets the captive portal systems used by hotels and conference centres to manage guest Wi-Fi access. Once the hackers gain access to the underlying infrastructure, they modify the DNS settings for every guest device connected to the network. This means that a guest typing “microsoft.com” into their browser could be silently redirected to a server controlled by the hackers, without any visible change to the URL displayed. The technique bypasses individual phishing emails entirely and can compromise hundreds or thousands of people simultaneously.
Victims in multiple US cities, as well as in Saudi Arabia and India, have been identified. The attackers appear to have prioritised hotels frequented by diplomats, government employees, and professionals in financial services, legal firms, healthcare, and energy. In some cases, victims have also been subjected to ClickFix attacks — fake error messages that trick users into running malicious scripts on their own machines. The malware deployed includes a Windows remote access Trojan called Cornflake and a PowerShell information stealer called ChocoShell, both of which are overseen by a command-and-control panel named Fruitstone.
The most effective defence for businesses is the enforcement of a full-tunnel VPN that routes all traffic, including DNS requests, through the corporate network before it reaches the internet. For individuals, using a mobile phone as a hotspot or connecting through a trusted VPN service provides significant protection. Any hotel captive portal that asks a user to install a driver or paste a command into a terminal window should be treated as an immediate red flag.
Exfil Squad and the UK Department for Education Breach
A previously unknown hacking group calling itself Exfil Squad has claimed responsibility for a cyberattack on the UK Department for Education’s help desk portal. According to reports, the attackers obtained over 600,000 records containing names, job titles, email addresses, and in some cases phone numbers of teachers, headteachers, and university staff. The information is not believed to include bank details or other highly sensitive personal data, but its release poses significant risks.
The attackers have threatened to publish the full dataset unless their ransom demand is met. In a statement reported by the Guardian, Exfil Squad wrote: “The payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay.” The group employed a tactic increasingly favoured by cybercriminals: data theft without encryption, sometimes called extortion-only ransomware. By skipping the encryption step, attackers reduce the time and complexity of the operation while still applying pressure through the threat of public exposure.
The breach has attracted the involvement of the National Cyber Security Centre and the National Crime Agency. The Department for Education has stated that the attack was contained quickly, limiting the volume of data that was accessed and stolen. However, the incident highlights the vulnerability of educational institutions, which must balance open, collaborative digital environments with robust security controls. Universities and schools face a uniquely difficult challenge: they must accommodate thousands of personal devices connecting to the same network, manage high turnover of students and staff each academic year, and operate under tight budget constraints that often leave cybersecurity underfunded.
Lessons from Cluley’s Near-Miss: What Every Crypto Holder Should Know
Cluley’s experience offers a valuable case study for anyone who owns cryptocurrency. The seed phrase must never be shared with anyone, under any circumstances. No legitimate organisation — no exchange, no wallet provider, no law enforcement agency — will ever ask for it. The moment someone requests those 24 words, the conversation is a scam.
Caller ID cannot be trusted. Spoofing technology is cheap and widely available. Criminals routinely impersonate banks, government agencies, and police services. A call appearing to come from a known number does not guarantee the caller is who they claim to be.
Verification is essential. Cluley did what any security professional would: he asked for details he could check. But even the presence of a LinkedIn profile matching the caller’s name — as Cluley found — is not sufficient proof. Attackers harvest real names and titles from social media to construct believable personas. The correct response to any unexpected contact from law enforcement is to end the conversation, obtain the officer’s name and reference number independently, and call back using a published, verified number for the relevant agency.
The wider context of this attack — combined with the State-sponsored hotel Wi-Fi campaign and the education sector breach — paints a picture of a threat environment in which the lines between common fraud, organised cybercrime, and state-backed espionage are increasingly blurred. The same techniques appear across all three categories: social engineering, data theft, credential compromise, and psychological manipulation. The defences, too, are shared. Vigilance, verification, and the disciplined use of technical controls such as hardware wallets, VPNs, and multi-factor authentication remain the most reliable bulwarks against a rapidly adapting adversary landscape.