HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Fake Police Officer Vishing Attempt Targets Crypto Seed Phrase of Security Blogger

A voice‑phishing call impersonating a police detective tried to extract the 24‑word seed phrase securing a cryptocurrency wallet. The incident underscores the importance of security‑awareness training and verification controls for credential protection.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 grahamcluley.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
grahamcluley.com

Fake Police Officer Vishing Attempt Targets Crypto Seed Phrase of Security Blogger

What Happened — A voice‑mail‑style caller impersonated a police detective and asked Graham Cluley for the 24‑word seed phrase that secures his cryptocurrency wallet. The social engineer used a familiar “Crimestoppers” number to add credibility. Cluley refused to disclose the seed, noting it is stored offline and never shared.

Why It Matters for Trust & Control Assurance

  • Demonstrates how credential‑focused social engineering (vishing) can bypass technical controls if users are not trained to verify authority.
  • Highlights the need for continuous security‑awareness programs that embed verification procedures and incident‑reporting workflows.
  • Aligns with the control objective of identity and access control – ensuring only authorized, verified parties can obtain privileged authentication material.

Who Is Affected – Financial‑services professionals, cryptocurrency holders, high‑profile individuals, and any organization whose staff manage privileged credentials.

Recommended Actions

  • Review and reinforce voice‑phishing (vishing) detection training; include role‑play scenarios with “law‑enforcement” impersonation.
  • Enforce a policy that secret recovery phrases are never disclosed verbally or via electronic channels.
  • Deploy a verification workflow (e.g., multi‑factor confirmation) for any request involving credential disclosure. Source: Smashing Security Podcast #479

Technical Notes

  • Attack vector: Vishing (social engineering via phone).
  • No malware or vulnerability was exploited; the threat relied on human trust.
  • No CVEs are associated with this incident. Source: same as above
📰 Original Source
https://grahamcluley.com/smashing-security-podcast-479/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →