CyberBeacon #63 – Gamers Are Opening the Company’s Doors to Hackers

This edition of the Aware Force Cyber Beacon explores five fast-moving technology and cybersecurity issues affecting employees, organizations, a...

blog

Edition #63 | Compiled July 21, 2026 by Aware Force Cybersecurity

Article content

Video games have quietly become one of the biggest “front doors” hackers use to reach both home PCs and corporate networks, riding on the sheer scale of gaming and game‑related content. How popular are video games? As many as 70% of top trending videos on YouTube are gaming‑related, far more than trailers or music videos.

  • The most frequent attempts to attack users through malicious or unwanted files disguised as Gen Z’s favorite games involve Grand Theft Auto, Minecraft, Call of Duty, The Sims, Roblox, and FIFA.
  • An analysis of more than 50,000 infected devices concluded that 41% of infostealer infections came from gaming‑related files, and roughly two out of five victims were compromised by downloads tied to mods, cheats, cracked games, or platform tools. Those infostealers don’t just swipe game logins; they harvest browser passwords, cookies, and VPN credentials that often unlock corporate email, cloud services, and remote‑access tools.
  • Gaming habits are deeply personal and often bleed into work life: employees install games on home PCs they also use for remote work, reuse passwords between game accounts and corporate systems, and follow YouTube creators who link out to unvetted downloads. That means security teams can’t just focus on “work apps” anymore; they need to treat gaming as a serious attack path, especially for infostealers and credential theft, and integrate it into policies, awareness training, and incident response plans.

Go Deeper


Article content

What happens if you upload your passwords into an AI platform like ChatGPT or Claude? The Wall Street Journal’s Nicole Nguyen tried 1Password’s new feature that allows it and found good news…and not so good news. Gift article: https://www.wsj.com/tech/ai/1password-for-claude-ai-agents-password-manager-111a7a8a?st=rQ8HDn&reflink=desktopwebshare_permalink

  • Password Manager app 1Password’s has rolled out new integration with the AI platform Claude that lets it sign in to websites by pulling credentials from an encrypted vault, filling login fields directly in the browser, and never exposing passwords or one‑time codes to the model or its memory. The fine print: Users must explicitly approve each login request through the 1Password app, and the assistant only learns which account was used, not the actual secret.
  • Law firms and incident‑response teams report seeing cases where employees pasted client records, proprietary code, or deal documents into consumer AI tools, thinking they were using the “enterprise” version. Once that data leaves corporate systems, organizations may have to treat it like any other data‑loss event: classify the exposure, review contracts, notify affected parties, and update policies and training.

Employees should never post these topics into an AI chatbot like ChatGPT:

  • Passwords, passcodes, and API keys
  • No usernames, passwords, one‑time codes, or “remember this login for me” prompts.
  • No Wi‑Fi passwords, VPN credentials, SSH keys, or API tokens for internal systems.
  • Personal identifiers and contact details
  • No Social Security numbers, SINs, national IDs, driver’s license or passport numbers.
  • No home addresses, personal phone numbers, or non‑work email addresses — yours, your family’s, or your customers’.
  • Sensitive work data: No customer lists, CRM exports, or spreadsheets with names, contact details, or account IDs.
  • No internal strategy decks, unreleased product plans, financial forecasts, or board materials.
  • Regulated or high‑risk information
  • No health records, lab results, insurance claims, or other medical details, which may be protected under laws like HIPAA.
  • No bank statements, credit‑card numbers, pay stubs, tax returns, or investment account details.
  • Client, partner, or case information: No legal case files, discovery documents, or anything covered by attorney‑client privilege.
  • No non‑public details about mergers, acquisitions, bids, or negotiations.
  • Intellectual property and creative work
  • No source code from proprietary systems, especially security or authentication code.
  • No unpublished manuscripts, scripts, training materials, or design files you’re not ready to share outside the organization.
  • Anything that could embarrass, endanger, or identify someone
  • No private HR issues, performance reviews, or disciplinary notes.
  • No gossip or personal details about coworkers, customers, or students.

Go Deeper



Article content

6,000 municipalities across the US use Flock’s automated license plate cameras to fight crime, supporters see Flock as a force multiplier: a relatively cheap network of 95,000 cameras that lets small departments find suspect vehicles in minutes instead of days.

  • For neighborhoods dealing with repeat break‑ins or catalytic‑converter theft, the payoff in arrests and deterrence feels tangible and immediate. But opponents say mission creep is almost guaranteed: data gets shared more widely than intended, officers use it for personal reasons, and the line between targeted investigation and mass tracking blurs.
  • Critics argue that this “always on” tracking effectively builds a location history for millions of drivers who were never suspected of a crime, echoing concerns that recently led the Supreme Court to restrict broad cellphone location searches.
  • Civil‑liberties groups and legal researchers have documented two dozen or more cases in which officers used license plate readers to stalk ex‑partners, check up on friends, or spy on people they were curious about. In Georgia, at least ten officers have been disciplined, fired, or charged for running themselves, family members, and acquaintances through the Flock database with no investigative reason.
  • At least 30 cities and counties have paused or ended Flock contracts, citing concerns about data sharing with federal agencies, immigration enforcement, or broad surveillance of protests and daily life. Other communities have doubled down, renegotiating contracts to tighten retention and sharing rules rather than walking away.

Go Deeper


Article content

Analysts warn that by 2028, some enterprise AI programs could cost more than the staff they were supposed to replace unless companies start treating prompts like billable units instead of “free magic.”

  • Beginning with your next budget planning, expect a spirited debate about “tokenomics.” The word emerged as crypto took off: it means understanding supply, distribution, and utility so a token’s value wasn’t just hype. Now it’s being applied to the fees charged to use AI engines. Every interaction with a model consumes tokens, and the bill scales with the number of prompts, depth of context, and model choice.
  • For some enterprises, the “meter is running” so fast that AI usage could cost more than the human work it replaced by around 2028 if left unchecked. That risk is amplified by shadow AI: surveys show that most knowledge workers now use AI tools weekly, with a sizable share using them daily, often on consumer accounts that are not centrally priced, secured, or governed.
  • Organizations will soon begin aggressively treating AI tokens like cloud compute or telecom minutes: set budgets, define who can use premium models, and require business cases for heavy or specialized workloads. Some firms are experimenting with internal “chargeback” models where departments see AI usage in dashboards, get monthly token statements, and must justify spikes, mirroring how early cloud adopters learned to curb surprise bills.

Go Deeper


In the this week’s Aware Force for employees: How to give your parents and grandparents the superpower to fight cybercrime. Contact us at [email protected] to see it.


Article content

FaceTime is now part of the scammer’s playbook: criminals start with fake fraud alerts, then escalate to a live video call where victims feel safe enough to show passwords, one‑time codes, and even move money while the crook watches. Apple is warning iPhone and iPad users to treat any unexpected FaceTime call about “account problems” as untrusted and to report suspicious calls directly to Apple, because the real exploit here is human trust, not a virus.

  • Banks and security firms report cases where criminals convince victims to install remote‑access tools or share their screen during a FaceTime or Zoom call, then log into online banking and move funds while the victim watches. Because nothing malicious must be installed on the phone itself, these scams can bypass traditional antivirus and rely entirely on social pressure, urgency, and the false authority of a live video call.
  • Some banks and tech‑support teams legitimately use video sessions to verify identities, walk customers through settings, and help people who can’t visit a branch. For some users, especially those in rural or mobility‑limited situations, FaceTime and similar apps are a lifeline for real support.
  • Apple staff, banks, and government agencies will not make unsolicited FaceTime calls demanding immediate action, passwords, or verification codes. The company urges anyone who gets a suspicious FaceTime call to end it, contact the organization using an official phone number, and email a screenshot of the call info to [email protected] so Apple can track patterns.

Go Deeper

Get the latest insights in cybersecurity.
Subscribe to the Aware Force Cyber Blog

Insightful cyber news, fresh ideas for engaging your employees and more.

Search

Richard Warner is a recognized expert on human cyber risk and the founder/CEO of Aware Force, where he and his team create cybersecurity content tailored to each client’s culture that is engaging, relatable, and effective.

Leveraging his decades of experience as a prominent journalist and communicator with outlets including FOX and the GPB Television Network, Richard helps organizations worldwide transform human weak links into their strongest digital defense.

He is based in Atlanta and pioneers effective strategies for security culture and employee engagement.

Featured Posts