Newsletter

February 2026 News & Tips | “Unrecorded” Recordings, Network Hijacking, and Digital Misinformation

February 24, 2026|

February 2026 News & Tips | “Unrecorded” Recordings, Network Hijacking, and Digital Misinformation
View this email in your browser
Welcome back to the TCE Strategy monthly technology and cybersecurity newsletter! The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to another month that was so full of important cybersecurity news that it was hard to pick which ones to keep in. From recorded videos that we were told are never recorded, to home networks being used to spread cybercriminal attacks, to more questions on the validity of footage of recent killings in Minneapolis, we have a lot of ground to cover. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families. Warning: The discussions below will address videos of violent crimes. If a discussion about that will offend you, this may be a newsletter you want to skip.

 

New Book launch!

I am thrilled to report that a book I co-authored titled The Age of Fakes!: How AI Abuse, Fake News, and Deepfakes Threaten Business and Society was launched on Amazon February 11th! This is an international collaboration between authors from Germany and the USA to bring to life how our society is being transformed and manipulated by Artificial Intelligence. My contribution is an examination of AI and the Law, which went in a number of directions that I wasn’t expecting, making it a very exciting project. A special thank you to Dr. Nikolai Behr, Thilo Baum, Nils Bäumer, Jim Harris, Thorsten Jekel, Mariam Kublashvili and Roland Pucher as co-contributors to this book. Please check it out!

 

When your Home is part of someone else’s Cyberweapon

In a very serious creep-factor story, a Chinese company called Ipidea has quietly installed software on over 9 million Android devices. This software was used to create a “residential proxy” network that Ipidea would then rent to the highest bidder. “Residential proxy” networks are used to obfuscate where Internet traffic is coming from. Let’s say that you are a cybercriminal that wants to send malicious social media posts or emails. If you send a million messages from a single computer network, that network will likely be flagged very quickly and blacklisted. However, if you send one message from a million different computer networks, it’s much harder to identify a single coordinated effort. Per this Wall Street Journal article, “Google sued the anonymous operators of a network of more than 10 million internet-connected televisions, tablets and projectors, saying they had secretly pre-installed residential proxy software on them.” In doing so, Google was able to seriously disrupt this operation. These Residential Proxy networks are a wonderful way for any entity to hide what they’re really doing on the Internet. Normally, software packages that spread residential proxy networks get installed in a number of different ways: They could be part of a free game or other piece of software you download. They could be installed when a user visits a questionable website. Or they could be pre-installed on a device that you purchase. 

Here is Google’s technical explanation of what they did. It’s very interesting reading for those who want to know more about this type of cybercriminal behavior.

Takeaways: Be very careful with anything you download from the Internet. Use 3rd party antivirus software, and consider a home firewall that has built-in features to detect and alert you to suspicious traffic coming from your network.
 

Video Recordings that Weren’t, but they Were

First off, the kidnapping of Nancy Guthrie is not a trivial matter. Often my newsletters have a cynical or joking ring to them, and, well, my personality does lean that way, if I’m being completely frank. This case is different. An octogenarian appears to have been violently kidnapped from her home in the middle of the night on Feb 1st, and as her disappearance enters its fourth week, it appears no closer to being solved as of this writing. The entire TCE Strategy team and I are wishing for her safe return.

This event is worthy of a cybersecurity blog because of the doorbell video evidence that was released. Shortly after the family called 911, the Pima County Sheriff's Department stated that video evidence from Mrs. Guthrie’s Nest doorbell was not available because she was not paying for a subscription. However, several days later on February 10th, the FBI released video footage from her doorbell camera. While it’s obviously being used to help solve an important crime in this case, the question can’t be ignored of how this video was recorded in the first place. Everyone agrees that Mrs. Guthrie wasn’t paying to have her videos recorded. Google’s own documentation states that saving recordings is a paid “premium” feature. Even so, the videos were somehow retrieved.

I can think of a couple of ways this could have occurred:

  1. Google stores all videos regardless of whether you pay for the service or not, but you can only access them if you pay for the service. They delete them only when they run out of storage space.

  2. Mrs. Guthrie was paying for this service at some point in the past, cancelled her subscription, but Google somehow failed to stop the recordings.

  3. There is some sort of local storage of videos on the doorbell itself. Mrs. Guthrie’s Nest doorbell was disconnected at 1:47AM, which I would assume would cause a loss of power to the doorbell. The only scenario where this makes sense is if “non-volatile” memory (NVRAM) was being used in the doorbell, which I’m not able to find any evidence of.

  4. Nest doorbells upload their videos to Google regardless of the subscription being paid for, and Google marks videos to be stored if a doorbell becomes disconnected, specifically for situations such as this.

  5. Or, perhaps Nest doorbells are recording everything they capture, either because Google sees a way to profit from doing it, or because someone is outright paying them to do it.

Surprisingly, the FBI gave a clue by stating the video was retrieved from “backend residual data”, which negates idea #3 above. Idea #4 is clearly the most favorable to Google from the standpoint of “we’re trying to help society when bad things happen, not spy on every one of our customers” standpoint, but instances of that kind of altruistic behavior from large corporations are very rare to come by. Idea #5 paints them in the most negative light. Interestingly, Google has not made any sort of statement one way or the other.

Takeaways: Assume that any Internet-connected product you buy that has a camera lens and/or a microphone is capable of recording anything/everything it sees, and assume that the product’s manufacturer, or a cybercriminal who is able to hack it, or a government agency that is able to search it can all get access to those videos. These concerns have led to a number of articles being published about this, including me being interviewed by KARE11, the NBC affiliate in the Twin Cities. Discussions on whether or not this ubiquitous recording is a net positive or negative to society is left as an exercise for the reader.
 

Follow up to videos of ICE shootings

Last month I covered AI concerns in the authenticity of the videos around the killings of Renee Goode and Alex Pretti. Part of the reason I stated that I believe the videos are authentic was because of how quickly they came out on social media after the shootings took place. Now that more time has gone by, several new videos have come to light, and they have been proven to be altered by AI, including ones with obvious AI hallucinations and other videos stating support from famous people who never made them.
 

The Internet, Social Media and Extremism

I continue to be more and more concerned about the Internet’s ability to not just allow, but genuinely encourage, all of us to live in our own personalized reality. When I grew up, the 10 o’clock news was basically the same 10 o’clock news for everyone. We could certainly have different opinions about it, and we might get slightly different angles on the same story depending on the news outlet in question, but I do not recall seeing wildly different views of reality unless it was some sort of obvious fringe publication. Now, the Internet has enabled each and every one of us to gravitate toward whatever we seem to be the most interested in, consciously or unconsciously. Our social media feeds and our choices in mainstream media outlets have wildly different views on the same event, and the proliferation of “conspiracy theories” has gone from almost unheard-of, to very obscure, to somewhat common, to more common than not, to almost everywhere. This is not a good thing.

There are obvious intersections between cybersecurity and this type of extremism. Cybercriminals want you to visit malicious websites or open malicious email attachments. One of the most effective ways to do this is to send messages designed to confirm one’s current world view, in the hopes that you will click on the social media ad, open the attachment, or follow the link in question. Examples of headlines that I’ve personally received in emails or texts: “Can you believe what the just did???” or “ is at it again!” or “ is fleecing us all!”

Recent events are also certain to provide avenues for cybercriminals to attack us. With last week’s announcement that recent USA tariffs were deemed illegal by the Supreme Court, I guarantee that small business owners are about to be flooded with texts and emails claiming that if you click the link they provide, they will walk you through how to get refunds on your tariffs. These are certain to be scams.
 

Takeaways:

  1. I recommend that each and every one of us actively look for news that challenges our world view. Anytime I see a story I want to better understand, I look for coverage of that story in liberal and conservative news outlets: if the reporting is even vaguely cohesive between the two, it’s likely legitimate news.

  2. Limit the news you receive via social media. Social media is a cesspool of misinformation. There is no fact checking on social media. Foreign governments actively and purposefully spread misinformation.

  3. Understand how easy it is for any of us to be influenced from a mostly centrist view to a view that borders on extremism. History has many examples of extremism, and they have all ended badly, many with devastating acts of violence. This problem isn’t new: here is my absolutely most favorite commentary on extremism, hands down. It came out decades ago, when social media didn’t exist and the Internet was unknown to 99% of the world.

 

While my focus is cybersecurity, my mission is simply to keep people safe. Safe from cybercriminals. Safe from misinformation. Safe from propaganda. Until next month, please stay safe.

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!

March 8-17, Cairns, Australia

March 23-30, Cozumel, Mexico

April 24-26, Brainerd, MN

May 25-29, Las Vegas, NV

June 19-26, Hayward, WI

July 23-28, Austin, TX

Nov 30-Dec 4th, Key West, FL

Dec 10-13, San Diego, CA

TCE Strategy in the News

Thank you to Ian Russell and the NBC KARE11 team for the opportunity to speak with them about the Nest doorbell videos related to the Nancy Guthrie kidnapping.

Interesting Articles

THRILLED TO HEAR IT! What happened to these guys was wrong on so many levels. I strongly recommend you listen to the Darknet Diaries podcast #59 to learn more.
"According to a service alert seen by BleepingComputer, this bug ... affects the Copilot "work tab" chat feature, which incorrectly reads and summarizes emails stored in users' Sent Items and Drafts folders, including messages that carry confidentiality labels explicitly designed to restrict access by automated tools."
 
Cybersecurity Tip of the Month

Phishing in 2026: Smarter Scams, Same Goal

Phishing attacks have evolved. Today’s scams aren’t just poorly written emails, they’re AI-generated messages, cloned voices, fake login pages that look identical to the real thing, and even deepfake videos. The goal is still the same: trick you into sharing passwords, financial information, authentication codes, or clicking links that install malware.

Phishing remains one of the biggest threats to individuals and businesses. The difference in 2026? The messages are more personalized, more convincing, and often arrive through multiple channels: email, text, social media, collaboration tools, and even voice calls.

Here’s how to protect yourself:

  1. Scrutinize the Sender, Everywhere
    Scammers now spoof emails, phone numbers, and even internal collaboration accounts. Check the full email address (not just the display name), and be cautious with unexpected messages on Slack, Teams, or text.

  2. Pause Before You Click or Scan
    Hover over links to preview the URL before clicking. Be cautious with QR codes, shortened links, or login pages that appear after clicking. When in doubt, navigate directly to the official website yourself.

  3. Watch for Emotional Manipulation
    Urgency, fear, secrecy, or unexpected rewards are still common tactics. AI makes these messages sound more natural, but the psychological pressure remains the giveaway.

  4. Protect Authentication Codes
    No legitimate company will ask for your password or multi-factor authentication (MFA) code. If someone asks you to “read back” a code you just received, it’s a scam.

  5. Verify Through Official Channels
    If a message claims to be from a company, colleague, or financial institution, verify it by contacting them directly using a known, trusted method, not by replying to the message.

  6. Keep Devices and Security Tools Updated
    Regular updates help protect against credential-harvesting sites, malicious downloads, and known vulnerabilities that phishing campaigns exploit.

  7. Practice Real-World Phishing Awareness
    Testing yourself with phishing simulations or quizzes helps you recognize evolving tactics. The more examples you see, the easier they are to spot.

Practice here:

https://phishingquiz.withgoogle.com/
https://www.opendns.com/phishing-quiz/
https://www.sonicwall.com/phishing-iq-test/

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2026 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp