September 2025 News & Tips | AI Hacking, Jaguar Land Rover Breach and St. Paul Cyberattack

September 2025 News & Tips | AI Hacking, Jaguar Land Rover Breach and St. Paul Cyberattack
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! September has been another whirlwind in the world of cybersecurity. From new hacks on AI to a cyberattack that has taken down Jaguar Land Rover for an entire month, we have a lot to review. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

 

New proof-of-concept on how to use AI to hack online storage (such as Google Drive)

In a very interesting article shared by Bruce Schneier in his monthly newsletter, a novel and easy-to-implement attack was presented at the Black Hat hacker conference recently. Here is how it works:

  1. A user of ChatGPT allows the AI engine to have access to his/her Gmail account and/or Google Drive data. In fact ChatGPT literally prompted me asking me if I wanted to do this a few weeks ago (I said no).

  2. A cybercriminal shares a Word document with a victim. It could have a name of “meeting minutes” or “list of favorite bands” or anything else. When the share occurs, the data is also shared with ChatGPT because of the link I described above.

  3. The next time the victim goes to ChatGPT and gives any sort of command that asks ChatGPT to look at his/her files (something like “summarize any meeting notes from the last week” or “find my pictures from my Puerto Rico trip” or “where is my recipe for beef stew”, ChatGPT will go through the users files looking for the requested information.

  4. The shared Word document the attacker sent is malicious, in that it has text in the document that is in a very small font and is the same color as the background of the document. That text asks ChatGPT to search for, say, encryption keys or bank account information or passwords or anything else in the victim’s Google Drive files, and the text also asks ChatGPT to send that information to the attacker’s email account.

  5. ChatGPT does exactly what it is asked to do and sends the victim’s data to the attacker.

This is extremely bad. The victim never has to open the file. The victim’s antivirus is unlikely to ever see the malicious Word document, as it never existed on the victim’s computer. This is what is called a “zero-click” vulnerability, as it does not require action from the victim (although in this case, it does require that the victim ask ChatGPT to so something with his/her files, but it could be an instruction about almost anything that will get ChatGPT to access the victim’s files, so it’s almost zero-click)

Takeaway: Do NOT give an AI engine unfettered access to your email or your file shares. Consider some of Google’s security measures to reduce the risk of AI-based attacks
 

Jaguar Land Rover breach halts operations for the entire month of September

There aren’t a lot of details on this one, but on August 31st, a cyberattack took place on Jaguar Land Rover’s critical IT systems. They have not confirmed that it was ransomware, but it sure smells like ransomware. Their 3 factories in the UK are all shuttered, and most of the 33,000 employees have been told to stay home. These factories normally produce roughly 1000 cars per day. They are currently producing zero cars. They are producing zero parts that are needed for cars at other plants. This is bad.

It often takes at least a week to start resurrecting systems after a major cyberattack. Sometimes system issues may require all systems to be unavailable into a 2nd week, but it’s very unusual to have no meaningful progress in recovering from an incident after a full two weeks. Well, as of this writing, all 3 factories remain shut down. The company has stated that they are shooting for an October 1st resumption of activities. That’s a long outage. The cybercriminal group “Scattered Spider” has claimed responsibility, but Jaguar Land Rover has not confirmed that.

Takeaway: Ransomware is a preventable crime. Offline data backups are your friend. Tested disaster response plans are very useful. CISA just released a best practices guide on how to recover from cyberattacks (and I agree with the vast majority of their recommendations), but a strong proactive cybersecurity posture is a MUCH better approach than a reactive one. Ransomware prevention is all about cybersecurity basics. Patching. Good passwords. Multi-factor authentication. Cybersecurity awareness training. Proactive vulnerability scans. Strong IT best practices where IT team members don’t log in with their domain administrator credentials for everyday work. Good antivirus that is monitored. These things matter. Just ask Jaguar Land Rover.
 

Follow-up on City of St. Paul breach last month

This newsletter covered the major breach of the City of St. Paul, MN, USA in our August issue. Recovery was surprisingly slow, but most services have been restored. The mayor announced on September 10th that the city is allocating $1 million toward improving the cybersecurity posture of the city. That is $1 million out of a total budget of $887 million. Will $1 million help if it’s spent correctly? Yes. Will it make the city reasonably secure from another major ransomware attack? To be honest, I seriously doubt it. One of the biggest issues in incident recovery is updating systems that are too old to be made secure against the threats of today. I’m talking about systems running operating systems that are no longer supported by their makers (nor any antivirus programs), applications that have known vulnerabilities but no patches are available. These are the equivalent of cars made before the invention of seat belts. Do they still work? Yes. Are they safe? No. Can they be made reasonably safe in a world filled with 70MPH highways? No. The City of St. Paul likely has systems that would take tens of millions of dollars to make ransomware resistant. A $1MM investment is a good start, but it’s likely a band aid in a situation where surgery is the only long-term solution.

 

Until next month, stay safe!

Upcoming Speaking Events


Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!

October 21-23, Detroit, MI

October 29-30, Boston, MA

December 1-5, Key West, FL

December 11-15, Phoenix, AZ

December 22-26, Ft. Myers, FL

March 8-17, 2026, Cairns, Australia

June 19-26, 2026, Hayward, WI

TCE Strategy in the News

Thank you to Ian Russell and the KARE11 team for the opportunity to have a follow-up interview about the financial investment to remediate the City of St. Paul data breach.

Interesting Articles

I agree with this article. If you get an email or text with a link to any website ending in .XIN, it's almost certainly a scam. Frankly, any emails or texts with links in them should be treated as potentially malicious.
It's not as bad as the Equifax breach, but it's bad. "[TransUnion] collects and maintains credit information on over 1 billion consumers worldwide, with approximately 200 million of those based in the U.S. This information is shared with 65,000 businesses, including lenders, insurers, and employers."
 
Cybersecurity Tip of the Month

 

                              Backing Up Personal Files


One of the simplest but most overlooked parts of cybersecurity is regularly backing up your files. With the pace of our digital lives, it’s easy to put this task off, but it can make all the difference if something goes wrong. Taking a few minutes once a month to back up ensures you don’t lose important, and sometimes irreplaceable, data. Whether you’re dealing with a forgotten password, ransomware attack, hardware failure, or even a lost laptop, having a backup makes recovery much easier. If you haven’t done it in a while, set aside time this weekend to get it done!

Here’s how:

  1. Use an external hard drive, SSD, or USB large enough for your data. Many affordable options start around 256GB, but larger drives are widely available online or at electronics stores.

  2. Download copies of files stored in cloud services like Google Drive, iCloud, Dropbox, OneDrive, or Google Photos so they’re included in your backup.

  3. Copy your key folders (Documents, Photos, Desktop, and Downloads) onto the external drive.

  4. Once the backup is complete, safely eject the drive and store it somewhere secure and separate from your computer.

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: