Leigh Kefford

Don't Be A Sitting Duck Podcast

Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats,...

Author

Leigh Kefford

Category

Technology

Podcast website

sittingduck.com.au

Latest episode

May 18, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

PNG & Pacific Under Cyber Attack | Special Edition 18.05.2026

Cyber criminals are now targeting Papua New Guinea and the Pacific region with increasing frequency — and many businesses still think they’re too small, too remote, or too unknown to become a target. In this special edition of the Don't Be A Sitting Duck Podcast , Leigh Kefford breaks down two recent ransomware incidents linked to Papua New Guinea and Fiji, including the alleged targeting of P...

A Phishing Email Exposed 5.5M Records — Are You Next? 01.05.2026

One phishing email. That’s all it took to expose over 5.5 million customer records. In this episode, we break down how hackers gained access to ADT’s systems—not through advanced hacking, but by targeting a person. We also dive into the growing wave of ransomware attacks hitting major brands like Zara, Carnival, and 7-Eleven, where attackers don’t just lock your data—they threaten to leak it. Here...

A QLD pharmacy ransomware attack highlights rising cyber risks in healthcare. Learn how it happened and how to protect your business. 21.04.2026

A Queensland pharmacy chain has allegedly been targeted by the Kairos ransomware group—highlighting a growing trend of cybercriminals targeting essential service providers, not just large enterprises. In this episode, we break down what happened, how ransomware attacks like this actually work, and why healthcare businesses are increasingly in the firing line. More importantly, we walk through prac...

Sydney University & iiNet Cyber Breaches: What Businesses Must Learn 31.12.2025

In this episode of the Don’t Be A Sitting Duck Podcast , we explore two recent and impactful Australian cyber incidents — the University of Sydney data breach and the iiNet customer data exposure. We explain how attackers gained access, what kinds of data were compromised, and most importantly, share actionable advice for businesses to reduce their risk of similar breaches. Main Stories Covered: U...

CPS 234 Explained: Why Cyber Security Is a Board Issue 21.12.2025

Cyber security is no longer just an IT problem—it’s a board-level responsibility. In this episode, Leigh Kefford breaks down APRA’s CPS 234 Information Security standard in plain English, explaining what it requires, why regulators care, and what happens when controls fail. We unpack board accountability, third-party risk, security testing, and incident response obligations—and why CPS 234 is fast...

Day 12: Your Phishing Defence Checklist — The Complete Guide 11.12.2025

Day 12 — The Grand Finale of the National PC 12 Days of Phishmas!   This episode brings together everything covered throughoutthe series into a complete, actionable Phishing Defence Checklist. You’ll learn:   The essential controls all businesses need Email, identity, device & cloud protections User behaviour improvements Backup & recovery readiness Tips for suppliers, payments & cultu...

Day 11: User Behaviour — The #1 Cybersecurity Risk 10.12.2025

Day 11 of the National PC 12 Days of Phishmas !   Today we explore why user behaviour is the biggestcybersecurity risk for every organisation. Technology alone can't protect your business — people playthe defining role.   In this episode: Why humans are targeted How attackers use trust & urgency The psychology behind phishing What data harvesting reveals How to reduce human error How to bu...

Day 10: The Ransomware Attack Chain — How One Click Leads to Disaster 09.12.2025

Day 10 of the National PC 12 Days of Phishmas !   Ransomware attacks don’t start with encryption — they startwith access, usually through a phishing email. This episode breaks down each stage of the ransomware attack chain and shows how to stop it early.   You’ll learn:  How attackers gain initialaccess What lateral movement lookslike How payloads are deployed Why backups get targeted How extortio...

Day 9: Social Engineering & Data Harvesting — How Attackers Study You Before They Strike 08.12.2025

Day 9 of the National PC 12 Days of Phishmas!   Cybercriminals don’t always break into systems — sometimesthey break into people. This episode explores how scammers use publicly availableinformation, emotional manipulation, and behavioural cues to create targetedattacks.  In this episode:  Where attackers gather information How social engineering manipulates users Why emotions create cyber vulnera...

Day 8: Account Takeover & Hijacked Email Threads — When Cybercriminals Become You 07.12.2025

Day 8 of the National PC 12 Days of Phishmas!   Today we’re breaking down Account Takeover (ATO) andHijacked Email Threads — two of the most convincing and damaging forms of phishing. In this episode:  How attackers gain access to real inboxes Why hijacked threads are so effective What signs to look for How these attacks lead to financial loss The essential steps to protect your organisation  🛡 Bo...

Day 6: Malicious Attachments & Cloud File Scams — The Hidden Threat in Your Inbox 07.12.2025

Why fake documents and shared file links are one of the most dangerous phishing threats for businesses. Day 6 of the 12 Days of Phishmas! Today’s episode breaks down one of the biggest ways cybercriminals gain access to your systems: malicious attachments and cloud file impersonation. These scams use fake PDFs, ZIP files, SharePoint links, OneDrive invites, and Google Drive notifications to infect...

Day 1: The Most Common Phishing Red Flags — What to Watch For 04.12.2025

🎄 Welcome to Day 1 of the 12 Days of Phishmas! We’re kicking off the series with the foundation of all cyber awareness: 🔍 The Most Common Phishing Red Flags These are the warning signs scammers can’t hide — the little clues that tell you something isn’t right. And understanding them can prevent the vast majority of cyber incidents. In this episode, I break down: The red flags hidden inside phish...

Australia’s Retailers Are Quietly Bringing Back Facial Recognition 04.12.2025

Australian retailers are quietly reintroducing facial recognition technology—even after public backlash. In this episode, Leigh breaks down why stores are turning to AI-driven biometric surveillance, what risks it creates for customers, and why business leaders should think carefully before deploying similar tools. We explore how the technology works, why it’s making a comeback, and the serious pr...

Cyber-Attack Shuts Down London Councils; Aussie Industry Breaches Exposed 02.12.2025

In this episode, we look at a major cyber-attack that forced multiple London councils offline, cutting essential services for hundreds of thousands of residents — and a shocking new report showing Australia’s mining and manufacturing sectors often take months (or longer) to detect and report data breaches, exposing personal data of millions. We break down how these incidents unfolded, why they mat...

Vietnam’s Social Media Heists & The Rise of Asia’s Cybercrime Underground 01.12.2025

Vietnam’s cybercriminals aren’t just hacking servers — they’re hijacking social media business accounts. In this episode, Leigh Kefford breaks down new findings from the CrowdStrike 2025 APJ eCrime Landscape Report — including how Vietnamese malware like Ailurophile Stealer is stealing ad accounts, the rise of Chinese-language cybercrime marketplaces, and why AI-driven ransomware is changing the g...

Human Error & Ransomware Risks for Australian Businesses 04.11.2025

In this episode of Don’t Be A Sitting Duck, I break down two critical risks for Australian organisations: the rising role of human error in data breaches, and the ever-present threat of ransomware. Using the latest figures from the OAIC and industry commentary, we explore how staff mistakes and mis-configurations are now major breach drivers, and why ransomware remains such a potent business conti...

Ransomware Realities: What You Need to Know 02.11.2025

Ransomware has become the most disruptive threat facing Australian businesses today. From small councils to local manufacturers, attacks are happening closer to home — and they’re getting smarter, faster, and more ruthless. In this episode, Leigh Kefford explores how ransomware works, what recent attacks reveal, and what practical steps every business can take to stay protected. Key Takeaways: Ran...

NSW AI Data Breach & Telco Hack – What Your Business Can Learn 01.11.2025

Today’s episode unpacks two alarming cybersecurity incidents in Australia that should act as red alerts for every business. First, we look at how a contractor for a government flood-recovery program uploaded thousands of applicant records into ChatGPT without authorisation—revealing vulnerabilities in AI tool usage. Then we dive into a breach at telco Dodo (and its parent Vocus Group) where email...

Australian Ransomware Wave Hits Law, Boats & Aviation 31.10.2025

This week on the Don’t Be A Sitting Duck Podcast , Leigh Kefford explores three major Australian cyber incidents — revealing how ransomware groups and vendor breaches continue to challenge even the most trusted organisations. WA law firm confirms breach following Anubis ransomware claim Malibu Boats Australia targeted by Qilin ransomware gang Air Services Australia vendor data exposure under inves...

Qantas Data Leak & Australia’s $5.8M Privacy Penalty 12.10.2025

In this episode, we dig into two gripping and high-stakes stories in cybersecurity. First, Qantas is one of nearly 40 global firms being extorted over stolen data from Salesforce, now leaking millions of customer records. Then, in Australia, a health services firm becomes the first to face a major civil penalty—$5.8 million—for a data breach that exposed sensitive personal records. These twin less...

Cyberattacks on Pharmacy, Brewer & UK Nursery 01.10.2025

In this episode of the Don’t Be A Sitting Duck Podcast , Leigh Kefford unpacks three alarming cyber incidents that reveal just how far attackers are willing to go: Toowoomba Pharmacy Ransomware Attack – The Friendly Society Dispensary hit by the DragonForce group, with nearly 36GB of sensitive staff and patient data stolen. Asahi Group Cyberattack in Japan – A global beverage giant forced to halt...

Chinese APT Threats Targeting Australian Critical Infrastructure 01.09.2025

In this episode, we unpack the alarming rise of state‑sponsored Chinese cyber actors compromising critical infrastructure—from backbone routers to military and government networks. You'll learn how these Advanced Persistent Threat groups maintain stealthy, long‑term access, and why this matters for national and business security. We break down how the attacks happen, explain the global coordin...

Microsoft 365 Calendar Phishing: Don’t Let Invites Fool You 01.09.2025

This episode uncovers a stealthy cyber‑attack slipping through inbox filters: Microsoft 365 calendar phishing. Scammers send fake billing alerts—like “Payment Failed” or “Account Suspended”—directly to your calendar. Without clicking anything, the threat arrives. We explain how they exploit default invite settings, why deleting or responding can put you on their radar, and most importantly, how yo...

FileFix Attack: Clipboard‑Based Threat Every Business Must Know 01.08.2025

In this episode, we dig into the newly discovered FileFix attack —a clever and stealthy cyber trick that exploits how people use their clipboard. No malware. No download. Just voice‑less manipulation of Windows Explorer and the clipboard to execute hidden PowerShell commands. We’ll break down how it works, why it’s so dangerous, and what businesses should do today to stay protected. Click here for...

Qantas Data Breach: Customer Info Leaked via Vendor 02.07.2025

Qantas has joined the long list of major companies hit by cybercrime — this time, through a third-party contact centre platform. In this special Don’t Be A Sitting Duck episode, Leigh Kefford unpacks how customer data was leaked, what it means for businesses, and why vendor risk can no longer be ignored. What You’ll Learn: Which customer details were compromised Why third-party platforms are your...

Listen to the Don't Be A Sitting Duck Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.