The B2B Podcast Index
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

Facepalm Retrospective: 2025’s Greatest Cyber Fails — From 123456 to the Louvre

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups · 2025-12-22 · 22 min

Episode notes

Welcome to the Small Business Cybersecurity Guy Christmas Special with host Noel Bradford and guests Mauven MacLeod and Graham Falkner. This episode is a rapid-fire, often hilarious and sometimes horrifying roundup of the most spectacular cyber security disasters of 2025, told with a no-nonsense focus on what small businesses should learn from them. We open with the MacHire fiasco: security researchers discovered an admin account on McDonald’s AI hiring chatbot (Paradox.ai/Olivia) protected by the password "123456," exposing up to 64 million applicant records. The researchers reported the flaw; no known mass theft occurred, but the episode underlines vendor risk and the dangers of legacy test accounts and absent MFA. Next, we cover the Louvre post-heist revelations: a €88m jewel theft followed by reports showing decades-old surveillance systems running Windows 2000/XP, passwords like "Louvre" and systemic neglect. The story is used to illustrate how even world-famous institutions fail at basic cyber hygiene.

Listen to this episodeAll The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups episodes →