Contents

Dear reader,

GCSC is here! After a lengthy process, Guernsey now has a Cyber Security Centre.

In total, 91 people attended the GCSC launch event this month, which saw guest speakers, input from both our Guernsey and Jersey team members, as well as industry suppliers poised to support local businesses. As I have previously mentioned: the winds of change are in fact still blowing when it comes to GCSC, with two full-time staff and a third on the way in due course.

We have published more content on our launch in this newsletter, and you can see more (with video) on our website.

There is still a significant amount of work to be done. The States of Guernsey expects GCSC to be fully operational quickly, serving every part of the community with its expertise and drawing on the wide network of existing CERTs across the globe.

The GCSC Operations Centre is coming along. The team moved into their new premises on 11 June, marking the culmination of a year-long project to bring us to this point. While there is still a significant amount of banging and drilling, the team are now getting settled and are excited to see what the future brings, and what they can offer the island they call home.

Until next time,

GCSC holds launch event

91 people attended GCSC’s launch event at the Old Government House Hotel on 9 June.

During the event - which took place on 9 June - guests heard from investigative journalist and author Geoff White and email prankster James Linton, as wellas Lynne Capie from Soteria Communications, and Director of Guernsey and Jersey Cyber Security Centres, Matt Palmer.

Speaking to the BBC, a spokesperson for the Guernsey Financial Services Commission said: “Given the continuing fast evolution of AI capabilities, which can be used by both good and bad actors, the commission welcomes the efforts of the States to further enhance Guernsey’s capabilities in this area.”

Local suppliers and members of GCSC’s Cyber Suppliers Advisory Group (including Clarity, Black Arrow Cyber and Cortida) also attended to showcase their expertise in this area and build on a growing relationship with GCSC, with guests able to attend a dedicated exhibitor fair during the event.

It feels like Guernsey’s in a slightly better place now than it was before [GCSC] came into being.

Andrew Carey, Island Health

Read the full article (including a full list of exhibitors) and watch our event video on the GCSC website via the button below.

Making a move

A view of the GCSC Operations Centre on 11 June

GCSC has now moved into its new premises as of 11 June, based in Marie Randall House, Upland Road, St Peter Port.

The office is now being re-fitted to accommodate GCSC, which will include new signage, operational infrastructure, and security modifications.

Work is still ongoing to ensure that GCSC becomes fully operational and is ready to support all islanders. GCSC offices will be available for members of the public to attend for advice and assistance, with dedicated time slots available for booking in the coming months once fitting is complete.

We will provide further updates on the development of GCSC in the coming months.

GCSC offices as of 17 June

Phish of the Month

Image by Le Vu on Unsplash

As far as cyber attack vectors go, phishing is still a popular choice for bad actors, even in 2026.

Whether targeting direct financial gain, attempting to harvest sensitive data or looking for initial entry into a corporate network: attackers target human behaviour and psychology. While there’s a lot of discussion around AI-enabled cyber attacks, standard phishing attacks are well-engineered that many of us are already fooled (this includes Troy Hunt of Have I Been Pwned fame, who announced last year that he had fallen for a phishing attack).

While the standard advice - carefully check the sender details and links, look for manufactured urgency and emotive content - will always be an important foundation, attackers are well aware of commonplace measures and continue to innovate. This series will explore specific examples of recent phishing attacks that have caught our attention.

Robinhood Trading Platform

What happened:

Phishing emails were sent to Robinhood users from the genuine support email (noreply@robinhood[.]com) by leveraging vulnerabilities in the trading platform's sign-up process, paired with a genuine feature of all Gmail accounts.

How it worked:

  1. Gmail’s aliasing feature allows you to add forwarding email addresses to your current address that still send to your primary inbox (using dots or plus signs). For example, victimphish@gmail[.]com, victimphish+me@gmail[.]com or victim.phish@gmail[.]com.

  2. Unlike Gmail, Robinhood treats dots as unique and does not ignore them. This means a unique account could be created using victim.phish@gmail[.]com and any support emails linked to the account would be sent to the victim’s account.

  3. Further vulnerabilities in the sign-up process allowed for HTML code to be injected which would both trigger a support email relating to unusual sign-in activity and transform the content of that support email to include phishing links.

Why it matters:

More sophisticated campaigns often exploit existing and trusted infrastructure. These phishing emails would have come directly from Robinhood's servers and benefitted from the implicit trust that carries. The emails would have passed all the technical checks that go along with it (anti-spoofing measures such as SPF, DKIM and DMARC which we have written about before here and remain vitally important).

What you can do:

Avoid engaging with any automated or unexpected emails directly and instead sign in separately via a trusted browser to verify the situation.

Click the button below to read more on this story, via Security Week.

Cyber Security in the News

Supply Chain Attacks Continue

Supply chain attacks continue to be in the news and show no sign of slowing down. The NPM registry is still actively exploited, Arch Linux has been targeted, and the once ubiquitous library Polyfill.io is still a risk in the wild. While much of this occurs behind the scenes for most islanders, the reality of our intertwined digital world means the impact remains widespread.

For example, the Polyfill vulnerability impacts more than 100,000 websites across the world. Polyfill[.]io is a service that provides polyfills, a small piece of website code that allows older web browsers to run modern functions that they would not ordinarily support. Because they’re so common when the Polyfill domain lapsed it became a valuable target for threat actors who - in turn - abused that existing trust to deploy their own code.

Supply chain attacks demonstrate that, regardless of our own operational security, regardless of when and how often we patch, we are all vulnerable to risks that originate further down the wire.

Read more on what a supply chain attack involves using the button below (Wikipedia).

Mythos, Fable Large Language Models (LLM) pulled by United States Government

The US Government has blocked access to the recently developed Mythos and Fable series of models by LLM provider Anthropic. Citing national security concerns, the directive aims to suspend any foreign nationals from accessing the tools, regardless of location.

While access to other models has not been affected the ruling comes as a shock to many, particularly those who had already paid for the subscription. Anthropic’s announcement on the subject stated that the letter of direction “did not provide specific details of its national security concern,” and that they are of the understanding that “the government believes it has become aware of a method of bypassing, or ‘jailbreaking’ Fable 5.”

The ruling comes as public discourse around the Mythos and Fable series of models focused on the potential dangers due to its hacking abilities, with big implications for cyber security if used in a malicious capacity.

Read Anthropic’s announcement on this topic below via their website.

Jobs in Cyber

Are you recruiting for a cyber role locally? Tell us at [email protected] and we’ll share your job listing with the community.

Tool of the Month

Each month, we provide a roundup of tools that our team have found useful, and which could be useful to cyber security professionals. If you’ve found a helpful tool you’d like to share, please email us and we’ll include it in a future newsletter.

Dangerzone

Worried about an attachment but can't ignore it? Dangerzone will open an untrusted file (most document and image types are supported) in an isolated environment and convert it into a safe PDF using optical character recognition (OCR).

Visit their website using the button below (Danger.zone). Please be careful not to upload legitimate confidential information to file checking services.

Did you know? GCSC can also check potentially malicious files for you in our sandbox, but please let us know before sending them over.

Keep reading