← Back to list

A Ethical Hacking Masterclass That Changed How I See Privacy!

A sophisticated attack doesn’t just exploit code; it exploits curiosity, trust, and cognitive bias. It’s time our defence strategy did the…

Idris Fabiyi in The Digital Edge · 2025-11-24 12:58 · 1 claps · 7.2 min read
#cybersecurity #ethical-hacking #ai #security #education
Open on Medium ↗
Wiki topics: SAF · Safety & Alignment AI · AI · General PSY · Psychology EDU · Education & Learning 🔒 · Cybersecurity

A Ethical Hacking Masterclass That Changed How I See Privacy!

A sophisticated attack doesn’t just exploit code; it exploits curiosity, trust, and cognitive bias. It’s time our defence strategy did the same.

Last month, I had the pleasure of watching another excellent session from our ‘Lunch and Learn’ Masterclass series. This one was a topic I am very passionate about, Cybercrime, hosted by my colleague Xavier Nel from the BPP University School of Technology. As a university, we host these masterclasses, which are designed to push our learners beyond their core curriculum and explore interesting tech-related topics, and this one explored Ethical Hacking & Cyber Security.

In this article, I want to share some of the key areas Xavier covered in his excellent Masterclass session, there’s so much to learn and reflect on. I want you to do something right now. Open Google and type this: site:linkedin.com OR site:facebook.com OR site:twitter.com OR site:instagram.com “YOUR NAME”.

Go ahead. I’ll wait…

What you’re about to see might make you uncomfortable. It certainly made me pause. Because what appeared on my screen wasn’t just a few innocuous links — it was a detailed map of my digital life, compiled in under three seconds, using nothing more sophisticated than Google’s search bar. This wasn’t some advanced hacking technique. This was reconnaissance 101. And it was terrifyingly effective.

Why We Keep Falling For It (The Human Vulnerability Factor)

During the session, Xavier posed a simple question: “Why are humans so vulnerable?”. The answer wasn’t technical. It’s that we are, by nature, trusting, curious, and very, very busy. We have an innate sense of trust. We want to see the best in people. Hackers don’t just exploit code; they exploit our emotions.

He shared a powerful, human story about an older relative who had been scammed four times by the same type of scam. “An older person who’s innately very trusting, doesn’t understand technology, gets very time pressured,” he explained. “Their partner was saying ‘it is a scam’ and they were saying ‘no, it’s not a scam, it’s legitimate’”. That’s the core of social engineering. It leverages our best traits — our empathy, our desire to be helpful, our trust — and turns them into our biggest vulnerabilities.

The Scale of the Problem (It’s Worse Than You Think)

Some real-world numbers.

  • 1.7 billion individuals were affected by data breaches in 2024 alone. That figure represents a threefold increase from 2023.
  • Two-thirds (67%) of organisations experienced at least one cyber-attack in the past year.

But the statistic that truly landed was this: the global cost of cybercrime is projected to hit £8 trillion annually, making it the world’s third largest “economy” if measured by GDP.

This isn’t a theoretical problem. He brought it home with recent UK examples we all remember:

  • Jaguar Land Rover: A ransomware attack forced a five-week shutdown and led to a £1.9 billion loss.
  • Marks & Spencer: An attack led to a projected £300 million profit loss.
  • The NHS: An attack by the ‘Qulin’ hacking group disrupted critical blood transfusion and pathology services for weeks.

This is happening right now, and the impact is no longer just digital. The Good, The Bad, and The Morally Ambiguous So, who is doing this? We broke down the terminology with a simple, brilliant analogy. He asked the room if anyone knew the origin of “white hat” and “black hat” hackers. The terms come from old Western movies. “The sheriff, the Marshall, the hero of the story, usually wore a white hat, and the villain had the Black Hat,”:

  • White Hat Hackers: These are the “heroes” — ethical hackers hired by companies to find vulnerabilities before the “baddies” do.
  • Black Hat Hackers: These are the “villains” — malicious attackers who exploit those vulnerabilities for personal gain.

But the most fascinating discussion was around Gray Hat Hackers. These individuals operate in a “morally ambiguous” middle ground. “They look for vulnerabilities… but they don’t use it to cause harm,”. Instead, they will contact the company and say, “Pay me £2000 and I will explain to you how I went about finding those gaps”. Is it ethical? Is it extortion? As Xavier noted, it’s “borderline,” and it perfectly highlights the complex ethics of this field.

The Google Dorking Experiment

This brought us back to the practical. “Google Dorking,” is just a fancy name for using Google’s advanced search operators to find information that isn’t easily accessible. This was the interactive part of the masterclass, and the chat lit up. He had us run searches for our own names, email addresses, and even our CVs. The reactions were a mix of relief and shock: “Mine’s pretty good. I’ve been quite meticulous about locking down my profile”. “There’s movie director from Nigeria with a similar name, thankfully most of the results about him”.

Have you been PWNED?!

A reference for another article you might think but, it’s actually a very helpful tool for checking if your data has been compromised. https://haveibeenpwned.com/

Using this, many of us had thankfully a limited footprint, some found old CVs and email addresses scattered across the web. The point was simple: this was just “scratching the surface”. The information is public, just waiting to be harvested.

The Data Broker Revelation

If the Google Dorking was a quiet alarm, this next part was a siren. Xavier put up a slide showing the average number of data points tech giants collect on us: Google (39), Twitter (25), Amazon (23), Facebook (14).

But the real shock? Data brokers companies you’ve never heard of hold an average of 5,000 pieces of data on each person! How do they get it? We did another poll: “How many of you actually read the cookie pop-up?” The result: 77% of us admitted we never do. We just want the “annoying” pop-up out of the way. But every click on “Accept” is a legal consent to data harvesting. It’s the impossible trade-off of the modern web: convenience for privacy.

When AI Becomes the Weapon

It wouldn’t be quite the Digital Edge article without mentioing the effects of AI, what happens when you combine this massive pool of personal data with the power of artificial intelligence? The answer is you get weaponised AI!

Some examples:

  • WormGPT: A malicious version of ChatGPT “specifically designed for malicious purposes”. It can scrape your social media data to craft a hyper-convincing phishing email. He cited a case where an AI-generated email tricked a Japanese company into making a £5 million fraudulent payment.
  • Clearview AI: A tool that “matches faces against billions of images scraped from the web,” effectively ending public anonymity.
  • Maltego: An algorithm that “maps relationships between entities” — linking your email, to your social profiles, to your colleagues, to your blog posts, creating a detailed digital trail.

What used to take a skilled hacker hours of manual research now takes AI seconds.

How to Fight Back (A Practical Defense Plan)

At this point, the room felt a bit heavy. So, how do we defend ourselves? Xavier first demystified the Lockheed Martin Cyber Kill Chain, an 8-stage framework that shows how an attack happens.

It starts with Reconnaissance (gathering info) and ends with Actions on Objectives (the data theft or ransomware). The key is to break the chain at Stage 1. And the defence strategies were all practical, actionable, and aimed at doing just that.

Here was his essential checklist:

  • Limit Public Exposure: Make your social media profiles private. Remove your birthday, workplace, and location from public view.
  • Monitor Your Digital Footprint: Use those same Google Dorking techniques to regularly check what’s publicly available about you.
  • Clean Up Old Accounts: He recommended a service called JustDeleteMe.com that helps you find and delete old accounts you’ve forgotten about.
  • Remove Metadata from Photos: Before uploading a photo, strip the EXIF data (location, device, time). “There’s nothing worse,” he warned, “than having an image with information about the image”.
  • Education: This was his most powerful point. Continuous learning and awareness are your single strongest shields, so for you reading this article, your well on your way, but, it doesn’t stop here.

The Ethics of Knowing (With Great Power…)

Perhaps one of the most important aspects of cybersecurity, the ethical one. Knowing this knowledge comes with a strong ethical warning. He put up the classic Spider-Man quote: “With great power comes great responsibility”. “Only do this on yourself”. He reminded us not to share or request access to any real system without explicit, written consent.

The lesson was clear: learning to think like a hacker is a skill. Using it ethically is a choice.

The only difference between a white hat and a black hat is intent and consent.

The Curious Mind as the Best Defense

The masterclass was a powerful and extremely useful. It wasn’t about being fearful, but about being informed. “The strongest shield against cyber threats is a curious mind guided by ethics”. “Be curious. Explore these things. So, question when these pop-ups are coming up… But, do these things in an ethical way”.

In 2025, ignorance isn’t bliss — it’s a vulnerability!

And the first step to defending yourself is understanding what you’re defending!

Xavier is one of the talented lectures we have at BPP University, School of Technology. Reach him here: https://www.linkedin.com/in/xavier-nel-91a19650/

If you’d like to learn more about what we offer, please visit bpp.com

References from the article.

[1] Cybersecurity Ventures. (2023). Cybercrime To Cost The World $10.5 Trillion Annually By 2025. Available: https://cybersecurityventures.com/cybercrime-to-cost-the-world-10-5-trillion-annually-by-2025/ [2] The Guardian. (2024). What is the Qilin ransomware gang blamed for NHS cyber-attack?. Available: https://www.theguardian.com/technology/article/2024/jun/04/what-is-the-qilin-ransomware-gang-blamed-for-nhs-cyber-attack [3] Lockheed Martin. (n.d.). The Cyber Kill Chain. Available: https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html [4] The Data Protection Commission (DPC). (2023). DPC investigation into Data Brokerage. Available: https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-publishes-report-its-investigation-data [5] Pew Research Center. (2014). Public Privacy Perceptions. Available: https://www.pewresearch.org/internet/2014/11/12/public-privacy-perceptions/


메타데이터
post_id
da9d60220b36
slug
a-ethical-hacking-masterclass-that-changed-how-i-see-privacy-da9d60220b36
url
https://medium.com/bpp-digital-edge/a-ethical-hacking-masterclass-that-changed-how-i-see-privacy-da9d60220b36
canonical_url
https://medium.com/bpp-digital-edge/a-ethical-hacking-masterclass-that-changed-how-i-see-privacy-da9d60220b36
author_url
https://medium.com/@idrisfabiyi
status
ok
fetched_at
2026-06-13 07:35:29