The most dangerous device on a company’s network this July isn’t the laptop IT issued. It’s the browser extension a bored teenager installed on that same laptop, twenty minutes ago, to get through a history project.
It’s a scenario Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa, has been flagging heading into the school holidays: a 15-year-old at home on the family laptop, the one a parent also uses for work, while that parent is down the hall on a high-stakes Teams call. The teenager searches for a “free AI tutor,” finds a browser extension that promises instant homework answers, and installs it. If that browser profile is shared, and it isn’t locked down with multi-factor authentication, the same extension can just as easily harvest session cookies and saved credentials that lead straight back to a corporate login.
“A curious child simply opened a door, and an attacker could walk through the household to reach the employer,” Collard says. During the South African winter holidays, when children spend long unsupervised hours online and parents work from the kitchen table beside them, she argues that door swings open more often than security teams would like.
One roof, one attack surface
The risk goes well beyond a shared laptop. A typical South African household now runs on connected devices: the app that switches the geyser off to save money, the robot vacuum, the smart TV box streaming the holidays away. Each one is a computer sitting on the same network as the work machine, which means an attacker who compromises one can probe the others, exploit a weak router, intercept unencrypted traffic, or hijack DNS.
That risk isn’t theoretical. The BADBOX 2.0 botnet compromised more than 10 million uncertified Android devices, cheap streaming boxes, tablets, digital projectors, and picture frames, some with malware pre-installed at the factory before they ever reached a shop shelf. It triggered an FBI advisory and a lawsuit from Google against the operators. In January, researchers identified a successor called Kimwolf, already running on more than two million infected devices, mostly unofficial TV boxes sold as a cheap route to unlimited streaming.
Kimwolf is technically linked to a different malware family, Aisuru, rather than being a direct descendant of BADBOX. Collard argues the distinction matters less than the pattern underneath it: cheap, uncertified hardware compromised at scale, sold into a market where exactly that kind of box moves fast. The bargain streaming device under the tree, she says, can already be working for someone else before it’s out of the box.
For a company, the consequence rarely shows up as a stolen TV box. It shows up as a stolen credential, a hijacked session, or a compromised home network, riding back into corporate systems on the shoulders of an employee who did nothing wrong.
The attacker has upgraded. The setting hasn’t kept up
Layer AI onto that picture and the gap widens further. KnowBe4’s latest Phishing Threat Trends Report found that 86% of phishing attacks were now AI-driven, alongside a 41% rise in attacks delivered through Microsoft Teams and a 139% surge in reverse-proxy attacks aimed at stealing Microsoft 365 credentials. The clumsy “Dear Sir/Madam” email is a decade out of date. What replaces it references your name, your role, and your organisation’s recent news, and arrives through email, chat, and calendar invites at the same time.
That upgrade lands exactly when people’s guard is lowest, at home, relaxed, half-listening to the children in the next room. It’s also landing on ground that South African organisations are largely unprepared for. Collard says security teams increasingly have to think about a workforce’s exposure that extends past the office, into the routers, passwords, and browser habits of the people employees live with, none of which will ever appear on an IT asset register.
Security training is digital parenting wearing a corporate lanyard
Collard is wary of the obvious corporate response. Extending monitoring into employees’ homes, she says, would be invasive, unworkable, and would burn the trust it’s trying to protect. Her starting point is different: make the stakes personal rather than institutional.
“Call it digital parenting: security awareness as a life skill that happens to protect the employer as a by-product,” she says. Most security training fails, in her view, because employees experience it as something done to them, a compliance module that protects the employer and nobody else. Reframed as a life skill, the motivation shifts: the instincts that catch a phishing email are the same instincts that catch a grooming attempt aimed at a child, a romance scam aimed at a parent, or a scheme aimed at draining a family’s savings. An employee who understands why a “free” game mod from an unverified source is dangerous, she argues, is better equipped to have that conversation with their own child than one working from a vague instruction to “be safe online.”
KnowBe4’s CAPY hub is built around that reframing: guidance people can take home voluntarily, covering how to protect children online, secure family devices, and spot scams aimed at older relatives. It treats the employee as a capable adult and the household as an ally rather than a liability, raising the digital literacy of everyone in the house without a single line of surveillance code.
The connected home will keep the geyser warm and the children entertained this holiday regardless of what any company does. Whether it also keeps the office safe depends on a conversation that happens around the kitchen table, long before anything reaches a security team’s dashboard.


