Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Report: Phishing Remains the Most Prevalent Cyber Threat

Surge in Phishing Attacks Hijacking Legitimate Microsoft Communications

Amount of Money Requested In BEC Attacks Nearly Doubled in Q4 2024

CyberheistNews Vol 15 #12 Key Takeaways from the KnowBe4 2025 Phishing Threat Trends Report

The Human Element: Addressing Cybersecurity Risk in Danish and Swedish Organizations

Act Now: Phishing-as-a-Service Attacks are on the Rise

Why Password Security Matters: The Danish and Swedish Password Problem

Hundreds of Malicious Android Apps Received 60 Million Downloads

Key Takeaways from the KnowBe4 2025 Phishing Threat Trends Report

Scammers Can Be Victims Too

Phishing Attacks Abuse Microsoft 365 to Bypass Security Filters

Be Vigilant: BEC Attacks Are on the Rise

Agentic AI: Why Cyber Defenders Finally Have the Upper Hand

The Cybersecurity Confidence Gap: Are Your Employees as Secure as They Think?

Booking.com Phishing Scam Targets Employees in the Hospitality Sector

CyberheistNews Vol 15 #11 [Heads Up] 245% Increase in SVG Files Used to Obfuscate Phishing Payloads

98% Spike in Phishing Campaigns Leveraging Russian (.ru) Domains

Make Your Real Emails Less Phishy

Protect Yourself: Social Engineering Fuels SIM Swapping Attacks

245% Increase in SVG Files Used to Obfuscate Phishing Payloads

AI and AI-agents: A Game-Changer for Both Cybersecurity and Cybercrime

Beware: Malvertising Campaign Hits Nearly a Million Devices

U.S. Justice Department Charges China’s Hackers-for-Hire Working IT Contractor i-Soon

The Myth of Geographic Immunity in Cybersecurity

CyberheistNews Vol 15 #10 [Heads Up] Sophisticated Phishing Attack Uses New JavaScript Obfuscation Trick

Your KnowBe4 Compliance Plus Fresh Content Updates from February 2025

Autonomous Agentic AI-Enabled Deepfake Social Engineering Malware is Coming Your Way!

Your KnowBe4 Fresh Content Updates from February 2025

Warning: Ransomware Threats Increased Fourfold in 2024

Software Will Become Agentic and the Security Lessons We Need To Learn

Invoice or Impersonation? 36.5% Spike in Phishing Attacks Leveraging QuickBooks’ Legitimate Domain in 2025

AI Literacy: A New Mandate Under the EU AI Act - What Your Organization Needs to Know

Data at Risk: 96% of Ransomware Attacks Involve Data Theft

[Heads Up] Sophisticated Phishing Attack Uses New JavaScript Obfuscation Trick

Q&A with Martin Kraemer on Information Sharing in Cybersecurity

Primary Refresh Tokens Aren’t Your Parent’s Browser Token

School is in Session: Surge in Phishing Attacks Targeting the Education Sector

CyberheistNews Vol 15 #09 [NEW] KnowBe4 Interviews a Fake North Korean Employee

Announcing: Audiocasts - A New Podcast-Like Training Content Type

Protect Yourself from Job Termination Scams

Protect Your Devices: Mobile Phishing Attacks Bypass Desktop Security Measures

KnowBe4 Named #1 Security Product and #2 Overall Software Product in G2’s 2025 Best Software Awards

Chinese Hackers Target Hospitals by Spoofing Medical Software

Phishing Attack Leads to Lateral Movement in Just 48 Minutes

Viral but Vulnerable: The Hidden Risks of Cybersecurity Misinformation on Social Media

Warning: Russian Threat Actors Are Targeting Signal Accounts With Malicious QR Codes

CyberheistNews Vol 15 #08 Protect Your Data: Russian Spear-Phishing Targets Microsoft 365 Accounts

[NEW] KnowBe4 Interviews a Fake North Korean Employee

Phishing Kit Abuses Open Graph to Target Social Media Users

Phishing Attacks Increased by Nearly 200% in H2 2024

Spear Phishing is the Top Cyber Threat to the Manufacturing Sector

CyberheistNews Vol 15 #07 Facebook Business Users Beware: Thousands Hit by New Phishing Scam

Scanning for Trouble: Behind the Scenes of Our QR Code Phishing Demo

Protect Your Data: Russian Spear-Phishing Targets Microsoft 365 Accounts

Phishing for Love: A Sharp Surge in Valentine’s Day-Themed Scams

New Research: Ransomware Data Extortion Skyrocketing

[POLL] Sam Altman: "I don't do Google searches anymore." How about you?

New Phishing Campaign Targets The X Accounts of Politicians, Tech Companies, Cryptocurrency, And More

Facebook Business Users Beware: Thousands Hit by New Phishing Scam

CyberheistNews Vol 15 #06 Phishing Up 76% – Deepfake Attacks Surge: Is Your Org the Next Target?

2024 Was a Record-Breaking Year For Ransomware

Cybersecurity Resilience and Culture Matters to Face the Growing Frequency and Sophistication of Cybercrime

From Madison Avenue to Malware

Don’t Fall Victim: DeepSeek-Themed Scams Are on the Rise

Make-Shift Brand Impersonation: Abusing Trusted Domains with Open Redirects

Warning: Organizations Need to Prep For AI-Powered Ransomware Attacks

From Firewalls to Digital Well-Being: A Whole-School Approach to Online Safety

Phishing Up 76% – Deepfake Attacks Surge: Is Your Org the Next Target?

CyberheistNews [Vol 15 #05 Eye Opener] Is DeepSeek The Next Threat in Social Engineering?

Warning: Phishing Campaign Targets Germany with New Malware

Your KnowBe4 Compliance Plus Fresh Content Updates from January 2025

Your KnowBe4 Fresh Content Updates from January 2025

Beware: Mobile Phishing Mimicking the USPS Is On the Rise

The Rising Tide of Cybercrime Concerns in Africa

Using Genuine Business Domains and Legitimate Services to Harvest Credentials

Tips for Detecting Real-time Deepfakes: A Guide to Staying One Step Ahead

Microsoft is Still the Most Commonly Impersonated Brand in Phishing Attacks

CyberheistNews Vol 15 #04 [HEADS UP] Bad Actors Abuse Google Translate to Craft Phishing Attacks

[Eye Opener] Is DeepSeek The Next Threat in Social Engineering?

Beware of Toll Scam Texts: How Cybercriminals are Targeting U.S. Drivers

Nearly Three-Quarters of UK Education Orgs Have Sustained Cyberattacks

Phishing is the Top Security Threat For Smartphone Users

84% of Healthcare Organizations Sustained Cyberattacks Last Year

4 Ways to Mature Your Human Risk Management Program

Russian Spear-Phishing Campaign Targets WhatsApp Accounts

Malvertising Campaign Abuses Google Ads to Target Advertisers

CyberheistNews Vol 15 #03 Waging War on Explicit Deepfakes. The Real Problem Behind the UK Crackdown.

Threat Actors Abuse Google Translate to Craft Phishing Links

Phishing Campaign Attempts to Bypass iOS Protections

From Pig Butchering to People Talking

Effective Security Awareness Training Really Does Reduce Data Breaches

Your KnowBe4 Compliance Plus Fresh Content Updates from December 2024

Ransomware Gangs Claimed More Than 5,000 Attacks in 2024

Brad Pitt Romance Scams Pushed By AI-Enabled Deepfakes

First Ever Magic Quadrant™ for Email Security Platforms by Gartner®

Your KnowBe4 Fresh Content Updates from December 2024

Japan Attributes More Than 200 Cyberattacks to China Threat Actor "MirrorFace"

CyberheistNews Vol 15 #02 [HEADS UP] Credential Phishing Increased by 703% in H2 2024

Waging War on Explicit Deepfakes. The Real Problem Behind the UK Crackdown

Phishing Campaign Abuses Legitimate Services to Send PayPal Requests

Malicious WordPress Plugin Assists in Phishing Attacks

[BUDGET AMMO DEPT] WSJ: "Cybersecurity Is the King of Business Worries"

Phishing for Gamers: Fake Offers Invite Gamers to Test New Gaming Titles

CyberheistNews Vol 15 #01 [No Time to Waste] The 2025 Cybersecurity Tightrope: What's Next for The World?

Credential Phishing Increased by 703% in H2 2024

Tax-Themed Phishing Campaign Delivers Malware Via Microsoft Management Console Files

FTC Warns Immigrants About Rising Social Media Immigration Scams

CyberheistNews Vol 14 #52 [Heads Up] Bad Actors Use Voice Phishing in Microsoft Teams To Spread Malware

Russia’s APT29 Launches Major Spear Phishing Campaign

"Get Beyond Security Awareness Training" Does Not Mean Forgetting About It

Mobile Phishing Attacks Use New Tactic to Bypass Security Measures

Attackers Abuse HubSpot’s Free Form Builder to Craft Phishing Pages

James Bond-Style Scamming Profits Explode

No, KnowBe4 Is Not Being Exploited

AI-Powered Investment Scams Surge: How 'Nomani' Steals Money and Data

Phishing Campaign Targets YouTube Creators

[Heads Up] Bad Actors Use Voice Phishing in Microsoft Teams To Spread DarkGate Malware

U.S. Justice Department Indicts Fake IT Workers From North Korea

Critical Infrastructure Under Siege: 42% Spike in Ransomware Attacks on Utilities

CyberheistNews Vol 14 #51 Phishing Attacks Are Now Leveraging Google Ads to Hijack Employee Payments

94% of U.K. Businesses Aren’t Adequately Prepared for AI-Driven Phishing Scams

Sophisticated Phishing Campaign Attempts to Bypass SEGs

Mobile Phishing Campaign Targets Job Seekers

Be Careful of Malicious Ads

Nearly Half a Billion Emails in 2024 Were Malicious

Phishing Attacks Are Now Leveraging Google Ads to Hijack Employee Payments

Phishing Holds the Top Spot as the Primary Entry Point for Ransomware Attacks

CyberheistNews Vol 14 #50 Cruel Year-End Twist: When Fake Firing Is A Real Phishing Attack

Your KnowBe4 Compliance Plus Fresh Content Updates from November 2024

The 40% Rise of Phishing Attacks: How New Domain Extensions Are Fueling Cyber Crime

IRS Warns of Holiday-Themed Shopping Scams

Why Controversial Phishing Emails Do Not Work

Unwrapping Cybersecurity: A Festive "Die Hard" Guide

FBI Warns of Cybercriminals Using Generative AI to Launch Phishing Attacks

Your KnowBe4 Fresh Content Updates from November 2024

Malicious Google Ads Target Users Seeking Solutions to Printer Problems

Phishing Attacks Impersonating Big Brands Start to Zero in on Just One Brand

And the Winner of The Inside Man Biggest Fan Contest 2024 is…

CyberheistNews Vol 14 #49 [Heads Up] Bad Actor Uses Deepnude AI Image Generator to Lure And Infect Users

China Threat Actor Targets Individuals and Entities in Japan Via Spear Phishing Campaign

Cruel Year-End Twist: When Fake Firing Is A Real Phishing Attack

[NEW PRODUCT]: KnowBe4’s AIDA: Revolutionizing Security Awareness Training with AI-Powered Automation and Personalization

Malicious Loan Apps Target Android Users in Africa, South America and Asia

Nearly Every Hacker Believes AI Tools Have Created a New Attack Vector

CISA Strongly Recommends Phishing-Resistant MFA

75% of Black Friday Spam Emails Are Scams

[New!] Check Out These Powerful New KnowBe4 AI Features

Chinese Threat Actor Targets Black Friday Shoppers With Phishing Campaign

U.K. Residents are Victims of the Latest Phishing Scam Targeting Starbuck Customer Credentials

CyberheistNews Vol 14 #48 [Eye Opener] Phishing Attacks Now Exploit Visio and SharePoint Files

Phishing Emails Use SVG Files to Avoid Detection

[Heads Up] Bad Actor Uses Deepnude AI Image Generator to Lure And Infect Users

Phishing Attacks Exploits the Open Enrollment Period

Fraud Awareness Week

Ransomware Gangs Evolve: They're Now Recruiting Penetration Testers

Out of 29 Billion Cybersecurity Events, Phishing was the Primary Method of Initial Attack

Beware of Fake Tech Support Scams

Dark Side of Deals: Emerging Scams for Black Friday, Cyber Monday and Giving Tuesday

Threat Actors are Sending Malicious QR Codes Via Snail Mail

A New Era In Human Risk Management:Introducing KnowBe4 HRM+

Purina’s Champions Program Is the Best I Have Seen

The World Premiere of The Inside Man - Season 6 in St. Petersburg, Florida

CyberheistNews Vol 14 #47 Step-by-Step To Creating Your First Realistic Deepfake Video in a Few Minutes

Phishing Attacks Exploit Microsoft Visio Files and SharePoint

Half of all Ransomware Attacks This Year Targeted Small Businesses

[World Premiere] KnowBe4 Debuts New Season 6 of Netflix-Style Security Awareness Video Series - “The Inside Man”

Fortifying Defenses Against AI-Powered OSINT Cyber Attacks

Criminal Threat Actor Uses Stolen Invoices to Distribute Malware

Nation-State Threat Actors Rely on Social Engineering First

Step-by-Step To Creating Your First Realistic Deepfake Video in a Few Minutes

CyberheistNews Vol 14 #46 [Eye Opener] Attackers Don't Hack, They Log In. Can You Stop Them?

[FREE RESOURCE KIT] Stay Cyber Safe this Holiday Season with Our Free 2024 Resource Kit!

Criminals Use Search Engine Poisoning to Boost Phishing Pages

Recon 2.0: AI-Driven OSINT in the Hands of Cybercriminals

[Eye Opener] Attackers Don’t Hack, They Log In. Can You Stop Them?

Phishing Campaign Impersonates OpenAI To Collect Financial Data

The Deceptive Media Era: Moving Beyond "Real vs. Fake"

Attackers Abuse DocuSign to Send Phony Invoices

[Last Chance] KB4-CON APJ Cybersecurity Event is in 10 Days

BlackBasta Ransomware Gang Uses New Social Engineering Tactics To Target Corporate Networks

CyberheistNews Vol 14 #45 [Heads Up] QR Code Phishing is Growing More Sophisticated

Celebrating 5 Million Learners: The Evolution of KnowBe4's Compliance Plus

If Social Engineering Is 70% - 90% of Attacks, Why Aren’t We Acting Like It?

Your KnowBe4 Compliance Plus Fresh Content Updates from October 2024

Phishing Alert: Cybercriminals Impersonating KnowBe4 Training Emails

Every Cybersecurity List Should Be a Risk-Ranked List

The Rise of Outsourced Cybersecurity: How CISOs are Adapting to New Challenges

Threat Actors Abuse LinkedIn to Target Job Seekers

Your KnowBe4 Fresh Content Updates from October 2024

QR Code Phishing is Growing More Sophisticated

75% of Organizations Have Experienced a Deepfake-Related Attack

Crooks are Sending Halloween-Themed Phishing Emails

CyberheistNews Vol 14 #44 [Heads Up] Cyber Attacks Now Shift to Mobile. Are Your Users Prepared?

4 out of 10 Phishing Emails Are Sent From a Compromised Email Account

Threat Actors Compromise Valid Accounts Via Social Engineering

Cyber Attack Tools Now Being Used To Help Phishing Pages Avoid Detection

The £3 Million Daily Heist

Cybersecurity Budgets Are Increasing, but Security Leaders Don’t Think It’s Enough

[2025 Is Too Late] - European Companies Must Act Now Against AI-Powered Cyber Threats

New Research: 140% Increase in Callback Phishing


Get the latest about social engineering

Subscribe to CyberheistNews