Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Ransomware Gangs Evolve: They're Now Recruiting Penetration Testers

Out of 29 Billion Cybersecurity Events, Phishing was the Primary Method of Initial Attack

Beware of Fake Tech Support Scams

Dark Side of Deals: Emerging Scams for Black Friday, Cyber Monday and Giving Tuesday

Threat Actors are Sending Malicious QR Codes Via Snail Mail

A New Era In Human Risk Management:Introducing KnowBe4 HRM+

Purina’s Champions Program Is the Best I Have Seen

The World Premiere of The Inside Man - Season 6 in St. Petersburg, Florida

CyberheistNews Vol 14 #47 Step-by-Step To Creating Your First Realistic Deepfake Video in a Few Minutes

Phishing Attacks Exploit Microsoft Visio Files and SharePoint

Half of all Ransomware Attacks This Year Targeted Small Businesses

[World Premiere] KnowBe4 Debuts New Season 6 of Netflix-Style Security Awareness Video Series - “The Inside Man”

Fortifying Defenses Against AI-Powered OSINT Cyber Attacks

Criminal Threat Actor Uses Stolen Invoices to Distribute Malware

Nation-State Threat Actors Rely on Social Engineering First

Step-by-Step To Creating Your First Realistic Deepfake Video in a Few Minutes

CyberheistNews Vol 14 #46 [Eye Opener] Attackers Don't Hack, They Log In. Can You Stop Them?

[FREE RESOURCE KIT] Stay Cyber Safe this Holiday Season with Our Free 2024 Resource Kit!

Criminals Use Search Engine Poisoning to Boost Phishing Pages

Recon 2.0: AI-Driven OSINT in the Hands of Cybercriminals

[Eye Opener] Attackers Don’t Hack, They Log In. Can You Stop Them?

Phishing Campaign Impersonates OpenAI To Collect Financial Data

The Deceptive Media Era: Moving Beyond "Real vs. Fake"

Attackers Abuse DocuSign to Send Phony Invoices

[Last Chance] KB4-CON APJ Cybersecurity Event is in 10 Days

BlackBasta Ransomware Gang Uses New Social Engineering Tactics To Target Corporate Networks

Attackers Abuse Eventbrite to Send Phishing Emails

CyberheistNews Vol 14 #45 [Heads Up] QR Code Phishing is Growing More Sophisticated

Celebrating 5 Million Learners: The Evolution of KnowBe4's Compliance Plus

If Social Engineering Is 70% - 90% of Attacks, Why Aren’t We Acting Like It?

Your KnowBe4 Compliance Plus Fresh Content Updates from October 2024

Phishing Alert: Cybercriminals Impersonating KnowBe4 Training Emails

Every Cybersecurity List Should Be a Risk-Ranked List

The Rise of Outsourced Cybersecurity: How CISOs are Adapting to New Challenges

Threat Actors Abuse LinkedIn to Target Job Seekers

Your KnowBe4 Fresh Content Updates from October 2024

QR Code Phishing is Growing More Sophisticated

75% of Organizations Have Experienced a Deepfake-Related Attack

Crooks are Sending Halloween-Themed Phishing Emails

CyberheistNews Vol 14 #44 [Heads Up] Cyber Attacks Now Shift to Mobile. Are Your Users Prepared?

4 out of 10 Phishing Emails Are Sent From a Compromised Email Account

Threat Actors Compromise Valid Accounts Via Social Engineering

Cyber Attack Tools Now Being Used To Help Phishing Pages Avoid Detection

The £3 Million Daily Heist

Cybersecurity Budgets Are Increasing, but Security Leaders Don’t Think It’s Enough

[2025 Is Too Late] - European Companies Must Act Now Against AI-Powered Cyber Threats

New Research: 140% Increase in Callback Phishing

Ransomware Gang Attack Tactics Have Shifted

More Than 33,000 People in the UK Have Been Hacked Over the Past Year

Nearly Two-Thirds of IT Leaders Have Fallen For Phishing Attacks

CyberheistNews Vol 14 #43 North Korean IT Worker Threat: 10 Critical Updates to Your Hiring Process

Where Do I Point the Camera?

Cyber Attackers are Adopting a “Mobile First” Attack Strategy

KnowBe4's Cybersecurity Experts Shine at Barnes & Noble in New York City

North Korean IT Worker Threat: 10 Critical Updates to Your Hiring Process

FBI Warns Scammers Are Targeting Law Firms For Phony Debt Collections

Phishing Attacks Are Abusing Legitimate Services to Avoid Detection

UK Company Hacked After Accidentally Hiring North Korean Cybercriminal

AI-Enhanced Cyber Attacks Tops the List of Data Security Threats

Chinese Threat Actor Targets OpenAI With Spear-Phishing Attacks

The Number of Malicious Emails Reaching Inboxes Is Declining

North Korean Hackers Continue to Target Job Seekers

KnowBe4 Named a Leader in the Fall 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) Software

CyberheistNews Vol 14 #42 [Heads Up] Majority of U.S. Execs Now Rank Cyber Threats as #1 Risk

KnowBe4 Named a Leader in the Fall 2024 G2 Grid Report for Security Awareness Training

What Spending 3 Hours in IKEA Taught Me About Cybersecurity Awareness

44% of U.S. Organizations Experienced One or More Ransomware Attacks in the Last Year

Meet SmartRisk Agent™: Unlock Your New Human Risk Management

"Operation Kaerb" Takes Down Sophisticated Phishing-as-a-Service Platform “iServer”

Sextortion Scammers Attempt to Hit “Close to Home”

Trinity Ransomware Targets the Healthcare Sector

Google App Scripts Become the Latest Way to Establish Credibility and Automate Phishing Attacks

Hurricane Deepfakes Flood Social Media

Attackers Abuse URL Rewriting to Evade Security Filters

[Cybersecurity Awareness Month] Keeping Your Mobile Devices Secure from the ‘Inside’ Out

CyberheistNews Vol 14 #41 [Wake-Up Call] Senator Falls Victim to Deepfake Scam. Are Your Users Next?

Free Phishing Platform Has Created More than 140,000 Spoofed Websites

What Bletchley Park Can Teach Us About Building a Strong Security Culture

North Korea's Secret IT Army and How to Combat It

Financial Services Industry Experiences a Massive Increase in Brand Abuse

Infostealer Threat Group “Marko Polo” Evolving Into an “Empire”

Cybercriminal Gang Targeting SMBs Using Business Email Compromise

Don’t Put Real Answers Into Your Password Reset Questions

New VPN Credential Attack Goes to Great Lengths to Obtain Access

The U.K.'s NCSC and U.S. FBI Warn of Iranian Spear-Phishing Attacks

Dick’s Sporting Goods Cyber Attack Underscores Importance of Email Security and Internal Controls

From Desire Paths to Security Highways: Lessons from Disney's Approach to User-Centric Design

[Wake-Up Call] Senator Falls Victim to Deepfake Scam—Are Your Users Next?

Threat Actors Behind MFA Bypass Service ‘OTP Agency’ Plead Guilty to Fraud

New Survey Shows 40% of Respondents Never Received Cybersecurity Training From Their Employer

[Cybersecurity Awareness Month] Responding to Cyber Incidents the ‘Inside Man’ Way: Fiona's Approach

The Number of Ransomware Attacks Around the World Increased by 73% in 2023

CyberheistNews Vol 14 #40 Online Scams Shorten Their Cycles 58% And Make More Money

Your KnowBe4 Compliance Plus Fresh Content Updates from September 2024

Scammers Use QR Code Stickers to Target UK Motorists

From Tetris to Minecraft: The Evolution of Security Awareness into Human Risk Management

Your KnowBe4 Fresh Content Updates from September 2024

The AI Revolution: Balancing Innovation and Ethics in the Age of Intelligent Technology

Election-Themed Phishing Threats Are on the Rise

[WTH?] Critical Vulnerabilities in Automated Tank Gauges. This Is Not OK.

[Cybersecurity Awareness Month] From ‘The Inside Man’ to Real Life: AI's Role in Modern Cyber Threats

McAfee Discovers New Phishing Campaign Targeting GitHub Users

CyberheistNews Vol 14 #39 [EYE OPENER] Beyond Analysts: The Undeniable Leadership We Have in HRM

Scammers Abuse Virtual Shopping Lists to Trick Walmart Customers

Half of all Financial Services Cyber Attacks Start with a Very Costly Phish

Educate Your Users About Malicious SEO Poisoning Attacks

Zscaler: There are 200 Malicious Lookalike Domains for Every 1 Impersonated Brand

Online Scams Are Shortening Their Cycles and Making More Money

Phishing Attacks Abuse Content Creation and Collaboration Platforms

Beyond Analyst Reports: KnowBe4's Undeniable Leadership in Human Risk Management

The Inside Man Biggest Fan Contest is Heating Up

U.S. Government Indicts Chinese National For Alleged Spear Phishing Attacks

A Must See for KnowBe4 Customers and Partners: Geoff White to Keynote KB4-CON EMEA 2024

North Korean Hackers Target Software Developers With Phony Coding Tests

SANS Releases Guide to Address Rise in Attacks on Manufacturing and Industrial Control Systems

CyberheistNews Vol 14 #38 [CODE RED] A Must-See New Webinar: How To Block North Korean Infiltrators

[Cybersecurity Awareness Month] Prepare for All Manner of Cyber Threats Like the Heroes of ‘The Inside Man’

New Ransomware Threat Group, RansomHub, is so Effective, the NSA is Already Warning You About Them

BEC Scams Have Caused $55 Billion in Losses Over the Past Ten Years

[4-Minute Survey] Share Your Thoughts on AI in InfoSec With Me?

Authorized Push Payment Fraud Responsible for Over Half of U.K. Frauds and Scams

Attackers Using HTTP Response Headers to Redirect Victims to Phishing Pages

Your Lawyers Are Increasingly Targeted by Phishing Attacks, Ransomware

Forget the Talent Gap – It’s an Experience Gap

Losses From Investment Scams have Increased Six-Fold Since 2021

CyberheistNews Vol 14 #37 Scammers Use Fake Funeral LiveStream Social Media Posts to Extort Victims

[On-Demand Webinar] On How To Avoid Hiring Nation-State Fake Employees

Election-Themed Scams Are on the Rise

Use of Malicious Links Surges by 133% in Q1, Setting the Tone for the First Half of 2024

Phishing Attack Takes a Two-Step Approach to Leverage Legitimate Sites and Evade Detection

Manufacturing Sector Is the Latest Target of Advanced Credential Harvesting Attacks

Phishing is Still the Top Initial Access Vector

Threat Actors Increasingly Exploit Deepfakes for Social Engineering

[Security Masterminds Podcast] The Human Side of Cybersecurity: Bridging the Gap with Empathy and Strategy

CyberheistNews Vol 14 #36 KnowBe4 Expands Children's Interactive Cybersecurity Activity Kit for 2024/2025 School Year

Organizations in the Middle East Targeted By Malware Impersonating Palo Alto GlobalProtect VPN

Major Scam Operation Uses Deepfake Videos

Your KnowBe4 Compliance Plus Fresh Content Updates from August 2024

Scammers Use Fake Funeral LiveStream Social Media Posts to Extort Victims

Nearly Half of Mid-Market and Enterprise Organizations Have Experienced Four or More Ransomware Attacks in the Last Year

Threat Actors Abuse Microsoft Sway to Launch QR Code Phishing Attacks

U.S. Experiences 52% Increase in the Number of Ransomware Attacks in One Year

Your KnowBe4 Fresh Content Updates from August 2024

Fewer, High-Profile Ransomware Attacks Are Yielding Higher Ransoms

Iran’s APT42 Targets WhatsApp Users With Spear-Phishing Attacks

Email Compromise Remains Top Threat Incident Type for the Third Quarter in a Row

Phishing Attacks Are Increasingly Targeting Social Media and Smartphone Users

CyberheistNews Vol 14 #35 [PROVED] Unsuspecting Call Recipients Are Super Vulnerable to AI Vishing

More Carrots and Fewer Sticks

Ransomware Recovery Costs Have Doubled for State and Local Governments

KnowBe4 Expands Children’s Interactive Cybersecurity Activity Kit for 2024/2025 School Year

Business Email Compromise Scams Rise 20%, Making up Nearly Half of all Spam Emails

The Number of Email-Based Cyber Attacks Detected Surge 239% in 1H 2024

Malvertising Campaign Impersonates Dozens of Google Products

Deceptive AI: A New Wave of Cyber Threats

US Political Campaigns Targeted by Iranian Spear Phishing Attacks

Phishing Scammers Leverage Microsoft Dynamics 365 to Target US Government Contractors

Threat Actors Abuse URL Rewriting to Mask Phishing Links

Cybersecurity in 2024: Reflecting on the Past, Preparing for the Future

CyberheistNews Vol 14 #34 [HEADS UP] Real Social Engineering Attack on KnowBe4 Employee Foiled

The Long Road to Recovery Following a Ransomware Attack

U.K. Management Almost Twice as Likely to Fall for Phishing Attacks Versus Entry-Level Employees

Ransomware Group Known as ‘Royal’ Rebrands as BlackSuit and Is Leveraging New Attack Methods

Is Disabling Clickable URL Links Enough?

[PROVED] Unsuspecting Call Recipients Are Super Vulnerable to AI Vishing

File-Sharing Phishing Attacks Increased by 350% Over the Past Year

Ransomware Payments Decline While Data Exfiltration Payments Are On The Rise

Latest Phishing Scam Uses Cross-Site Scripting Attack to Harvest Personal Details

Employment Scams Continue to Target Job Seekers Via Phony Employment Offers

Real Social Engineering Attack on KnowBe4 Employee Foiled

Reflecting on KnowBe4's 5th Consecutive TrustRadius Tech Cares Award

Summer Lovin' or Summer Scammin'?

Chameleon Malware Poses as CRM App

CyberheistNews Vol 14 #33 Your Users Still Fall For Phishing Attacks Because of URL Shorteners

Attackers Abuse Google Drawings to Host Phishing Pages

[FREE RESOURCE KIT] 2024 Cybersecurity Awareness Month Kit Now Available

Hacker Stories: A Facebook Physical Threat

A Whopping 33% of Young Americans Are Exposed to Political Lies on TikTok

[WHOA] - This 'Unpatch Attack' Is A New One To Me!

Not Just Us: North Korean Remote IT Fraudster Arrested in Tennessee

New Phishing Campaign Targets Israeli Organizations To Deliver Malware

SEC Report Provides Insight into Key Tronic Ransomware Costs Totaling Over $17 Million

[On-Demand Webinar] 2024 Phishing Insights: What 11.9 Million User Behaviors Reveal About Your Risk

62% of Phishing Emails Bypassed DMARC Checks in 1H of 2024

“Pastejacking” Attacks Are Becoming a Thing (Because Users are Falling for Them)

AI Tools Have Increased the Sophistication of Social Engineering Attacks

New Malvertising Campaign Impersonates Google Authenticator

CyberheistNews Vol 14 #32 QR Code Phishing is Still on the Rise - The SEG is Dead

KnowBe4 Honors the World Famous Hacker for the First National Social Engineering Day

Creating a Big Security Culture With a Tiny Button

Brand Impersonation of Microsoft Increases 50% in One Quarter

Your Users Still Fall For Phishing Attacks Because of URL Shorteners

Prisoner Swap Includes Russian Hackers and KGB Assassin

Global Cyber Attacks See Highest Increases in the Last Two Years

New Research: Smaller Companies Receiving Higher Rates Of Phishing Emails

KnowBe4 Named a Leader in the Summer 2024 G2 Grid Report for Security Orchestration, Automation, and Response (SOAR) Software

Half of Travel-Themed Spam Emails Are Scams

The First Half of 2024 Results in More Than 1 Billion Data Breach Victims

KnowBe4 Named a Leader in the Summer 2024 G2 Grid Report for Security Awareness Training

Organizations Prepare for More Evolved AI-Based Cyber Attacks as Deepfakes Become Top Concern


Get the latest about social engineering

Subscribe to CyberheistNews