Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Report: Sophisticated Fraud Attacks Are on the Rise

The Ghost in the Machine: How a Multi-Stage Phishing Campaign Evades Security to Steal Microsoft 365 Credentials

New Criminal Toolkit Abuses Browser Push Notifications

KnowBe4 Is a Leader In the Gartner® Magic Quadrant™ for Email Security For the Second Consecutive Year

CyberheistNews Vol 15 #48 [New Deepfake Danger] 1 in 5 Biometric Attacks Are Now AI-Driven

Scammers Are Exploiting the Holiday Shopping Season

Phishing Campaign Uses Fake Party Invites to Deliver Remote Access Tools

One-Size-Fits-All Security Training Fits Nobody

Blurred Chats, Bigger Risks

EMEA Finance and Banking: A Sector Under Siege

UK’s New Cyber Security and Resilience Bill: What Does It Mean For Critical Infrastructure Organisations?

What Happens When Cybercriminals Compromise a Sportswear Giant?

CyberheistNews Vol 15 #47 [Be Prepared] How to Block New Mobile Malware Holiday Attacks

Report: Deepfake Attacks Are on the Rise

Be Prepared: Mobile Phishing Expected to Surge Fourfold During the Holiday Season

Report: Ransomware Attacks Surged Globally in October

How KnowBe4 Uses AI Efficiently to Get the Best Results

Warning: New Phishing Kit Targets Italian Entities

CyberheistNews Vol 15 #46 [The Click Trap] Users Pasting Malware With Just One Shortcut

New Android Malware Platform Targets Bank Accounts

2025 Cybersecurity Awareness Month by the Numbers

Your KnowBe4 Compliance Plus Fresh Content Updates from October 2025

Tycoon 2FA Phishing Kit Grows More Sophisticated

Introducing KnowBe4 Studios | Fresh Content Updates from October 2025

Warning: ClickFix Attacks are Growing More Sophisticated

CyberheistNews Vol 15 #45 [Under the Radar] Scammers Use Real Bodies, Fake Faces in Extortion Scams

Quantum Route Redirect: Anonymous Tool Streamlining Global Phishing Attack

Africa is Being Targeted by a Surge in AI-Fueled Phishing Attacks

Warning: Malicious Apps Are Impersonating AI Tools

Phishing Emails Use Invisible Hyphens to Avoid Detection

Microsoft Help Desk Phishing Attempt

LastPass Phishing Campaign Informs Users of Phony Death Notifications

New Study Warns of AI-Driven Extortion Attacks

Human Error is Still a Top Contributor to Cyberattacks

The Rapid Advancement of Malicious AI Is Changing Cyberdefense Forevermore

CyberheistNews Vol 15 #44 [Mystery] Tough One: Is It or Is It Not an HP Scam?

Report: AI Poisoning Attacks Are Easier Than Previously Thought

UN Convention Against Cybercrime Is a Huge Win!

When a “Contact Us” Form Becomes “Contact a Cybercriminal”

Report: Organizations Are Struggling to Keep Up With AI-Powered Attacks

Insider Risk, Ethical Walls and the Future of Data Governance in Financial Services

The Human-AI Partnership: Securing the New Dual-Front of Business Risk

Is It Or Is It Not an HP Scam?

CyberheistNews Vol 15 #43 [Heads Up] Block Attackers Who Abuse Grok to Spread Phishing Links

Report: More Than Half of Adults Encountered a Scam Last Year

[Cyber Security Awareness Month] Doppelgänger Promotes Incident Hiding: Why Saying Something When You See Something Is So Important

Phishing Campaign Impersonates Google Careers Recruiters

Phishing Campaign Impersonates Password Managers

Minimizing Liability Is Not The Same as Security: Lessons from Recent Airport Cyber Disruptions

Attackers Abuse Grok to Spread Phishing Links

Building Trust in the Digital Age: How Financial Services Can Balance Security and Speed

Alert: Watch Out For Phishing Attacks in the Wake of the AWS Outage

CyberheistNews Vol 15 #42 [Heads Up] Fake 'Support Calls' Used to Breach Your Salesforce Accounts

Half of Young People in the UK Cite Non-Consensual Deepfakes as a Top Fear

[Cybersecurity Awareness Month]: Keeping Enkryptor at Bay: How We All Can Help Beat Back Ransomware

Phishing Remains the Top Initial Access Vector in Cyberattacks Across Europe

We Need to Teach Our AIs to Securely Code

Protect Yourself From Voice Phishing Attacks Targeting Salesforce Instances

The Compliance Catch-22: How Financial Institutions Can Master Data Governance and Regulatory Risk

CyberheistNews Vol 15 #41 [AI Misuse Alert] New Phishing Campaign Uses AI Tools to Evade Detection

A Surge in Text Message Scams Targets Younger Americans

Warning: Job Scams Surge by More than 1000%

[Cybersecurity Awareness Month] The Rise of Dr. Deepfake: Combatting Social Engineering’s Newest Weapon

The Engine Room: Powering Your Human Risk Management Strategy with Intelligent Tech

Report: North Korea Expands Its Remote Employment Schemes

The Hidden Cybersecurity Threat: Securing the Human-AI Relationship

A TikTok for Deepfakes? OpenAI Could Be Making It a Reality

If You Have Not Realized It, Vishing Is Really Taking Off

Multitasking Employees Are Particularly Vulnerable to Phishing Attacks

Securing the Human-AI Boundary: Why the Future of Cybersecurity Must Train People and AI Agents

Cyber Risk Still #1: Why AI Is Raising the Stakes - and the Opportunities

New Phishing Campaign Uses AI Tools to Evade Detection

CyberheistNews Vol 15 #40 The Behavioral Science When Your Best People Are Click Magnets

Security Leaders Cite AI-Driven Phishing Attacks as a Top Concern

[Cybersecurity Awareness Month] Watch Out for the Cyberpunks: Outsmarting Social Engineering in Retro Arcade Style

Your KnowBe4 Compliance Plus Fresh Content Updates from September 2025

The DEEP Matrix: Your Map to a Unified Defense

North Korean Hackers Target Job Seekers With Social Engineering Tricks

Report: Deepfake Attacks Have Targeted Nearly Two-Thirds of Organizations

Your KnowBe4 Fresh Content Updates from September 2025

Why KB4-CON EMEA 2025 Should Be Your Must-Attend Cybersecurity Conference This October

Building Trust in AI: KnowBe4's Journey Toward ISO 42001 Certification

Get Your Game On! 3 Ways to Use the 2025 Cybersecurity Awareness Month Resource Kit

Going DEEP: A Simple Framework for a Complex Problem

CyberheistNews Vol 15 #39 [Watch Your Back] Why Your Security Strategy Needs a Human Upgrade Now

The 3 Biggest Email Security Challenges Facing Legal Organizations

The Behavioral Science Behind the Click

New AI-Driven Phishing Platform Automates Attack Campaigns

Attackers Use AI Development Tools to Craft Phony CAPTCHA Pages

Attackers Abuse Google’s AppSheet to Send Phishing Emails

CyberheistNews Vol 15 #38 Why Does Protecting AI Agents Need To Be Status Quo?

Why Your Security Strategy Needs a Human Upgrade

North Korean Hackers Target Job Seekers With ClickFix Attacks

AI-Assisted Phishing Attacks Are an Increasingly Serious Threat

CyberheistNews Vol 15 #37 [New Report] Shadow AI Threats Are Increasing. Here's How to Spot Them

Training AI Agents Will Be Status Quo

Report: AI-Powered Phishing Fuels Ransomware Losses

Phishing Campaign Abuses iCloud Calendar Invites

FBI Issues Guidance for Avoiding Deepfake Scams

PayPal Scam From PayPal

Report: Shadow AI Poses an Increasing Risk to Organizations

"Yep, I got pwned. Sorry everyone, very embarrassing."

CyberheistNews Vol 15 #36 One of the Biggest Mysteries in Cybersecurity: Why Don't We Demand This?

Smishing Campaign Targets California Taxpayers With Phony Refund Offers

Advanced Educational Competition – Ask Your Employees To Submit Their Best Phishing

Warning: New Spear Phishing Campaign Targets Executives

Hospitals Need to Prepare for AI-Powered Phishing Attacks

A Warrant Is Out for Your Arrest

Report: AI Can Now Automate Entire Attack Chains

Beyond the Audit Box: Building Security That Works in the Real World

CyberheistNews Vol 15 #35 [Watch Out] Hackers Now Use AI to Write Better Phish

Your KnowBe4 Compliance Plus Fresh Content Updates from August 2025

One of the Biggest Mysteries in Cybersecurity: Why Don’t We Demand This?

Your KnowBe4 Fresh Content Updates from August 2025

New Phishing Kit Bypasses MFA to Steal Microsoft 365 Credentials

Report: Cybercriminals are Hiring Social Engineering Talent

Back to School: Cybersecurity Education for All Ages

CyberheistNews Vol 15 #34 [Watch Out] That Urgent Payroll Update Alert? It's a Phishing Attack

Threat Actors Are Increasingly Abusing Generative AI Tools for Phishing

The Technical Sophistication Behind the "Free" Gift Scam: Evading Detection

The Hidden Cost of "Free" Gifts: How Survey Scams Are Evolving to Steal Financial Data

Warning: Social Engineering is a Growing Threat to the Industrial Sector

Phishing Attacks Target Brokerage Accounts to Manipulate Stock Prices

New Homoglyph Phishing Campaign Impersonates Booking.com

The Attacker’s Playbook: A Technical Analysis of Quishing and Encrypted SVG Payloads Used in HR Impersonation Phishing Attacks

That ‘Urgent Payroll Update’ Email is a Trap: A Look at the Latest HR Phishing Tactics

From Human Resources to Human Risk: Why HR is the Perfect Department for Cybercriminals to Impersonate

North Korean Threat Actor Delivers Ransomware Via Phishing Emails

CyberheistNews Vol 15 #33 [Beware] When Your AI Helper Becomes a Hacker's Dream Tool

How KnowBe4 Defend Seamlessly Integrates with Microsoft Defender for Office 365 Quarantine—And Why SOC Teams Should Care

[FREE RESOURCE KIT] Cybersecurity Awareness Month Kit 2025 Now Available

A Practical Guide to the European Union’s Cybersecurity Funding for SMEs

Celebrating KnowBe4's 6th Consecutive TrustRadius Tech Cares Award

Beyond the Inbox: How Old-School Mail Scams Are Still Stealing Your Money

Alert: Tech Support Scammers Send Phony Podcast Invites

CyberheistNews Vol 15 #32 How Hackers Exploit Microsoft Teams in Social Engineering Attacks

Honoring KnowBe4's 15 Years of Excellence with a New Brand Identity

Your KnowBe4 Fresh Content Updates from July 2025

Your KnowBe4 Compliance Plus Fresh Content Updates from July 2025

FBI Report: Attackers Are Sending Physical Packages with Malicious QR Codes

Anatomy of a Vishing Scam

Social Engineering Attacks Surged in the First Half of 2025

Beyond Traditional Defenses: Why French Cyber Resilience Needs to Improve

Warning: New Phishing Campaign Targets Instagram Users

ClickFix Social Engineering is Becoming More Popular

CyberheistNews Vol 15 #31 [Heads Up] Malicious M365 Connectors Put 300M Accounts at Risk

How Hackers Exploit Microsoft Teams in Social Engineering Attacks

If You Think Social Engineering Is Bad, It’s Going To Get Worse

FBI Issues Guidance on Thwarting North Korea’s Fraudulent IT Schemes

Malicious Connectors Potentially Impact Hundreds of Millions of Microsoft 365 Users

[CASE STUDY] Retail Organization Sees 50-Fold Increase in Phishing Reporting with KnowBe4's Phish Alert Button and Training

CyberheistNews Vol 15 #30 [Heads Up] Ransomware is Back—and Smarter Than Ever in 2025: Trends

Boost Your Browsing Security: Integrate SecurityCoach with Microsoft Edge for Business

KnowBe4 Named a 2025 Gartner Peer Insights™ Customers’ Choice for Email Security Platforms

[New Whitepaper] Best Security Practices for AI Prompting and Building Agent Systems

Warning: Ransomware Attacks Surged by 63% Last Quarter

Bridging the Gap: Human Risk in African Cybersecurity

Ransomware Trends in 2025

New APIsec University Training Modules Now Available in KnowBe4’s Diamond Library

CyberheistNews Vol 15 #29 [Jawdropper] AI Is Luring Travelers to Places That Don't Even Exist!

Job Seekers Beware: Many People Are Falling for Employment Scams

Thousands of Spoofed News Sites Are Pushing Investment Fraud Scams

FTC Advisory: How to Protect Yourself Against Job Scams

The Attack On Browser-Based AI Agents Is Coming

Digital Factories, Digital Dangers: Why Manufacturing is a Prime Target for Cyberattacks

Engineered To Evade: How Phishing Attacks Are Designed To Get Through Your Secure Email Gateway

CyberheistNews Vol 15 #28 [The $1B Question] Is Your Security Team Ready for AI Prompt Attacks?

AI-Generated Summaries Mistakenly Suggest Phishing Sites

Alert: Scattered Spider is Targeting the Aviation Sector

AI Attacks Are Coming in a Big Way Now!

Psychological Contract Breach and the Power of Security Culture - Research Insights

CyberheistNews Vol 15 #27 Is Your Human Risk Management Program Really Making a Difference? Measure It Now

What Makes Southeast Asia the “Ground Zero of Cybercrime”?

Is your Human Risk Management Program Creating Measurable Change? Find Out with Our Free Program Maturity Assessment

CyberheistNews Vol 15 #26 [My Clicking Time Bomb] What Do I Do About the Repeat Clickers?

Your KnowBe4 Compliance Plus Fresh Content Updates from June 2025

US Tech Executives Cite Cyberattacks as Their Top Concern

Your KnowBe4 Fresh Content Updates from June 2025

Warning: Scammers are Targeting WhatsApp Users

What Is Human Risk Management?

Europol Warns of Social Engineering Attacks

CyberheistNews Vol 15 #25 Microsoft & KnowBe4 Collab: Strengthen Email Security Through Strategic Integration

A Clicking Time Bomb: What To Do About Repeat Clickers

FTC States That Scams Cost U.S. Consumers $158.3 Billion in One Year

Happy 2nd Birthday to Our KnowBe4 Community!

Warning: Voice Deepfakes Continue to Improve

Phishing Deep Dive: EU-Affiliated Survey Platform Exploited in Sophisticated Credential Harvesting Campaign

KnowBe4 Collaborates with Microsoft: Strengthening Email Security Through Strategic Integration

CyberheistNews Vol 15 #24 [Red Alert] How a Fake Cybersecurity Firm Turned Out a Real Threat

Protect Yourself: Vishing Attacks Are Growing More Sophisticated

Google Report Outlines the Latest Scam Trends

Checkups and Checklists: Cyber Risk Isn’t Just a Technical Problem

What Is AI?

How to Recognize Fraudulent North Korean Job Applicants

How a Fake Cybersecurity Firm Became a Real Threat

Human Risk Management: Cybersecurity as a Business Enabler

OpenAI Report Describes AI-Assisted Social Engineering Attacks

KnowBe4 Wins Big with 2025 TrustRadius Top Rated Awards

CyberheistNews Vol 15 #23 [Heads Up] Your Kid's School Cybersecurity Gets Worse at an Alarming Rate

Spear-Phishing Campaign Targets Financial Executives


Get the latest insights, trends and security news. Subscribe to CyberheistNews.