Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Scam Of The Week: Nepal Earthquake

More than 5,000 people dead and counting. And you can also count on cyber-criminals exploiting the disaster. What else is new. Disgusting. Scammers are now using the Nepal disaster to ...
Continue Reading

New Multi-Language Ransomware Crypt0l0cker

Ransomware is being localized for large Asian countries now. There is an ongoing attack targeting Korea, followed by Malaysia and then Japan. If you have business partners or subsidiaries ...
Continue Reading

Tesla Attack Caused By Social Engineering

A few days ago, you may have read the news that Tesla Motors had their website and Twitter accounts hijacked by pranksters. OpenDNS has a blog post that goes into great technical detail.
Continue Reading

CyberheistNews Vol 5 #17 Apr 28, 2015 FUN CARTOON: The 5 Generations Of Security Awareness Training

FUN CARTOON: The 5 Generations Of Security Awareness Training For a change, let's have some fun for a moment. InfoSec is gloomy enough as you will see if you keep on reading. So first the ...
Continue Reading

Ransomware Mafia Now Uses Bitcoin As Obfuscation Layer

Bitcoin is a very speculative currency, still relatively easy to manipulate compared to the major currencies, and subject to massive increases and drops in value. Currently the falling ...
Continue Reading

How Criminals Exploit Gaps In Your Security Awareness Training

I was at RSA in San Francisco last week. Great show, with ~30,000 attendees and packed exhibit halls at the Moscone Center. We invited KnowBe4 customers who were attending RSA for a ...
Continue Reading

CyberheistNews Vol 5 #16 Apr 21, 2015 - Scam Of The Week: IRS Refund Ransomware

*|CyberHeistNews|* Scam Of The Week: IRS Refund Ransomware CyberheistNews Vol 5 #16 Apr 21, 2015 Scam Of The Week: IRS Refund Ransomware Many of us waited till the last moment before the ...
Continue Reading

The 5 Security Awareness Training Generations [CARTOON]

Today, your employees are frequently exposed to advanced phishing and ransomware attacks. Your users are the weak link in your IT security. There are 5 ways (generations) to train ...
Continue Reading

Scam Of The Week: IRS Refund Ransomware

Many of us waited till the last moment before the April 15 tax deadline and are now holding our collective breath in expectation of that possibly rewarding refund. The problem is that ...
Continue Reading

90% of phishing incidents trace back to PEBKAC and ID10T errors

Don't have time to read through the massive Verizon's 2015 Data Breach Investigations Report? Here is a great summary; 90% of Security incidents are still caused by PEBKAC and ID10T ...
Continue Reading

New TeslaCrypt Ransomware Uses More Exploit Kits As Infection Vector

The new Internet Security Threat report from Symantec shows that the growth of file-encrypting ransomware expanded from 8,274 in 2013 to 373,342 in 2014. This is 45 times more ...
Continue Reading

If You Think Security Awareness Training is Expensive, Try Ignorance

Facts surrounding spear phishing all point to employees as the most cited culprits and security awareness training as the most effective remedy. Yet all training programs are not equal. ...
Continue Reading

CyberheistNews Vol 5 #15 Apr 14, 2015 New Ransomware CrypVault Evades AV With Simple Batch Scripts

New Ransomware CrypVault Evades AV With Simple Batch Scripts A new ransomware strain dubbed CRYPVAULT is being spread as an email attachment. It's beta testing in Eastern Europe and is ...
Continue Reading

Ransomware Infects 30-PC network of health care company

In this Wednesday, April 1, 2015 photo, Jeff Salter, CEO of Caring Senior Service, poses for a photo in his company office building in San Antonio. Last December, the network of nearly 30 ...
Continue Reading

Wall Street Journal Video About Ransomware and Botnets

Wall Street Journal Video About Ransomware and Botnets The WSJ asked itself: Who Will Cybercriminals Target Next? (click on the picture to see the video at the WSJ website). ...
Continue Reading

So, What Is The Real Reason The White House Got Hacked?

According to a new CyberEdge research survey of 19 sectors, including government, spearphishing is the biggest concern to IT security pros, more worrisome than even malware. And only 20 ...
Continue Reading

Websense: Malware-as-a-Service Makes Cybercrime Easier

Websense released their annual Threat Report, which is interesting if you want to know what’s really happening in the criminal cyber landscape. Here are a few highlights, with a link to ...
Continue Reading

New Ransomware CrypVault Makes Files Look Like They Are Quarantined

New Ransomware CrypVault Evades AV With Simple Batch Scripts A new ransomware strain dubbed CRYPVAULT by Trend Micro is being spread as an email attachment. It's currently focusing on ...
Continue Reading

KnowBe4 Offers White House Free Security Awareness Training

April 7, 2015 - CNN reported that The White House said it noticed suspicious activity in the unclassified network that serves the executive office of the president. The KnowBe4 Blog ...
Continue Reading

Facebook sends simulated phishing attacks to their employees

Fortune reported: "Each fall, Facebook hosts an event called Hacktober in which its security experts attempt to trick employees into falling for common hacking tricks such as phishing ...
Continue Reading

CyberheistNews Vol 5 #14 IBM ALERT: 'Dyre Wolf' Uses Spear Phishing For $1Mil+ Cyberheists

IBM ALERT: 'Dyre Wolf' Uses Spear Phishing For $1Mil+ Cyberheists Last week, IBM Security reported on an active cyberheist campaign using a variant of the Dyre Trojan that has ...
Continue Reading

SHOCKER: Data Breaches Cost Big Companies Very Little

Two articles today in Fortune Magazine and Harvard Business Review each lifted a piece of the veil about a dirty little secret about data breaches. From Home Depot to Target to Sony, big ...
Continue Reading

Police Pay Ransom After Ransomware Phishing Attack

TEWKSBURY – Last December Tewksbury Police confronted a new, and growing, frontier in cyberterrorism when the CryptoLocker ransomware virus infected the department’s network, encrypting ...
Continue Reading

10 Hacking Facts / How They Impact You [Infographic]

Cybersecurity is one of the most pressing concerns for business and consumers, especially when it comes to social media. So much personal identifiable information (PII) exists across the ...
Continue Reading

IBM: 'Dyre Wolf' Cyber Gang Uses Spear Phishing For $1 Million Cyberheists

Last week, IBM Security reported on an active cyberheist campaign using a variant of the Dyre Trojan that has successfully stolen more than $1 million at a time from targeted enterprise ...
Continue Reading

NEW: This Week's Five Most Popular HackBusters Posts #2

There is an enormous amount of noise in the security space, so how do you know what people really talk about and think is the most important topic? Well, we created the Hackbusters site ...
Continue Reading

KnowBe4 First Quarter 2015

Our first quarter knocked it out of the park. Normally Q4 is the highest quarter in the year, but we eclipsed last year's Q4 handsomely. Year-over-year, Q1 of 2015 was 354 percent over Q1 ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews