Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Fixing the #1 Problem in Computer Security: A Data-Driven Defense

This is a great whitepaper you can download for free at Microsoft written by IT Security Guru Roger Grimes. Here is the Executive Summary: "Many companies do not appropriately align ...
Continue Reading

CyberheistNews Vol #5 #41 KnowBe4 Got A CEO Fraud Phishing Attack. Wrong Mark!

*|CyberHeistNews|* CyberheistNews Vol #5 #41 Sept 29, 2015 KnowBe4 Got A CEO Fraud Phishing Attack. Wrong Mark! KnowBe4 has been warning against "CEO Fraud" emails for a few months now, ...
Continue Reading

Ransomware Attacks Move From Consumers To Small Medium Business

The criminal gangs that live off ransomware infections are targeting Small Medium Business (SMB) instead of consumers, a new Trend Micro Analysis shows. The reason SMB is being targeted ...
Continue Reading

Miami County pays CryptoWall Ransom To Get 911 Center Back Online

The Miami County Communication Center’s administrative computer network system was compromised with a CryptoWall 3.0 ransomware infection which locked down their 911 emergency center. ...
Continue Reading

The Meaning Of The U.S. and China Hacking Agreement

Last Friday, after years of data breaches by Chinese hackers, many months of negotiations and occasional threats from the White House, while China's President Xi was in DC, the U.S. and ...
Continue Reading

The ten immutable laws of security administration revisited

Casper Manes at GFI wrote a great blog post that I'm crossposting here. Welcome back to our series for people looking to break into the Infosec field or just learn more about information ...
Continue Reading

KnowBe4 got a CEO Fraud phishing attack. Wrong Mark!

KnowBe4 has been warning against "CEO Fraud" emails for a few months now, the FBI also calls them "Business Email Compromise" (BEC). I had been hoping we would get one of these ourselves, ...
Continue Reading

CyberheistNews Vol #5 #40 Scam Of The Week: Deceptive Amazon Account Threat

CyberheistNews Vol #5 #40 Sept 22, 2015 Scam Of The Week: Deceptive Amazon Account Threat Seeing the fact that Amazon is the World's largest retailer it's surprising that there aren't ...
Continue Reading

What is the REAL cost of a data breach?

A new survey done by Kaspersky with participation of 5,500 companies in 26 countries finally shows the real cost of a data breach broken out by Small and Medium Business (SMB) and ...
Continue Reading

BitPay loses 1.8 Million In Phishing Attack

BitPay lost $1.8 million in a phishing attack late last year, according to lawsuit filed by the bitcoin payment processing firm against an insurer it is trying to get to cover some of the ...
Continue Reading

Scam Of The Week: Amazon Account Threat

Seen the fact that Amazon is the World's largest retailer it's surprising that there aren't more of these scams, but this one sticks out as particularly deceptive. Often cyber criminals ...
Continue Reading

FBI ALERT: Cybercriminals Spoof Your Domain With CEO Fraud

The FBI recently warned against a new cyber crime wave. It's called "CEO Fraud" where cybercriminals impersonate your CEO using your own spoofed domain name, and order employees to ...
Continue Reading

Half Of Your Users Are Now Spear Phishing Targets

In a presentation at the Intelligence & National Security Summit, Bill Evanina, Director of the National Counterintelligence and Security Center (NCSC) announced "There have been just ...
Continue Reading

Banks Do Not Pay You Back If You Get Hit With A Cyberheist

I was very happy to see that NPR has jumped on a story I have been trying to get out for a while. John Ydstie has a new example, where he shows the incredible hassle and disappointment ...
Continue Reading

CyberheistNews Vol #5 #39 Expert Russians Hackers Use Satellites To Hide Amazing Exploits

*|CyberHeistNews|* CyberheistNews Vol #5 #39 Sept 15, 2015 Expert Russians Hackers Use Satellites To Hide Amazing Exploits Ouroboros, one of the world’s most sophisticated hacking groups ...
Continue Reading

US Counter-Intel Czar Warns Hack Victims Against Spear Phishing

WASHINGTON–In a presentation at the Intelligence & National Security Summit, the director of the National Counterintelligence and Security Center (NCSC) announced a "new ...
Continue Reading

Expert Russians Hackers Use Satellites To Hide Amazing Exploits

Ouroboros, one of the world’s most sophisticated hacking groups with close ties to the Russian government, has been accused of hijacking unencrypted commercial satellite communications. ...
Continue Reading

Pentagon Hacked Again, Compromising Employee Financial Info

Hackers infiltrated the Pentagon food court's computer system, compromising the credit and debit card info of an unknown number of employees. Lt. Col. Tom Crosson, a Defense Department ...
Continue Reading

Aggressive Android ransomware spreading in the USA

Your Android device's lock screen PIN keeps your phone's contents safe, but not from a new strain of ransomware which hijacks your phone or tablet. Security researchers at ESET discovered ...
Continue Reading

2015 U.S Hacking Incidents More Than Previous Two Years Combined

In 2015 U.S. organizations are seeing a significant spike in hacking incidents. Over 122 Million records breached just from hacking alone. That is not counting all of the other incidents ...
Continue Reading

[INFOGRAPHIC] Security of The Internet of Things (IoT)

The Internet of Things is far from secure. Don't trust me, just check the FBI, they are getting worried about this too. I have talked about hacks of Internet enabled devices before, ...
Continue Reading

Three Big Ransomware Campaigns Victimize Tens Of Thousands

Cybercrime has not given up on ransomware just yet. In fact, it's expanding as different Eastern European mafias are competing with each other for market share in this segment. Here are ...
Continue Reading

CyberheistNews Vol #5 #38 Scam Of The Week: Drowned Syrian Boy

CyberheistNews Vol #5 #38 Sept 1, 2015 Scam Of The Week: Drowned Syrian Boy Lowlifes are exploiting the recent picture of three-year-old Syrian boy Alyan Kurdi. He drowned while ...
Continue Reading

A Cyberheist Subscriber's Own Hacking Horror Story

Here is a cyberheist subscriber who sent me their own hacking horror story. "Stu, thought I’d give you one. You can use it if you want. Just make it anonymous. So, being in IT we think we ...
Continue Reading

Social Engineering Heaven: Combine AshMad Hack With OPM Data

The Office of Personnel Management has just closed a 133 million dollar contract to protect 21.5 million OPM data breach victims for three years. Wow, "Barn, Horse" anyone? This is an ...
Continue Reading

KnowBe4 Grand Opening Sept 2015

September 3rd, 2015 - KnowBe4 had the grand opening of our new facility in Tampa Bay, Florida. The 15,000 square foot top floor has a wrap-around 360 panoramic view of the Gulf of Mexico ...
Continue Reading

CyberheistNews Vol #5 #37 Scam Of The Week: Business Email Compromise

CyberheistNews Vol 5 #37 Sept 1, 2015 Scam Of The Week: Business Email Compromise Last week, the FBI via their Internet Crime Complaint Center announced some astounding numbers, worse ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews