Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Fixing the #1 Problem in Computer Security: A Data-Driven Defense

This is a great whitepaper you can download for free at Microsoft written by IT Security Guru Roger Grimes. Here is the Executive Summary: "Many companies do not appropriately align ...

CyberheistNews Vol #5 #41 KnowBe4 Got A CEO Fraud Phishing Attack. Wrong Mark!

*|CyberHeistNews|* CyberheistNews Vol #5 #41 Sept 29, 2015 KnowBe4 Got A CEO Fraud Phishing Attack. Wrong Mark! KnowBe4 has been warning against "CEO Fraud" emails for a few months now, ...

Ransomware Attacks Move From Consumers To Small Medium Business

The criminal gangs that live off ransomware infections are targeting Small Medium Business (SMB) instead of consumers, a new Trend Micro Analysis shows. The reason SMB is being targeted ...

Miami County pays CryptoWall Ransom To Get 911 Center Back Online

The Miami County Communication Center’s administrative computer network system was compromised with a CryptoWall 3.0 ransomware infection which locked down their 911 emergency center. ...

The Meaning Of The U.S. and China Hacking Agreement

Last Friday, after years of data breaches by Chinese hackers, many months of negotiations and occasional threats from the White House, while China's President Xi was in DC, the U.S. and ...

The ten immutable laws of security administration revisited

Casper Manes at GFI wrote a great blog post that I'm crossposting here. Welcome back to our series for people looking to break into the Infosec field or just learn more about information ...

KnowBe4 got a CEO Fraud phishing attack. Wrong Mark!

KnowBe4 has been warning against "CEO Fraud" emails for a few months now, the FBI also calls them "Business Email Compromise" (BEC). I had been hoping we would get one of these ourselves, ...

CyberheistNews Vol #5 #40 Scam Of The Week: Deceptive Amazon Account Threat

CyberheistNews Vol #5 #40 Sept 22, 2015 Scam Of The Week: Deceptive Amazon Account Threat Seeing the fact that Amazon is the World's largest retailer it's surprising that there aren't ...

What is the REAL cost of a data breach?

A new survey done by Kaspersky with participation of 5,500 companies in 26 countries finally shows the real cost of a data breach broken out by Small and Medium Business (SMB) and ...

BitPay loses 1.8 Million In Phishing Attack

BitPay lost $1.8 million in a phishing attack late last year, according to lawsuit filed by the bitcoin payment processing firm against an insurer it is trying to get to cover some of the ...

Scam Of The Week: Amazon Account Threat

Seen the fact that Amazon is the World's largest retailer it's surprising that there aren't more of these scams, but this one sticks out as particularly deceptive. Often cyber criminals ...

FBI ALERT: Cybercriminals Spoof Your Domain With CEO Fraud

The FBI recently warned against a new cyber crime wave. It's called "CEO Fraud" where cybercriminals impersonate your CEO using your own spoofed domain name, and order employees to ...

Half Of Your Users Are Now Spear Phishing Targets

In a presentation at the Intelligence & National Security Summit, Bill Evanina, Director of the National Counterintelligence and Security Center (NCSC) announced "There have been just ...

Banks Do Not Pay You Back If You Get Hit With A Cyberheist

I was very happy to see that NPR has jumped on a story I have been trying to get out for a while. John Ydstie has a new example, where he shows the incredible hassle and disappointment ...

CyberheistNews Vol #5 #39 Expert Russians Hackers Use Satellites To Hide Amazing Exploits

*|CyberHeistNews|* CyberheistNews Vol #5 #39 Sept 15, 2015 Expert Russians Hackers Use Satellites To Hide Amazing Exploits Ouroboros, one of the world’s most sophisticated hacking groups ...

US Counter-Intel Czar Warns Hack Victims Against Spear Phishing

WASHINGTON–In a presentation at the Intelligence & National Security Summit, the director of the National Counterintelligence and Security Center (NCSC) announced a "new ...

Expert Russians Hackers Use Satellites To Hide Amazing Exploits

Ouroboros, one of the world’s most sophisticated hacking groups with close ties to the Russian government, has been accused of hijacking unencrypted commercial satellite communications. ...

Pentagon Hacked Again, Compromising Employee Financial Info

Hackers infiltrated the Pentagon food court's computer system, compromising the credit and debit card info of an unknown number of employees. Lt. Col. Tom Crosson, a Defense Department ...

Aggressive Android ransomware spreading in the USA

Your Android device's lock screen PIN keeps your phone's contents safe, but not from a new strain of ransomware which hijacks your phone or tablet. Security researchers at ESET discovered ...

2015 U.S Hacking Incidents More Than Previous Two Years Combined

In 2015 U.S. organizations are seeing a significant spike in hacking incidents. Over 122 Million records breached just from hacking alone. That is not counting all of the other incidents ...

[INFOGRAPHIC] Security of The Internet of Things (IoT)

The Internet of Things is far from secure. Don't trust me, just check the FBI, they are getting worried about this too. I have talked about hacks of Internet enabled devices before, ...

Three Big Ransomware Campaigns Victimize Tens Of Thousands

Cybercrime has not given up on ransomware just yet. In fact, it's expanding as different Eastern European mafias are competing with each other for market share in this segment. Here are ...

CyberheistNews Vol #5 #38 Scam Of The Week: Drowned Syrian Boy

CyberheistNews Vol #5 #38 Sept 1, 2015 Scam Of The Week: Drowned Syrian Boy Lowlifes are exploiting the recent picture of three-year-old Syrian boy Alyan Kurdi. He drowned while ...

A Cyberheist Subscriber's Own Hacking Horror Story

Here is a cyberheist subscriber who sent me their own hacking horror story. "Stu, thought I’d give you one. You can use it if you want. Just make it anonymous. So, being in IT we think we ...

Social Engineering Heaven: Combine AshMad Hack With OPM Data

The Office of Personnel Management has just closed a 133 million dollar contract to protect 21.5 million OPM data breach victims for three years. Wow, "Barn, Horse" anyone? This is an ...

KnowBe4 Grand Opening Sept 2015

September 3rd, 2015 - KnowBe4 had the grand opening of our new facility in Tampa Bay, Florida. The 15,000 square foot top floor has a wrap-around 360 panoramic view of the Gulf of Mexico ...

CyberheistNews Vol #5 #37 Scam Of The Week: Business Email Compromise

CyberheistNews Vol 5 #37 Sept 1, 2015 Scam Of The Week: Business Email Compromise Last week, the FBI via their Internet Crime Complaint Center announced some astounding numbers, worse ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.