Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Russian Breach US Grid? Nah, Someone Fell For Social Engineering And Enabled Macros

Breathlessly, the Washington Post reports that the Russian Grizzly Steppe malware was found within the system of a Vermont power utility. Nah, they just dodged a bullet. This time someone ...

Russia Hacking America Started With Phishing Attacks

As one of his last actions in office, President Obama expelled 35 Russian diplomats spies in retaliation for Russia interfering with the U.S. election process, after intelligence agencies ...

Disk-Killer Malware Adds Ransomware Feature And Charges $200,000+ 

Talk about adding insult to injury with this new KillDisk version. Here is how social engineering can cost you dearly. The Sandworm cybercrime gang has upped its game. They were initially ...

You Need To Know The Top 10 IT Security Trends For 2017

I have been looking at the coming year and what trends you will probably see actually deployed in your network. These trends are the practical things that will help you to keep your ...

Scam Of The Week: George Michael Dies At 53. Watch out for phishing attacks

Today, news broke that George Michael was found dead on Sunday at his home in Goring in Oxfordshire, England. He was 53. A police statement said: “Thames Valley Police were called to a ...

Download This Hacked App And Die - Literally.

In the WSJ of Dec 22, 2016 there is an article that hides the real headline. It talks about the research done by CrowdStrike which shows that the DNC hack was done by a hacker group known ...

Is Lynda.com A Hacking Victim? They Lost 55K Records Somehow...

Lynda.com, the online learning unit of LinkedIn, has reset passwords for some of its users after it discovered recently that an unauthorized external party had accessed a database ...

CyberheistNews Vol 6 #51 Scam of the Week: The 1 Billion Yahoo Hack

CyberheistNews | KnowBe4

L.A. County Phishing Attack: 750,000 record data breach

Confidential health data or personal information of more than 750,000 people may have been accessed in a cyberattack on Los Angeles County employees in May that led to charges this week ...

Scam Of The Week: The 1 Billion Yahoo Hack

This is getting old. It's all over the press... again. Here is a Reuters article where I am quoted, which covers the most recent billion-record Yahoo hack. Some people asked me after our ...

The rise of ransomware-as-a-service. Stu Sjouwerman CSO Interview

My Interview at CSO About Ransomware-as-a-Service Joan Goodchild, Editor-in-chief at CSO sat me down and asked why Ransomware-as-a-Service has taken off recently: "It’s not just your ...

KnowBe4 and Barracuda Team Up to Educate and Protect Users Against Phishing Attacks

KnowBe4, the most popular security awareness training and simulated phishing platform, and Barracuda Networks, Inc. (NYSE: CUDA), a leading provider of cloud-enabled security and data ...

IBM study: 70% of Businesses Attacked Pay Ransomware

A rather mind-blowing 70% of businesses hit by ransomware paid the hackers to regain access to hijacked systems and files, according to a new IBM X-Force Ransomware report. Of the ...

And Another Billion More Yahoo Accounts Hacked

In the September/ October timeframe this year it became clear that Yahoo had lost more than 500 million records which was the biggest hack of the year. Who knew that they would top ...

[ALERT] Yikes, A New And Scary Double-Ransomware Whammy.

Sophos reported on one of the more scary ransomware strains I have seen lately. It's called Goldeneye and encrypts the workstation twice: both the files and the Master File Table (MFT). ...

New Book Coming Soon from Kevin Mitnick for You

The Art of Invisibility: The World's Most Famous Hacker Teaches You How to Be Safe in the Age of Big Brother and Big Data Kevin Mitnick, the world's most famous hacker, and KnowBe4's ...

SanFran Muni Ransomware Hacker Gets Hacked Back!

A couple of weeks ago, a yet unknown attacker hacked the computer systems of the San Francisco’s Municipal railway causing a free ride for all that Saturday. The ransomware hacker was ...

Former NSA Director Michael Hayden: "We have a Russia Problem"

I have been saying this here for the last few years, but if you get it confirmed by a former NSA director, that's nice to hear. The Wall Street Journal just reported that President Barack ...

Want Your Ransomed Files Back? Just Infect Someone Else!

Larry Abrams just reported: "Yesterday a new in-development ransomware was discovered by MalwareHunterTeam called Popcorn Time that intends to give victim's a very unusual, and criminal, ...

Locky Ransomware Campaign Using Osiris Extension from Egyptian Mythology

The threat actors behind Locky ransomware have moved on from Norse gods such as Zepto, Odin and Thor and into Egyptian mythology with a new campaign that uses the extension .osiris when ...

Phishing from the Middle: Social Engineering Refined

By Eric Howes, KnowBe4 Principal Lab Researcher. Phishing attacks have long been associated with malicious emails that spoof well-known institutions in order to trick users into coughing ...

Phishing Reply Tracking Is Now Available for All KnowBe4 Customers

Two of the big cybersecurity attacks are the CEO Fraud (aka Business Email Compromise) which has caused $3.4 billion in damages as well as the W-2 Scams which social engineer ...

CyberheistNews Vol 6 #49 Welcome To The CyberheistNews 2017 Crystal Ball Issue.

CyberheistNews Vol 6 #49 Welcome To The CyberheistNews 2017 Crystal Ball Issue. In December I spend a few days analyzing our space, and predict the coming year. The Crystal Ball issue is ...

Kaspersky: DDoS Often Smokescreen For Phishing Attack

Distributed denial of service attacks, also known as DDoS, are becoming a major threat. They can bring websites and networks down, and generally make a lot of noise demanding attention. ...

Phishing Attack Hits Saudi Govt Networks With Disk-Wiping Malware

Hackers penetrated six Saudi Arabian government agencies including its General Authority of Civil Aviation, and bricked thousands of computers with the well-known Shamoon disk-wiper ...

Russian Central Bank Loses 2 Billion Rubles in Cyberheist

Reuters reported that hackers stole more than 2 billion rubles ($31 million) from correspondent accounts at the Russian central bank, the bank said on Friday. “We can’t say exactly when, ...

The Top Five Names In Cybersecurity

Looking for the top names in cybersecurity? Look no further than the Cybersecurity 500 list of the world’s hottest and most innovative cybersecurity companies: ...

Scam Of The Week - Fake News: a Content-based Social Engineering Attack

Facebook, Google, and Twitter have recently been facing scrutiny for promoting fake news stories. Depending on your sources and who you believe, fake news played and is still playing a ...

10 Ways To Avoid Holiday Scams

With the biggest cybercriminal hacking holidays of the year upon us, it's time for a reminder of red flags to pay attention to when shopping either online or in brick-and-mortar stores.

Why Advanced Ransomware Is Cybercrime's Most Profitable Business Model

RSA did a revealing ransomware risk-reward analysis. See that $6 million number over to the right? Why does cybercrime like ransomware so much? Low Risk, High Payoff From the bad guy's ...

Yes, that message is really from Facebook. And, yes, it's really malicious.

By Eric Howes, KnowBe4 Principal Lab Researcher Just two weeks after we reported that the bad guys had effectively converted LinkedIin into a phishing platform, Facebook once again found ...

KnowBe4 Selected as SC Media 2017 Professional Award Finalist

KnowBe4, the world's most popular platform for new-school security awareness training was named a finalist in the SC Awards 2017 for exemplary professional leadership in cybersecurity. ...

Ransomware Roundup November 2016

Crysis decryption keys posted The decryption keys of the Crysis ransomware were posted on Pastebin, which allows victims to decrypt their hijacked files without paying. Crysis was ...

New Phishing Category: Controversial/NSFW*Offensive Language*

We get thousands of real phishing emails in, reported to us by customers using the free KnowBe4 Phish Alert Button. On a daily basis, these reported phishing emails get analyzed by the ...

This social engineering attack starts with a fake customer-service call

Michael Kan at CSO reported on a TrustWave blog post with some troublesome news: "Hotel and restaurant chains, beware. A notorious cybercriminal gang is tricking businesses into ...

KnowBe4’s Phish Alert Button Now Works With G Suite!

Do your users know what to do when they receive a suspicious email? Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report ...

KnowBe4 Ranked Number 50 Fastest Growing Company in North America on Deloitte’s 2016 Technology Fast 500™

Some very good news! Tampa Bay, FL — November 16, 2016 — KnowBe4, provider of the world’s most popular platform for security awareness training and simulated phishing attacks, today ...

Urgent Phishing Alert: Warn Your Users Against AdultFriendFinder Scams Now

Your end-users may have seen this in the news yesterday, or will read about it today. A massive data breach of the adult dating and entertainment company Friend Finder Network has exposed ...

Healthcare Sees 20 Data Loss Incidents PER DAY Due To Ransomware

In late October, three of the U.K.’s National Health Service (NHS) hospitals’ computer systems were attacked by malware that forced the hospital to cancel scheduled surgeries and divert ...

Scam Of The Week: Watch Out For Fake Apps

The shoe retailer Foot Locker Inc. has three iPhone apps. But that did not stop an entity calling itself Footlocke Sports Co., Ltd. from offering 16 shoe and clothing apps in the App ...

The LinkedIn Phishing Attack: How They Did It

by Eric Howes (Principal Lab Researcher) & Ryann Falke (Sales Development Representative) Last week we documented several interesting credentials phishes delivered through LinkedIn ...

My Antivirus Failed The RanSim Test. How Do I Fix This?

So, you downloaded KnowBe4's Ransomware Simulator test and your antivirus security software failed one or more of the ransomware scenarios. When this happens we almost always get asked: ...

OK, want to laugh your a$$ off? Watch this Apple parody!

It's not all doom and gloom!

New Locky Ransomware Phishing Attack: Credit Card Suspended And Suspicious Money Movements

Graham Cluley was the first to report on a new Locky ransomware phishing attack where the emails claim to be "credit card suspended" and "suspicious money movement" warnings. He said: "In ...

Tech support scammers abuse bug in HTML5 to freeze computers

Malwarebytes Researcher Jerome Segura reported on a new Tech Support scam that uses a known HTML5 bug to freeze the system and trick people to call a fake support number. Note, it does ...

City Of El Paso Victim Of 3 Million Dollar Phishing Scam

During a news conference Wednesday afternoon, city officials revealed that cybercriminals pretending to be a vendor scammed the city's Accounts Receivable Department out of about $3 ...

New Version Of Nymaim Malware Targets High-Level Managers

A new version of the Nymaim malware family targets high-level managers with attached malicious Word documents and drops ransomware and banking trojans. The cyber research team at Verint ...

Yes, that email is really from LinkedIn. And, yes, it's really malicious.

By Eric Howes, KnowBe4 Principal Lab Researcher. Several months ago we blogged about a startling discovery by threat researchers at Proofpoint: the bad guys had figured out a way to turn ...

Boy have we grown... KnowBe4 Halloween 2014, 2015, 2016

Halloween 2014 15 employees. Scroll down for the later years!

Scam Of The Week: Tech Support Claims Your Hard Disk Will Be Deleted

Symantec warns that tech support scams are getting more sophisticated by the month: "These scams remain one of the major and evolving forces in the computer security landscape. Between ...

How Podesta got hacked: HelpDesk said 'Password' phishing email was real

John Podesta, Chairman of the 2016 Hillary Clinton presidential campaign was a victim of social engineering and rushed advice from his IT helpdesk. It's a comedy of errors. The helpdesk ...

82% of Email Servers are Misconfigured, Allowing Domain Spoofing

We reviewed thousands of domains that have been through our domain spoof test and analyzed more than 10,000 email servers. We found that 82% of these are misconfigured.

Insurance underwriter Beazley: "Ransomware attacks will be four times higher in 2016"

The Wall Street Journal is getting the message. They said : "For companies concerned about the soaring number of ransomware attacks–in which hackers take control of data or systems and ...

Who Is Learning How to Take Down the Internet?

It was all over the news. A sustained DDoS attack that caused outages for a large number of Web sites Friday was launched with the help of hacked “Internet of Things” (IoT) devices. Jeff ...

Researchers discover new malicious IoT worm

Researchers at RapidityNetworks discovered a new malicious worm using Telnet that infects IoT devices using their insecure default credentials and uses a peer-to-peer network to install ...

Ransomware Strain Count Surpasses 200

Michael Gillespie tweeted: "Whew! ID #Ransomware can now identify 200 ransomware families. :) Sad such a milestone was hit so quickly..." He added a list from the malwarehunterteam site, ...

The New Posterboy of CyberInsecurity: John Podesta Fell For Social Engineering Attack

Motherboard has a great article explaining just how Podesta, Chairman of the 2016 Hillary Clinton presidential campaign got hacked. (Podesta previously served as Chief of Staff to ...

A Slick Phish with a Hidden Surprise

By Eric Howes, KnowBe4 Principal Lab Researcher. Yesterday one of our customers was hit with a highly targeted phishing attack -- one of the slicker attacks we've seen in a while. Once we ...

"My AV blocked RanSim.exe So I'm Safe" No You Are Not

I'm noticing a lot of people saying the ransim.exe file is getting blocked by your AV. You have to actually allow the initial processes to run to do the simulation. It is the five test ...

Python Ransomware Uses A Unique Key For Each File That Is Encrypted

A new ransomware strain written in Python called CryPy was disclosed by Avast malware analyst Jakub Kroustek. It seems that Pyton is getting more popular as a ransomware development ...

Yahoo Hack Triggers 'Material Adverse Change' Clause

The Wall Street Journal reported that Verizon's lawyers are looking at using the "material adverse clause' to renegotiate the terms of the $4.8 billion deal they struck on July. Verizon’s ...

More than 60% of US office workers are unaware of the ransomware threat

Nearly half of ransomware attacks are aimed at office workers, but almost two-thirds of those polled are unaware of the threat More than 60% of US office workers are unaware of ransomware ...

[ALERT] Scam Of The Week: Brad Pitt Found Dead (Suicide)

The divorce between Brad Pitt and Angelina Jolie has been used by the bad guys for a "celebrity death hoax" which unfortunately is high-grade click bait. It's the most recent one to hit ...

AI-powered ransomware is coming, and it's going to be terrifying

Business Insider started an article with the following: "Imagine you've got a meeting with a client, and shortly before you leave, they send you over a confirmation and a map with ...

October Is The Time To Kill Old-School Security Awareness Training

CSO had an excellent article that states the case that you need to get rid of old-school awareness training which you do for compliance reasons only. Their photo illustration was funny as ...

Scam Of The Week: Insidious New IRS Social Engineering Attack

There is a new insidious IRS scam that you need to warn your employees, friends and family about, and inform your HR department to start with. Seasoned internet criminals are sending ...

KnowBe4 beats stellar Q2 and grows 369% YoY in Q3

(Tampa Bay, FL) October 9, 2016 --- KnowBe4 is excited to announce we were able to beat our stellar Q2, and maintain our explosive year over year growth, Q3 2016 being 369% over Q3 2015. ...

Did You Know That Ransomware Can Stop SQL So It Can Encrypt The Database?

I have been knee deep into Ransomware since September 2013 when the granddaddy of modern ransomware CryptoLocker made well over 20 million bucks in a few months. But sometimes I learn ...

The 7 Levels Of Hackers

Eric Chabrow over at the Government Info Security blog found an interesting post by Stuart Coulson, who is a director of a hosting provider in the U.K. Coulson wrote a somewhat longish ...

Massive Cerber Ransomware Campaign Flooding Your Employees' Inboxes

By Eric Howes, KnowBe4 Principal Lab Researcher. This Monday morning many of our customers came in to work to find a rather rude surprise lurking in their inboxes: a massive Cerber ...

KnowBe4 Is Excited To Announce Active Directory Integration

We are stoked to announce the new integration with Active Directory! The Active Directory Integration (ADI) helps you easily upload user data and eliminate manual updates by automatically ...

Is Security Making The Grade? What IT And Business Pros Really Think

Great joint survey by CSO, CIO and ComputerWorld by Amy Bennett which is excelllent ammo to add to a budget request that needs to be approved by a C-level exec. Here's why: "If you sense ...

Uh oh, Yahoo May Have Been COMPLETELY Pwned

We predicted that this would happen on September 23rd when the news broke that Yahoo lost "at least" 500 Million credentials. Just for a change I'm quoting myself here: :-D "Right, that ...

This weird ransomware strain spreads like a virus in the cloud

Here is a ransomware horror story for you... An obscure 2-year old ransomware strain called Virlock has a nasty feature: it is capable of stealthily spreading itself via cloud storage and ...

InfoArmor: The Yahoo Hackers Were Not State-sponsored

Eastern European organized crime, not state-sponsored hackers, were behind the record breaking 2014 Yahoo data breach that exposed information about hundreds of millions of Yahoo user ...

Brazen: Phishing Attacks The Bad Guys Send When No One's Looking

When we talk with folks outside the security industry about what we see from the bad guys on a daily basis, we often get the response, "Wow! That's really sneaky." And it's true. The bad ...

Ransomware Is Now Officially Extortion Under California Law

Of course everyone knows that hacking into a computer is a federal crime, and infecting a system with ransomware already falls into that bucket. However, California’s SB-1137, signed into ...

Gang Uses Social Engineering To Steal 147 Million Dollars

Police have arrested a 147 million international fraud and money laundering ring, and jailed nine fraudsters jailed for over 27 years The gang targeted thousands of Lloyds and RBS ...

What is the Necurs Botnet And How Does It Spread Locky Ransomware?

In Short: The Necurs botnet is one of the world's largest botnets with more than 6 million zombie machines tied into it. It's run by Russian organized cybercrime and responsible for ...

Don't Make These Two Major Multi-Factor Security Mistakes

An employee sent this recent horror story to me (thanks Rachel). Remember there are three ways of learning. :-D Read it in a book, blog (or training session) understand it and apply it ...

Price Discrimination: The Fantom Menace of Ransomware

By Eric Howes, KnowBe4 Principal Lab Researcher. Over the past few months we've discussed the rising use of price discrimination among purveyors of ransomware to maximize their returns on ...

New KnowBe4 Phishing Campaign Creation Screen

You asked and we listened! We’ve enhanced our Phishing Campaign creation options to give you more flexibility and customization when phishing your users! You can now: Phish your users ...

These 500 Million Hacked Yahoo Accounts Are A Phishing Paradise. Warn Your Users!

It's all over the press. Here is a quote from Reuters: "Yahoo Inc said on Thursday information associated with at least 500 million user accounts was stolen from its network in 2014 by ...

New Version of iSpy Trojan Steals Your Software Licenses

Earlier this year we posted about Jsocket, a highly malicious Trojan that we spotted being delivered through phishing emails shared with us via the Phish Alert Button (PAB). Although ...

Scam Of The Week: Apple Store Phishing Attack Goes For Whole Enchilada

Phishing attacks using false Apple Store email messages, fake landing pages and sometimes fake login pages are still a very popular attack vector. They still make it through all the ...

Bad Guy FAIL! or, When a Simple Credentials Phish Goes Horribly Wrong

By Eric Howes, KnowBe4 Principal Lab Researcher. Anyone who works a job in the computer security industry inevitably develops a kind of dark appreciation for the mad skills so often ...

As Neutrino takes a hit, RIG Exploit Kit jumps at the opportunity and spreads ransomware

Andra Zaharia (the picture is really her) from the Danish Heimdal Security wrote something interesting this morning that I thought you'd like to know:

Reported Phishes of the Week

KnowBe4's Templates Mistress Katie has been busy again adding a new batch of phishing templates to the collection of "System Templates" available to active subscribers.

A new "long con" Scam Of The Week: Binary Options

Most scams on the internet are "short con" scams, compare them to hit & run. However, "long con" scams have started to show up that can take a few months to finally steal the money. ...

Investment fund loses $6 million in CEO Fraud and shuts down

CNBC reported some pretty stunning breaking news. I cannot come up with a better case for new-school security awareness training for employees in accounting and HR. A lawsuit filed on ...

CyberheistNews Vol 6 #38 [ALERT] FBI Warns Ransomware Attacks Are Getting More Dangerous And Expensive

*|CyberHeistNews|* CyberheistNews Vol 6 #38 [ALERT] The FBI Warns That Ransomware Attacks Are Getting More Dangerous And Expensive In an alert published this week, the U.S. Federal Bureau ...

McAfee: Ransomware Has Grown 128 Percent Over 2015

Intel Security's McAfee Labs Threat Report for September 2016 provides insight into the latest security statistics and trends, ranging from botnets to ransomware to malware "zoos." Large ...

Meet Mamba: New Full Disk Encryption Ransomware

SecurityAffairs just published a new discovery that you need to know about. A Brazilian Infosec research group, Morphus Labs, just discovered a new Full Disk Encryption (FDE) ransomware ...

[ALERT] FBI Warns Ransomware Attacks Get More Targeted And Expensive

In an alert published today, the U.S. Federal Bureau of Investigation (FBI) warned that recent ransomware variants have targeted and compromised vulnerable business servers (rather than ...

New Vicious And Highly Targeted Ransomware Attacks Made Public

Here’s an example of a highly targeted ransomware attack, with bad guys using a phony Bank of Montreal (BMO) template to social engineer possible victims into clicking on a malicious ...

A Single Ransomware Gang Made $121M In 2016

Intel Security today released its McAfee Labs Threats Report: September 2016, which assesses the growing ransomware threat; surveys the “who and how” of data loss; explains the practical ...

Targeted Lawsuit Phishing Attack With Sophisticated Payload

We are seeing a big phishing wave with a social engineering attack that threatens with a personalized lawsuit using the domain name of the targeted victim. This is an interesting payload ...

Adding Insult To Injury: The Ginsu Knives Approach To Ransomware

Kaspersky has a fascinating blog post on a new strain of ransomware called RAA that is not only fairly sophisticated, but incredibly abusive:

Seagate Sued By Own Employees For CEO Fraud Attack

Hard drive manufacturer Seagate was sued by its own employees as the result of a successful CEO fraud attack where all the personal information of 10,000 existing and former employees ...

Philadelphia Ransomware Strain Offers "Mercy" Button

Larry Abrams at Bleepingcomputer reported on a new strain that raises some eyebrows. "A new version of the Stampado ransomware called Philadelphia has started being sold for $400 USD by a ...

Scam Of The Week: A New Type Of Tech Support Fraud

We spotted an unusual phishing email which revealed a new scam your users will soon find in their inbox. Time to inoculate them before it becomes a problem! Many online service providers ...

Having some Phun With Phishers - CEO Fraud Blow-By-Blow

For the last 9 years I have been a board member of the public/private Clearwater Downtown Partnership. And as many public organizations, all the board member information is freely ...

"But, But, But... I Didn't Click!" False Positives In Phishing Tests

The following question was posted in the SANS Securing The Human forum. I thought it was a very good point and asked our VP Product Greg Kras for his perspective. First the question:

Funny Phishing Story: Your Online Order Receipt

A customer sent us this: Hi, I wanted to share with you a funny story…. My boss calls me into her office, very serious like. She sits me down and asks “Did you use the company credit card ...

KnowBe4 Is Hiring: QA Engineer and Sr Ruby Developer

Hi All, KnowBe4 is looking for a few good people. Specifically we are hiring a QA Engineer and a Senior Ruby Developer. Know anyone? Send them to our Jobs page on the website. KnowBe4 is ...

Coming Soon to an Inbox Near You: A New Type Of Tech Support Scam

By Eric Howes, KnowBe4 Principal Lab Researcher. Yesterday we spotted an unusual phishing email that we'd like to share with readers. If nothing else, it tells us that the increased ...

Tampa FBI: Your business is going to get hacked (or get infected with ransomware)

The Tampa Bay Business Journal published an interview with FBI Special Agent Lawrence Wolfenden. Wolfenden is a 25-year veteran of the FBI, the lead agency for investigating cyber attacks ...

Phishing Attack With Malicious Word Doc Changes Proxy Settings

Microsoft recently came across a threat that uses social engineering but delivers a different payload than the usual Office document with macros. Its primary purpose is to change a user’s ...

New Cry Ransomware Strain Has Unusual Advanced Features

Larry Abrams at Bleepingcomputer reported on a new strain with a few unusual features: "A new ransomware that pretends to be from a fake organization called the Central Security Treatment ...

Evidence Hillary Was Speared In Phishing Attack

The Smoking Gun reported: "SEPTEMBER 2--The FBI’s Hillary Clinton investigation turned up evidence that her e-mail accounts were targeted in multiple “spear phishing” attacks, one of ...

Criminal Phishing-as-a-Service Platform Steals Credentials

Want someone's credentials? Just social engineer them. Phishing is still responsible for 91% of data breaches and has been for the last few years. A Russian cyber mafia has created a ...

I have an invitation to join a new exciting online community: Hackbusters!

KnowBe4 has been running the HackBusters site for a few years now, providing you with trending IT security news. We are expanding it and have launched a new exciting online community! You ...

Cyberheist Nets 44 Million In Single CEO Fraud Attack

Earlier in August, one of the world's largest cable manufacturers Leoni AG publicly confessed that it had fallen victim to a classic CEO Fraud attack that has cost the company a whopping ...

CrowdStrike: "Russian Hackers Attack DC Think Tanks With Phishing Emails"

The Wall Street Journal reported this morning that "A Russian hacking group linked to a series of computer intrusions at the Democratic National Committee and other organizations is now ...

Two New KnowBe4 Phishing Categories: Scam Of The Week and Reported Phishes of the Week

KnowBe4's Templates Mistress Katie has added two new categories to the System Templates: 1) SCAM OF THE WEEK - this will act as an optional weekly newsletter for you to send to your ...

IT Security Is A Protoscience, Think 19th Century Chemistry

So I get the Andreessen Horowitz newsletter. It has a topic called "Security is a protoscience (and more on 'so you want to work in security') - Michal Zalewski" I'm intrigued so I click ...

KnowBe4's Field Guide to Macro Warning Screens

Earlier this week today we assisted several companies that were hit by ransomware. Although companies and organizations hit by ransomware can usually pinpoint the source or employee ...

Ransomware & Voicemail Notifications, Redux

Several days ago we posted about a new ransomware campaign pushing Cerber through malicious ZIP files attached to voicemail-themed phishing emails. Fast on the heels of that campaign ...

Here is a Real DDoS Plus Ransomware Extortion Attack

One of our customers received the following email today. It's a clear extortion attempt, they are threatening to execute a combined DDoS and Cerber ransomware attack. These bad guys claim ...

Heads-up! Voice message notification email warning could be ransomware

Don't play voicemail messages from suspicious sources. Example displayed in MS Outlook. Image credit: SANS ISC.

How Highly Personalized Ransomware Attacks Are Getting

CyberheistNews Subscriber Stuart Sanders sent me this: "A friend of mine in Melbourne Australia has been whacked by several crypto attacks on his clients in the last week. He supports ...

Cerber Ransomware Plague Earns 2 Mil With Just 0.3% Victims Paying Up

A new report by Check Point software's researchers showed that Cerber's Ransomware-as-a-Service (RaaS) affiliate program is a success with more than 160 participants at current count, and ...

Clinton Foundation Gets Spear-Phished By Russians, Hires FireEye To Investigate

REUTERS just reported that the Clinton charitable foundation hired the security firm FireEye to examine its network after seeing indications they might have been hacked by Russians, ...

FireEye warns 'massive' Locky ransomware campaign hits America

The dangerous Locky ransomware is being hurled at a variety of industries, healthcare being the number one target, according to FireEye researcher Ronghwa Chong. We have talked about ...

New Feature: 2-Factor Authentication

All user accounts may now be enabled to require MFA (multi-factor authentication) [also called 2FA, 2 Factor Authentication]. Once configured and enabled for an account the system will ...

KnowBe4 Debuts at #139 on Inc 500 List of America’s Fastest Growing Private Companies

I have some exciting news: KnowBe4 made it in the Inc 500! To start off with, a very big thank you to all our customers who understood the need to manage the ongoing problem of social ...

I was interviewed by DARKReading at BlackHat [VIDEO]

While at BlackHat, the editorial team from DARKReading wanted to know more about what we were doing at KnowBe4. This was a fun, relaxed 15 minutes where we chatted about problems like ...

The Ultimate Pop-up Phishing Warning Message

'Just weeks after she started preparing opposition research files on Donald Trump’s campaign chairman Paul Manafort last spring, Democratic National Committee consultant Alexandra Chalupa ...

PokemonGo Ransomware installs Backdoor Account and Spreads to other Drives

With the popularity of PokemonGo, it was inevitable that a malware developer would create a ransomware that impersonates it. This is the case with a new Hidden-Tear ransomware discovered ...

Hitler ransomware just deletes files instead of encrypting them

Security experts detected and analyzed a new threat, the Hitler ransomware, that doesn’t encrypt files but simply deletes them. Larry Abrams at Bleepingcomputer commented: " It looks like ...

Scam Of The Week: New Social Security Account Fraud

Bad guys are abusing the Social Security Administration's (SSA) online service called My SocialSecurity Account in two ways: A phishing scam which encourages employees to create an ...

July 2016 Ransomware Roundup: New Strains And New Nasty Features

The ransomware market is rapidly maturing, we start seeing upgraded strains and rebranded versions sold cheaply in the Dark Web. And mainstream media have finally glommed on after years ...

When the Bad Guys Go to Ransomware B-School

By Eric Howes, KnowBe4 Principal Lab Researcher. As we have documented numerous times in this space over the past few years, the bad guys have proven to be relentless innovators, ...

The Latest from Black Hat 2016: Ransomware By the Numbers

The annual Black Hat security conference always produces a wealth of interesting papers, presentations, talks, live demos, and security news. This year's Black Hat USA 2016 event, which ...

Yes, that email is really from Paypal. And, yes, it's really malicious.

Score another one for the bad guys, who have yet again demonstrated their seemingly inexhaustible ability to concoct new methods to exploit legitimate services in order to bypass existing ...

First Half 2016 Top 10 Phone Scams Revealed

You may not have heard of Atlanta-based Pindrop Labs. They have developed an innovative way to detect fraudulent phone calls called a "phone print", and their solutions reduce fraud ...

New KnowBe4 Phishing Templates: A Summary 7/30/2016

Over the past few weeks our Phishing Templates Mistress Katie and her team have added 17 new templates for use by customers in their simulated phishing campaigns.

Scam Of The Week: Illegal Game of Thrones Download

Illegally downloading television shows and movies from a variety of torrent websites is done all the time. The HBO series, "Game of Thrones" is the #1 downloaded, not surprisingly. This ...

New Ransomware-as-a-Service Offering Goes Live

The cybermafia behind the Petya/Mischa ransomware just launched their RaaS offering July 25th. It pays "distributors" a part of the ransom that gets extorted from victims and increases ...

Cyber Attack Maps...Accurate Or Just Eye Candy?

Here are the top 5 Cyber Attack Maps found in Google. They all seem to show the cyber attacks in a slightly different perspective. This is the Norse attack map as an example:

Why does Kevin Mitnick recommend 20+ character passwords?

The background is based on current state-of-the-art password cracking technology. In short, hackers penetrate the network, get access to a domain controller and pull the file with all ...

Scam Of The Week: RNC Attendees Get Hacked Through Fake Wi-Fi Networks

The PR people at Avast decided to have some fun and created a series of fake Wi-Fi networks at various locations around the Republican National Congress in Cleveland. Avast’s team set up ...

Why take files hostage when you can take victim's private lives instead?

A new malware strain dubbed "Delilah" is being sprung on unsuspecting victims visiting "popular adult and gaming sites." The goal of this malware, which is currently being classified as a ...

Criminal Ransomware Now Cheaper Than Standard Antivirus

For just $39 you, too, can have your very own ransomware with a lifetime license. What does a year's subscription to one of the major antivirus cost? Last I checked, much more than $39. ...

Scam Of The Week: Pokémon Malware, Muggings And Other Mayhem

In case you just came back from vacation, there literally is a new craze going on with an augmented-reality smartphone app called Pokémon Go. It's a geocaching game, meaning it's tied to ...

Locky Ransomware Encrypts Files Even When Machine Is Offline

Locky is currently one of the top 3 ransomware threats, following closely behind CryptoWall. It's not surprising that this strain has undergone several updates since the beginning of the ...

The fine art of not being stupid - security awareness training

Brian Honan wrote a GREAT post at HelpnetSecurity. This is a cross-post of his excellent article, nothing changed, all the internal links to helpnet security were left in place. "There is ...

Lazy Ransomware Bad Guys Just Delete Your Files - Never Mind Decrypting

There is a new strain of "ransomware" that does not bother with the whole encryption thing at all. These bad guys seem to think it's just an unnecessary distraction and too much work. ...

Scam Of The Week: FBI Warns Against Data Breach Extortion

The number of data breaches keeps going up. Last week it was more than 1,000 Wendy's where credit card records got ripped off. Fraudsters quickly use the news release of a high-profile ...

Personal security cameras hacked, stream live on websites

Shocking video of people's private lives are streaming over the internet. Hackers are able to easily tap into personal security cameras and stream them on websites for the world to see, ...

July 2016 Ransomware Roundup: New Strains And New Nasty Features

The ransomware market is rapidly maturing, we start seeing upgraded strains and rebranded versions sold cheaply in the Dark Web. And mainstream media have finally glommed on after years ...

14 Ways A Cyberheist Hits Your Bottom Line: Total Cost Of A Hack

What is the true cost of a data breach? After analyzing a health plan breach, research firm Deloitte says the toll of a cyberheist is significantly underestimated. The firm in a report ...

Wow, the bad guys are moving fast with CEO Fraud!

KnowBe4 is expanding fast, we now have 120 employees and we just hired a new controller late May to help out our very busy CFO. Part of the KnowBe4 onboarding is getting through our ...

We need your help. Could you do a KnowBe4 review at Gartner?

NOTE: This is for KnowBe4 Customers only. Top IT analyst firm Gartner has just created a new "Peer Insights" review site. As a customer, we are inviting you to create a review of KnowBe4 ...

KnowBe4 has explosive year over year growth of 454% for Q2 2016

(Tampa Bay, FL) July 1, 2016 --- KnowBe4 announced its explosive year over year growth of 454% for Q2 2016, with a record number of 655 new corporate accounts in June alone, rising to ...

Doh! New "Bart" Ransomware from Threat Actors Spreading Dridex and Locky

Proofpoint researchers discovered a new strain of ransomware called "Bart" - no kidding. The Russian Cyber Mafia behind Dridex 220 and Locky are using the RockLoader malware to download ...

New Study Shows Your Apps Could Be Putting Your Personal Information At Risk

A recent study by Cloudlock, a cyber security company, revealed several popular apps that could allow hackers an easy gateway to access your personal information.

IT pros: Half Of Our CEOs Fall Victim To Phishing Scams

Executive boards need better cyber security training, given half of C-level execs fall victim to phishing attacks, according to research conducted by security firm AlienVault. The ...

[ZERO DAY ALERT] Ransomware Targets MS Office 365 Users

Apparently, MS Office 365 built-in security tools are not cutting it. A new strain of the Cerber Ransomware is now targeting MS Office 365 email users with a massive zero-day attack that ...

Intel Thinks Antivirus Is Shit And Dumps Useless McAfee

Remember that in a gray past, Intel had an antivirus product called Intel LanDesk Virus Protect? Well, that Intel LanDesk Virus Protect got acquired by Symantec in 1998, and Intel must ...

"BadTunnel" Social Engineering Attack Hijacks Your Network Traffic

A researcher in China has discovered a design flaw in Microsoft Windows that affects all versions of the operating system using NetBIOS spoofing —including Windows 10— and lets an ...

Top website domains are vulnerable to email spoofing

Don’t be surprised if you see spam coming from the top websites in the world. Lax security standards are allowing anyone to "spoof" emails from some of the most-visited domains, according ...

Russian Cyber Mafia Is Back From Vacation With Smarter Locky Ransomware Strain

Threatpost reported that the notorious Necurs botnet is back in business, after mysteriously going dark for nearly a month. Researchers report the Necurs has returned to spewing massive ...

IT'S SHOWTIME! Kevin Mitnick Episode on NATIONAL GEOGRAPHIC - THIS SUNDAY

National Geographic has done a special on Kevin Mitnick and it plays this Sunday!

New KnowBe4 Survey: Ransomware Infections Double In Two Years

We have just released the first long-time study focusing on IT Pros experience with ransomware. In June 2016 we surveyed 1,138 companies in a variety of industries and compared your ...

Expect Micro Ransomware: Extortion One Document At A Time

I have been following the development of ransomware closely since September 2013 when the ransomware plague was unleashed on the internet in the form of CryptoLocker and its copycats. At ...

New RAA Ransomware Strain Created Entirely Using Javascript

Larry Abrams, who runs Bleepingcomputer was first to report on a new strain of ransomware called RAA. The criminal coders took the somewhat unusual step of writing the whole thing in ...

Scam Of The Week: Orlando Nightclub Phishing Attacks

Just when you think they cannot sink any lower, criminal internet scum is now exploiting the tragedy in Orlando. Unfortunately, from this spot I have been warning about these lowlifes ...

FBI: Business e-mail scam losses top $3 billion, a 1,300% increase in since Jan.

The FBI’s Internet Crime Complaint Center (IC3) this week said the scourge it calls the Business Email Compromise continues to rack-up victims and money – over $3 billion in losses so ...

New Type of Spear Phishing Directly Targeted at IT Pros

A member of the SpiceWorks IT forums reported he had received a new type of hybrid attack: first a phone call to his desk, followed up with a phishing email laced with malware, promoting ...

Scam Of The Week: Nasty Two-factor Auth Text Hack

We all know that two-factor authentication (2FA) is much better than just simple user/password credentials. However, there is a nasty spoofing trick that bypasses 2FA if the user does not ...

Individual ransomware payments skyrocket to a whopping $20,000

Heads-up! Individual ransomware payments are getting very expensive. Companies are stockpiling Bitcoin in case they are hit, and a new low-profile strain of ransomware is actually causing ...

Yikes: Ransomware scam targets lawyers with phony ethics complaints

Mike Mosedale at the Minnesota Lawyer wrote: "Talk about your dirty tricks. A new internet scam is targeting lawyers by exploiting one of their great fears: getting slapped with a ...

CyberheistNews Vol #6 #23

Scam Of The Week: FBI Warns Against Email Extortion

Your employees are being attacked both inside and outside the office. This new email extortion scam called CEO fraud can hit in both places, so it makes sense to warn them about this ...

UltraDeCrypter Ransomware DOES NOT Decrypt Your Files

KnowBe4 gets regular calls from system admins who found us on the internet that are between a rock and a hard place. Backups failed and they have no way to revert to normal files. Worse, ...

[ALERT] 93% of phishing attacks now have ransomware payloads

Oh boy. Things have gotten from bad to worse in an awful hurry. I remember the first time I reported on ransomware in the CyberheistNews Issue Feb 11, 2014, where an attorney's office ...

Looks Like 8 More Cyberheists By North Koreans

Gottfried Leibbrandt, chief executive of the world’s largest interbank funds-transfer system SWIFT, has said repeatedly that the prospect of cybercrime is what keeps him awake at night. ...

[INFOGRAPHIC] Don't Be The Victim Of A Cyberheist

We have created a new infographic for your users, as part of your ongoing security awareness training program. It's a few good reminders how to stay safe online, and to keep their ...

Top Ransomware campaign managers make 13 times more than avg Russian wages

A short report by Flashpoint gives us some insight into a recent ransomware campaign, which so far has generated a serious amount of profit considering it takes little effort to operate.

Phishing Attacks Ramp Into 2016 With Major Increase

In its most recent Phishing Trends Report, the APWG noted a 250% increase in phishing sites between October 2015 and March 2016 — and the 2016 increase shows the never ending criminal ...

Ransomware domains increased 3500% in Q1 2016

There has been a whopping 3500% increase in ransomware domains in the first quarter of 2016, compared to the last quarter of 2015. Those are the highlights of a new report by network ...

CEO And CFO Fired After Aerospace Company Grounded By CEO Fraud

Here is a great way for C-level execs to lose their job: allow your company to become the victim of CEO Fraud. That happened to the CEO and CFO of FACC, part of both Airbus' and Boeings' ...

CryptoWall, Locky, and Cerber Are Today's Top 3 Ransomware Threats

US cyber-security firm Fortinet reports that, between April 1, 2016, and May 15, 2016, the top five most prevalent ransomware families were in this order: CryptoWall (41.04%), Locky ...

New Strain Of Cerber Ransomware Being Offered As RaaS On Russian Hacking Forum

Security Researchers at Forcepoint discovered that a Russian hacking forum on the dark web is selling the Cerber ransomware as a RaaS (Ransom-as-a-service). This is a new form since ...

Are North Koreans The Bad Guys Behind Brazen Cyberheists?

In March, we posted a story about a cyberheist where hackers tried to steal a cool 1 Billion dollars from the Bangladesh Central Bank, but a simple typo thwarted most of their attempt. ...

The Nightmare of Exploits Past. How Phishing Attacks Use Old Vulnerabilities

By Eric Howes, KnowBe4's Principal Lab Researcher Remember .PIF files? If you're like us, the extension probably rings a bell somewhere deep in the dustiest recesses of your mind -- the ...

Scam Of The Week: Summer Olympics Canceled in Rio

Heads-up! There is a spike in phishing attacks with Summer Olympics themes, and in the coming months the bad guys are going to be all over this. Kaspersky Labs researchers are reporting ...

Microsoft Alert: ZCryptor Ransomware With Worm Feature

Microsoft released an alert about a new ransomware strain called ZCryptor, which works like a worm and spreads via removable and network drives. The MalwareForMe blog reported this first ...

Shields Up! New DMA Locker V4 Unleashes Major Ransomware Assault

DMA Locker is an excellent example of cybercrime's furious speed of innovation. Version 1 showed up in January 2016, and V2 a month later, but the implementation of the encryption ...

Massive Locky Ransomware Campaign Targets Amazon Users

Comodo Threat Research Labs just posted an alert that a massive campaign of phishing emails have been sent with a spoofed "from" address: auto-shipping@amazon.com. The subject is “Your ...

[ALERT] Cerber Ransomware Strain Adds DDoS Bot Causing More Damage

Excuse my French, but Holy S#!+, some ransomware developers have created a new evil way to monetize their operations by adding a DDoS component to their malicious payloads. Security ...

Scam Of The Week: LinkedIn Email Change Your Password

You probably remember the 2012 LinkedIn data breach. It was a big deal because something like 6.5 million user account passwords were posted online, but LinkedIn never confirmed the final ...

"What methodologies does KnowBe4 use in developing our training?"

Someone interested in using our integrated platform for training and phishing asked us: ""What methodologies does KnowBe4 use in developing our training?" We use the ARCS Model. ARCS is ...

What does a "Human Firewall" look like, anyway?

By Eric Howes, KnowBe4's Principal Lab Researcher So you've subscribed to Security Awareness Training that includes training modules as well as simulated phishing campaigns for your ...

We just received the ultimate in weird nested malware

Last night a customer sent us a phish via the KnowBe4 Phish Alert Button ( free download here) that must win some kind of award for the longest chain of required user interactions -- all ...

How To Stop Your Ex-Girlfriend Sending Nude Photos To A Fake Facebook Profile

In a case of sophisticated social engineering, a fraudster created a fake profile of actor Vincent Gallo. He then proceeded to engage in a 2-month long scam, flirting online and sending ...

TeslaCrypt Gives Up and Releases Master Decryption Key

Larry Abrams from the Bleepingcomputer site noted: "In a surprising end to TeslaCrypt, the developers shut down their ransomware and released the master decryption key. Over the past few ...

Tech Support Scammers start locking Windows PCs

Tech support scammers have come up with a new way to trick users into sharing their payment card information: screen lockers showing fake Windows alerts telling users that their Windows ...

[ALERT] Fraudsters Steal Tax, Salary Data From ADP. Are Employees At Risk?

It turns out that HR giant ADP, which provides payroll, tax and benefits administration for more than 640,000 companies, was vulnerable to an ID theft scam. The criminal hackers made off ...

Scam Of The Week: Bogus IT Security Company Websites

Tech Support Scams are nothing new, but the bad guys are furiously innovating and there is a new variation you need to warn your users about. A few years ago this started out with bogus ...

This Has Been A Crazy Week In Ransomware

That's what Larry Abrams from Bleepingcomputer started out with yesterday, and he was right! We have had six new ransomware strains, one new RaaS (Ransomware-as-a-Service) and one major ...

What Is The #1 Cause Of Healthcare Data Breaches?

As a new story about hospital ransomware or a stolen laptop containing PHI seemingly emerges every day, it comes as no surprise that healthcare data breaches have steadily increased in ...

Poll Results: "Should Someone Who Falls For A W-2 Phishing Attack Be Fired?"

It's an interesting question, because the specific circumstances were explained in an article about this particular incident. There were 186 answers to this poll, and here are the results ...

Ransomware and CEO Fraud Dominate 2016

An interesting Q1-16 threat report from the folks at Proofpoint. Every day, they analyze more than 1 billion email messages, hundreds of millions of social media posts, and more than 150 ...

New Petya Comes Loaded with Double-Barrel Ransomware Attack

A new twist on the Petya ransomware and how it now uses a backup ransomware attack. Remember, Petya is a new type of ransomware that doesn’t encrypt specific files but makes the entire ...

New evil android phishing trojans empty your bank account

Infragard warned that the FBI has identified two Android malware families, SlemBunk and Marcher, actively phishing for specified US financial institutions’ customer credentials. The ...

Congress warned about cybersecurity after attempted ransomware attack on House

In an email provided to TechCrunch, the House technology service desk warned representatives of increased ransomware attacks on the House network. The email warns that attackers are ...

InfoSec Analyst: "We Make People Suck At IT Security"

IT Security analyst Ben Tomhave calls himself an infosec obsessive and I admire his insightful analyses when they appear. This time he commented on the recent attacks that followed the ...

Prince Death Overdose Caught On Video! Stolen out of a spear phishing attack?

Our CTO was picking up some groceries and saw this at the check-out, stolen straight out of a spear phishing email... or was it? LOL.

The Hidden Dangers of .HTML Attachments

By Eric Howes, KnowBe4's Principal Lab Researcher Over the past six to nine months .DOC and .JS file attachments have dominated the news surrounding the rise in phishing attacks. The ...

Troy, Mich Investment Firm Loses $500,000 in CEO Fraud

An employee at a Troy, Mich., investment firm fell for a CEO Fraud attack and was social engineered into transferring almost $500,000 to a Hong Kong bank. The error was noticed eight days ...

New KnowBe4 Feature: Vulnerable Browser Plugin Detection

How Can I See If My Users Have Vulnerable Browser Plugins Installed? Within your console, you can automatically detect what vulnerable plugins any clickers on your phishing tests have ...

Verizon 2016 Data Breach Report: "Phishing Tops The List Of Increasing Concerns"

Verizon yearly does a comprehensive report on security and data breaches. It is excellent ammo to get budget approval for new-school security awareness training. Why? Hundreds of security ...

[ALERT] 2016 Is A Ransomware Horror Show. Here's The Roundup Of 32 New Strains!

If you've been in the IT trenches over the past year, you've probably noticed the announcements of new strains of ransomware are accelerating. The research team at Proofpoint just ...

The Phishing Attack That Came Out Of Zendesk

Yesterday, April 25 2016, we encountered a new phishing email being delivered through Zendesk. The credentials phish itself is a straightforward social engineering attack. The email body ...

Scary New CryptXXX Ransomware Also Steals Your Bitcoins

Now here's a new hybrid nasty that does a multitude of nefarious things. Proofpoint researchers found that it was built by the same cyber mafia that's behind the Reveton malware. A few ...

Scam Of The Week: Secure Document Phishing Attacks Trap Employees

In this Scam Of The Week we are warning against a new wave of phishing scams. In the industry this is called the "secure doc" theme. It's getting very popular with the bad guys. We see a ...

Scam Of The Week: Prince Last Words On Video

Today, news broke that Prince Rogers Nelson was found dead in his home in Minneapolis at age 57. He was found unresponsive in an elevator and was declared dead shortly after. He performed ...

[ FTC ALERT ] Don't Get Scammed By Earthquake Phishing Emails

It's the old story. A disaster strikes and 24 hours later you get emails with urgent request for help as hundreds of wounded victims need food, water and shelter. And the bad guys are at ...

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016"

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016" CNN Money reports about new estimates from the FBI show that the costs from ransomware have ...

A Short History & Evolution of Ransomware

Ransomware attacks cause downtime, data loss, possible intellectual property theft, and in certain industries a ransomware attack is now looked at as a possible data breach. Ransomware is ...

CTB-Locker Ransomware Uses Blockchain to Store & Deliver Decryption Keys

A mysterious update in the behavior of the CTB-Locker ransomware strain alerted security researchers to pull some strings and see what was going on. The CTB-Locker ransomware family, ...

Ransomware On Pace To Be A 2016 $1 Billion Dollar Business

CNN Money reports about new estimates from the FBI that show the costs of ransomware have reached an all-time high this year. Threat actors made $209 million in the first quarter of 2016 ...

Phishing Attacks Hit the C-Suite With High Value Scams [INFOGRAPHIC]

OK, here is great ammo to get more IT security budget. Why? This article and infographic make it real to the C-suite that they themselves have a big phishing target on their back. You all ...

US Company Falls Victim To $100 Million CEO Email Fraud

An as yet unknown American company fell victim to nearly $100 million in CEO Fraud. Employees were social engineered by spoofed emails that claimed to be one of its legitimate vendors, ...

They Shoot Files, Don't They? Jigsaw Ransomware Does...

By Eric Howes, KnowBe4 Principal Lab Researcher. A few days ago our friends at BleepingComputer.com announced the discovery of a new form of ransomware, which they dubbed Jigsaw ...

Pinellas Man Falls Victim To Ransomware

Pinellas County resident Scott Germak thought he was getting free Tampa Bay Rays tickets based on a phishing email that appeared to be a legitimate message coming from GTE Financial, his ...

The Future Of Ransomware: CryptoWorms?

Cisco's Talos Labs researchers had a look into the future and described how ransomware would evolve. It's a nightmare. They created a sophisticated framework for next-gen ransomware that ...

Exciting New Features In KnowBe4 Spring 2016 Release

We have several cool new features in the Spring 2016 release! These features were previously out of reach for IT managers with limited budget, and we're excited you can use them now with ...

CyberheistNews Vol 6 #15 [FBI ALERT] Dramatic Increase In Email CEO Fraud To 2.3 Billion.

*|CyberHeistNews|*

CryptoHost Ransomware Locks Files In A Password Protected RAR File

A new ransomware strain called CryptoHost was discovered, which claims that it encrypts your data and then demands a ransom of .33 bitcoins to get your files back (~140 USD at the current ...

Hello mass spear phishing, meet ransomware!

Ransomware is now one of the greatest threats on the internet. In the past, IT Security firms used to monitor spear-phishing attacks by espionage outfits, but these techniques are now ...

How Mattel Lost $3M In CEO Fraud Phishing

Great story by Erika Kinetz at the Associated Press. How Mattel was the victim of CEO Fraud using phishing and social engineering to trick one of their executives in China to make a $3 ...

Maktub Ransomware Knows Where You Live

It's happening in the UK today, and you can expect it in America tomorrow [correction- it's already happening today]. The bad guys in Eastern Europe are often using the U.K. as their beta ...

KnowBe4 Gets 1st place for the Tampa Best Places To Work

We're stoked here. We got 1st place for the Tampa Best Places To Work - small business category!!! The Tampa Bay Times has a yearly "Best Places To Work" contest, and surveys the ...

Users Really Do Plug in USB Drives They Find

Been suspecting that your users are plugging in any USB stick they find, to see what is on it? Well, you are right, they actually do that. Fresh scientific research by Google, and the ...

[FBI ALERT] Dramatic Increase in e-mail CEO Fraud To 2.3 Billion.

A brand new Alert by the FBI on April 4th 2016 warns of a major increase in what they call business email compromise or BEC (we call it CEO Fraud), amounting to a whopping $2.3 billion in ...

More About Petya Hard Disk Lock BSoD Ransomware

[UPDATE April 10, 2016] Petya's ransomware's encryption has been defeated and a password generator has been released. See bottom of the post. March 25, news came out about a new type of ...

KnowBe4 Has Blowout First Quarter 2016

KnowBe4, the United States’ most popular integrated platform for security awareness training and simulated phishing tests, announced it attained a top spot (#220) in the Cybersecurity ...

It's CONFIRMED: MedStar Receives A Massive Ransomware Demand

It is now confirmed, The MedStar Hospital Chain was hit with ransomware and has received a digital ransom note. A Baltimore Sun reporter has seen a copy of the cybercriminal's demands. ...

I am introducing a new phishing term: "Attackment"

Phishing attacks usually have a payload of infected attachments. With the recent ransomware attacks on hospitals I was asked for a press quote and the word "Attackment" suddenly came into ...

Ransomware Attack Shuts Down Medstar Washington Hospital

The Washington Post reported that a ransomware infection penetrated the computer network of MedStar Health early Monday morning, forcing the Washington health care behemoth to shut down ...

New Feature: IP Geolocation

When a user clicks on a link in a simulated phishing attack, or opens an attachment, we record the IP address of the request. For various reasons, KnowBe4 customers have requested us to ...

Scam Of The Week: Phishing Email Uses Accurate GPS Data To Catch Speeding Drivers

[UPDATE] See new information at the bottom of this posts. A phishing scam posing as a speeding ticket email with a malicious link is nothing new. But here's an innovation that should give ...

Survey: 62% of Companies Lack Confidence in Ability to Confront Ransomware Threat

Tripwire just published a new study which suggests that a majority of businesses might not be adequately prepared to either prevent or fully recover from ransomware infections. They ...

New Ransomware Written In Windows PowerShell

Lucian Constantin at CSO had the scoop. A new ransomware program written in Windows PowerShell is being used in attacks against enterprises, including health care organizations, ...

PETYA ransomware Locks Users Out by Overwriting Master Boot Record

Security researchers at Trend Micro have found a new type of ransomware that doesn’t encrypt specific files but makes the entire hard drive inaccessible. The malware has been named Petya ...

Social Engineering Tactics101: 18 ways to hack a human [INFOGRAPHIC]

CSO Online found a great infographic created by the folks of Smartfile. They started out with: "What will the cause of your next security breach? Will it be your firewall? Will it be your ...

New Maktub Ransomware Strain - Beautiful And Dangerous

Maktub Locker is the name of a new Russian strain of ransomware. The word Maktub is Arabic for "fate", suggesting it is inevitable you will get infected with ransomware. They have spent a ...

Tampa Bay Business Owner Affected By Ransomware

Ransomware continues to be a successfull business for the cybercriminals of the world. It can easily get past even the best anti-virus software through a user just clicking once on ...

InfoSec World 2016 Conference & Expo

Responsible for IT Security?

TeamViewer Denies It Is Surprise Ransomware Infection Vector

A modified version of EDA2, an open source ransomware strain developed by Turkish computer engineering student Utku Sen, --by the way, thanks Utku, that was a very smart idea-- has been ...

FBI and Microsoft Warn Against Hybrid Targeted Samas Ransomware Attack

The FBI and Microsoft have issued a new alert, a warning of hybrid targeted ransomware attacks that attempt to encrypt an organization’s entire network. This is a new approach where ...

Chinese hackers behind U.S. ransomware attacks - security firms

Reuters was the first out with a story about criminal Chinese hackers also trying to get into the ransomware racket. They started out with: "Hackers using tactics and tools previously ...

Scam Of The Week: TurboTax Phishing Attack

It's tax season and the bad guys are in full swing. They try to get your Accounting or HR team to send over the W-2s of all employees, but they also target employees in the office and/or ...

SURVEY: Even if You Don't Pay, Ransomware Attacks Are Very Expensive

According to a new survey by Intermedia called "2016 Crypto-Ransomware Report", ransomware attacks are increasingly targeting larger companies, costing them dearly. Employees are usually ...

New KnowBe4 Phishing Templates

We have added a dozen new phishing templates in the past few days. All are based on actual bad guy phishing emails seen in the last 2 weeks. At least one is less than 24 hours old. Most ...

TeslaCrypt Ransomware v3.01 Updated With Unique Keys For Each Victim

TeslaCrypt is a relatively new ransomware variant which has made it in the Top 5, and has rapidly innovated in its efforts to evade detection. The latest version which is one of the most ...

Ransomware Attacks Use NY Times, BBC, Other Media Sites

Over the weekend, The NY Times, BBC, Newsweek, AOL, MSN, The HIll and other major news sites had their ad networks hijacked again by criminals using the Angler Exploit Kit to deliver ...

Inoculate Employees Against The Locky Ransomware

KnowBe4 has immediately responded to Dridex's Locky ransomware attack by releasing a new attachment option which is called "MS Office document with Macro". This new option allows a ...

CyberheistNews Vol #6 #11

Deadly Dridex Cybercrime Gang Has Just Moved Into Ransomware

One thing that is driving mainstream recognition of ransomware is the move by the Dridex banking Trojan gang into ransomware with their Locky strain. They have taken over from CryptoWall, ...

The structure of Russia's exports in 2014, including ransomware

Check the orange slice depicting the percentage of ransomware exports. I found this on someone's twitter feed and loved it!

Hackers Spoil Their $1 Billion Cyberheist With a Typo

It helps to know how to spell when you try to rob a billion from a dirt poor country. A spelling mistake thwarted hackers in stealing a $1 billion dollars from the Bangladesh Bank, and ...

Weird New Cerber Ransomware Speaks To Its Victims

There is a new strain of ransomware called Cerber that takes creepiness to the next level. It drops three files on the victim's desktop named "# DECRYPT MY FILES #." These files contain ...

IRS Warns Against A Widespread CEO Fraud Phishing Scam

OK, heads up! This tax season there is a widespread new scam that specifically targets your HR and Accounting professionals. They get an urgent email from "the CEO" who asks them for all ...

CEO Fraud Phishing Attack steals 11,000 W-2s From Health Care Workers

A phishing incident has compromised the personal information of 11,000 Pennsylvania Main Line Health employees. Officials said the incident occurred on Feb. 16 when an employee fell for a ...

CyberheistNews Vol 6 #9 How To Suck At Information Security – A Cheat Sheet

CyberheistNews Vol Vol 6 #9 How To Suck At Information Security – A Cheat Sheet Lenny Zeltser is a business and tech leader with extensive experience in Infosec. His areas of expertise ...

Snapchat Employee Fell For W-2 Phishing Scam

A Snapchat employee fell for a W-2 phishing scam last week, compromising the identity information of other existing and ex-employees. The FBI calls this a Business Email Compromise, also ...

[ALERT] New Strain Of CEO Fraud: Urgent Request for W-2s

This morning, our Controller received an email from "me", stating the following: Alanna I want you to send me the list of W-2 copy of employees wage and tax statement for 2015, I need ...

44% of ransomware victims in the UK have paid to recover their data

Danielle Correa at SC Magazine wrote: "A Bitdefender global study with respondents from the UK, the US, France, Germany, Denmark and Romania was conducted by iSense Solutions to discover ...

Scam Of The Week - Netflix For Free

Netflix’s popularity continues to grow fast, and they recently launched their streaming service globally. Obviously that makes them a hacker target. At the moment, there are active ...

Apple Defies U.S. Magistrate's Order To Unlock Shooter Suspect's iPhone

Apple this week released a statement regarding what has been an ongoing battle for months. The FBI requested that Apple unlock the encypted iPhone belonging to San Bernadino shooter Syed ...

It's Here. New Locky Ransomware Hidden In Infected Word Files

[UPDATED FEB 22, 2016] It was only a matter of time, but some miscreant finally did it. There is a new ransomware strain somewhat amateurishly called "Locky", but this is professional ...

Ransomware Roundup 2/15/2016

The bad guys have been awfully busy these last few days. Here is your ransomware roundup with the latest "new features".

The KnowBe4 Phish Alert Button Versus JSocket RAT

Since releasing its free PhishAlert button in November 2015, KnowBe4 has been receiving a steady stream of emails flagged by users as potential phishing attacks. The email threats ...

When do end-users click on phishing links?

We had a data scientist take a look at more than 4 years of aggregated clicking data and he came up with some interesting results, expressed in graphs. Here are some of the highlights:

Please vote for KnowBe4 at the Cybersecurity Excellence Awards.

Here is a short summary of why we are asking for your vote: Highest growth in customers over all competitive products Most complete suite of anti-phishing tools Easy-to-use, ...

American Chamber Of Commerce Scam Is Spear-phishing Prep

You may be aware of Steven Weisman, Esq. He writes a great daily blog called Scamicide, and is a is a nationally recognized identity theft expert, experienced university lecturer, proven ...

Ransomware Criminals Infect Thousands With Weird WordPress Hack

An unexpectedly large number of WordPress websites have been mysteriously compromised and are delivering the TeslaCrypt ransomware to unwitting end-users. Antivirus is not catching this ...

World's Most Famous Hacker Raises $8 Million To Play In Billion Dollar Security Awareness Training Market

Hi Guys, this is too good to miss. Check out this brand new article in Forbes Magazine. They started out with:

FDIC Warns Banks To Beef Up Cyber Security

I found a very interesting article at the ValueWalk site about the FDIC requiring banks to improve their cyber security, they started out with:

This Week's Five Most Popular HackBusters Posts

There is an enormous amount of noise in the security space, so how do you know what people really talk about and think is the most important topic? Well, we created the Hackbusters site ...

This Week's Ransomware Roundup

1) I was going to write up all the ransomware related news and then ran across this article by Senior Editor Sara Peters at Darkreading. Saves me some time! She started out with: ...

Scam Of The Week: Your Stolen iPhone Has Been Found

Between 3 and 4 million smartphones are stolen every year. It's your modern-day purse snatching. Many people put their entire private and work lives on these devices that can cost up to ...

Alert: Stupid And Damaging New Ransomware Called 7ev3n

Larry Abrams had the scoop: "A new ransomware has been spotted called 7ev3n that encrypts your data and demands 13 bitcoins to decrypt your files. A 13 bitcoin [almost $5,000] ransom ...

CyberheistNews Vol 6 #4 Scam Of The Week: Phish With Hidden Sting

As you may have heard, KnowBe4 has released a no-charge Outlook Add-in that allows your employees to report phishing attacks to your Incident Response team with just one click. It's ...

Crelan Bank Loses 75.8 Million Dollars In CEO Fraud

The Belgian Crelan Bank was the victim of a 70 million euro (75.8M U.S.) fraud that was launched from another country. They claim (PDF) this CEO Fraud was discovered during an internal ...

CEO Fraud Costs Boeing Vendor 54 Million Dollars

Effective security awareness training for your high-risk employees is becoming a major priority. The accounting team of FACC, who design and manufacture aircraft components for Boeing and ...

PAYCHEX: 60% Of Hacked SMBs Are Out Of Business 6 Months Later

Paychex wrote a great article about the urgency of creating a cyber security culture in your business. This is excellent ammo to send to your C-level execs: "Creating a cyber security ...

Scam Of The Week: Phish With Hidden Sting

As you may have heard, KnowBe4 has released a no-charge Outlook Add-in that allows employees to report phishing attacks to their Incident Response team with just one click. It's called ...

CyberheistNews Vol 6 #3 Scam Of The Week: Dell Tech Support Service Tag Hack

This is a real one. A number of people using Dell PCs have been contacted by scammers claiming to be Dell Tech Support who actually had specific data that only Dell could have had. We're ...

Tampa is 842% above the national average in malware infections

A new study by Enigma Software revealed the hardest hit cities in the country when it comes to computer viruses. Tampa was ranked #2 for malware infections per person. That's 842% above ...

Files Lost Forever Due To Buggy Ransomware

Researchers discovered a sample of ransomware that damages files permanently. The malicious code is based on the work of Turkish Oktu Sen security researchers, who last year made their ...

Scam Of The Week: Dell Tech Support Service Tag Hack

This is a real one. A number of people using Dell PCs have been contacted by scammers claiming to be Dell Tech Support who actually had specific data that only Dell could have had. We're ...

CyberheistNews Vol 6 #2 Scam Of The Week: Fantasy Football Site Hacked

For this Scam Of The Week, we decided to go out on a limb and run a "What If" scenario" on an attack that we think is very likely.

KnowBe4 has explosive year over year growth of 358% for Q4 2015

(Tampa Bay, FL) January 11, 2016 --- KnowBe4 announced its explosive year over year growth of 358% for Q4 2015, with a record number of new corporate accounts and a stellar customer ...

CyberheistNews Vol 6 #1 First Javascript-only Ransomware-as-a-Service Discovered

Cybercrime has piggybacked on the extremely successful SaaS model and several strains of Ransomware-as-a-Service (RaaS) like TOX, Fakben and Radamant have appeared in 2015

First Javascript-only Ransomware-as-a-Service Discovered

Cybercrime has piggybacked on the extremely successful SaaS model and several strains of Ransomware-as-a-Service (RaaS) like TOX, Fakben and Radamant have appeared in 2015. However, a new ...

Scam Of The Week: Massive LinkedIn Spam Steals Passwords

"I feel like a complete idiot. I just got taken by a LinkedIn spam that may have just stolen my banking password." These words dropped in my inbox, written a while ago by Dan Tynan, ...

Credit Union Chilling CEO Fraud Story

I received this the last day of the year from a Director of IT Security who works at a mid-size credit union. "Stu, I think you’ll be interested in my story. If you want to share it, just ...

Cyber criminals release hard to recognize social engineering scam.

Jerome Segura, a senior security researcher over at our friends at Malwarebytes reported about a new, in-the-wild tech support scam that has moved from Amazon Web Services to Rackspace's ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.