Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

It's CONFIRMED: MedStar Receives A Massive Ransomware Demand

It is now confirmed, The MedStar Hospital Chain was hit with ransomware and has received a digital ransom note. A Baltimore Sun reporter has seen a copy of the cybercriminal's demands. ...
Continue Reading

I am introducing a new phishing term: "Attackment"

Phishing attacks usually have a payload of infected attachments. With the recent ransomware attacks on hospitals I was asked for a press quote and the word "Attackment" suddenly came into ...
Continue Reading

Ransomware Attack Shuts Down Medstar Washington Hospital

The Washington Post reported that a ransomware infection penetrated the computer network of MedStar Health early Monday morning, forcing the Washington health care behemoth to shut down ...
Continue Reading

New Feature: IP Geolocation

When a user clicks on a link in a simulated phishing attack, or opens an attachment, we record the IP address of the request. For various reasons, KnowBe4 customers have requested us to ...
Continue Reading

Scam Of The Week: Phishing Email Uses Accurate GPS Data To Catch Speeding Drivers

[UPDATE] See new information at the bottom of this posts. A phishing scam posing as a speeding ticket email with a malicious link is nothing new. But here's an innovation that should give ...
Continue Reading

Survey: 62% of Companies Lack Confidence in Ability to Confront Ransomware Threat

Tripwire just published a new study which suggests that a majority of businesses might not be adequately prepared to either prevent or fully recover from ransomware infections. They ...
Continue Reading

New Ransomware Written In Windows PowerShell

Lucian Constantin at CSO had the scoop. A new ransomware program written in Windows PowerShell is being used in attacks against enterprises, including health care organizations, ...
Continue Reading

PETYA ransomware Locks Users Out by Overwriting Master Boot Record

Security researchers at Trend Micro have found a new type of ransomware that doesn’t encrypt specific files but makes the entire hard drive inaccessible. The malware has been named Petya ...
Continue Reading

Social Engineering Tactics101: 18 ways to hack a human [INFOGRAPHIC]

CSO Online found a great infographic created by the folks of Smartfile. They started out with: "What will the cause of your next security breach? Will it be your firewall? Will it be your ...
Continue Reading

New Maktub Ransomware Strain - Beautiful And Dangerous

Maktub Locker is the name of a new Russian strain of ransomware. The word Maktub is Arabic for "fate", suggesting it is inevitable you will get infected with ransomware. They have spent a ...
Continue Reading

Tampa Bay Business Owner Affected By Ransomware

Ransomware continues to be a successfull business for the cybercriminals of the world. It can easily get past even the best anti-virus software through a user just clicking once on ...
Continue Reading

InfoSec World 2016 Conference & Expo

Responsible for IT Security?
Continue Reading

TeamViewer Denies It Is Surprise Ransomware Infection Vector

A modified version of EDA2, an open source ransomware strain developed by Turkish computer engineering student Utku Sen, --by the way, thanks Utku, that was a very smart idea-- has been ...
Continue Reading

FBI and Microsoft Warn Against Hybrid Targeted Samas Ransomware Attack

The FBI and Microsoft have issued a new alert, a warning of hybrid targeted ransomware attacks that attempt to encrypt an organization’s entire network. This is a new approach where ...
Continue Reading

Chinese hackers behind U.S. ransomware attacks - security firms

Reuters was the first out with a story about criminal Chinese hackers also trying to get into the ransomware racket. They started out with: "Hackers using tactics and tools previously ...
Continue Reading

Scam Of The Week: TurboTax Phishing Attack

It's tax season and the bad guys are in full swing. They try to get your Accounting or HR team to send over the W-2s of all employees, but they also target employees in the office and/or ...
Continue Reading

SURVEY: Even if You Don't Pay, Ransomware Attacks Are Very Expensive

According to a new survey by Intermedia called "2016 Crypto-Ransomware Report", ransomware attacks are increasingly targeting larger companies, costing them dearly. Employees are usually ...
Continue Reading

New KnowBe4 Phishing Templates

We have added a dozen new phishing templates in the past few days. All are based on actual bad guy phishing emails seen in the last 2 weeks. At least one is less than 24 hours old. Most ...
Continue Reading

TeslaCrypt Ransomware v3.01 Updated With Unique Keys For Each Victim

TeslaCrypt is a relatively new ransomware variant which has made it in the Top 5, and has rapidly innovated in its efforts to evade detection. The latest version which is one of the most ...
Continue Reading

Ransomware Attacks Use NY Times, BBC, Other Media Sites

Over the weekend, The NY Times, BBC, Newsweek, AOL, MSN, The HIll and other major news sites had their ad networks hijacked again by criminals using the Angler Exploit Kit to deliver ...
Continue Reading

Inoculate Employees Against The Locky Ransomware

KnowBe4 has immediately responded to Dridex's Locky ransomware attack by releasing a new attachment option which is called "MS Office document with Macro". This new option allows a ...
Continue Reading

CyberheistNews Vol #6 #11

Continue Reading

Deadly Dridex Cybercrime Gang Has Just Moved Into Ransomware

One thing that is driving mainstream recognition of ransomware is the move by the Dridex banking Trojan gang into ransomware with their Locky strain. They have taken over from CryptoWall, ...
Continue Reading

The structure of Russia's exports in 2014, including ransomware

Check the orange slice depicting the percentage of ransomware exports. I found this on someone's twitter feed and loved it!
Continue Reading

Hackers Spoil Their $1 Billion Cyberheist With a Typo

It helps to know how to spell when you try to rob a billion from a dirt poor country. A spelling mistake thwarted hackers in stealing a $1 billion dollars from the Bangladesh Bank, and ...
Continue Reading

Weird New Cerber Ransomware Speaks To Its Victims

There is a new strain of ransomware called Cerber that takes creepiness to the next level. It drops three files on the victim's desktop named "# DECRYPT MY FILES #." These files contain ...
Continue Reading

IRS Warns Against A Widespread CEO Fraud Phishing Scam

OK, heads up! This tax season there is a widespread new scam that specifically targets your HR and Accounting professionals. They get an urgent email from "the CEO" who asks them for all ...
Continue Reading

CEO Fraud Phishing Attack steals 11,000 W-2s From Health Care Workers

A phishing incident has compromised the personal information of 11,000 Pennsylvania Main Line Health employees. Officials said the incident occurred on Feb. 16 when an employee fell for a ...
Continue Reading

CyberheistNews Vol 6 #9 How To Suck At Information Security – A Cheat Sheet

CyberheistNews Vol Vol 6 #9 How To Suck At Information Security – A Cheat Sheet Lenny Zeltser is a business and tech leader with extensive experience in Infosec. His areas of expertise ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews