Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

[ALERT] 2016 Is A Ransomware Horror Show. Here's The Roundup Of 32 New Strains!

If you've been in the IT trenches over the past year, you've probably noticed the announcements of new strains of ransomware are accelerating. The research team at Proofpoint just ...
Continue Reading

The Phishing Attack That Came Out Of Zendesk

Yesterday, April 25 2016, we encountered a new phishing email being delivered through Zendesk. The credentials phish itself is a straightforward social engineering attack. The email body ...
Continue Reading

Scary New CryptXXX Ransomware Also Steals Your Bitcoins

Now here's a new hybrid nasty that does a multitude of nefarious things. Proofpoint researchers found that it was built by the same cyber mafia that's behind the Reveton malware. A few ...
Continue Reading

Scam Of The Week: Secure Document Phishing Attacks Trap Employees

In this Scam Of The Week we are warning against a new wave of phishing scams. In the industry this is called the "secure doc" theme. It's getting very popular with the bad guys. We see a ...
Continue Reading

Scam Of The Week: Prince Last Words On Video

Today, news broke that Prince Rogers Nelson was found dead in his home in Minneapolis at age 57. He was found unresponsive in an elevator and was declared dead shortly after. He performed ...
Continue Reading

[ FTC ALERT ] Don't Get Scammed By Earthquake Phishing Emails

It's the old story. A disaster strikes and 24 hours later you get emails with urgent request for help as hundreds of wounded victims need food, water and shelter. And the bad guys are at ...
Continue Reading

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016"

CyberheistNews Vol 6 #16 FBI: "Ransomware On Pace To Be A 1 Billion Dollar Business In 2016" CNN Money reports about new estimates from the FBI show that the costs from ransomware have ...
Continue Reading

A Short History & Evolution of Ransomware

Ransomware attacks cause downtime, data loss, possible intellectual property theft, and in certain industries a ransomware attack is now looked at as a possible data breach. Ransomware is ...
Continue Reading

CTB-Locker Ransomware Uses Blockchain to Store & Deliver Decryption Keys

A mysterious update in the behavior of the CTB-Locker ransomware strain alerted security researchers to pull some strings and see what was going on. The CTB-Locker ransomware family, ...
Continue Reading

Ransomware On Pace To Be A 2016 $1 Billion Dollar Business

CNN Money reports about new estimates from the FBI that show the costs of ransomware have reached an all-time high this year. Threat actors made $209 million in the first quarter of 2016 ...
Continue Reading

Phishing Attacks Hit the C-Suite With High Value Scams [INFOGRAPHIC]

OK, here is great ammo to get more IT security budget. Why? This article and infographic make it real to the C-suite that they themselves have a big phishing target on their back. You all ...
Continue Reading

US Company Falls Victim To $100 Million CEO Email Fraud

An as yet unknown American company fell victim to nearly $100 million in CEO Fraud. Employees were social engineered by spoofed emails that claimed to be one of its legitimate vendors, ...
Continue Reading

They Shoot Files, Don't They? Jigsaw Ransomware Does...

By Eric Howes, KnowBe4 Principal Lab Researcher. A few days ago our friends at BleepingComputer.com announced the discovery of a new form of ransomware, which they dubbed Jigsaw ...
Continue Reading

Pinellas Man Falls Victim To Ransomware

Pinellas County resident Scott Germak thought he was getting free Tampa Bay Rays tickets based on a phishing email that appeared to be a legitimate message coming from GTE Financial, his ...
Continue Reading

The Future Of Ransomware: CryptoWorms?

Cisco's Talos Labs researchers had a look into the future and described how ransomware would evolve. It's a nightmare. They created a sophisticated framework for next-gen ransomware that ...
Continue Reading

Exciting New Features In KnowBe4 Spring 2016 Release

We have several cool new features in the Spring 2016 release! These features were previously out of reach for IT managers with limited budget, and we're excited you can use them now with ...
Continue Reading

CryptoHost Ransomware Locks Files In A Password Protected RAR File

A new ransomware strain called CryptoHost was discovered, which claims that it encrypts your data and then demands a ransom of .33 bitcoins to get your files back (~140 USD at the current ...
Continue Reading

Hello mass spear phishing, meet ransomware!

Ransomware is now one of the greatest threats on the internet. In the past, IT Security firms used to monitor spear-phishing attacks by espionage outfits, but these techniques are now ...
Continue Reading

How Mattel Lost $3M In CEO Fraud Phishing

Great story by Erika Kinetz at the Associated Press. How Mattel was the victim of CEO Fraud using phishing and social engineering to trick one of their executives in China to make a $3 ...
Continue Reading

Maktub Ransomware Knows Where You Live

It's happening in the UK today, and you can expect it in America tomorrow [correction- it's already happening today]. The bad guys in Eastern Europe are often using the U.K. as their beta ...
Continue Reading

KnowBe4 Gets 1st place for the Tampa Best Places To Work

We're stoked here. We got 1st place for the Tampa Best Places To Work - small business category!!! The Tampa Bay Times has a yearly "Best Places To Work" contest, and surveys the ...
Continue Reading

Users Really Do Plug in USB Drives They Find

Been suspecting that your users are plugging in any USB stick they find, to see what is on it? Well, you are right, they actually do that. Fresh scientific research by Google, and the ...
Continue Reading

[FBI ALERT] Dramatic Increase in e-mail CEO Fraud To 2.3 Billion.

A brand new Alert by the FBI on April 4th 2016 warns of a major increase in what they call business email compromise or BEC (we call it CEO Fraud), amounting to a whopping $2.3 billion in ...
Continue Reading

More About Petya Hard Disk Lock BSoD Ransomware

[UPDATE April 10, 2016] Petya's ransomware's encryption has been defeated and a password generator has been released. See bottom of the post. March 25, news came out about a new type of ...
Continue Reading

KnowBe4 Has Blowout First Quarter 2016

KnowBe4, the United States’ most popular integrated platform for security awareness training and simulated phishing tests, announced it attained a top spot (#220) in the Cybersecurity ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews