Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

CEO And CFO Fired After Aerospace Company Grounded By CEO Fraud

Here is a great way for C-level execs to lose their job: allow your company to become the victim of CEO Fraud. That happened to the CEO and CFO of FACC, part of both Airbus' and Boeings' ...
Continue Reading

CryptoWall, Locky, and Cerber Are Today's Top 3 Ransomware Threats

US cyber-security firm Fortinet reports that, between April 1, 2016, and May 15, 2016, the top five most prevalent ransomware families were in this order: CryptoWall (41.04%), Locky ...
Continue Reading

New Strain Of Cerber Ransomware Being Offered As RaaS On Russian Hacking Forum

Security Researchers at Forcepoint discovered that a Russian hacking forum on the dark web is selling the Cerber ransomware as a RaaS (Ransom-as-a-service). This is a new form since ...
Continue Reading

Are North Koreans The Bad Guys Behind Brazen Cyberheists?

In March, we posted a story about a cyberheist where hackers tried to steal a cool 1 Billion dollars from the Bangladesh Central Bank, but a simple typo thwarted most of their attempt. ...
Continue Reading

The Nightmare of Exploits Past. How Phishing Attacks Use Old Vulnerabilities

By Eric Howes, KnowBe4's Principal Lab Researcher Remember .PIF files? If you're like us, the extension probably rings a bell somewhere deep in the dustiest recesses of your mind -- the ...
Continue Reading

Scam Of The Week: Summer Olympics Canceled in Rio

Heads-up! There is a spike in phishing attacks with Summer Olympics themes, and in the coming months the bad guys are going to be all over this. Kaspersky Labs researchers are reporting ...
Continue Reading

Microsoft Alert: ZCryptor Ransomware With Worm Feature

Microsoft released an alert about a new ransomware strain called ZCryptor, which works like a worm and spreads via removable and network drives. The MalwareForMe blog reported this first ...
Continue Reading

Shields Up! New DMA Locker V4 Unleashes Major Ransomware Assault

DMA Locker is an excellent example of cybercrime's furious speed of innovation. Version 1 showed up in January 2016, and V2 a month later, but the implementation of the encryption ...
Continue Reading

Massive Locky Ransomware Campaign Targets Amazon Users

Comodo Threat Research Labs just posted an alert that a massive campaign of phishing emails have been sent with a spoofed "from" address: auto-shipping@amazon.com. The subject is “Your ...
Continue Reading

[ALERT] Cerber Ransomware Strain Adds DDoS Bot Causing More Damage

Excuse my French, but Holy S#!+, some ransomware developers have created a new evil way to monetize their operations by adding a DDoS component to their malicious payloads. Security ...
Continue Reading

Scam Of The Week: LinkedIn Email Change Your Password

You probably remember the 2012 LinkedIn data breach. It was a big deal because something like 6.5 million user account passwords were posted online, but LinkedIn never confirmed the final ...
Continue Reading

"What methodologies does KnowBe4 use in developing our training?"

Someone interested in using our integrated platform for training and phishing asked us: ""What methodologies does KnowBe4 use in developing our training?" We use the ARCS Model. ARCS is ...
Continue Reading

What does a "Human Firewall" look like, anyway?

By Eric Howes, KnowBe4's Principal Lab Researcher So you've subscribed to Security Awareness Training that includes training modules as well as simulated phishing campaigns for your ...
Continue Reading

We just received the ultimate in weird nested malware

Last night a customer sent us a phish via the KnowBe4 Phish Alert Button ( free download here) that must win some kind of award for the longest chain of required user interactions -- all ...
Continue Reading

How To Stop Your Ex-Girlfriend Sending Nude Photos To A Fake Facebook Profile

In a case of sophisticated social engineering, a fraudster created a fake profile of actor Vincent Gallo. He then proceeded to engage in a 2-month long scam, flirting online and sending ...
Continue Reading

TeslaCrypt Gives Up and Releases Master Decryption Key

Larry Abrams from the Bleepingcomputer site noted: "In a surprising end to TeslaCrypt, the developers shut down their ransomware and released the master decryption key. Over the past few ...
Continue Reading

Tech Support Scammers start locking Windows PCs

Tech support scammers have come up with a new way to trick users into sharing their payment card information: screen lockers showing fake Windows alerts telling users that their Windows ...
Continue Reading

[ALERT] Fraudsters Steal Tax, Salary Data From ADP. Are Employees At Risk?

It turns out that HR giant ADP, which provides payroll, tax and benefits administration for more than 640,000 companies, was vulnerable to an ID theft scam. The criminal hackers made off ...
Continue Reading

Scam Of The Week: Bogus IT Security Company Websites

Tech Support Scams are nothing new, but the bad guys are furiously innovating and there is a new variation you need to warn your users about. A few years ago this started out with bogus ...
Continue Reading

This Has Been A Crazy Week In Ransomware

That's what Larry Abrams from Bleepingcomputer started out with yesterday, and he was right! We have had six new ransomware strains, one new RaaS (Ransomware-as-a-Service) and one major ...
Continue Reading

What Is The #1 Cause Of Healthcare Data Breaches?

As a new story about hospital ransomware or a stolen laptop containing PHI seemingly emerges every day, it comes as no surprise that healthcare data breaches have steadily increased in ...
Continue Reading

Poll Results: "Should Someone Who Falls For A W-2 Phishing Attack Be Fired?"

It's an interesting question, because the specific circumstances were explained in an article about this particular incident. There were 186 answers to this poll, and here are the results ...
Continue Reading

Ransomware and CEO Fraud Dominate 2016

An interesting Q1-16 threat report from the folks at Proofpoint. Every day, they analyze more than 1 billion email messages, hundreds of millions of social media posts, and more than 150 ...
Continue Reading

New Petya Comes Loaded with Double-Barrel Ransomware Attack

A new twist on the Petya ransomware and how it now uses a backup ransomware attack. Remember, Petya is a new type of ransomware that doesn’t encrypt specific files but makes the entire ...
Continue Reading

New evil android phishing trojans empty your bank account

Infragard warned that the FBI has identified two Android malware families, SlemBunk and Marcher, actively phishing for specified US financial institutions’ customer credentials. The ...
Continue Reading

Congress warned about cybersecurity after attempted ransomware attack on House

In an email provided to TechCrunch, the House technology service desk warned representatives of increased ransomware attacks on the House network. The email warns that attackers are ...
Continue Reading

InfoSec Analyst: "We Make People Suck At IT Security"

IT Security analyst Ben Tomhave calls himself an infosec obsessive and I admire his insightful analyses when they appear. This time he commented on the recent attacks that followed the ...
Continue Reading

Prince Death Overdose Caught On Video! Stolen out of a spear phishing attack?

Our CTO was picking up some groceries and saw this at the check-out, stolen straight out of a spear phishing email... or was it? LOL.
Continue Reading

The Hidden Dangers of .HTML Attachments

By Eric Howes, KnowBe4's Principal Lab Researcher Over the past six to nine months .DOC and .JS file attachments have dominated the news surrounding the rise in phishing attacks. The ...
Continue Reading

Troy, Mich Investment Firm Loses $500,000 in CEO Fraud

An employee at a Troy, Mich., investment firm fell for a CEO Fraud attack and was social engineered into transferring almost $500,000 to a Hong Kong bank. The error was noticed eight days ...
Continue Reading

New KnowBe4 Feature: Vulnerable Browser Plugin Detection

How Can I See If My Users Have Vulnerable Browser Plugins Installed? Within your console, you can automatically detect what vulnerable plugins any clickers on your phishing tests have ...
Continue Reading

Verizon 2016 Data Breach Report: "Phishing Tops The List Of Increasing Concerns"

Verizon yearly does a comprehensive report on security and data breaches. It is excellent ammo to get budget approval for new-school security awareness training. Why? Hundreds of security ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews