Advanced Educational Competition – Ask Your Employees To Submit Their Best Phishing
I occasionally get human risk management (HRM) administrators asking me to help them with ideas of “contests” to better educate their end-users.
Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.
CISO Advisor
I occasionally get human risk management (HRM) administrators asking me to help them with ideas of “contests” to better educate their end-users.
A super common voice phone call phishing scam (i.e., vishing) is when the scammer calls you and pretends to be a law enforcement official with a warrant for your arrest for not answering ...
“The problem is much, much worse than most people acknowledge.” One of the biggest enduring mysteries for me in cybersecurity is why most cybersecurity curricula don’t teach secure coding ...
In a world so full of digital online scams, it’s hard to remember that scammers abuse our postal mailing systems as well.
I hear about a ton of similar-sounding scam calls, where the scammer is pretending to be from a service you use (or used), offering you a substantial monthly discount (30% or more) if you ...
ClickFix attacks have been around for decades; only the name is new.
There is no other way to say it clearer, social engineering is going to be a lot, lot worse soon and far more successful than it is today. And that’s saying a lot. It’s already pretty bad.
Most Microsoft 365 users aren’t aware of this recently growing serious email threat vector.
I’ve been following ransomware since the first one, the AIDS Cop Trojan, was released in December 1989.
We are working tirelessly on our AI First strategy to better protect both humans and their AI tools.
AI is going to allow better, faster, and more pervasive attacks.
I am used to repeating some pretty big numbers when talking about the financial impact of cybercrimes. When you look into the data, it is pretty easy to start talking about tens of ...
What is AI really? Throughout this article, I will remove the hype and get to the most honest answer ever.
A KnowBe4 co-worker of mine recently got this SMS phishing message (i.e., smish).
Human risk management involves more than security awareness training, but training is a huge part of the mix.
I got this Coinbase-related scam in my personal inbox last week.
Agentic AI-enabled ransomware is not here yet, but likely will be very soon. I am talking this year or by 2026.
Just because you’re using a passkey doesn’t mean your password is gone.
Recently, I covered a T-Mobile scam where a friend of mine narrowly avoided losing money. In that scam, the attackers called up pretending to be from T-Mobile offering him a ...
A friend of mine got a call on his phone and he regrettably picked it up. The number was 267-332-3644. The area code is from Bucks County, PA, where he used to live many years ago.