Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Stu Sjouwerman

Founder and Executive Chairman

Stu Sjouwerman (pronounced “shower-man”) is the Founder and Executive Chairman of KnowBe4, Inc., which hosts the world’s most popular integrated security awareness training and simulated phishing platform, with over 54,000 organization customers and more than 50 million users. A serial entrepreneur and data security expert with 30 years in the IT industry, Stu was the co-founder of Inc. 500 company Sunbelt Software, a multiple award-winning anti-malware software company that was acquired in 2010.


Recent Posts

Ransomware Gangs Now Have Enough Money to Afford Zero-Day Exploits

Normally so expensive that they are only associated with nation-states, zero-day vulnerabilities are now within reach of ransomware gangs that have amassed fortunes to continue attacks.

Malicious Retail Phishing Sites Spike Ahead of Shopping Holidays

Researchers at Check Point have observed a record number of malicious phishing shopping websites that have been set up over the past two months. The researchers assume these sites were ...

Trends in Cybercrime Report Phishing, Non-Payment Scams, and Extortion

Social engineering attacks account for the vast majority of cybercrime in the US, according to researchers at SEON. The security firm found that phishing, non-payment or non-delivery ...

Rosa Smothers is Featured in the Women Know Cyber Documentary

Our very own Rosa Smothers, SVP of Cyber Operations, has been featured in the Women Know Cyber documentary by Cybercrime Magazine.

Phishing Emails Use Small Font Size to Bypass Security Filters

Researchers at Avanan have spotted phishing emails that use a font size of one to fool email security scanners. The emails appear to be password expiration notifications from Microsoft ...

One-Fifth of U.K. Residents Have Experienced a ‘Proof of Vaccination’ Attack

As the pandemic now focuses on proving vaccination status in many locales, scammers are taking the opportunity to leverage the need for documentation to steal personal information.

“Customer Complaint” May Get Your Attention

A spear phishing campaign is sending phony “customer complaints” that contain a link to a malicious website, according to Paul Ducklin at Naked Security. The phishing emails appear to ...

Will Ransomware Extortion Tactics Ever Stop Evolving?

The latest development in extortion methods by developers of Conti shows we should begin to continually expect new and innovative extortion tactics by cybercriminal gangs moving forward.

Use of Ransomware Data Leak Sites Begin to Slow Down?

New analysis of ransomware attacks by security vendor Digital Shadows in their Ransomware Q3 Roll Up highlights the current state of data leak site use with a peek into what may be to ...

Bait Attacks as Reconnaissance

Researchers at Barracuda warn that attackers are sending non-malicious emails as a precursor to targeted phishing attacks.

Phishing Attacks Aimed at Social Accounts Now in the Top Three Targeted Sectors

New data on the use of impersonation in phishing attacks focused on social media accounts shows some very realistic and worrisome websites and emails that could definitely fool you.

Business Email Compromise-as-a-Service Emerges as Attempted Fraud Soars to as High as $6 Million

BEC scammers set their sights on payoffs in the millions of dollars, and are following the path of their ransomware counterparts by evolving services while organizations struggle to keep ...

The TodayZoo Phishing Kit Has All the Obfuscation and Impersonation Needed to Fool Your Users

New details from Microsoft on this pieced-together phishing kit reveal some unique tactics designed to avoid detection by security solutions and users alike while stealing credentials.

Median Ransomware Payment Jumps 50% as Mid-Market Becomes More Targeted

Changes in attack tactics in the last quarter alone demonstrate a shift in focus for ransomware gangs, as the number of companies attacked with 100 to 1,000 employees grows.

New 'Frankenphishing' Tactic Combines Other Phishing Kits Into One

RiskIQ has observed another phishing kit that’s been pieced together from portions of other phishing kits.

[HEADS UP] Popular Stock Trading Platform Becomes Next Victim of Data Breach

Bleeping Computer recently reported a data breach from popular stock trading platform Robinhood. This breach has impacted over 7 million of their customers.

New Browser Cookie “Smash and Grab” Attack Targets YouTube Creators

New attack details from Google’s Threat Analysis Group show how cybercriminals are innovating ways to use an initial attack to aid in additional crypto scams.

Enabling and Securing Remote Workers are Top Concerns as 80% of Organizations Experience Cyberattacks as Often as Once per Hour

Organizations appear to be overconfident in their ability to protect themselves, despite glaring gaps in security, according to new data from cyber protection vendor, Acronis.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.