CyberheistNews Vol 16 #33 | August 18th, 2026
[Blind Spot] Employees Are Easier to Scam Than They Think
A survey from Trustmi found that most employees believe they'd be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red flags. Generative AI has given attackers the ability to craft extremely convincing, error-free phishing emails.
"Findings suggest employee confidence is rooted in their ability to spot traditional fraud tactics," the report says. "A large majority (78% of respondents) said they were confident they could identify a fraudulent payment request at work.
"But they're still looking for the traditional phishing tactics - such as typos or fake email addresses - they were trained to recognize years ago. 70% rank typos, fonts or grammatical errors as their No. 1 warning sign."
While typos and grammatical errors are still red flags, employees need to be aware that many phishing emails now have perfect spelling and grammar. Users should be on the lookout for other signs of social engineering as well.
"Every other cue trails well behind: 25% cite an unfamiliar sender, 22% [cite] unusual urgency and 16% [cite] a suspicious invoice," the researchers write. "Even unusual urgency - the pressure tactic common to executive-impersonation and payment-diversion scams - ranks near the bottom.
"The reliance on old signals is sharpest among the youngest workers: Gen Z ranks grammar mistakes as a top warning sign more than any other generation (82%), compared with 50% of Baby Boomers."
Employees are also lagging in awareness of established social engineering techniques. Most respondents (81%) said they would trust a payment request that appeared in an existing email thread, even though attackers have been hijacking existing email threads for years to launch business email compromise (BEC) attacks.
Blog post with links:
https://blog.knowbe4.com/employees-overconfident-ability-to-spot-scams
The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember
You think about security 365 days a year. Come October, everyone else finally joins in. We're here to help you make the most of that spotlight and make your life easier while you do it.
This session walks through what's worked for other security teams (and what hasn't), so you don't have to learn it the hard way.
Join Dale Hackett, Systems Administrator and Information Security Admin with EXP Services, and Javvad Malik, KnowBe4 CISO Advisor, for real dos and don'ts from teams who've run their own Cybersecurity Awareness Month. Plus, how KnowBe4's free kit can help you launch your campaign without starting from a blank page.
You'll walk away knowing:
- How to make it fun without missing your audience. The games and activities that get people talking
- How to get more people to finish training (Hint: not another reminder email)
- Why you don't need to start from scratch. A ready-made kit gives you a running start
- A four-week action plan focusing on modern threats such as phishing, AI and deepfakes, data security and reporting to equip your users
Register now, and walk into October with a plan that works and a security posture that sticks past November.
Date/Time: THIS WEEK, Thursday, August, 20 @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/cam-webinar-2026?partnerref=CHN2
Why Securing AI Agents Is More Critical Than Ever
By Erich Kron
AI agents offer unprecedented capabilities, speed, automation, deep context and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals. You simply cannot rely on yesterday's risk management playbooks to handle today's AI-driven threats.
1. Attacks Driven By AI
Cybercriminals are leveraging AI to make classic attack vectors far more potent:
Hyper-Personalized Social Engineering: AI-assisted scams are vastly more effective. Chainalysis reported that hackers utilizing AI stole 4.5 times more value in crypto than those who didn't.
Accelerated Vulnerability Hunting: AI tools are discovering zero-day vulnerabilities at an unprecedented rate, causing publicly disclosed vulnerabilities to surge.
Autonomous "Hack Bots": Attackers now deploy autonomous AI agents to handle the entire lifecycle of a cyberattack, from identifying targets and writing custom malware to orchestrating personalized phishing campaigns, exfiltrating data and calculating optimal ransom demands.
2. Attacks Targeted At Your AI
Every new AI tool introduced into an ecosystem expands the organization's attack surface. Modern AI systems face dozens of novel exploit vectors, including:
Prompt and Context Injections: Tricking an agent into executing unauthorized commands hidden in everyday data (e.g., a malicious email).
Data, Model and Memory Poisoning: Corrupting the inputs, storage or internal logic of an AI model.
Identity and Privilege Exploitation: Abusing elevated access assigned to autonomous agents (Excessive Agency).
Jailbreaking and Supply Chain Exploits: Manipulating system prompts, underlying model weights or compromised third-party APIs and models.
Example Attack Scenario:
An employee uses an AI desktop assistant to manage email and scheduling. An attacker sends a seemingly normal email containing a hidden prompt injection. When the AI assistant reads and processes the email, the injected command executes, granting the attacker total control over the host system.
3. The Hidden Danger: Shadow AI and Over-Privileged Agents
Two major factors exacerbate the threat posed by AI agents:
Unmonitored "Shadow AI": Employees frequently use AI tools without IT approval, often without realizing it. For instance, a basic grammar-checking extension might silently update into an active AI agent that uploads sensitive company data to a third-party cloud.
Elevated Permissions: To perform autonomously, AI agents are increasingly granted elevated local or domain administrative privileges. Because identity management frameworks for AI are still evolving, compromising a single agent often gives hackers broad administrative control.
Vulnerability Chaining: Threat actors can use AI to chain multiple minor flaws across connected agents, turning small vulnerabilities into widespread breaches.
4. Defense Strategies: How to Protect Your Environment
To counter AI-driven risks, security teams must modernize their defensive tactics:
Enforce Strict AI Access Policies: Require formal IT review and authorization before any AI tool or agent is installed, and deploy automated controls to block unapproved agents.
Maintain Continuous, Real-Time Inventory: Periodic asset scans (e.g., weekly or monthly) are no longer sufficient. Organizations need continuous discovery to spot and assess new AI agents immediately.
Fight AI with AI: Traditional security tools cannot match the speed of autonomous attacks. Deploy AI-enabled security solutions capable of detecting, analyzing and responding to threats in real time.
Implement Formal Threat Modeling: Evaluate all built-in and third-party AI assets against established frameworks, such as:
- MITRE ATLAS Matrix
- NIST AI Risk Management Framework
- OWASP Top 10 for LLM Applications / GenAI Security Project
- Google Secure AI Framework (SAIF)
- ISO/IEC 42001
Autonomous AI agents bring immense productivity gains, but they drastically elevate organizational risk. To navigate this new landscape safely, defenders must proactively adapt their security strategies, deploy automated defenses and govern AI usage with precision.
Blog post with links:
https://blog.knowbe4.com/securing-ai-agents-more-critical-than-ever
How to Defend Your Microsoft Teams Against AI Phishing Attacks
Today, one in five attacks on Microsoft Teams is multichannel, using email to make contact and chat apps to launch the attack. Securing your inbox alone is no longer enough to close this dangerous security gap. Cybercriminals aren't just targeting email anymore—they are using AI to trick employees across every messaging tool they rely on. When old security tools miss these attacks, your entire messaging setup is left exposed.
Join Javvad Malik, KnowBe4's Lead CISO Advisor, to learn why messaging security must go beyond the inbox, and how a modern approach uses behavioral AI to stop attacks before they spread. We'll show you how to protect your team across email and chat without making security complicated.
You'll learn:
- Why attackers love chat and how they move from email into apps like Microsoft Teams.
- Why basic rules miss smart phishing tricks, fake emails and bad links.
- How smart AI stops attacks, looking at message context and sender habits to catch threats before users see them.
- How real-time warnings teach users to spot suspicious messages.
- Ways to prevent accidental leaks and automatically block wrong-recipient emails and stop sensitive data from leaving your business.
Close every security gap and learn how to spot hidden messaging risks.
Date/Time: Tuesday, August 25, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/defend-your-teams-against-ai-phishing-attacks?partnerref=CHN
WSJ: Inside North Korea’s Operation to Conquer the American Job Market
Leaked data, interviews and never-before-seen videos obtained by The Wall Street Journal reveal how a single team of these workers infiltrated at least eight companies in just a few months. Send to your C-Level team:
https://www.wsj.com/business/media/inside-north-koreas-operation-to-conquer-the-american-job-market-93729962
Note: I first reported on this on July 23, 2024(!) This is the blog post: "How a North Korean Fake IT Worker Tried to Infiltrate Us"
https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us
In further North Korean reporting, their threat actors built local AI tools to assist in phishing attacks. Researchers at Genians warn that "Kimsuky" is now running local LLM environments to integrate AI across its phishing operations.
"The threat actor has previously reused documents stolen or obtained during earlier attacks as decoy documents in subsequent spear phishing campaigns," the researchers write. "However, since 2026, a pattern of attacks has been observed in which documents created using generative AI are continuously used as decoy files."
Genians has the story:
https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
Do Your Users Know What To Do When They Receive a Suspicious Email?
Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report it, forfeiting a possible early warning?
KnowBe4's FREE (yes, you read that right) Phish Alert Button gives your users a safe way to forward email threats to the security team for analysis and deletes the email from the user's inbox to prevent future exposure. All with just one click! And now, supports Outlook Mobile!
Phish Alert Benefits
- Reinforces your organization's security culture
- Users can report suspicious emails with just one click
- Incident Response gets early phishing alerts from users, creating a network of "sensors"
- Email is deleted from the user's inbox to prevent future exposure
- Easy deployment via .EXE file for Outlook, Google Workspace deployment for Gmail (Chrome) and manifest install for Microsoft 365
Sign Up
https://info.knowbe4.com/free-tools/phish-alert-button-chn
Note: The Phish Alert Button supports Outlook 2010, 2013, 2016 & Outlook for Microsoft 365, Exchange 2013 & 2016, Chrome 54 and later (Linux, OS X and Windows) and Outlook Mobile!
AI Is Creating a New Attack Surface—and a New Defense Model
We attended Black Hat last week, and to no one's surprise, AI dominated the conversation. Enterprises are rapidly deploying models, copilots, agents and autonomous workflows to capture major productivity gains, often faster than governance and security controls can keep up. That is creating an entirely new attack surface.
Security teams must now protect prompts, models, training data, data storage and AI agents alongside traditional endpoints, identities, applications and cloud infrastructure. Threat actors will increasingly use prompt injection, model poisoning, data leakage and agent manipulation to influence how AI systems "think," what information they access and which actions they take.
As agents become embedded in business processes, compromising one could become as valuable as compromising a human employee.
At the same time, AI is driving the rise of autonomous cyber defense. Security operations centers are already strained by excessive alert volume, complex environments and persistent talent shortages. AI agents could help investigate alerts, collect evidence, correlate events, recommend or execute remediation and respond to threats in real time. Instead of manually handling every alert, tomorrow's security analysts may supervise teams of specialized agents that perform much of the operational work.
That could dramatically improve productivity, but it introduces a critical requirement: organizations cannot simply trust AI-generated decisions—they must be able to verify them. Expect growing demand for AI observability, governance and trust capabilities that show what an agent did, why it did it and whether the action stayed within policy.
The strategic takeaway is that AI security is becoming a continuous operational and compliance discipline, not a one-time tooling purchase. Organizations will need ongoing visibility and control across AI behavior, data access, identity, decision-making and remediation.
That broader scope is likely to favor platform providers that own key control planes over isolated point products. The fastest-growing categories may include AI security and trust platforms, agentic identity security, AI observability, data security posture management, autonomous security operations and AI-native threat detection.
The biggest winners will likely be vendors that can secure AI systems while using AI to automate defensive decisions—areas that barely existed a few years ago but could become multibillion-dollar markets by the end of the decade.
The KnowBe4 Product Manager for the new Agent Risk Manager product gave me a demo and I was impressed. Here is your heads up! Check it out:
https://www.knowbe4.com/products/ai-agent-risk-manager
Let's stay safe out there.
Warm regards,
Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.
PS: The White House is setting up a program that would let private cybersecurity companies conduct government-authorized operations against foreign cybercriminal groups, including surveillance and disruption of their infrastructure:
https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
PPS: [ALWAYS BE LEARNING] In 2013 the Nobel Committee gave Robert Shiller the prize in Economics. Two years before the Nobel, Shiller filmed this lecture at Yale: "Financial Markets 252." Almost none of the people who needed to watch it did:
https://x.com/0xZenq/status/2087217479164756021/video/1?s=66
- Roger Staubach - Athlete (born 1942)
- Eleanor Roosevelt - Former First Lady of the United States (1884 - 1962)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-33-blind-spot-employees-are-easier-to-scam-than-they-think
Report: Agentic AI is Driving a "Rising Code Tide," Not Just Disruption
The initial investor and security debate surrounding AI-native development platforms—such as Cursor, Devin and Claude Code—focused heavily on "seat-based disruption," with fears that AI agents would simply replace human developers.
However, new research suggests that AI agents are instead lifting the entire software development stack, creating a "rising tide" of activity that demands more—not less—infrastructure.
According to a recent analysis from Baird Equity Research, as the cost of producing software falls dramatically, enterprises are moving beyond simple displacement. They aren't just producing the same output with fewer people; they are aggressively pursuing projects that previously failed the ROI hurdle.
Developers are migrating toward higher-value work while agents absorb lower-level execution, leading to a net increase in software production and a corresponding need for infrastructure to store, test, build, secure and govern it.
Crucially, this shift creates what can be described as a "security and governance tax." One human developer produces a finite amount of activity, but one human supervising hundreds of autonomous agents can generate orders of magnitude more. Each of these agents has the ability to read code, access credentials, invoke external tools and push changes to production.
As activity scales, the ability to maintain visibility—knowing who (or what agent) did what, with which data and under which policy—becomes a prerequisite for scaling, not just an operational "nice-to-have." The economic model is shifting from human-seat pricing to activity-based metering, with the value of security and orchestration migrating upward.
AI is not just a deflationary force; it is a generator of new, complex security surfaces that require robust, human-in-the-loop oversight to manage.
[Report] AI Chatbots Are More Effective at Building Trust Than Human Scammers
A study has found that AI chatbots can be more effective at social engineering than human scammers, WIRED reports. The researchers looked at a form of romance scam commonly known as "pig butchering," in which scammers spend weeks or months building a relationship with the victim before tricking them into sending money for a phony investment scheme.
"[The researchers] found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human 'scammers' in their experiment," WIRED says.
Since the majority of the scam consists of non-malicious conversations, the researchers found that even legitimate AI chatbots could be used to automate the trust-building stage. Once the scammer is ready to ask for money, a human operator takes over.
Yisroel Mirsky, a computer science professor at Ben Gurion University who led the research, stated, "By having the full first stage of the scam performed automatically with LLMs at scale, you bring the victim up to this point where they have a very high level of trust.
"Then by transitioning it over to the human scammer at the end, this completely bypasses any vendor safeguards. With relatively little effort, we're able to make an agent that can outperform a human at building this exploitable emotional trust."
Notably, when the participants in the study were informed that one of the conversations they were having was with an AI chatbot, nearly all of them were able to identify which conversation it was. Before they were told, however, only one participant suspected that they were talking to an AI.
One of the researchers, Gilad Gressel, noted, "That's exactly how scams are, actually. Once the scam victim realizes what's going on, it's obvious. But when you're in the illusion of it, you just don't see it."
WIRED has the story:
https://www.wired.com/story/ai-scammers-are-better-at-building-trust-than-humans/
What KnowBe4 Customers Say
"I would be remiss if I didn't tell you that working with this team at KnowBe4 has been an absolutely magnificent experience. Tom has been the most informative, involved, passionate, and knowledgeable Account Manager I've ever had across any platform, not just security awareness. And Christina is on the ball 100%, every single time. I really, really have really loved working with this team!"
- H.L., Technical Program Manager
- AI-assisted spear phishing increases link click rates by a factor of 2.4:
https://techxplore.com/news/2026-08-field-ai-personalized-phishing-cheaper.html - Water Sector Pushes Washington for Cyber Protection after Hacking Spree:
https://www.wsj.com/pro/cybersecurity/water-groups-push-washington-for-cyber-rules-after-hacking-spree-39a48952? - OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users:
https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/ - Delta probes Wi-Fi de-auth attack on flight carrying DEF CON attendees:
https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ - FBI says cybercriminals are hacking into victims' online accounts to steal their intimate pictures:
https://techcrunch.com/2026/08/11/fbi-says-cybercriminals-are-hacking-into-victims-online-accounts-to-steal-their-intimate-pictures/ - German General: "Russia’s Hybrid Attacks Probe NATO Defenses":
https://www.wsj.com/world/europe/top-german-general-says-russia-is-probing-nato-defenses-with-hybrid-attacks-18597d36? - CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign:
https://therecord.media/cisa-gives-federal-agencies-two-weeks-to-patch-dprk-microsoft-bug - Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop:
https://www.digitaltrends.com/computing/microsoft-wants-you-to-ditch-sms-passwords-as-ai-makes-phishing-harder-to-stop/ - North Korean hackers have breached more than 1,600 companies around the world:
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/ - U.S. hospitals warn of phishing campaign impersonating MyChart:
https://www.cleveland19.com/2026/08/12/metrohealth-warns-patients-fraudulent-mychart-phishing-emails/
- Virtual Vaca #1 - 10 Most Beautiful Places To Visit In Madagascar:
https://youtu.be/Hr65ePMpYIw - Virtual Vaca #2 - Downtown Chicago, Illinois, in 4K HDR ULTRA HD:
https://youtu.be/cTdK-biyKKU - Virtual Vaca #3 - Europe’s BEST overlooked Country: 6 Days in SLOVENIA:
https://youtu.be/MVrpWS7s3mI - Extreme Moments | Best of August 2026:
https://youtu.be/t__JcCZ3dDE - Sound barrier-breaking driver sets zero-emissions land speed record:
https://newatlas.com/automotive/jcb-hydromax-land-speed-record/? - Tough Driving Willys CJ-3B Jeep (short):
https://youtube.com/shorts/fgSWL3RAJc8 - Germany Has Finally Built a Decent Airport:
https://youtu.be/nx7nUpDec1Q - How IMAX 70MM Film is Projected!:
https://youtu.be/7S_geBV5bLQ - A Bussalp 3 Way Wingsuit Flight:
https://youtu.be/Zd-uE06cF4I - Need some space? Visual Excellence in 8K HDR 60fps Dolby Vision:
https://youtu.be/DUxafByOGSY - For Da Kids #1 - Golden Retriever Accidentally Teaches 3 Orphan Goslings To Fly:
https://youtu.be/3onPnMQFw2k - For Da Kids #2 - Pigeon loses ability to fly. He adapts by becoming one of the dogs:
https://youtu.be/mW1QcIAxth8 - For Da Kids #3- Dog is shy unless dinner is late:
https://youtu.be/UyZ4UJECSTY - For Da Kids #4 - Terrified Cat Takes a Leap of Faith to Reach Safety:
https://youtu.be/1zN59viNI5w - For Da Kids #5 - Passersby Rush to Save Exhausted Horse:
https://youtu.be/WxnbyhvjpWw

