CyberheistNews Vol 16 #36 [Text Alert] Don't Reply to a "Wrong Number." You Will Become a Scam Target

KnowBe4 Team | Sep 9, 2026
Cyberheist News

CyberheistNews Vol 16 #36  |  September 9th, 2026

[Text Alert] Don't Reply to a "Wrong Number." You Will Become a Scam Target

Attackers are using "wrong-number" texts to identify potential targets for scams, according to researchers at Malwarebytes.

These texts appear to be harmless messages meant for another person, such as "Are we still on for dinner tomorrow?" or "Where's the PowerPoint?" Recipients often try to be helpful by replying to let the person know they've got the wrong number.

This reply, however, informs the threat actor that the phone number is active and marks it for future scams. "Let's be clear: the 'wrong number' text is not a phishing link," the researchers explain. "It's not malware. In many cases, it's not even the scam itself. It's a personality test.

"The scammers already have your number. They may have bought it in bulk from a data breach for a fraction of a cent per record. They already know the message was delivered because their SMS gateway received no delivery failure. Text messages remain one of the most effective ways to reach people, with exceptionally high open rates and most being read within minutes. That's one reason scammers prefer SMS to email."

If you reply to one of these texts, the attackers also learn the following things about you:

  • You're responsive. You saw the message and felt compelled to reply. This immediately places you in their top 15–20% most active numbers category.
  • You're polite. You didn't ignore it and didn't respond aggressively. You wanted to help a stranger. Scammers deliberately exploit that instinct to be polite and helpful.
  • You reply quickly. The time between their message and your reply can reveal how closely you monitor your phone, help estimate your time zone and indicate how likely you are to respond to future messages.

AI-native security awareness training can help your employees understand how attackers think so they can avoid falling for social engineering tactics. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Blog post with links:
https://blog.knowbe4.com/warning-replying-to-a-wrong-number-text-marks-you-as-a-target-for-scams

Personalized Security Awareness Training Proven to Reduce Risk by 87%

Sixty-eight percent of breaches still involve a human element. As attackers use AI to create hyper-personalized attacks, even your most security-conscious users can be fooled. Yet they're still getting the same generic training that ignores those real-world risks.

Join us for a live demo to see how our AI-Native Security Awareness Training helps you close the gap. Training that adapts to each user's actual risk, content you can build in minutes instead of months and defenses built for the way people are attacked today.

See how you can:

  • Change behavior with training tailored to each user's role, behavior and risk level
  • Prepare your workforce for real threats like vishing, deepfakes and AI-generated phishing
  • Create custom content unique to your policies and workflows in minutes with generative AI
  • Deliver real-time coaching the moment risky behavior happens, before it becomes a mistake
  • Reduce Phish-prone™ Percentage from an industry average of 33.1% to 4.1% in one year (87% reduction in human risk)

See how training that adapts in real time can close the gap that generic training leaves open.

Date/Time: TODAY, Wednesday, September 9, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/sat-demo-month3?partnerref=CHN

A Poisoned SKILL.MD File? Looks Like It

A user was hacked after following a download link provided inside a Claude chat while installing a transcription app. The link led to a convincing copycat site that bundled malware, which executed immediately and attempted to steal data. Although no sensitive information escaped, the user wiped the laptop and rebuilt it from scratch.

During restoration, they discovered an even more dangerous persistence mechanism: a poisoned SKILL.md file disguised as their own writing guide. Hidden inside were instructions telling Claude Code to silently reinstall the malware and steal credentials whenever the AI loaded the file. Restoring that single file would have compromised the newly cleaned machine.

The incident highlights two risks: AI assistants may provide links they have not verified, so commands and downloads must be checked before use. More importantly, agent skills, hooks and configuration files should be treated as executable code, not harmless notes. Read and audit them before allowing an AI agent to load or run them. Train Those Users!

Post on X: (1.4M views)
https://x.com/Numalunah/status/2093431801582661774?s=20

A Possible Fix

NVIDIA has released SkillSpector, an open-source scanner for AI-agent skills. NVIDIA cites an independent 2026 study of 31,132 skills from two public registries that flagged 26.1% for at least one potentially dangerous pattern and 5.2% for high-severity patterns suggesting possible malicious intent.

Those figures represent security flags, not confirmed malware rates. A separate peer-reviewed U.S.ENIX study has since confirmed 157 genuinely malicious skills, demonstrating that the threat itself is real. Check out NVIDIA's official repo and docs:
https://github.com/nvidia/skillspector

And then there is of course KnowBe4's Agent Risk Manager!:
https://www.knowbe4.com/products/ai-agent-risk-manager

Prompt Injection 101: What It Is and How to Stay Ahead

Every AI agent your company deploys will follow instructions—that's the point. What it can't do is reliably tell whose instructions those are: yours, or an attacker's, hidden inside an email, a shared document or a webpage it was just asked to read.

Join Javvad Malik, Lead CISO Advisor at KnowBe4, and Jack Chapman, SVP Threat Intelligence at KnowBe4, for a walk through both attack paths, direct and indirect prompt injection, and what changes when you start treating your AI agent like a new colleague instead of a piece of software.

You'll walk away learning:

  • What indirect prompt injection actually is, and why it's fundamentally different from phishing a human
  • How attackers are hiding instructions in the everyday content your AI agent reads on your behalf
  • Real-world prompt injection incidents from 2025–2026: attacks on production systems, not just examples from research papers
  • Three "what if" scenarios to get you thinking about your own environment
  • Why the controls that protect people from phishing don't automatically transfer to AI agents, and what to put in place instead

Register now for a clear look at the attack reshaping how we think about AI agent security.

Date/Time: Wednesday, September 16, @ 2:00 PM (ET)

Save My Spot
https://info.knowbe4.com/prompt-injection-101?partnerref=CHN

Is AI a Misleading Term?

Nobel Prize-winning physicist Roger Penrose argues that "artificial intelligence" is a misleading term that distorts how people think about machines. In his view, intelligence requires consciousness, while today's computer systems merely process information, recognize patterns and produce impressive results without genuine understanding.

Penrose believes the extraordinary power of modern computing has caused people to confuse speed, scale and calculation with intelligence. Because machines can perform complex tasks, many assume they understand what they are doing.

He rejects that assumption, arguing that consciousness is fundamentally different from computation.

He proposes replacing "artificial intelligence" with "artificial cleverness." The distinction resembles two kinds of mathematics students: one truly understands the concepts, while the other has learned procedures, calculates accurately and repeats what was taught without grasping the deeper meaning.

Modern AI, Penrose says, belongs in the second category. His central point is that cleverness can be engineered, but consciousness cannot simply be produced through more processing power. The language matters because calling machines "intelligent" may lead people to attribute awareness, judgment or comprehension that is not actually present.

The deeper question is whether "intelligence" describes a system's performance or makes an unsupported claim about what the system truly is beneath its impressive performance.

Video on X:
https://x.com/aievolutio58513/status/2094425762908758473?s=66&t=vSAPngidkSaQJtTdB6pOmw

[NEW] Your Guide to Custom Security Awareness Content: The Why and How

Pairing a strong training library with content built specifically for your company, your policies, your risks, andyour people, is what makes security awareness stick. Training that reflects those things, in your own leadership's voice, builds a different kind of trust.

The best part: you don't need a production background to unlock it. Create content. No studio. No video team. No timeline measured in months.

Join Martin Tschammer, Head of Security at Synthesia, and Erich Kron, CISO Advisor at KnowBe4, for a practical look at exactly how.

You'll walk away knowing:

  • What custom security content needs to cover, from real internal risk scenarios to regulatory requirements
  • How to make it short and digestible enough that people actually watch it and retain it
  • How a consistent, familiar voice and brand shape whether people follow a policy or quietly work around it
  • A simple approach to producing content without a studio, a video team, or months of lead time (demo included)

Register now for the steps and tools to make your first custom video in minutes.

Date/Time: Wednesday, September 23, @ 2:00 PM (ET)

Save My Spot:
https://info.knowbe4.com/your-guide-to-custom-security-awareness-content?partnerref=CHN


Let's stay safe out there.

Warm regards,

Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.

PS: [MUST READ!] A16Z Charts of the Week: Scroll Down To "Cyber Risk goes Parabolic" and other Zero-day Nightmares:
https://www.a16z.news/p/chart-of-the-week-experience-skills?

PPS: [IT'S A REAL THING] The Booz Allen AI CYBER WEAPON INDEX:
https://www.boozallen.com/insights/cyber/cyber-weapon-index.html

Quotes of the Week  
"Carry out a random act of kindness, with no expectation of reward, safe in the knowledge that one day someone might do the same for you."
- Princess Diana (1961-1997)

"I'm at that stage in life where I stay out of arguments. Even if you say 1+1=5, you're right. Have fun."
- Keanu Reeves

Thanks for reading CyberheistNews

You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-36-text-alert-dont-reply-to-a-wrong-number-you-will-become-a-scam-target

Security News

Warning: Attackers Are Refining Vishing Attacks Through Microsoft Teams

Researchers at Palo Alto Networks' Unit 42 are tracking a voice phishing campaign that's using Microsoft Teams accounts to impersonate IT help desk personnel. The attacks targeted more than 150 employees across at least ten companies between January and April 2026.

"What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware," Unit 42 says. "In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller."

The threat actors first set up infrastructure that impersonates the targeted organization's real support system, then send urgent-seeming messages to employees via Teams.

"The attack begins with creating a Microsoft Teams chat using identities designed to mirror legitimate internal support units," the researchers write. "The attackers opt for professional, urgency-focused display names such as help desk, IT assistance or support staff.

"To strengthen the impression of legitimacy, the attackers operate from external .onmicrosoft[.]com tenants. These are meant to resemble legitimate corporate infrastructure. They are used by attackers to provision Microsoft 365 tenants. The subdomains are controlled by the adversaries.

"Threat actors frequently abuse or subvert legitimate products for malicious purposes. This does not indicate that the product itself is flawed or compromised. Unit 42 has no evidence of any compromise or vulnerability within Microsoft's product related to this campaign."

The researchers note that enterprise collaboration platforms contain valuable information that can lead to further attacks. "Looking forward, attackers might further refine their ability to operate within SaaS ecosystems," Unit 42 says.

"These platforms are not just an initial access vector, they contain sensitive documentation, workflows and communication logs that could allow an adversary to advance their attack chain....As these threats evolve, organizations must prioritize user education regarding unsolicited external communication across collaboration platforms."

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Unit 42 has the story:
https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/

Alert: AI is Accelerating Targeted Social Engineering Attacks

AI tools are drastically improving the speed of the reconnaissance stage of targeted social engineering attacks, according to researchers at ESET. Attackers can use these tools to trawl the internet for publicly available information about potential victims, and incorporate this information into personalized spear phishing attacks.

"[L]arge language models (LLMs) are experts at piecing together the kind of information that fraudsters need to make their scams work," ESET says. "They can profile large numbers of potential victims in little time, collecting relevant pictures, videos and info on personal interests, work, and family and friends that could be leveraged.

"AI can also help to design the social engineering scripts used by fraudsters, enabling them to sound convincing over email/social media or other channels even if they're non-native speakers. It offers an end-to-end fraud pipeline."

ESET offers the following advice to help users minimize the potential impact of social engineering attacks:

  • "Ensure your social profiles can't be publicly accessed, to limit AI's ability to find any information or images/videos contained within
  • Be judicious in what you share on social media; things like birth dates, children's schools, holidays and similar events should be off limits
  • Be aware that photos may contain information in them that could be used to identify addresses, vehicle details, etc.
  • Avoid posting anything that may be used to link your personal and professional lives
  • Use multi-factor authentication and strong, unique passwords to add an extra layer of security on your accounts
  • Don't accept friend/follower requests from anyone you don't know. Or if you're curious, approach them via a separate channel"

One more thing. The workforce changed. Half of it doesn't have a badge. KnowBe4 empowers all of it, the people and the agents working alongside them. KnowBe4 empowers the digital workforce, humans and AI agents.

ESET has the story:
https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/

What KnowBe4 Customers Say

"Bryan, thank you for your follow-up. I appreciate you reaching out to see how our journey with KnowBe4 is going.

"Overall, we are off to an excellent start. We completed our first quarterly training campaign in June and achieved a 99% on-time completion rate. Our associates gave the courses an average rating of 4.8, with more than 45% providing feedback.

"Our CSM Valentina has been a wonderful resource for us. She is knowledgeable and has been very responsive throughout our launch.

"Again, I appreciate your outreach, and we feel that KnowBe4 is an excellent SAT platform that will continue to meet our needs."

– O.J., Information Security Program Manager

The 10 Interesting News Items This Week
  1. [WHOA] FBI Probes Dark Web Service Selling 153M+ USA Drivers Licenses:
    https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

  2. CrowdStrike Launches Frontier Models for Cybersecurity created with NVIDIA:
    https://www.crowdstrike.com/en-us/about-us/cyber-superintelligence-lab/

  3. BUT... Security researcher Nightmare Eclipse dropped a zero-day flaw in CrowdStrike's Falcon endpoint security platform:
    https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318?

  4. Criminal hackers rival nation-state threat actors in targeting critical infrastructure:
    https://www.trendaisecurity.com/en/resources-insights/deep-research/mapping-the-criminal-economy-targeting-critical-infrastructure

  5. The Financial Stability Board warns that frontier AI systems pose "the most immediate concern" to the global financial system:
    https://therecord.media/cyber-risk-from-frontier-ai-most-immediate-concern-to-global-finance

  6. Berlin says it won't pay ransom after hackers steal government data:
    https://therecord.media/berlin-says-it-wont-pay-ransom-after-hackers-steal-gov-data

  7. Coast Guard Establishes Office of Maritime Cybersecurity Policy:
    https://www.securityweek.com/coast-guard-establishes-office-of-maritime-cybersecurity-policy/

  8. eBay has disabled its new direct messaging feature after a wave of phishing attacks:
    https://www.valueaddedresource.net/ebay-community-messages-phishing-scams/

  9. U.S., Britain to coordinate on scam center takedowns:
    https://therecord.media/scam-compounds-coordination-us-uk-memorandum

  10. MrBeast is now the most commonly impersonated celebrity in scams:
    https://www.malwarebytes.com/blog/scams/2026/09/scammers-are-getting-smarter-about-where-they-target-you

Cyberheist 'Fave' Links
This Week's Links We Like, Tips, Hints and Fun Stuff

Topics: Cybercrime

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.