My lazy Sunday afternoon was interrupted...

Stu Sjouwerman | Aug 12, 2020

evil_twin_domains

My lazy Sunday afternoon was interrupted with what appeared to be a prank, a social engineering attempt, or something else that remains to be identified. 

 

Apparently, someone took it upon themselves to create a lookalike domain of another training company (see Domain Doppelganger below) and route traffic from that lookalike domain to our website.

Even though ICANN has options to keep domain ownership anonymous, we still decided to immediately investigate. We continue to be in conversations with the other training company in hopes to identify the root cause.

Being the market leader for security awareness training and simulated phishing, we know to expect pranks and attempts to hack, so it comes as no great surprise. We do not condone this type of activity because it goes against our culture; we pride ourselves on our radical transparency with our staff, our customers, our partners, and the InfoSec community.

At the time of this writing, we don't know who created the typo-squatter domain, and we are taking measures to investigate. Stay tuned for further updates as they may arise.  
 
With security awareness top of mind, everybody wins. 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.