Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Ransoms Increase 43% as More Ransomware Attacks Include the Threat to Leak Exfiltrated Data

With average payments rising to over $220K, organizations scramble to stop ransomware attacks as gangs begin taking more advantage of software vulnerabilities as their attack vector.
Continue Reading

Healthcare Organizations Should Expect Cyber Insurance Premiums to Increase 25 to 50% This Year

In light of recent upticks in payouts – particularly around ransomware – cyber insurers are better understanding the risk and are adjusting rates accordingly.
Continue Reading

Paying the Ransom Is Not Just About Decryption

I just read that a well-known pipeline company paid $5M to the ransomware hacker group. And despite that, they are still having to use their backups because the decryption process is too ...
Continue Reading

Kicking You While You’re Down: Ransomware Attacks Begin to Adopt a “Triple Extortion” Model

New tactics spotted by security researchers at CheckPoint indicate a growing pattern by ransomware gangs to use additional extortion actions to increase revenues and ensure payment.
Continue Reading

Ransomware Attack Demands Cause Cyber Insurance Claim Amounts to Skyrocket

The perfect storm of large enterprises, cyber insurance policies, successful ransomware attacks, and ransom demands in the tens of millions now consistently result in seven-figure claim ...
Continue Reading

New Verizon DBIR: Credentials Stolen in 85% of Social Engineering Breaches

Verizon’s latest data breach report puts a spotlight on one of the largest and most unpredictable risk factors in your cybersecurity strategy – your users.
Continue Reading

FBI Finds Phishing Sites Abusing Search Results and Ads to Steal Banking Credentials

The US Federal Bureau of Investigation has sent out a private industry notification (PIN) warning that cybercriminals are using search engine ads and search results to spread phishing ...
Continue Reading

A  New Smishing Trojan is Out and About

Researchers at Pradeo have observed a new Android malware campaign that uses text messages asking victims to pay a small fee for a delivery. The messages contain a link that will install ...
Continue Reading

New QuickBooks-Themed Phishing Attack Seeks to Infect Victims with Dridex Malware

Purporting to be invoices and payment reminders, this new campaign targets users of the popular accounting software to install the banking trojan on its victims endpoints.
Continue Reading

Email-Based Threats Increase 64% as Attacks Grow in Sophistication and Volume

New data from Mimecast shows how email-based threats are not only the greatest perceived concern, but are proving to be the reason for increased experienced attacks.
Continue Reading

Phishing Scammers Remove ‘External Sender’ Email Warnings Impersonating Internal Users

With little more than some CSS and HTML coding, a security researcher demonstrates how easy it is to eliminate security warnings placed on email messages by security products.
Continue Reading

Your Organization Needs to Take Security Awareness Training More Seriously

Your organization needs to take security awareness training (SAT) more seriously. I mean truly serious, really serious, and not relegated to some quasi-, semi-serious status that the vast ...
Continue Reading

Wine-Themed Phishing Attacks Have Turned Sour During the Pandemic

Scammers took advantage of people’s desire to order wine online during the pandemic, Decanter reports. Researchers at Recorded Future disclosed in a recent report that wine-related ...
Continue Reading

Huge Business Email Compromise Campaign Targets More Than 120 Organizations

According to Bleeping Computer, Microsoft reported that a large business email compromise (BEC) campaign has targeted dozens of organizations. The industries targeted varied from real ...
Continue Reading

Fake Court Order Used to Take Over Domains

Motherboard reports that a scammer used a phony court order to trick a domain registrar into giving them control over a domain that posted links to dark web drug markets. The scammer then ...
Continue Reading

[ALERT] Time to Truly Reckon with the Dark Reality of Ransomware’s Critical Costs

By now, I’m sure you’ve already been inundated with all the news about the US’s largest gasoline pipeline being shut down and restarted because of a ransomware attack. As reported by the ...
Continue Reading

[On-Demand Webinar] A Master Class on IT Security: Roger Grimes Teaches You Phishing Mitigation

Phishing attacks have come a long way from the spray-and-pray emails of just a few decades ago. Now they’re more targeted, more cunning and more dangerous. And this enormous security gap ...
Continue Reading

Student’s Attempt to Pirate Software Leads to Ryuk Ransomware Attack

Bleeping Computer recently reported that a student attempted to pirate expensive data visualization software, which resulted in a Ryuk ransomware attack.
Continue Reading

KnowBe4 Fresh Content Updates from April: Including New AI-Driven Phishing Feature

Here are important fresh content updates and new features to share with you that happened in the month of April.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews