Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Business Email Compromise-as-a-Service Emerges as Attempted Fraud Soars to as High as $6 Million

BEC scammers set their sights on payoffs in the millions of dollars, and are following the path of their ransomware counterparts by evolving services while organizations struggle to keep ...
Continue Reading

The TodayZoo Phishing Kit Has All the Obfuscation and Impersonation Needed to Fool Your Users

New details from Microsoft on this pieced-together phishing kit reveal some unique tactics designed to avoid detection by security solutions and users alike while stealing credentials.
Continue Reading

Median Ransomware Payment Jumps 50% as Mid-Market Becomes More Targeted

Changes in attack tactics in the last quarter alone demonstrate a shift in focus for ransomware gangs, as the number of companies attacked with 100 to 1,000 employees grows.
Continue Reading

New 'Frankenphishing' Tactic Combines Other Phishing Kits Into One

RiskIQ has observed another phishing kit that’s been pieced together from portions of other phishing kits.
Continue Reading

[HEADS UP] Popular Stock Trading Platform Becomes Next Victim of Data Breach

Bleeping Computer recently reported a data breach from popular stock trading platform Robinhood. This breach has impacted over 7 million of their customers.
Continue Reading

New Browser Cookie “Smash and Grab” Attack Targets YouTube Creators

New attack details from Google’s Threat Analysis Group show how cybercriminals are innovating ways to use an initial attack to aid in additional crypto scams.
Continue Reading

Enabling and Securing Remote Workers are Top Concerns as 80% of Organizations Experience Cyberattacks as Often as Once per Hour

Organizations appear to be overconfident in their ability to protect themselves, despite glaring gaps in security, according to new data from cyber protection vendor, Acronis.
Continue Reading

Preparing for Black Friday Scams

Researchers at Tessian caution that people should be wary of scams as Black Friday approaches. The researchers found that thirty percent of people in the US reported receiving a phishing ...
Continue Reading

How Not To Get Phished: It Is the Message Not the Medium

Back in the early 1990s, when I was first getting into the IT field as a full-time network administrator, I was tasked with writing up our corporation’s new email policy. Email was just ...
Continue Reading

Your KnowBe4 Fresh Content Updates from October 2021

Check out the 22 new pieces of training content added in October, alongside the always fresh content update highlights.
Continue Reading

FBI Warns that Financial Events are Occasions for Extortion

The US Federal Bureau of Investigation (FBI) has warned that ransomware operators are targeting companies that are going through financial events. The timing is designed to elicit and ...
Continue Reading

Not that You Would, but Looking for a Sugar Daddy's a Bad Idea

Scammers are using social media to target young women with offers to be their “sugar daddy,” according to Laura Josepha Zimmermann at Avast. Zimmermann received a message on Instagram ...
Continue Reading

[On-Demand Webinar] Hacking Your Organization: 7 Steps Cybercriminals Use to Take Total Control of Your Network

The scary fact is that the majority of data breaches are caused by human error. With so many technical controls in place hackers are still getting through to your end users. How are they ...
Continue Reading

Misconceptions and Assumptions about Cybersecurity

Misconceptions about cybersecurity can lead to employees falling for preventable attacks, according to Jayant Chakravarti at Toolbox. One misconception is that Apple devices are ...
Continue Reading

Multi-Stage Vishing Attacks are Coming to an Inbox Near You

New attacks initially coming in via email are directing victims to make phone calls to attacker-controlled call centers in order to provide banking and credit card details.
Continue Reading

Eight Romance Phishing Scammers with Ties to Nigerian Organized Crime Arrested After Stealing Nearly $7 Million

This latest arrest by the South African Police Service (SAPS) demonstrates how romance scams that have been around for decades remain alive and well… and profitable.
Continue Reading

Over Half of all Impersonation Attacks Target Non-Executive Employees

A new report shows how cybercriminals focus on users that are less vigilant and more prone to falling for social engineering and impersonation tactics designed to gain access to finances.
Continue Reading

KnowBe4's Q3 2021 Top-Clicked Phishing Email Report Includes New Global Data [INFOGRAPHIC]

KnowBe4's latest quarterly report on top-clicked phishing email subjects is here. We are now looking at the top categories globally, general subjects (in the United States and Europe, ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews