Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

UK Royal Mail Smishing Crew Nabbed By City Of London Police

According to a report by ZDNet, there were arrests made due to suspicions of sending 'smishing' texts. Smishing is a form of phishing that sends SMS messages in order to steal personal ...
Continue Reading

[On-Demand Webinar] Setting the Trap: Crafty Ways the Bad Guys Trick Your Users to Own Your Network Featuring Kevin Mitnick

The bad guys are out there, watching and waiting for an opportunity to strike. They have carefully researched your organization in order to set the perfect trap. And the perfect ...
Continue Reading

More Targeted Phishing Attacks Are Coming!

I have been in the cybersecurity business for 34 years. I am not an innately brilliant, but one of the things I seem to do well is to spot trends as they happen early in their cycle. It ...
Continue Reading

Low-Grade Ways of Bypassing Email Scanners

Cybercriminals are replacing common words in phishing scams with synonyms in order to bypass security filters, according to researchers at Avanan. For example, one phishing lure contained ...
Continue Reading

Ransomware-as-a-Service is Organizing, Becoming More Devastating and Costly

Take a look at the complex relationships that exist today between the ransomware gangs and the various services they utilize, and you quickly realize this is a very organized and ...
Continue Reading

The FBI’s Internet Crime Complaint Center Marks Its 6 Millionth Complaint as Pace Accelerates

The rate at which cyberattacks are increasing are being noticed by both their victims and the FBI, who are seeing more people affected by online crimes and scams.
Continue Reading

Credential Stuffing the Financial Services Sector

Credential stuffing in the financial services industry has risen significantly over the past year, according to Akamai’s latest State of the Internet / Security report. Credential ...
Continue Reading

When Cryptocurrency Investments Really Are Too Good To Be True

The US Federal Trade Commission (FTC) reports that victims have lost more than $80 million in cryptocurrency scams since October of last year, with about $2 million of that total going to ...
Continue Reading

Transparent Tribe Uses Spoofed Domains in Social Engineering Attacks

Researchers at Cisco Talos warn that the threat actor known as “Transparent Tribe” (also known as APT36 and Mythic Leopard) is using spoofed websites and malicious documents to deliver ...
Continue Reading

[NEW PhishER Feature] Flip the Script on Phishing Emails with PhishFlip

We are excited to announce the availability of PhishFlip™ as part of the PhishER product to all PhishER customers.
Continue Reading

Ransoms Increase 43% as More Ransomware Attacks Include the Threat to Leak Exfiltrated Data

With average payments rising to over $220K, organizations scramble to stop ransomware attacks as gangs begin taking more advantage of software vulnerabilities as their attack vector.
Continue Reading

Healthcare Organizations Should Expect Cyber Insurance Premiums to Increase 25 to 50% This Year

In light of recent upticks in payouts – particularly around ransomware – cyber insurers are better understanding the risk and are adjusting rates accordingly.
Continue Reading

Paying the Ransom Is Not Just About Decryption

I just read that a well-known pipeline company paid $5M to the ransomware hacker group. And despite that, they are still having to use their backups because the decryption process is too ...
Continue Reading

Kicking You While You’re Down: Ransomware Attacks Begin to Adopt a “Triple Extortion” Model

New tactics spotted by security researchers at CheckPoint indicate a growing pattern by ransomware gangs to use additional extortion actions to increase revenues and ensure payment.
Continue Reading

Ransomware Attack Demands Cause Cyber Insurance Claim Amounts to Skyrocket

The perfect storm of large enterprises, cyber insurance policies, successful ransomware attacks, and ransom demands in the tens of millions now consistently result in seven-figure claim ...
Continue Reading

New Verizon DBIR: Credentials Stolen in 85% of Social Engineering Breaches

Verizon’s latest data breach report puts a spotlight on one of the largest and most unpredictable risk factors in your cybersecurity strategy – your users.
Continue Reading

FBI Finds Phishing Sites Abusing Search Results and Ads to Steal Banking Credentials

The US Federal Bureau of Investigation has sent out a private industry notification (PIN) warning that cybercriminals are using search engine ads and search results to spread phishing ...
Continue Reading

A  New Smishing Trojan is Out and About

Researchers at Pradeo have observed a new Android malware campaign that uses text messages asking victims to pay a small fee for a delivery. The messages contain a link that will install ...
Continue Reading

New QuickBooks-Themed Phishing Attack Seeks to Infect Victims with Dridex Malware

Purporting to be invoices and payment reminders, this new campaign targets users of the popular accounting software to install the banking trojan on its victims endpoints.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews