Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Victims: After a Data Breach, Changing Passwords and Good Password Hygiene Remain Unimportant

New shocking data shows how unconcerned victim users are after being notified of a data breach involving their credentials, personal information, and even social media accounts.

New TSA PreCheck Scam Seeks to Collect Your Personal and Credit Card Details

Doing one of the best jobs impersonating a website ever seen, this new scam attempts to take those renewing or initially signing up through a believable process that most would fall for.

Half of All Organizations Have Had Employees Approached to Aid in Ransomware Attacks

Partially due to the shift to working remotely, cybercriminals are finding some resemblance of success in getting internal assistance, begging the question of what to do about it.

SideCopy: How an Intelligence Service Uses Phishbait

Researchers at Malwarebytes offer more details on a spear phishing campaign run by a Pakistani threat actor that’s come to be known as “SideCopy.” The campaign was first reported by ...

New Phishing Campaign has Fake DHL Shipping

Researchers at Avanan have spotted a new phishing campaign that’s impersonating DHL with phony shipping notifications. The emails inform the recipients that they need to update their ...

Your KnowBe4 Fresh Content Updates from November 2021

Check out the 28 new pieces of training content added in November, alongside the always fresh content update highlights.

[Heads Up] First Omicron Phishing Attack Spotted In The UK

Bleepingcomputer had the scoop. Phishing actors have quickly started to exploit the emergence of the Omicron COVID-19 variant and now use it as a lure in their malicious email campaigns. ...

Morgan Stanley Warns Against “Brushing Scam”

Morgan Stanley has outlined several common scams everyone should be on the lookout for during the holiday season. The first involves phony delivery notifications. These scams are common ...

Ingenious New Attack Technique Uses Windows Store to Install Malware

Just when you thought threat actors couldn’t find another way to launch a dropper, a new method has surfaced that takes advantage of native functionality found in Windows 10.

91% of All Baiting Attacks Use Gmail to Collect Intel on Potential Victims

This rudimentary form of phishing contains no malicious links or attachments but serves a very important purpose for cybercriminals and scammers looking to better target victims.

[On-Demand Webinar] When Cybercriminals Hide in Plain Sight: Hacking Platforms You Know and Trust

Today’s hackers are concealing their attacks in places you wouldn’t expect… utilizing tools your users know and trust to deliver their malicious payloads. From hijacked single sign-on ...

Holiday Shopping and Phishing-as-a-Service

Researchers at Egress observed a massive increase in phishing kits in the run-up to Black Friday, particularly those impersonating Amazon.

Bitcoin Scam Videos on Instagram are Part of an Elaborate Account Takeover Scam

This elaborate scam uses social engineering to trick victims into sending the hacker Bitcoin while holding Instagram accounts hostage.

Phishing Attacks Smash All Records in Q3 2021 With the Highest Monthly Number of Attacks Ever

New data shows the business of phishing is moving “up and to the right” in nearly every way measurable, indicating a serious problem as threat actors continue to see growing success.

Mobile Phishing Attacks Surge 161% in the Energy Industry

The need for increased mobile security in the Energy sector has become evident with new data highlighting why these phishing attacks are occurring and effective ways to stop them.

Data Breach Costs Increase by $1 Million When Remote Workers Are Involved

You already knew remote workers increase the risk of cyberattack. New data spells out exactly what the impact of a remote workforce is on data breaches and the cost to remediate.

Spear Phishing Campaign Targets North Korean Defectors

A state-sponsored threat actor is sending spear phishing emails to North Korean defectors and also to journalists who cover matters related to North Korea, according to researchers at ...

Phishing Reported in IKEA’s Internal Email System

IKEA has been working to contain a continuing phishing campaign that’s afflicting the furniture and houseware chain’s internal email system. BleepingComputer describes it as a ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.