Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

The Cost of Ransoms Demanded and Paid Double in 2020!

According to new data from UK cyber insurer Beazley shows ransomware claims have increased materially and calls for organizations to employ a layered cyber defense.

Over Half of Users Admit to Reusing the Same Password on Multiple Accounts

New data reported earlier this year by Security Magazine shared a report from Secure OAuth that 53% of users reuse the same passwords on multiple accounts. Among those 44% admit to using ...

A Christmas poem to remind everyone to stay safe for the Holidays!

KnowBe4 customer , Eric McManis from Armellini Logistics Corporation sent us a Christmas poem that he sent out to his organization to remind everyone to stay safe for the Holidays! I hope ...

[NEW PhishER Feature] Use Security Roles to Create a Multi-Tiered Incident Response System in PhishER

You asked, we listened! We're excited to introduce the new Security Roles feature within your PhishER platform! You now have the ability to create different user roles for your security ...

[INFOGRAPHIC] Holiday Phishing Red Flags to Watch Out For

Phishing attacks never slow down during the holiday season. Experian reported that 1 in 4 victims fell victim to fraud during the holidays.

Learning More on Social Engineering Tactics are the Key to Preventing Phishing Expeditions

Understanding social engineering attacks is the key to thwarting them, according to Juan Badell and Russell Petrich, content designers for Sophos’s phishing simulation service. Badell and ...

Solarwinds MFA Bypass Attack Pushes Limits

Excellent, long-time, tech reporter Dan Goodin reported in Ars Technica that the recent Solarwinds’ supply chain attack involved hackers bypassing a popular multi-factor authentication ...

University-themed Phishbait Angles for Students

Researchers at Zix have observed phishing emails sent from legitimate but compromised university email accounts, impersonating the university’s IT department. The emails notified users ...

Facebook Describes APT32 Social Engineering Campaign

Facebook’s security team has taken action against a phishing operation run by APT32 (also known as OceanLotus), a threat actor associated with the Vietnamese government. Facebook says the ...

New Security Doc For Your End-users: "The Iceberg"

Did you see our new "tip of the iceberg" security doc? Send this Public Service Announcement to your end-users. It is a great piece that was created based on the focus group feedback - ...

[HEADS UP] New York DMV Warns of Phishing Attack

According to the Press Republican, the New York State Department of Motor Vehicles warned New Yorkers last Friday of ongoing SMS phishing (aka smishing) attack.

85% Of Employees are More Likely to Leak Files Now Than Pre-Coronavirus

According to research released Thursday by Code42, 85% of employees are more likely to leak files today than before the COVID-19 pandemic.

Zoom Phishing is Still Rampant

Cybercriminals are still using Zoom and other conferencing platforms as phishbait, according to Zlati Meyer at Fast Company. This phishing theme isn’t likely to let up any time soon, so ...

Data Breaches Are Expected to Decline While Ransomware and BEC Gain Steam

A new report from the Identity Theft Research Center discusses which cybersecurity attacks will be most impactful next year as part of the ITRC’s 2021 predictions.

5 Tips For Consolidating Remote Work Tech Debt

In 2020, nearly every organisation embraced remote working to some extent or another. For some, the transition was smooth and easy, as they already had a mobile workforce and were largely ...

All 200 Million Office 365 Users at Risk by a New Global Spear Phishing Attack Spoofing Microsoft.com

A new spear phishing campaign appearing to come from a microsoft.com email address is targeting organizations in critical industries that use Office 365 for email to steal credentials.

Shame! Shame! I Got Phished

I can’t be phished. At least that’s what I used to believe.

CISA Emergency Directive: Pull Plug On SOLARWINDS ORION NOW.

It's all over the press. A wide swath of U.S. Government orgs were hacked by the Russians. They accessed those networks by slipping malware into a SolarWinds software update, according to ...

Just How Far Can Three Cybercriminals Reach? How about 150 Countries!

As three members of the cybercriminal group TMT were recently arrested, details emerge around the breadth and depth of their attacks from a year-long Interpol investigation.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.