Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Amazon Prime Phishbait: Lessons Learned

An Amazon phishing campaign is accidentally sending out links that lead straight to the attacker’s remote access console, according to Paul Ducklin at Naked Security. Ducklin explains ...
Continue Reading

[BREAKING NEWS] 'Shark' Gets Hooked for $380K in Email Phishing Scam

"Shark Tank" star Barbara Corcoran is missing nearly $400,000 Wednesday morning after her office was victimized by email scammers who used a tiny typo to gain the upper hand.
Continue Reading

Verizon: More Than Half of Users Click on Multiple Phishing Links. Social Engineering, Innovation are Responsible

The latest data from Verizon’s 2020 Mobile Security Index report shows that both consumer and business users make it all too easy for cyberattackers to fool them into becoming a victim.
Continue Reading

An Influence or Wire Fraud?

A 22-year-old Instagram and YouTube influencer named Kayla Massa has been arrested after allegedly convincing her followers to assist her in a fraud scheme, Quartz reports. Prosecutors ...
Continue Reading

39 Percent of Organizations Were Victims of a Mobile Attack Despite Improved Security

Brand new data from Verizon shows businesses sacrificed when it comes to mobile security; a decision that caused compromises with impacts well-beyond just a simple breach.
Continue Reading

KnowBe4 Named a Leader in The Forrester Wave for Security Awareness and Training Solutions

We have some great news to share with our customers and global security professionals alike. KnowBe4 has been named a Leader in The Forrester Wave™ : Security Awareness and Training ...
Continue Reading

Why Minimizing Human Error is the Only Viable Defense Against Spear Phishing

Phishing attacks have become one of the business world's top cybersecurity concerns. These social engineering attacks have been rising over the years, with the most recent report from the ...
Continue Reading

Spamming Tools are a Commodity in the Criminal Underworld

Cheap and easy-to-use phishing kits and other social engineering tools are readily available for purchase on the black market, according to researchers at Digital Shadows. Criminals ...
Continue Reading

Spear Phishing Tops the Canadian Anti-Fraud Center’s List of Attacks

The latest data out of the Canadian Government points out how targeted spear phishing fraud attacks via email are the most lucrative method of attack for cybercriminals in 2019.
Continue Reading

WSJ: "Losing $450,000 in Three Days: Hackers Trick Victims Into Big Wire Transfers"

Rachel Louise Ensign wrote a great story for the WSJ about CEO Fraud, also known by the FBI as Business Email Compromise. I'm quoting an extract and I strongly recommend sending a link to ...
Continue Reading

A Single BEC Gang is Launching Thousands of Attacks Per Year

A unique cybercriminal group launched business email compromise (BEC) attacks against more than 2,100 companies in the US between April and August 2019, according to researchers at Agari. ...
Continue Reading

[EYE-OPENER] Dutch Minister Of Justice And Security: "Fighting Phishing Starts With Awareness"

"The fight against phishing starts with raising the awareness of internet users, stated Justice and Security Minister Grapperhaus. He responded to figures from Dutch banks showing that ...
Continue Reading

[Heads-up] Ransomware Criminals Hack An Accounting Company And Cause A Data Breach For Their Customers

Last December, a ransomware infection of Albany, New York-based accounting firm BST & Co. CPAs LLC exposed the confidential data of their customers, causing a data breach for one of ...
Continue Reading

Massive 13,467% Growth in WhatsApp Phishing URLs Seen as Top Impersonated Domains Are on the Decline

The latest data from email security vendor Vade Secure shows drastic shifts in domain impersonation trends cybercriminals are using to carry out phishing attacks.
Continue Reading

Ransomware Attack Leaves 43,000 Employees Without Email

The recent attack on facilities management company ISS has created a significant disruption in their operations, communication, and services worldwide.
Continue Reading

The Real-life Email You Never Want To Get From Your CEO Because The Feds Called...

From The Desk Of Mark *********, CEO, ********* Corporation
Continue Reading

Here Is A Real-life Bank Phone Scam Blocked By A Security Awareness Trained Employee

Brad Mathis at our partner Keller Schroeder sent me the following real-life story from Matt, a KnowBe4 Security Awareness Training client...
Continue Reading

Emotet Malware Shows Up in SMiShing Attacks Disguised as Bank Notifications

A newly discovered attack looks to try to make a victim of mobile device holders using a two-pronged attack that uses Emotet and, perhaps, Trickbot.
Continue Reading

Most Organizations Stick to Legacy Password Security Practices Despite Experiencing Cyberattacks

In a surprising twist, new data sheds light on the lack of proper security around passwords and authentication by IT at a time when cyberattacks are all but an absolute given.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews