Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Cruel Hoax Scams Elderly Woman

An 89-year-old woman in Delaware lost $9,500 to scammers who told her that her grandson had been arrested for causing a car accident, Delaware Online reports. The scammers called the ...

Ransomware Predicted to Cost $20 Billion in Damages Globally by 2021

As the state of ransomware attacks shift from simple data encryption scams to attacks intent on bringing an organization’s network to its’ knees, the cost of remediation is expected to ...

Exploiting the Coronavirus: The Spammers, the Scammers, and the Bad Guys

By Eric Howes, KnowBe4 Principal Lab Researcher. If you've been paying attention to the news over the past week or so, you've undoubtedly noticed that the majority of the stories on your ...

Use Advocates to Spread Your Security Awareness Training Program

I’ve always been a big fan of train-the-trainer programs. Even if you are a great computer security consultant and trainer, there is a limit to what you, one person or one team, can do. ...

February Content Update: Including Season 2 of Netflix-Style Series 'The Inside Man'

Here are a few important updates to share with you from the month of February.

New Norton LifeLock Phishing Scam Installs Remote Access Trojan

In yet another case of brand impersonation, this new phishing scam seeks out the millions of LifeLock customers and follows a seasoned infection path, with the goal being persistence and ...

Yet Another Utility Company Falls Victim to Ransomware Attack

The latest ransomware attack on yet another utility company echos the warnings from last year’s report on utilities’ readiness for a cyberattack.

Stealthy 'Netwalker' Ransomware Using Windows Explorer And 'Art of Deception' To Infect Enterprise Networks

Researchers at Quick Heal Security Labs have discovered a new strain of the “Mailto” ransomware nicknamed “Netwalker" that uses the art of deception to evade detection. The new strain ...

Did you know that KnowBe4 provides Managed Phishing Services?

You have determined the need for a mature, effective security awareness training program to make sure your employees do not fall for phishing emails or social engineering attacks. As part ...

UK Telegraph: "Huge ransomware attack laid bare French lingerie firm"... And Bankrupted It

Leave it to the wordsmiths of the British Press to come up with a catchy title like this... However, the topic is dead serious.

Anti-Virus, Identity Protection Phishbait

A phishing campaign is using fake NortonLifelock documents to trick victims into installing a remote access tool, according to researchers at Palo Alto Networks’ Unit 42. The documents ...

KnowBe4 and Agari Announce New Partnership to Transform Phishing Protection

As market leaders, KnowBe4 and Agari have joined forces to help stop identity-based email attacks. Together, we have created a best-in-class approach to defend against phishing attacks at ...

New Sophisticated Credential-Stealing Malware, Forelord, Attacks the Middle East

This latest APT highlights the levels of sophistication attackers will go to just to establish persistence, infect the endpoint, and steal credentials from the victim organization.

Courts Limit Payout on Insurance Claim to Just One Section of the Liability Policy

The latest ruling shows how the courts are becoming well-versed in the ways of cyberattacks, and are holding both insurers and policyholders to the letter of the contract.

Social Security Administration Warns of Phone Scams On March 5th "Slam The Scam Day"

The Social Security Administration in Association with the Federal Trade Commission's (FTC) National Consumer Protection Week, want to remind everyone that scammers are now targeting ...

[On-Demand] Never Assume Breach: Build a Data-Driven Defense Strategy to Secure Your Organization's Most Valuable Assets

Even the world’s most successful organizations have significant weaknesses in their IT security defenses, which today’s determined hackers can exploit at will. There’s even a term for it: ...

Cut-and-Paste Phishbait

Naked Security describes a phishing campaign that’s convincingly spoofing emails from the online payment company Stripe. The email informs the recipient that an unknown device has logged ...

Data Breach After Effects: Consequences and Learning Lessons

If you think your organization is safe from a data breach, think again. Data breaches could be deadly for any organization big or small.

New Sophisticated “Exaggerated Lion” BEC Check Scam Uses Mules to Cash Out

You may wonder exactly how BEC scammers see a payday. New insight from security vendor Agari documents how a secondary check scam dupes unsuspecting victims to help.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.