Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Racoon: Infostealer Malware Collects Credentials, Financial and Personal Information

Access to a compromised endpoint may no longer be enough. So, enterprising malware authors offer up infostealers to help exfiltrate valuable data from an infected machine.

None But the Lonely Heart Would Fall for an Emoji

Researchers at Malwarebytes and X-Force IRIS have come across an ongoing phishing campaign that’s using romance-themed emails to distribute the Nemty ransomware, BleepingComputer reports. ...

Experts: Expect Summer Olympics-Themed Cyberattacks in the Coming Months

The business of the games will provide cybercriminals with countless options to scam participants, sponsors, and spectators using contextual details and social engineering.

Ransomware Attack On Wool Industry Halted Sales Across Australia Last Week

It is yet to be seen how a cyber attack which shut down wool sales last week will affect growers in Tasmania. Last Tuesday Talman Software, which is used by the majority of wool industry ...

Bogus Singapore Police Site Serves as a Watering Hole

The Singapore Police Force (SPF) released an advisory warning about a phishing site that’s spoofing the Force’s website, Channel News Asia reports. The bogus website informs the user that ...

Nigerian Man Arrested 3 Years After $850,000 Stolen in Email Scam

The Boulder County Sheriff’s Office says a Nigerian man has been arrested more than three years after $850,000 was stolen in construction bond money from the Boulder Valley School ...

Afraid You're Communicating Too Frequently? Rethink That.

This blog was co-written by Joanna Huismann and Aimee Laycock. Communication is not always easy (let’s be honest, we have all wanted to scream with frustration at our partner or a family ...

Guess Who Else is Now Doing Security Training Surveys?

By Eric Howes, KnowBe4 Principal Lab Researcher. A few months ago, KnowBe4 began offering customers two new kinds of scientifically-based assessments to help IT departments get a better ...

Amazon Prime Phishbait: Lessons Learned

An Amazon phishing campaign is accidentally sending out links that lead straight to the attacker’s remote access console, according to Paul Ducklin at Naked Security. Ducklin explains ...

[BREAKING NEWS] 'Shark' Gets Hooked for $380K in Email Phishing Scam

"Shark Tank" star Barbara Corcoran is missing nearly $400,000 Wednesday morning after her office was victimized by email scammers who used a tiny typo to gain the upper hand.

Verizon: More Than Half of Users Click on Multiple Phishing Links. Social Engineering, Innovation are Responsible

The latest data from Verizon’s 2020 Mobile Security Index report shows that both consumer and business users make it all too easy for cyberattackers to fool them into becoming a victim.

An Influence or Wire Fraud?

A 22-year-old Instagram and YouTube influencer named Kayla Massa has been arrested after allegedly convincing her followers to assist her in a fraud scheme, Quartz reports. Prosecutors ...

39 Percent of Organizations Were Victims of a Mobile Attack Despite Improved Security

Brand new data from Verizon shows businesses sacrificed when it comes to mobile security; a decision that caused compromises with impacts well-beyond just a simple breach.

KnowBe4 Named a Leader in The Forrester Wave for Security Awareness and Training Solutions

We have some great news to share with our customers and global security professionals alike. KnowBe4 has been named a Leader in The Forrester Wave™ : Security Awareness and Training ...

Why Minimizing Human Error is the Only Viable Defense Against Spear Phishing

Phishing attacks have become one of the business world's top cybersecurity concerns. These social engineering attacks have been rising over the years, with the most recent report from the ...

Spamming Tools are a Commodity in the Criminal Underworld

Cheap and easy-to-use phishing kits and other social engineering tools are readily available for purchase on the black market, according to researchers at Digital Shadows. Criminals ...

Spear Phishing Tops the Canadian Anti-Fraud Center’s List of Attacks

The latest data out of the Canadian Government points out how targeted spear phishing fraud attacks via email are the most lucrative method of attack for cybercriminals in 2019.

WSJ: "Losing $450,000 in Three Days: Hackers Trick Victims Into Big Wire Transfers"

Rachel Louise Ensign wrote a great story for the WSJ about CEO Fraud, also known by the FBI as Business Email Compromise. I'm quoting an extract and I strongly recommend sending a link to ...

A Single BEC Gang is Launching Thousands of Attacks Per Year

A unique cybercriminal group launched business email compromise (BEC) attacks against more than 2,100 companies in the US between April and August 2019, according to researchers at Agari. ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.