Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

One Pricy Hospital Bill: Ransomware Attack Costs Hospital $1 Million, Requiring Notice to Municipal Bond Holders

Most organizations think about the impact of a ransomware attack being limited to recovery, legal, PR, and perhaps paying the ransom. In this case bond holders could take a hit.

Ransomware Attacks Increase 41 Percent as Cybercriminals Double-Down on Taking Your Money

New data from New Zealand security firm Emsisoft shows that more organizations are being successfully being attacked and held for ransom, putting operations at risk.

Education is Necessary to Stay Ahead of Threats

Most people don’t realize how vulnerable they are to social engineering until they experience it, according to Anna Collard, the founder of KnowBe4’s South African security awareness ...

Phishing Attacks Use Victim Interest in Oscar-Nominated Movies to Steal Credit Cards, Install Malware

People wanting to watch high-profile movies are the latest target in scams that trick users into offering up credit card details for a chance to download films not yet available for ...

[Heads-up] New Ransomware Strain Hijacks A Vulnerable Windows Driver To Turn Off Your Antivirus And Infect The Network

Security company Sophos warns of a new ransomware strain that uses a vulnerable driver in an attempt to break into a Windows system and then disable the running security software.

Trenton School Treasurer Spots a 'Phishing Expedition'

Someone went on a ‘phishing expedition’ trying to trick a Trenton School Board of Education member into transferring thousands of dollars into their account, but a Trenton School ...

Another SMS Scam

A new PayPal SMS phishing campaign is making the rounds, according to Paul Ducklin at Naked Security. The text messages in this campaign purport to come from PayPal and inform recipients ...

SEC Releases Results of Cybersecurity and Resiliency Practices Examinations

The SEC’s Office of Compliance Inspections and Examinations (OCIE) published a new report on the findings from examining the methods used by market participant organizations.

Ransomware Attack Leaves Logistics Company with Disabled Systems, Manual Processes, and Customer Delays

The devastation after a ransomware attack on global logistics company Toll Group demonstrates the impact a simple ransomware attack can have on operations.

Email Test Finds More Than 50% of Kingston School District Employees Vulnerable to Phishing

More than half of the people who have Kingston school district email accounts opened a potentially damaging phishing email sent to them by a firm that's helping the district gauge ...

January Content Update: Including the new 2020 KnowBe4 Social Engineering Red Flags Training Module

Here are a few important updates to share with you from the month of January.

Anatomy of a Rental Phishing Scam

There was an unsuccessful phishing attempt that security professional Jeffrey Ladish almost fell for. Jeffrey was house searching and was looking on Craigslist and Zillow for rental ...

Six Security Questions You Should Keep in Mind for Third Parties

Organizations are beginning to understand the consequences of a data breach or a phishing attack and the negative impact they can really have. But what are the security risks for third ...

Ransomware Takes its Toll

Ransomware is defined as vicious malware that locks users out of their devices or blocks access to files until a sum of money or ransom is paid. Ransomware attacks cause downtime, data ...

Charities Need to Watch Out for Scammers

The UK’s National Council for Voluntary Organisations (NCVO) has warned charities to be wary of scammers, Charity Digital News reports. The NCVO’s Road Ahead 2020 report outlines trends ...

Look-alike Domain Spoofing Scam Takes Charity for $1 Million

In yet another case of business email compromise, a charity is fooled through a combination of diligence, sophistication, and social engineering.

EKANS Ransomware Attacks Focus on Disrupting Businesses Reliant Upon Industrial Control Systems

Leveraging knowledge of industrial control systems, this relatively new ransomware variant is looking to be as disruptive as possible to operations by killing processes and encrypting ...

[On-Demand] Learn How to Forensically Examine Phishing Emails to Better  Protect Your Organization

Cyber crime has become an arms race where the bad guys constantly evolve their attacks while you, the vigilant defender, must diligently expand your know how to prevent intrusions into ...

Not the Antiques Roadshow

Scammers conned a Dutch museum into sending them £2.4 million (about $3.1 million) by posing as a real London-based art dealer who planned to sell the museum a John Constable painting, ...

New DoppelPaymer Ransomware Makes Money Off of You Whether You Pay the Ransom or Not

Taking a page from the Maze ransomware playbook, the creators of DoppelPaymer don’t just encrypt your data; they have found channels to sell if it you don’t pay up.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.