Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Another SMS Scam

A new PayPal SMS phishing campaign is making the rounds, according to Paul Ducklin at Naked Security. The text messages in this campaign purport to come from PayPal and inform recipients ...

SEC Releases Results of Cybersecurity and Resiliency Practices Examinations

The SEC’s Office of Compliance Inspections and Examinations (OCIE) published a new report on the findings from examining the methods used by market participant organizations.

Ransomware Attack Leaves Logistics Company with Disabled Systems, Manual Processes, and Customer Delays

The devastation after a ransomware attack on global logistics company Toll Group demonstrates the impact a simple ransomware attack can have on operations.

Email Test Finds More Than 50% of Kingston School District Employees Vulnerable to Phishing

More than half of the people who have Kingston school district email accounts opened a potentially damaging phishing email sent to them by a firm that's helping the district gauge ...

January Content Update: Including the new 2020 KnowBe4 Social Engineering Red Flags Training Module

Here are a few important updates to share with you from the month of January.

Anatomy of a Rental Phishing Scam

There was an unsuccessful phishing attempt that security professional Jeffrey Ladish almost fell for. Jeffrey was house searching and was looking on Craigslist and Zillow for rental ...

Six Security Questions You Should Keep in Mind for Third Parties

Organizations are beginning to understand the consequences of a data breach or a phishing attack and the negative impact they can really have. But what are the security risks for third ...

Ransomware Takes its Toll

Ransomware is defined as vicious malware that locks users out of their devices or blocks access to files until a sum of money or ransom is paid. Ransomware attacks cause downtime, data ...

Charities Need to Watch Out for Scammers

The UK’s National Council for Voluntary Organisations (NCVO) has warned charities to be wary of scammers, Charity Digital News reports. The NCVO’s Road Ahead 2020 report outlines trends ...

Look-alike Domain Spoofing Scam Takes Charity for $1 Million

In yet another case of business email compromise, a charity is fooled through a combination of diligence, sophistication, and social engineering.

EKANS Ransomware Attacks Focus on Disrupting Businesses Reliant Upon Industrial Control Systems

Leveraging knowledge of industrial control systems, this relatively new ransomware variant is looking to be as disruptive as possible to operations by killing processes and encrypting ...

[On-Demand] Learn How to Forensically Examine Phishing Emails to Better  Protect Your Organization

Cyber crime has become an arms race where the bad guys constantly evolve their attacks while you, the vigilant defender, must diligently expand your know how to prevent intrusions into ...

Not the Antiques Roadshow

Scammers conned a Dutch museum into sending them £2.4 million (about $3.1 million) by posing as a real London-based art dealer who planned to sell the museum a John Constable painting, ...

New DoppelPaymer Ransomware Makes Money Off of You Whether You Pay the Ransom or Not

Taking a page from the Maze ransomware playbook, the creators of DoppelPaymer don’t just encrypt your data; they have found channels to sell if it you don’t pay up.

Law Firms Are the Latest Victims of Maze’s Ransomware and Extortion Attacks

With five law firms hit within just the last week, the Maze ransomware is making itself known and should be a warning to any and all legal firms that preventing an attack is paramount.

Product Update: The New KnowBe4 ModStore is Here

Good news!! The new ModStore is now live in the console. KnowBe4 is excited to announce the rollout of a new and improved interface for the KnowBe4 ModStore in your KnowBe4 console. The ...

Unusual New Botnet-driven Phishing Attack With Tricky Downloaders

A large phishing campaign is distributing malicious Excel documents and utilizing irritating pop-ups to trick users into enabling macros, researchers at Lastline have found. The campaign ...

Ashley Madison Data Breach Comes Back to Haunt Customers with New Sextortion Scam

Just when you thought everyone forgot about participation on the ill-famed cheaters website, a new phishing scam looks to use the breached data as the basis for extorting the site’s users.

It Was Only a Matter of Time: Sodinokibi Hold Dark Web Hacking Competition

Feeling like a page taken out of the SpaceX competitions, the latest shock comes from news of an underworld hacking competition intent on sharing cutting edge malicious code.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.