Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Kiwi Drivers Phished with Bogus License Renewals

The New Zealand Transport Agency (NZTA) has warned of an ongoing email phishing campaign using fake vehicle license renewal reminders, 1 News reports. The emails appear legitimate and ...

TrickBot Hackers Have Created the Ultimate “On the Fly” Update Backdoor

The newly-created “PowerTrick” backdoor leaves malware ready to accept new commands and victim organizations perpetually in danger of the next thing the malware’s creators can think of.

You Should Be Scared of the Latest Strains of Phobos Ransomware

In an unusual twist, it’s not actually the ransomware itself that makes the newer forms of Phobos so frightening; it’s the people behind the attacks that will have you worried.

Travelex Warns Customers: Watch Out For Phishing Or Telephone Scams In Aftermath of Ransomware Attack

A little more than two weeks ago on New Year’s Eve, Foreign Currency services supplier Travelex was hit by a Sodinokibi (REvil) Ransomware attack. It has yet to recover and its web sites ...

Happy Hotel With a Sad Ending

Tokyo, Japan-based Almex which operates the Japanese Happy Hotels announced it has been hacked and that customer data including email address, birth date, gender, phone number, log in, ...

Nobel Laureates Get Scammed, Too

Nobel Prize-winning economist and New York Times Opinion columnist Paul Krugman appears to have been taken in by a phishing scam, Business Insider reports. In a tweet that’s since been ...

Security-Related and Giveaway Phishing Email Subject Lines Get the Most Clicks

KnowBe4 revealed the results of its Q4 2019 top-clicked phishing report. The results found that simulated phishing tests with an urgent message to check a password immediately were most ...

New SNAKE Ransomware is an Attack Mix of Obfuscation, Encryption, and Corporate Disruption

Beware! This new targeted attack variant of ransomware is smart, sophisticated, and does a lot more than just encrypt files.

Hackers Target the Special Olympics of New York and Use them to Launch Phishing Attacks

This latest attack demonstrates how cybercriminals can leverage one organization as merely a part of a larger phishing campaign to scam countless individuals out of credentials or money.

Fast Work By Cops Recovers $710,000 After CEO Fraud Attack Hits Long Island County Government

Finally some good news. Newsday reports that in record time, Nassau County, New York, recovered $710,000 that was transferred to scammers who were impersonating an existing county vendor.

New Languages Added to KMSAT Learner Experience

Late Friday, the product team added 6 new languages to the KMSAT Learner Experience bringing the total number to 21 languages supported. The new languages include:

[New Ransomware Threat] Now Cyber Criminals Demand Ransom From The PATIENTS After A Plastic Surgery Clinic Data Breach

Just when you thought it could not get any worse... it did. Criminal hackers are now demanding that all the patients of Florida provider Richard Davis, MD pay a ransom to prevent the ...

Texas School District Loses $2.3 Million In BEC Scam

Texas’s Manor Independent School District was the victim of a costly 2.3 million dollar Business Email Compromise (BEC) scam in November of 2019.

Auto Dealership Becomes Latest Victim of Ransomware Attack Costing Up to $500,000

The opening of a seemingly benign email from a coworker by an unsuspecting employee set in motion an attack that brought operations to a halt and resulted in some costly remediation. The ...

Microsoft Sues Hacker Group for Data Theft of Highly Sensitive Information

A new recently unsealed lawsuit against a North Korean hacker group shows how even the largest companies can be successfully attacked by phishing.

An Overview of Phishing from the Accounting Sector

Employee training is an essential long-term defense against phishing attacks, according to David Barton and Kimberly Anderson at UHY Advisors. In an article for Accounting Today, Barton ...

[Scam Of The Week] Don't Fall For This Tricky: “Start your 2020 with a gift from us”

Paul Ducklin at Naked Security warned us about a scam that just surfaced and promises a gift by courier from overseas where the other person hasn’t told you what they’re sending – the ...

REvil Ransomware: "Pay Us One Way Or The Other!"

The Wall Street Journal and Bleeping Computer reported that Travelex, a foreign-currency exchange company, was hit by the ReVil/Sodinokibi actors on New Year's Eve and that its network ...

Cybercriminal Offers a “How To” Guide for Robbing Banks; Uses Cayman National Bank as the Example

This latest document from notorious hacker Phineas Phisher, along with a leaked report from PwC, shows how easy it is for a bank to be hacked and defrauded.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.