Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Announcing A New 8-Minute Training Module - Social Media: Staying Secure in a Connected World

As you probably know, social media is the number one place that attackers can get intel about your organization to make their "hacking of your humans" more effective. We have been hearing ...

U.S. Government Issues Warning About Possible Iranian Cyberattacks

Christopher C. Krebs, Director of Cybersecurity and Infrastructure Security Agency issued a warning about a potential new wave of Iranian cyber-attacks targeting U.S. assets after Maj. ...

Seven Kinds of Malware, and all Arrive by Social Engineering

Naked Security outlines seven different categories of malware and describes how each of them through social engineering techniques can affect your organization. Some or all of these ...

Global Climate Change Phishbait

A number of phishing campaigns have been using Christmas-themed emails encouraging recipients to support climate activist Greta Thunberg, according to Paul Ducklin at Naked Security. ...

Wawa Data Breach Class Action Filed

There was a massive data breach suffered by Wawa, a convenience store chain of more than 850 stores around the country. Wawa had recently disclosed that it had suffered a data breach that ...

75% of European Enterprises Cite a Lack of Awareness Training a Challenge to Establish a Proper Cybersecurity Stance

The latest data from VMware and Forbes Insights shows organizations across EMEA are deficient in a number of fundamental cybersecurity needs.

More Fake Windows 10 Updates Spell Hefty Ransoms for Victims

With Windows 7 ending support this month, organizations moving to or already on Windows 10 need to be wary of “update” phishing scams intent on installing ransomware.

New Report Shows the Success of Business Email Compromise Come from a Calculated Attack Approach

The newest data from security vendor Barracuda provides insight into exactly how attackers execute BEC attacks and what makes them so successful.

[Heads-up] Sextortion Crime Gang Now Uses New Tactics To Bypass Your Spam Filters

In a business environment, employees use Google Translate on a regular basis to get access to documents they need to work with, or websites that are in another language.

Cities and Governments are the Latest Target in a New “Leakware” Attack

This new type of attack focuses on threatening to steal and publish data on the web, asking for a ransom to be paid to keep the attackers from doing so.

Online Credential Scam Becomes a Phone Port Attack and then Turns into a Sextortion Scam

If experiencing a single cyberattack isn’t enough, this complex attack that shifted mid-stream demonstrates how attackers take advantage of victim details as an attack unfolds.

FBI Warns U.S. Companies About Maze Ransomware

The FBI is warning U.S. companies about a series of recent ransomware attacks in which the perpetrator, sometimes posing as a government agency, steals data and then encrypts it to ...

KnowBe4 Has A Blow-Out 2019 Fourth Quarter

In the fourth quarter of 2019, KnowBe4 reached 54% growth over Q4 2018, increasing customer accounts to well over 30,000.

Phishing Remains the Most Widespread Risk

As organizations look to improving their defenses, it’s worth remembering that attackers usually get through those defenses by manipulating the human beings those security measures are in ...

4 patients sue Alabama health system after ransomware attack

BeckerHospitalReview just posted a new wrinkle in the battle against ransomware: "Four patients filed a class action lawsuit against Tuscaloosa, Ala.-based DCH Health System, alleging ...

The Good, the Better, and the Best in Information Security

Every day, there is news about the latest data breaches, phishing attacks, the number of records that were exposed, how organizations are not doing enough to protect themselves. All of ...

Tax Season Warning: the IRS on Social Engineering

We have had occasion to warn of this before, but as 2020 begins and April 15th approaches, it may be worth another mention. The US Internal Revenue Service wants taxpayers to keep a sharp ...

2020 Cybersecurity Predictions by KnowBe4’s Experts

With data breaches hitting headlines daily, IT pros are constantly concerned about the next big threat. Whether it’s ransomware, phishing, or completely new attack vectors, there’s always ...

December 2019 Updates to our Data Protection Notices

In support of upcoming changes to data privacy laws we are making a few updates to our privacy policy. We have added language to help provide our customers clarity on KnowBe4’s ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.