Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Phishing Simulations Should be Educational, not Punitive

Phishing training programs need to be focused on educating employees rather than on shaming them, according to David Spark and Allan Alford, co-hosts of the Defense in Depth podcast. On ...

They Know If You've Been Bad or Good...

Like most of the rest of us, malicious actors the world over love the holidays. It's a prime season to run social engineering schemes on users who are already of a mind to open their ...

Responsibility...just because they are aware, doesn’t mean that they actually care.

This blog was cowritten by Joanna Huisman, KnowBe4's new SVP Strategic Insights & Research and Aimee Laycock. They say it takes a village to raise a child. It’s similar to any ...

110 Nursing Homes Cut Off from Health Records in Ransomware Attack

Brian Krebs reported: "A ransomware outbreak has besieged a Wisconsin based IT company that provides cloud data hosting, security and access management to more than 100 nursing homes ...

Waterloo Brewing loses $2.1 million in social engineering cyberattack

Waterloo Brewing Ltd. says it has lost $2.1 million in what it calls a social engineering cyberattack. The Ontario brewery says the incident occurred in early November and involved the ...

Scripting the Language of Fraud

Scammers are constantly improving their craft and reusing techniques that are proven to work, and they sometimes share the most effective lines with other scammers, according to NPR. ...

Companies Expected to Lose $5.2 Trillion in Opportunity Due to Cyber Attacks Over the Next Five Years

The big business of cyberthreats gets stamped with a huge price tag by professional services company Accenture in their latest report on Securing the Digital Economy.

Ransomware Claims Are Up 50% in 2019 With Attacks Outpacing the Previous Five Years

According to cyber insurer Chubb, ransomware attacks are shifting industry focus and are becoming both more frequent and more expensive to address.

[Heads-up. This Is Ugly] After Refusing The Maze Ransomware Payment, Their Stolen Data Was Leaked

After a deadline was missed for receiving a ransom payment, the group behind Maze Ransomware has published almost 700 MB worth of data and files stolen from a security staffing firm. Our ...

French Hospital Crippled by Ransomware

Patient care at a large hospital in northern France has suffered considerably after a major ransomware attack at the weekend, according to local reports. The University Hospital Center ...

A massive international email scam netted $3 million worth of top-secret US military equipment

In a recent case first reported by Quartz, a crew of international cyber criminals allegedly convinced an unidentified US defense contractor to send them millions of dollars worth of ...

It's Happening The World Over: $300K Lost To Phone Scammer

A woman in Singapore lost $300,000 to a scammer posing as a Singtel customer service employee, according to the Straits Times. The scammer told the victim he would fix some problems with ...

An Australian Watering Hole (but in Canberra, not the Outback)

The Australian Federal Parliament suffered a malware infection earlier this year after some users fell victim to a watering hole attack, the Australian Broadcasting Corporation (ABC) ...

Cybercriminal Gang, Silent Starling, Creates New ‘Vendor Email Compromise’ Category

New attacks focus on organizations with global supply chains looking to trick a supplier’s customers into paying fake invoices and have already impacted 500 organizations worldwide.

Malware Delivered Via Fake Browser Updates Are Back and are More Sophisticated Than Ever

Leveraging vulnerable website content management platforms, these attacks seek to trick users into installing malware under the guise that their web browser is out-of-date.

Now HERE is an interesting Phishing Campaign!

It's a phishing campaign against phishing campaigns! :-D It's a public service program that educates organizations and societies globally on the greatest cyber risk of all - the falsehood ...

Ransomware Attack Hits Louisiana State Servers

Louisiana Governor John Bel Edwards on Monday revealed that a ransomware attack hit state servers, prompting a response from the state’s cyber-security team. The incident appears to have ...

A Look at Election Influence And Social Engineering

Attempts to influence elections are by no means new, but highly targeted online advertising requires people to think about social engineering in the form of political messaging in a new ...

Real Estate Scams Have Gone Global. Bad Guys Caused Tens of Thousands of Dollars Damage Down Under

Scammers hijacked a total of $70,000 by imitating an Australian settlement agent’s email address, and then tricking two property buyers into sending the money to the wrong account, Perth ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.