Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Friday Afternoon, Monday Morning, and Law Firm Risk

Law firm employees appear to be getting better at avoiding real estate scams, says Toni Ryder-McMullin at Today’s Conveyancer. Conveyance is the act of transferring an ownership interest ...
Continue Reading

reCAPTCHA Phishbait Targets Google Users

A phishing campaign is using a phony Google reCAPTCHA system to deliver banking malware, according to researchers at Sucuri. The attackers are sending emails, supposedly from a Polish ...
Continue Reading

It’s Cheaper Than You Think to Launch a Cyber Attack

According to the latest data from Deloitte, the cost of committing a cybercrime is so surprisingly low that anyone and everyone can afford to be a bad guy.
Continue Reading

Healthcare Data Breaches Involve Triple the Records in 2018

As the healthcare industry continues to be a target in cyberattacks focused on data breaches of patient health records, the latest data shows that cybercriminals are taking more than ever.
Continue Reading

KnowBe4 Named One of the Best Cybersecurity Blogs in the UK

I’m proud to announce that KnowBe4’s blog has been selected by 4D Data Centres as one of the top cybersecurity blogs of the year. These awards acknowledge outstanding content within the ...
Continue Reading

Identity Theft by Low-Interest Credit Card Offer

Scammers have stolen large amounts of personal and financial information from thousands of Canadians via fraudulent phone calls offering lower interest rates on credit cards, an ...
Continue Reading

It's The Season for Tax Scams... Again

America's Internal Revenue Service is warning taxpayers about a surge in phishing emails, links, and phone calls during tax season, according to Toni Birdsong at McAfee. The scammers pose ...
Continue Reading

Bogus Job Offers as Phishbait

A series of phishing campaigns are targeting companies in various industries with phony job offers using direct messages on LinkedIn, according to researchers at Proofpoint. The attacker ...
Continue Reading

Going to RSA in San Francisco Next Week? Get your Free Book Signed by Kevin Mitnick at KnowBe4’s Booth# 4624 North

Check out all the activities KnowBe4 will be doing at RSA:
Continue Reading

Kevin Mitnick Demos Outlook Exchange Exploit

In a webinar last week Kevin Mitnick, KnowBe4's Chief Hacking Officer, shared a shocking demonstration of a recent Outlook Exchange exploit in which delegated access is allowed from any ...
Continue Reading

Cyber Espionage Warning: The Most Advanced Hacking Groups Are Getting More Ambitious

Once attackers might have needed the latest zero-days to gain access to corporate networks, but now it's spear-phishing emails using social engineering tactics that are most likely to ...
Continue Reading

The NoRelationship Attack Bypasses Office 365 Email Attachment Security

Attackers are bypassing Office 365 email attachment security by editing the relationship files that are included with Office documents, according to Yoav Nathaniel at Avanan. A ...
Continue Reading

Phishing campaign attempts to spread a new brand of snooping malware

Danny Palmer at ZDNet had the scoop: "A cyber espionage campaign is targeting national security think tanks and academic institutions in the US in what's believed to be an intelligence ...
Continue Reading

KnowBe4 Named Gold Winner for Cybersecurity Excellence Awards in Fastest Growing Cybersecurity Company Category

I'm excited to announce we have been named as the gold winner in the fastest growing cybersecurity company for between 500 to 999 employees category by the Cybersecurity Excellence Awards.
Continue Reading

We Are In The Wrong Business. Cyber Extortionists Make $360K A Year.

Extortion scams capitalize on compromised credentials, sensitive data, and technical vulnerabilities on Internet-facing applications to pressure victims to pay up.
Continue Reading

Various Types Of Phishing Attacks Defined

The definition of phishing is a cybercrime in which potential victims are contacted via email, telephone or text message by someone posing as a legitimate institution to lure individuals ...
Continue Reading

Hackers take over Tampa Mayor Bob Buckhorn's Twitter account, make bomb threat at Tampa Airport

TAMPA, Fla. (WFLA) - Tampa police are investigating a bomb threat made against Tampa International Airport after hackers took over Tampa Mayor Bob Buckhorn’s Twitter account Thursday ...
Continue Reading

Helping Employees Not Cause Data Breaches

Untrained employees with poor security habits pose a major risk to their employers, according to Ciara O’Brien at the Irish Times. O’Brien cites recent research conducted by Amarach on ...
Continue Reading

Wendy’s to pay $50M in data breach settlement

Wendy’s has agreed to pay $50 million to settle negligence claims following its 2015-2016 data breach that affected more than 1,000 of the burger chain’s locations.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews