Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Ransomware is a Growing Threat to Every Industry

Ransomware is a global problem that is only getting worse, as evinced by Datto’s 2018 Global State of the Channel Ransomware Report. The report surveyed more than 2,400 IT professionals, ...
Continue Reading

Hackbusters - Where Can You Discuss All Things Social Engineering?

The KnowBe4 Hackbuster’s Forum is an online community dedicated to stopping the bad guys that use social engineering to hack your organization.
Continue Reading

Scammers are Posing as Huawei’s Captive CFO

An advance fee scam is targeting individuals in China following the arrest of Huawei’s CFO, Meng Wanzou, according to the SANS Internet Storm Center. Ms. Meng, who is also the daughter of ...
Continue Reading

Half of Management Teams Don’t Understand Business Process Compromise

A new survey by Trend Micro reveals that 43% of organizations in twelve countries have been affected by Business Process Compromise (BPC) attacks. In spite of this, 50% of management ...
Continue Reading

Employee Education and Training is a Key Component of a Culture of Security

Organizations need to focus on education and training rather than blaming employees for security gaffes, according to the speakers in a panel debate at Computing′s Enterprise Security and ...
Continue Reading

KnowBe4 Published in The Top 10 Nicest Offices in Tampa!

Just published, KnowBe4 in Full Stack Talent's Article on The Top 10 Nicest Offices In Tampa! (They came a few weeks ago to take pictures of our office space.)
Continue Reading

CyberheistNews Vol 8 #49

Continue Reading

Cybercriminals Use 1.7 Million Compromised PCs in Botnet Advertising Fraud Scam

The Russian-born, botnet-driven advertising fraud scam, 3ve, generated over $29 million in revenue using fileless malware variant Kovter, botnets, and unsuspecting users.
Continue Reading

Ransomware Remains the Largest Source of Cyber Claims and Downtime

Details shared from Canadian insurer CFC Underwriting highlight the realities of ransomware attacks, and just how negatively impactful the aftermath is on business.
Continue Reading

ModStore Release Announcement: "Using the Phish Alert Button"- 3-minute Short Version

Now live in the ModStore is a new Phish Alert video module: Using the Phish Alert Button - Basic Use This is the PAB (super short version) that we created based on requests from admins ...
Continue Reading

[ALERT] Now The Bad Guys Are Phishing For Your Retirement Money

Eric Howes, KnowBe4 Principal Lab Researcher observed: "Here is a screenshot of a phishing email that came in Friday. In it the bad guys attempt to apply the same modus operandi currently ...
Continue Reading

[Scam Of The Week] New Sextortion Attacks Take A Dark Turn And Infect People With GandCrab Ransomware

Our friends at Proofpoint reported that last week employees in the United States have been bombarded by a spam attack that pushed a double-whammy of a sextortion attempt combined with a ...
Continue Reading

The FBI Catches CEO Fraud Scammers by Giving Them a Taste of Their Own Medicine

The case of how the FBI turned the tables on cybercriminals using the very same tactics demonstrates how powerful the art of social engineering and deception can get a victim to act.
Continue Reading

True Phishing Confessions From A Compromised Company. This One Has A Twist At The End

"The email you hope you never have to send to clients/customers" OK, so here is another horror story that you hope you can prevent from happening to your own organization. This is an ...
Continue Reading

When Does a Legitimate Password Reset Email Feel Like a Phishing Attack? Just Ask Citrix Users

A recent password reset email from ShareFile (a Citrix company) put some users on edge, questioning both the emails legitimacy and why the reset.
Continue Reading

CEO Fraud Attacks are Citing the California Wildfires

Criminals are using the California wildfires as a social engineering tactic to manipulate people into buying gift cards supposedly intended for victims of the disaster, according to James ...
Continue Reading

Google Maps’ Bank Listings Updated by Scammers

Scammers are taking advantage of Google Maps by modifying the contact information of the service’s bank listings. After replacing banks’ legitimate phone numbers with numbers of their ...
Continue Reading

GreyEnergy Malware Spreads Through Phishing Emails

The GreyEnergy APT primarily uses phishing emails as its initial infection method, according to analysis by Nozomi Networks. The malware has been targeting industrial control systems in ...
Continue Reading

Phishing Emails are Targeting Spotify Users

A phishing campaign is attempting to steal login credentials from Spotify users, according to researchers at AppRiver. The emails ask users to click a hyperlink to confirm their accounts, ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews