Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Cybersecurity is the IT area where most CIOs expect to boost spending

MarketWatch reports that cybersecurity companies appear to be benefiting from fat IT spending budgets fueled by tax cuts and fears of hackers. A recent Morgan Stanley survey found that ...
Continue Reading

Fake Hotel Website Scams Target Travelers and Hotels

Cybercriminals will take advantage of any situation that separates people from their money. And what better way than to purport to be a reputable hotel and take reservations?
Continue Reading

Is it Shark Week at your Organization?

Curiosity for one of the most aggressive and dangerous beasts in the ocean has us dedicating a week to learning about it. Should cyberattacks that put your organization at risk get equal ...
Continue Reading

Second Quarter 2018 Top-Clicked Phishing Email Subjects [INFOGRAPHIC]

We've been reporting on the top-clicked phishing email subjects every quarter for a while now across three different categories: general emails, those related to social media, and 'in the ...
Continue Reading

WSJ: "Russian Hackers Reach U.S. Power Utility Control Rooms"

Now here is some news that concerns me deeply. I knew it was bad, but I did not know it was this bad.
Continue Reading

New Training Module: Safe Travels for Road Warriors

I'm excited to announce a new module that has been quite some time in the making! A 12-minute animated course with lots of interactivity for those that travel for business—and some very ...
Continue Reading

Employee Negligence – Your Organization's (bigger than you think) Nightmare

A new study shows a vast majority of C-level executives see employee negligence as one of their most pressing security risks.
Continue Reading

CyberheistNews Vol 8 #29

Continue Reading

New Policy Feature Added to the KnowBe4 Platform

KnowBe4 is excited to announce the introduction of the new Policy feature. The Policy feature gives you as an Admin the ability to store, distribute, and track various policy ...
Continue Reading

Scam of the Day: Sextortion, Old Passwords, and You

The “Sextortion” phishing scam makes use of compromised password data, recipient gullibility, and visits to porn websites to separate victims from their money. The scam message comes from ...
Continue Reading

Scam Of The Week: *Another* New CEO Fraud Phishing Wrinkle

So, here's a new CEO Fraud phish: see these fresh screen shots from emails reported to us through the free KnowBe4 Phish Alert Button. Bad guys spoof the managing partner and CPA and an ...
Continue Reading

Effective Social Engineering Matters More than Zero-Days

There's an interesting criminal campaign in progress against government targets in Ukraine. Note that we usually first see them there, and then they spread out to Western Europe and the ...
Continue Reading

Samsam Ransomware infected thousands of LabCorp systems via brute force RDP

LabCorp contained the attack within 50 minutes, says they're at about 90-percent operational capacity
Continue Reading

Russian Reminders: Phishing is Fruitful

The recent indictment by special counsel Robert Mueller of 12 Russian military officials for the hacking of Democratic servers and emails in 2016 is a powerful reminder – phishing works.
Continue Reading

$250,000 CEO Fraud In A Municipal Finance Department

Local, state, and Federal authorities are investigating a phishing attack that victimized the city of Alamogordo, New Mexico. One of the city's procurement officers received what appeared ...
Continue Reading

Can We Ever Truly Stop Ransomware?

A recent Class-Action lawsuit against EHR vendor Allscripts raises the question of where fault should lie when ransomware attacks are successful.
Continue Reading

FBI Warns that Business Email Compromise (CEO Fraud) is a "$12 Billion Scam"

The FBI is again warning of the threat posed by business email compromise (BEC, aka CEO Fraud) and email account compromise (EAC). Together, says the Bureau, these have cost businesses ...
Continue Reading

SANS: "Less Than Half of Cyberattacks Detected via Antivirus"

We have been saying here for a while that antivirus is dead, but SANS just confirmed it in a new report that starts with: "Companies are buying next-gen antivirus and fileless attack ...
Continue Reading

UK SMEs: Know Your Enemy. Plan Your Defense

Organizations in the UK with 250 employees or less need a solid understanding of the attack potential, methods used, and how to prepare.
Continue Reading

CyberheistNews Vol 8 #28

Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews