Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Vacation Dream Home Phishing Nightmare (but with a Happy Ending)

Mike Malone and his wife found the vacation condo of their dreams in Florida. They were in touch with a real estate agent who was handling the deal when suddenly their condo purchase ...

How Mature is Your Security Awareness?

Here at KnowBe4, we believe the greatest defense against security threats is an organization with a strong security culture – one that elevates an employee’s awareness around threats, ...

[Heads-up] Massive Downtime Caused By Bad Guys Killing Bank's 9,500+ Systems To Hide Stealing 10 Million Dollars Via SWIFT

A cyberattack against Banco De Chile (BDC)—that country's largest financial institution—bricked a hair-raising 9,000 workstations and 500 servers. However, killing these machines was ...

More than 70% of users prefer MFA over old style password / username

More than 70 percent of computer users will choose password-less multi-factor authentication (MFA) over traditional usernames and passwords, according to new behavior research. The ...

Finally, The Criminals Pay in CEO Fraud Scam

Some good news finally. It seems that the bad guys do get caught sometimes. In this case, 70 cybercriminals in the U.S. and Nigeria.

Looking for a Job? Beware of Recruitment Sites!

There’s yet another reason to not let your employees go looking for a new job on company time: cybercriminals are now leveraging recruitment sites.

New Global Research Underscores Continued Increase in Phishing Threats and Impact on Staff & Productivity

Barracuda today announced key findings from a new global research report. Here are the highlights:

New Study: 25% of employees use the same password for every account. AUGH!

Employees may be a company's greatest asset, but they also remain the greatest cyber security risk, according to a Monday report from OpenVPN.

Scam of The Week: Celebrity Deaths Kate Spade and Anthony Bourdain

Two celebrities committed suicide this week, and unfortunately that's going to be exploited by lowlife internet criminals in a variety of ways.

New Phishing Campaign Uses IQY Attachments to Bypass Antivirus And Installs RATs

A malicious spam campaign, distributed by the Necurs botnet, is using a new attachment type that is doing a good job in bypassing your antivirus and mail filters.

We Received A CEO Fraud Phishing Attack From Our Own Personal Accountants

This is an up-close and personal account of how my wife Rebecca and I (we hope) dodged a cybercrime bullet. You probably do not know that I am an elected official of the City of ...

Kate Spade Suicide Phishing Templates

This is another celebrity death which will spawn a raft of phishing and social media attacks. We recommend to inoculate your users before they make it through the filters.

Watch Out For World Cup Soccer Phishing Scams

The 2018 FIFA World Cup has drawn a worldwide audience. It's also attracted phishing scams using event tickets as bait. Tickets for the matches can only be purchased legitimately through ...

[Heads-up] Ransomware Insurance Expert: "Bad Guys Do More Damage Than They Used To"

The ransomware plague is not letting up and rapidly getting more technically sophisticated. New strains are popping up every month, using innovative methods to spread. Worse, the ransom ...

Punycode Makes SMiShing Attacks More Deceiving

Phishing attacks carried out via text messages that use the “Punycode” technique to make nefarious URLs look legitimate are becoming more popular, cloud security firm Zscaler says.

Satan Ransomware Spawns New And Innovative Methods to Spread

It’s a worrying trend that ransomware isn’t going away. Worse, it's constantly adapting to include brand new exploits/techniques and spreads in more innovative and successful ways. Today, ...

The Con of Social Engineering: Law Firms are Easy Prey

Excellent article at www.law.com about social engineering! A discussion of the threat that social engineering (aka the "human side of hacking") poses to law firms, and some tips and ...

Hacking Humans—a new CyberWire podcast covering social engineering launched this week

Each week the CyberWire’s Hacking Humans podcast looks behind the social engineering scams, phishing schemes, and criminal exploits that make headlines and take a heavy toll on ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.