Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Phishing from the Middle: Social Engineering Refined

By Eric Howes, KnowBe4 Principal Lab Researcher. Phishing attacks have long been associated with malicious emails that spoof well-known institutions in order to trick users into coughing ...
Continue Reading

Phishing Reply Tracking Is Now Available for All KnowBe4 Customers

Two of the big cybersecurity attacks are the CEO Fraud (aka Business Email Compromise) which has caused $3.4 billion in damages as well as the W-2 Scams which social engineer ...
Continue Reading

CyberheistNews Vol 6 #49 Welcome To The CyberheistNews 2017 Crystal Ball Issue.

CyberheistNews Vol 6 #49 Welcome To The CyberheistNews 2017 Crystal Ball Issue. In December I spend a few days analyzing our space, and predict the coming year. The Crystal Ball issue is ...
Continue Reading

Kaspersky: DDoS Often Smokescreen For Phishing Attack

Distributed denial of service attacks, also known as DDoS, are becoming a major threat. They can bring websites and networks down, and generally make a lot of noise demanding attention. ...
Continue Reading

Phishing Attack Hits Saudi Govt Networks With Disk-Wiping Malware

Hackers penetrated six Saudi Arabian government agencies including its General Authority of Civil Aviation, and bricked thousands of computers with the well-known Shamoon disk-wiper ...
Continue Reading

Russian Central Bank Loses 2 Billion Rubles in Cyberheist

Reuters reported that hackers stole more than 2 billion rubles ($31 million) from correspondent accounts at the Russian central bank, the bank said on Friday. “We can’t say exactly when, ...
Continue Reading

The Top Five Names In Cybersecurity

Looking for the top names in cybersecurity? Look no further than the Cybersecurity 500 list of the world’s hottest and most innovative cybersecurity companies: ...
Continue Reading

Scam Of The Week - Fake News: a Content-based Social Engineering Attack

Facebook, Google, and Twitter have recently been facing scrutiny for promoting fake news stories. Depending on your sources and who you believe, fake news played and is still playing a ...
Continue Reading

10 Ways To Avoid Holiday Scams

With the biggest cybercriminal hacking holidays of the year upon us, it's time for a reminder of red flags to pay attention to when shopping either online or in brick-and-mortar stores.
Continue Reading

Why Advanced Ransomware Is Cybercrime's Most Profitable Business Model

RSA did a revealing ransomware risk-reward analysis. See that $6 million number over to the right? Why does cybercrime like ransomware so much? Low Risk, High Payoff From the bad guy's ...
Continue Reading

Yes, that message is really from Facebook. And, yes, it's really malicious.

By Eric Howes, KnowBe4 Principal Lab Researcher Just two weeks after we reported that the bad guys had effectively converted LinkedIin into a phishing platform, Facebook once again found ...
Continue Reading

KnowBe4 Selected as SC Media 2017 Professional Award Finalist

KnowBe4, the world's most popular platform for new-school security awareness training was named a finalist in the SC Awards 2017 for exemplary professional leadership in cybersecurity. ...
Continue Reading

Ransomware Roundup November 2016

Crysis decryption keys posted The decryption keys of the Crysis ransomware were posted on Pastebin, which allows victims to decrypt their hijacked files without paying. Crysis was ...
Continue Reading

New Phishing Category: Controversial/NSFW*Offensive Language*

We get thousands of real phishing emails in, reported to us by customers using the free KnowBe4 Phish Alert Button. On a daily basis, these reported phishing emails get analyzed by the ...
Continue Reading

This social engineering attack starts with a fake customer-service call

Michael Kan at CSO reported on a TrustWave blog post with some troublesome news: "Hotel and restaurant chains, beware. A notorious cybercriminal gang is tricking businesses into ...
Continue Reading

KnowBe4’s Phish Alert Button Now Works With G Suite!

Do your users know what to do when they receive a suspicious email? Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report ...
Continue Reading

KnowBe4 Ranked Number 50 Fastest Growing Company in North America on Deloitte’s 2016 Technology Fast 500™

Some very good news! Tampa Bay, FL — November 16, 2016 — KnowBe4, provider of the world’s most popular platform for security awareness training and simulated phishing attacks, today ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews