Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Urgent Phishing Alert: Warn Your Users Against AdultFriendFinder Scams Now

Your end-users may have seen this in the news yesterday, or will read about it today. A massive data breach of the adult dating and entertainment company Friend Finder Network has exposed ...
Continue Reading

Healthcare Sees 20 Data Loss Incidents PER DAY Due To Ransomware

In late October, three of the U.K.’s National Health Service (NHS) hospitals’ computer systems were attacked by malware that forced the hospital to cancel scheduled surgeries and divert ...
Continue Reading

Scam Of The Week: Watch Out For Fake Apps

The shoe retailer Foot Locker Inc. has three iPhone apps. But that did not stop an entity calling itself Footlocke Sports Co., Ltd. from offering 16 shoe and clothing apps in the App ...
Continue Reading

The LinkedIn Phishing Attack: How They Did It

by Eric Howes (Principal Lab Researcher) & Ryann Falke (Sales Development Representative) Last week we documented several interesting credentials phishes delivered through LinkedIn ...
Continue Reading

My Antivirus Failed The RanSim Test. How Do I Fix This?

So, you downloaded KnowBe4's Ransomware Simulator test and your antivirus security software failed one or more of the ransomware scenarios. When this happens we almost always get asked: ...
Continue Reading

OK, want to laugh your a$$ off? Watch this Apple parody!

It's not all doom and gloom!
Continue Reading

New Locky Ransomware Phishing Attack: Credit Card Suspended And Suspicious Money Movements

Graham Cluley was the first to report on a new Locky ransomware phishing attack where the emails claim to be "credit card suspended" and "suspicious money movement" warnings. He said: "In ...
Continue Reading

Tech support scammers abuse bug in HTML5 to freeze computers

Malwarebytes Researcher Jerome Segura reported on a new Tech Support scam that uses a known HTML5 bug to freeze the system and trick people to call a fake support number. Note, it does ...
Continue Reading

City Of El Paso Victim Of 3 Million Dollar Phishing Scam

During a news conference Wednesday afternoon, city officials revealed that cybercriminals pretending to be a vendor scammed the city's Accounts Receivable Department out of about $3 ...
Continue Reading

New Version Of Nymaim Malware Targets High-Level Managers

A new version of the Nymaim malware family targets high-level managers with attached malicious Word documents and drops ransomware and banking trojans. The cyber research team at Verint ...
Continue Reading

Yes, that email is really from LinkedIn. And, yes, it's really malicious.

By Eric Howes, KnowBe4 Principal Lab Researcher. Several months ago we blogged about a startling discovery by threat researchers at Proofpoint: the bad guys had figured out a way to turn ...
Continue Reading

Boy have we grown... KnowBe4 Halloween 2014, 2015, 2016

Halloween 2014 15 employees. Scroll down for the later years!
Continue Reading

Scam Of The Week: Tech Support Claims Your Hard Disk Will Be Deleted

Symantec warns that tech support scams are getting more sophisticated by the month: "These scams remain one of the major and evolving forces in the computer security landscape. Between ...
Continue Reading

How Podesta got hacked: HelpDesk said 'Password' phishing email was real

John Podesta, Chairman of the 2016 Hillary Clinton presidential campaign was a victim of social engineering and rushed advice from his IT helpdesk. It's a comedy of errors. The helpdesk ...
Continue Reading

82% of Email Servers are Misconfigured, Allowing Domain Spoofing

We reviewed thousands of domains that have been through our domain spoof test and analyzed more than 10,000 email servers. We found that 82% of these are misconfigured.
Continue Reading

Insurance underwriter Beazley: "Ransomware attacks will be four times higher in 2016"

The Wall Street Journal is getting the message. They said : "For companies concerned about the soaring number of ransomware attacks–in which hackers take control of data or systems and ...
Continue Reading

Who Is Learning How to Take Down the Internet?

It was all over the news. A sustained DDoS attack that caused outages for a large number of Web sites Friday was launched with the help of hacked “Internet of Things” (IoT) devices. Jeff ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews