Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

[ALERT] 93% of phishing attacks now have ransomware payloads

Oh boy. Things have gotten from bad to worse in an awful hurry. I remember the first time I reported on ransomware in the CyberheistNews Issue Feb 11, 2014, where an attorney's office ...
Continue Reading

Looks Like 8 More Cyberheists By North Koreans

Gottfried Leibbrandt, chief executive of the world’s largest interbank funds-transfer system SWIFT, has said repeatedly that the prospect of cybercrime is what keeps him awake at night. ...
Continue Reading

[INFOGRAPHIC] Don't Be The Victim Of A Cyberheist

We have created a new infographic for your users, as part of your ongoing security awareness training program. It's a few good reminders how to stay safe online, and to keep their ...
Continue Reading

Top Ransomware campaign managers make 13 times more than avg Russian wages

A short report by Flashpoint gives us some insight into a recent ransomware campaign, which so far has generated a serious amount of profit considering it takes little effort to operate.
Continue Reading

Phishing Attacks Ramp Into 2016 With Major Increase

In its most recent Phishing Trends Report, the APWG noted a 250% increase in phishing sites between October 2015 and March 2016 — and the 2016 increase shows the never ending criminal ...
Continue Reading

Ransomware domains increased 3500% in Q1 2016

There has been a whopping 3500% increase in ransomware domains in the first quarter of 2016, compared to the last quarter of 2015. Those are the highlights of a new report by network ...
Continue Reading

CEO And CFO Fired After Aerospace Company Grounded By CEO Fraud

Here is a great way for C-level execs to lose their job: allow your company to become the victim of CEO Fraud. That happened to the CEO and CFO of FACC, part of both Airbus' and Boeings' ...
Continue Reading

CryptoWall, Locky, and Cerber Are Today's Top 3 Ransomware Threats

US cyber-security firm Fortinet reports that, between April 1, 2016, and May 15, 2016, the top five most prevalent ransomware families were in this order: CryptoWall (41.04%), Locky ...
Continue Reading

New Strain Of Cerber Ransomware Being Offered As RaaS On Russian Hacking Forum

Security Researchers at Forcepoint discovered that a Russian hacking forum on the dark web is selling the Cerber ransomware as a RaaS (Ransom-as-a-service). This is a new form since ...
Continue Reading

Are North Koreans The Bad Guys Behind Brazen Cyberheists?

In March, we posted a story about a cyberheist where hackers tried to steal a cool 1 Billion dollars from the Bangladesh Central Bank, but a simple typo thwarted most of their attempt. ...
Continue Reading

The Nightmare of Exploits Past. How Phishing Attacks Use Old Vulnerabilities

By Eric Howes, KnowBe4's Principal Lab Researcher Remember .PIF files? If you're like us, the extension probably rings a bell somewhere deep in the dustiest recesses of your mind -- the ...
Continue Reading

Scam Of The Week: Summer Olympics Canceled in Rio

Heads-up! There is a spike in phishing attacks with Summer Olympics themes, and in the coming months the bad guys are going to be all over this. Kaspersky Labs researchers are reporting ...
Continue Reading

Microsoft Alert: ZCryptor Ransomware With Worm Feature

Microsoft released an alert about a new ransomware strain called ZCryptor, which works like a worm and spreads via removable and network drives. The MalwareForMe blog reported this first ...
Continue Reading

Shields Up! New DMA Locker V4 Unleashes Major Ransomware Assault

DMA Locker is an excellent example of cybercrime's furious speed of innovation. Version 1 showed up in January 2016, and V2 a month later, but the implementation of the encryption ...
Continue Reading

Massive Locky Ransomware Campaign Targets Amazon Users

Comodo Threat Research Labs just posted an alert that a massive campaign of phishing emails have been sent with a spoofed "from" address: auto-shipping@amazon.com. The subject is “Your ...
Continue Reading

[ALERT] Cerber Ransomware Strain Adds DDoS Bot Causing More Damage

Excuse my French, but Holy S#!+, some ransomware developers have created a new evil way to monetize their operations by adding a DDoS component to their malicious payloads. Security ...
Continue Reading

Scam Of The Week: LinkedIn Email Change Your Password

You probably remember the 2012 LinkedIn data breach. It was a big deal because something like 6.5 million user account passwords were posted online, but LinkedIn never confirmed the final ...
Continue Reading

"What methodologies does KnowBe4 use in developing our training?"

Someone interested in using our integrated platform for training and phishing asked us: ""What methodologies does KnowBe4 use in developing our training?" We use the ARCS Model. ARCS is ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews