Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Anthem Breach Began with Phishing of Employees

Last updated 2/12/2015 - The foreign hackers who stole up to 80 million records from Anthem social engineered their way into the company's network by obtaining the credentials of five ...
Continue Reading

Hacked Lawyers Office Sends Phishing Attack To Customers

An interesting new wrinkle in phishing attacks is in the wild as we speak. A system administrator reported the following on the spiceworks forum:
Continue Reading

Malware Hijacks Microsoft Outlook And Spreads Banking Trojan

I mentioned a few months ago that I expected something like this, but it has materialized faster than I expected. Trend Micro researchers discovered a new version of the Dyre banking ...
Continue Reading

CyberheistNews Vol 5 #6 Feb 10, 2015 New Ransomware Strain Encrypts Files From RAM / Scam Of The Week

New Ransomware Strain Encrypts Files From RAM / Scam Of The Week Security researchers at venture-backed Invincea have discovered a new Russian ransomware strain they called "Fessleak". It ...
Continue Reading

Spear Phishing Attack Makes $17.2 Million In Three Days

Corporate cybercrime on an international scale has hit one of Omaha’s biggest and oldest companies. CEO Chuck Elsea's email address was spoofed and this cost them millions because their ...
Continue Reading

What KnowBe4 Users Say About The Service

Feb 6, 2015 at 3:40 PM: Cyali said: "I'll be redoing our security policy shortly, as well as spearheading a project to put together a real IT orientation as part of our onboarding process.
Continue Reading

Brand new ransomware strain encrypts files from memory

Security researchers at venture-backed Fairfax, Virginia-based Invincea have discovered a new Russian ransomware strain they called "Fessleak" which delivers its malicious code straight ...
Continue Reading

Slideshow: The Worst Of The Worst Phishing Scams

www.CSOonline.com provides news, analysis and research on a broad range of security and risk management topics. Areas of focus include information security, physical security, business ...
Continue Reading

Data Breach at Health Insurer Anthem 80 million records

Last updated Feb 7, 2015 - Both the Wall Street Journal and cyber security blogger Brian Krebs reported that Anthem Inc., the nation’s second largest health insurer disclosed that hackers ...
Continue Reading

CyberheistNews Vol 5 #5 Scam Of The Week: Child Predator Phishing Email

Scam Of The Week: Child Predator Phishing Email Just when you think phishing criminals cannot sink any further, you get confronted with a "new low". This phishing scam preys a on parent's ...
Continue Reading

Graphics Make Phishing Attacks Work Better

A successful phishing attack has several elements that all together convince the victim that the email is legit and that they need to act on the message. One of these elements sems to be ...
Continue Reading

Fake Chrome Update Phishing Email Installs Ransomware

Jerome Segura at MalwareBytes was the first to report about a phishing attack that uses a fake "Chrome Update" to trick end-users into installing ransomware on their workstation. So, I ...
Continue Reading

RansomWeb: Cyber Criminals Hold Whole Website Hostage

Now this is a whole new wrinkle in criminal ransomware. Malicious hacker crews have started taking over whole websites, injecting some code to file-by-file first encrypt and then decrypt ...
Continue Reading

Scam Of The Week Child Predator Phishing Scam

Child Predator Phishing Scam Preys On Parents Fears Please send a link to this blog post to your friends and family right away?
Continue Reading

CyberheistNews Vol 5 #4 Jan 27, 2015 Scam Of The Week: LinkedIn Support Phishing Emails

Scam Of The Week: LinkedIn Support Phishing Emails The scam is at least 15 years old if not more, but unfortunately this type of social engineering still works. Remind your users one more ...
Continue Reading

Scam Of The Week: LinkedIn Support Phishing Emails

The scam is at least 15 years old if not more, but unfortunately this type of social engineering still works. Remind your users one more time that emails like this can hit their inbox at ...
Continue Reading

FBI Alert: Ransomware Infection Leads To Wire Transfer Fraud

OK, Heads-up! Here is the deal. The FBI and the Internet Crime Complaint Center (IC3) two days ago warned about a new version of a man-in-the-middle scam that targets your CEO, CTO, CFO, ...
Continue Reading

Scam Of The Week: ISIS Attack / 12Mil New Malwares Per Month

Scam Of The Week: ISIS Attack It is a mystery that bad guys have not jumped on this in higher volume. However, a major malware phishing campaign claiming ISIS attacks, has been found in ...
Continue Reading

Scam Of The Week: ISIS Attack

It is a mystery that bad guys have not jumped on this in higher volume. However, a major malware phishing campaign claiming ISIS attacks is out in the wild at the moment in Australia.
Continue Reading

NY Times: North Koreans hacked Sony with spear-phishing attacks.

The next revelation about the Sony Picture hack: The NSA was already inside the North Korean's networks and could have warned Sony about the pending attack.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews