Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Weird New Cerber Ransomware Speaks To Its Victims

There is a new strain of ransomware called Cerber that takes creepiness to the next level. It drops three files on the victim's desktop named "# DECRYPT MY FILES #." These files contain ...

IRS Warns Against A Widespread CEO Fraud Phishing Scam

OK, heads up! This tax season there is a widespread new scam that specifically targets your HR and Accounting professionals. They get an urgent email from "the CEO" who asks them for all ...

CEO Fraud Phishing Attack steals 11,000 W-2s From Health Care Workers

A phishing incident has compromised the personal information of 11,000 Pennsylvania Main Line Health employees. Officials said the incident occurred on Feb. 16 when an employee fell for a ...

Apple Defies U.S. Magistrate's Order To Unlock Shooter Suspect's iPhone

Apple this week released a statement regarding what has been an ongoing battle for months. The FBI requested that Apple unlock the encypted iPhone belonging to San Bernadino shooter Syed ...

Crelan Bank Loses 75.8 Million Dollars In CEO Fraud

The Belgian Crelan Bank was the victim of a 70 million euro (75.8M U.S.) fraud that was launched from another country. They claim (PDF) this CEO Fraud was discovered during an internal ...

Tampa is 842% above the national average in malware infections

A new study by Enigma Software revealed the hardest hit cities in the country when it comes to computer viruses. Tampa was ranked #2 for malware infections per person. That's 842% above ...

CyberheistNews Vol 6 #2 Scam Of The Week: Fantasy Football Site Hacked

For this Scam Of The Week, we decided to go out on a limb and run a "What If" scenario" on an attack that we think is very likely.

Scam Of The Week: Massive LinkedIn Spam Steals Passwords

"I feel like a complete idiot. I just got taken by a LinkedIn spam that may have just stolen my banking password." These words dropped in my inbox, written a while ago by Dan Tynan, ...

[INFOGRAPHIC] The Top 5 Holiday Scams To Warn Your Users About

There are certain holiday scams we tend to see year after year. This infographic is great to share with your users to help them make smarter security decisions!

New Triple Threat Chimera: Ransomware, Extortion And Data Breach

OK, Heads Up! This has not hit U.S. shores yet, but it's just a matter of time. This nasty bit of crimeware is being beta-tested in Germany at the moment, and that is where the reports ...

FBI ALERT: Cybercriminals Spoof Your Domain With CEO Fraud

The FBI recently warned against a new cyber crime wave. It's called "CEO Fraud" where cybercriminals impersonate your CEO using your own spoofed domain name, and order employees to ...

Ransomware Resume Phishing Security Test Gets Monster Open Rate

Now here is a real IT Horror Story. A brand new KnowBe4 customer which had not yet trained their employees decided to test their staff with one of the new templates we had just released.

It's heeere! Criminal Ransomware as a Service

As we predicted in our whitepaper "Your Money or Your Life/Files", there is now shake-and-bake criminal ransomware that aspiring Internet criminals can put together in a few minutes. Meet ...

Adult Friend Finder Hack Is Nightmare Phishing Problem

Guys, we have a real phishing problem with this Adult Friend Finder (AFF) hack. This particular adult site is one of the most heavily-trafficked websites in the U.S. and has 40 million ...

Social Engineering Exploit Fools HR with Infected IT Resumes

Researchers recently detected a clever email-based attack that combines phishing and social engineering techniques in order to trick users into opening a malicious document. In this ...

Scam Of The Week: 911 Phone Threat

Residents in Ohio are being "beta tested" by cybercrime for a scam that will inevitably also hit all other states. Here is your Scam Of The Week heads-up. This particular scam will also ...

PCI Publishes Guidance On Security Awareness Training

The Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of ...

CryptoWall 2.0 Ransomware Moves to TOR network

A new version of the world's most widespread ransomware CryptoWall has migrated to the TOR network. It has been upgraded to version 2.0, and continues to encrypt files so that ransom can ...

Reveton Ransomware Adds Powerful Password Stealer

The Avast Blog reports a new "password stealer" feature in the Reveton ransomware. Reveton is the type of "police" lock/screen ransomware which falsely alerts users they've broken some ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.