KnowBe4 Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in human and agent security including social and prompt engineering, ransomware and phishing attacks.

Paying the Ransom Is Not Just About Decryption

I just read that a well-known pipeline company paid $5M to the ransomware hacker group. And despite that, they are still having to use their backups because the decryption process is too ...

Kicking You While You’re Down: Ransomware Attacks Begin to Adopt a “Triple Extortion” Model

New tactics spotted by security researchers at CheckPoint indicate a growing pattern by ransomware gangs to use additional extortion actions to increase revenues and ensure payment.

Ransomware Attack Demands Cause Cyber Insurance Claim Amounts to Skyrocket

The perfect storm of large enterprises, cyber insurance policies, successful ransomware attacks, and ransom demands in the tens of millions now consistently result in seven-figure claim ...

New Verizon DBIR: Credentials Stolen in 85% of Social Engineering Breaches

Verizon’s latest data breach report puts a spotlight on one of the largest and most unpredictable risk factors in your cybersecurity strategy – your users.

FBI Finds Phishing Sites Abusing Search Results and Ads to Steal Banking Credentials

The US Federal Bureau of Investigation has sent out a private industry notification (PIN) warning that cybercriminals are using search engine ads and search results to spread phishing ...

A  New Smishing Trojan is Out and About

Researchers at Pradeo have observed a new Android malware campaign that uses text messages asking victims to pay a small fee for a delivery. The messages contain a link that will install ...

New QuickBooks-Themed Phishing Attack Seeks to Infect Victims with Dridex Malware

Purporting to be invoices and payment reminders, this new campaign targets users of the popular accounting software to install the banking trojan on its victims endpoints.

Email-Based Threats Increase 64% as Attacks Grow in Sophistication and Volume

New data from Mimecast shows how email-based threats are not only the greatest perceived concern, but are proving to be the reason for increased experienced attacks.

Phishing Scammers Remove ‘External Sender’ Email Warnings Impersonating Internal Users

With little more than some CSS and HTML coding, a security researcher demonstrates how easy it is to eliminate security warnings placed on email messages by security products.

Your Organization Needs to Take Security Awareness Training More Seriously

Your organization needs to take security awareness training (SAT) more seriously. I mean truly serious, really serious, and not relegated to some quasi-, semi-serious status that the vast ...