Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Scam Of The Week: TurboTax Phishing Attack

It's tax season and the bad guys are in full swing. They try to get your Accounting or HR team to send over the W-2s of all employees, but they also target employees in the office and/or ...

SURVEY: Even if You Don't Pay, Ransomware Attacks Are Very Expensive

According to a new survey by Intermedia called "2016 Crypto-Ransomware Report", ransomware attacks are increasingly targeting larger companies, costing them dearly. Employees are usually ...

New KnowBe4 Phishing Templates

We have added a dozen new phishing templates in the past few days. All are based on actual bad guy phishing emails seen in the last 2 weeks. At least one is less than 24 hours old. Most ...

TeslaCrypt Ransomware v3.01 Updated With Unique Keys For Each Victim

TeslaCrypt is a relatively new ransomware variant which has made it in the Top 5, and has rapidly innovated in its efforts to evade detection. The latest version which is one of the most ...

Ransomware Attacks Use NY Times, BBC, Other Media Sites

Over the weekend, The NY Times, BBC, Newsweek, AOL, MSN, The HIll and other major news sites had their ad networks hijacked again by criminals using the Angler Exploit Kit to deliver ...

Inoculate Employees Against The Locky Ransomware

KnowBe4 has immediately responded to Dridex's Locky ransomware attack by releasing a new attachment option which is called "MS Office document with Macro". This new option allows a ...

CyberheistNews Vol #6 #11

Deadly Dridex Cybercrime Gang Has Just Moved Into Ransomware

One thing that is driving mainstream recognition of ransomware is the move by the Dridex banking Trojan gang into ransomware with their Locky strain. They have taken over from CryptoWall, ...

The structure of Russia's exports in 2014, including ransomware

Check the orange slice depicting the percentage of ransomware exports. I found this on someone's twitter feed and loved it!

Hackers Spoil Their $1 Billion Cyberheist With a Typo

It helps to know how to spell when you try to rob a billion from a dirt poor country. A spelling mistake thwarted hackers in stealing a $1 billion dollars from the Bangladesh Bank, and ...

Weird New Cerber Ransomware Speaks To Its Victims

There is a new strain of ransomware called Cerber that takes creepiness to the next level. It drops three files on the victim's desktop named "# DECRYPT MY FILES #." These files contain ...

IRS Warns Against A Widespread CEO Fraud Phishing Scam

OK, heads up! This tax season there is a widespread new scam that specifically targets your HR and Accounting professionals. They get an urgent email from "the CEO" who asks them for all ...

CEO Fraud Phishing Attack steals 11,000 W-2s From Health Care Workers

A phishing incident has compromised the personal information of 11,000 Pennsylvania Main Line Health employees. Officials said the incident occurred on Feb. 16 when an employee fell for a ...

CyberheistNews Vol 6 #9 How To Suck At Information Security – A Cheat Sheet

CyberheistNews Vol Vol 6 #9 How To Suck At Information Security – A Cheat Sheet Lenny Zeltser is a business and tech leader with extensive experience in Infosec. His areas of expertise ...

Snapchat Employee Fell For W-2 Phishing Scam

A Snapchat employee fell for a W-2 phishing scam last week, compromising the identity information of other existing and ex-employees. The FBI calls this a Business Email Compromise, also ...

[ALERT] New Strain Of CEO Fraud: Urgent Request for W-2s

This morning, our Controller received an email from "me", stating the following: Alanna I want you to send me the list of W-2 copy of employees wage and tax statement for 2015, I need ...

44% of ransomware victims in the UK have paid to recover their data

Danielle Correa at SC Magazine wrote: "A Bitdefender global study with respondents from the UK, the US, France, Germany, Denmark and Romania was conducted by iSense Solutions to discover ...

Scam Of The Week - Netflix For Free

Netflix’s popularity continues to grow fast, and they recently launched their streaming service globally. Obviously that makes them a hacker target. At the moment, there are active ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.