Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

CyberheistNews Vol 6 #2 Scam Of The Week: Fantasy Football Site Hacked

For this Scam Of The Week, we decided to go out on a limb and run a "What If" scenario" on an attack that we think is very likely.

Scam Of The Week: Massive LinkedIn Spam Steals Passwords

"I feel like a complete idiot. I just got taken by a LinkedIn spam that may have just stolen my banking password." These words dropped in my inbox, written a while ago by Dan Tynan, ...

[INFOGRAPHIC] The Top 5 Holiday Scams To Warn Your Users About

There are certain holiday scams we tend to see year after year. This infographic is great to share with your users to help them make smarter security decisions!

New Triple Threat Chimera: Ransomware, Extortion And Data Breach

OK, Heads Up! This has not hit U.S. shores yet, but it's just a matter of time. This nasty bit of crimeware is being beta-tested in Germany at the moment, and that is where the reports ...

FBI ALERT: Cybercriminals Spoof Your Domain With CEO Fraud

The FBI recently warned against a new cyber crime wave. It's called "CEO Fraud" where cybercriminals impersonate your CEO using your own spoofed domain name, and order employees to ...

Ransomware Resume Phishing Security Test Gets Monster Open Rate

Now here is a real IT Horror Story. A brand new KnowBe4 customer which had not yet trained their employees decided to test their staff with one of the new templates we had just released.

It's heeere! Criminal Ransomware as a Service

As we predicted in our whitepaper "Your Money or Your Life/Files", there is now shake-and-bake criminal ransomware that aspiring Internet criminals can put together in a few minutes. Meet ...

Adult Friend Finder Hack Is Nightmare Phishing Problem

Guys, we have a real phishing problem with this Adult Friend Finder (AFF) hack. This particular adult site is one of the most heavily-trafficked websites in the U.S. and has 40 million ...

Social Engineering Exploit Fools HR with Infected IT Resumes

Researchers recently detected a clever email-based attack that combines phishing and social engineering techniques in order to trick users into opening a malicious document. In this ...

Scam Of The Week: 911 Phone Threat

Residents in Ohio are being "beta tested" by cybercrime for a scam that will inevitably also hit all other states. Here is your Scam Of The Week heads-up. This particular scam will also ...

PCI Publishes Guidance On Security Awareness Training

The Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of ...

CryptoWall 2.0 Ransomware Moves to TOR network

A new version of the world's most widespread ransomware CryptoWall has migrated to the TOR network. It has been upgraded to version 2.0, and continues to encrypt files so that ransom can ...

Reveton Ransomware Adds Powerful Password Stealer

The Avast Blog reports a new "password stealer" feature in the Reveton ransomware. Reveton is the type of "police" lock/screen ransomware which falsely alerts users they've broken some ...

KnowBe4's Email Exposure Check Discovers Data Breach

You are probably aware of the free one-time Email Exposure Check Pro (EEC Pro) we can run for you. We find all the email addresses of your domain that are out there available on the ...

Cryptolocker Ransomware Variant Hits Synology Users: Synolocker

When your products get targeted with custom made ransomware, you know you've got it made. We're talking about NAS (network-attached storage) built by Synology in Taiwan. the malware has ...

CryptoLocker copycat Cryptoblocker encrypts differently

Scam Of The Week: eBay Password Reset Phishing Emails

Ok, unless you were on an Internet-free vacation (fat chance); you have heard that eBay managed to lose all its 145 million credentials.

WARNING Third Ransomware Strain Called CryptorBit Attacks

Welcome to the new world of malware.

80% Fail To Maintain PCI Compliance Between Assessments

OUCH. Verizon said in a report this month that nearly 80% of organizations that achieve annual compliance with the PCI Data Security Standard -fail- to maintain that status after passing ...

NIST Releases Voluntary Cybersecurity Compliance Framework


Get the latest insights, trends and security news. Subscribe to CyberheistNews.