Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Executive Impersonation Business Email Compromise Attacks Go Beyond English Worldwide

Despite hearing mostly about BEC attacks in English-speaking countries, analysis of new attack groups highlight the threat of these kinds of attacks in other languages.

[On-Demand] A Master Class on Cybersecurity: Roger Grimes Teaches Data-Driven Defense

Even the world’s most successful organizations have significant weaknesses in their cybersecurity defenses, which determined hackers can exploit at will. There’s even a term for it: ...

Your KnowBe4 Fresh Content Updates from February 2023

Check out the 24 new pieces of training content added in February, alongside the always fresh content update highlights, events and new features.

Financial Services Sector at Risk of More Significant Impacts of Email-Based Cyber Attacks

Financial services businesses are already in the sights of cybercriminals, and understanding how cyber attacks impact this sector specifically can help establish the need for improved ...

CISA's latest ransomware warning promotes fighting social engineering at the top of the document, once again

So, today CISA released another ransomware notice. The Cybersecurity and Infrastructure Security Agency is an agency of the United States Department of Homeland Security that is ...

[On-Demand] 5 Ways PhishER Saves You Time and Money

Time is the one resource you never get back. Cutting the amount of time between the moment your user reports a suspicious email and when your InfoSec team responds can mean the difference ...

Customer Care Numbers as Phishbait

Researchers at CloudSEK have published a report looking at fraudulent customer service phone numbers in India. The researchers found around 20,000 of these phone numbers targeting users ...

[Eye Opener] Businessweek: The Satellite Hack Everyone Is Finally Talking About

This morning, Bloomberg News pointed at a brand new article at BusinessWeek, one of their media properties. This is an excellent article that exposes the vulnerabilities when ...

Remote Workers Significantly Increase the Cost of Remediating Email-Based Cyberattacks as Costs Average $1 Million

With the average cost of the most expensive successful email attack at over $1 million, it’s necessary to begin to zero in on where the material sources of risk exist to keep these ...

NameCheap’s SendGrid Email Account Compromised, Used to Send Phishing Emails

Since phishing attacks need legitimacy to increase their deliverability, this latest twist shows how phishing scammers and hackers are working together to ensure phishing attacks continue.

Business Email Compromise Gang Gets Jail Time for Stealing Millions

An international cybercriminal operation responsible for millions of dollars in business email compromise (BEC) scams has finally been dismantled.

Blind Eagle Goes Phishing

BlackBerry has published a report on a threat actor, Blind Eagle, also known as APT-C-36, which has been operating against targets in Ecuador and Colombia since at least 2019. Its most ...

CyberheistNews Vol 13 #09 [Eye Opener] Should You Click on Unsubscribe?

CyberheistNews Vol 13 #09 | February 28th, 2023 [Eye Opener] Should You Click on Unsubscribe? By Roger A. Grimes. Some common questions we get are "Should I click on an unwanted email's ...

GLBA and Other Regulations Wake Up to the Importance of Security Awareness Training With  June 9, 2023 Deadline

Most computer security practitioners have understood for many years the importance of having an aggressive security awareness training program. As social engineering is involved in 70% to ...

Thousands of NPM Packages Used to Spread Phishing Links

Researchers at Checkmarx warn that attackers uploaded more than 15,000 packages to NPM, the open-source repository for JavaScript packages, to distribute phishing links. The packages ...

Malware Report: The Number of Unique Phishing Emails in Q4 Rose by 36%

With nearly 280 million phishing emails detected by just one vendor, and the increase in the number of unique emails, organizations have a lot to be worried about in 2023.

W-2s Are Just the Beginning of Tax-Related Scams This Year

Email scammers can’t pass up a tried and true theme that is almost guaranteed to produce results. And with W-2 forms being sent out, it marks the start of this year’s expected campaigns.

Ransomware Attacks Using Extortion Tactics Reaches Critical Mass at 96% of all Attacks

New cyber attack data from 2022 is providing insight into what to expect in 2023, including ransomware campaigns.

28% of Users Open BEC Emails as BEC Attack Volume Skyrockets by 178%

New data shows users aren’t scrutinizing emails used in business email compromise (BEC) attacks, allowing critical changes in banking details that would impact the victim's organization ...

What Is a Good Survey Rating for Security and Compliance Training?

We received great feedback from many of you after sharing data about completion percentages last month so much that we thought, “What other things can we share from our vast amount of ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.