Phishing Alert: Cybercriminals Impersonating KnowBe4 Training Emails



Phishing Attacks In the ever-evolving landscape of cybersecurity threats, we've recently encountered a sophisticated phishing attempt targeting one of our valued KnowBe4 customers. This incident serves as a crucial reminder of the importance of remaining vigilant and maintaining robust email security measures.

Our customer received a suspicious email that closely mimicked KnowBe4's legitimate "Please Complete Assigned Training" notifications. At first glance, the email appeared authentic, demonstrating the increasing sophistication of phishing attacks.

Here's an example of what the phishing email looked like:

Screenshot 2024-10-31 at 1.39.13 PM

Fortunately, the customer's email security controls successfully blocked the malicious email as it failed DMARC  authentication.

Key Indicators of the Phishing Attempt

  1. Spoofed Sender Domain: Upon examining the email headers, it was discovered that the email was sent from a suspicious domain: [@]docusign[.]gr[.]com. This is a clear red flag, as legitimate KnowBe4 emails would never originate from a third-party domain.

  2. Malicious URL: The email contained a link to concursolutions[.]us[.]com, which is not associated with KnowBe4. At the time of writing, this site has been taken down, but it was likely a phishing page designed to steal credentials or other sensitive information.

Lessons Learned and Best Practices

This incident highlights several important points:

  1. Email Authentication is Crucial: The customer's DMARC implementation successfully caught this phishing attempt. We strongly recommend all organizations implement and maintain strict DMARC, SPF, and DKIM policies.

  2. URL Inspection: Always hover over links to verify their destination before clicking. In this case, the URL clearly did not lead to a KnowBe4-owned domain.

  3. Sender Verification: Check the full email address of the sender, not just the display name. Legitimate KnowBe4 emails will always come from a knowbe4.com domain.

  4. Stay Informed: Cybercriminals are constantly updating their tactics. Regular security awareness training helps employees stay ahead of these evolving threats.

  5. When in Doubt, Reach Out: If you're unsure about an email's legitimacy, contact your IT department or the supposed sender through a known, trusted channel.

We urge all our customers and partners to remain vigilant against these types of attacks. Cybercriminals are increasingly targeting security-aware organizations, hoping to catch even the most cautious users off guard.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews