Real Social Engineering Attack on KnowBe4 Employee Foiled

Stu Sjouwerman | Aug 14, 2024

SM-headerDavidB, the KnowBe4 VP of Asia Pacific and Japan, recently experienced a sophisticated social engineering attack via WhatsApp.

Late one evening, David received a call from someone impersonating Ani, KnowBe4's CHRO.

It started as a phone call, but intentionally set up so that the "connection was bad" and the call kept dropping. So David never really heard someone speaking, just background noise. Which led to the bad actor explaining he was on a flight, and requesting to do text because the "onboard wi-fi was apparently not allowing Whatsapp audio or video."

Although it was unusual for Ani to call at such hours, David did not immediately suspect foul play due to the current busy period. When they connected through text, the impersonator asked if David had any contacts at DBS Bank in Singapore to assist with an urgent financial matter.

The impersonator explained that they needed to wire funds for a family medical emergency, but the transfer was delayed by 48 hours. The request was not for money directly, but the impersonator mentioned an amount that quickly dropped when David said he'd like to help but he didn't have those funds, raising his suspicions.

Additionally, the caller addressed David by name instead of his usual friendly nickname that Ani typically used. David joked about needing to hit the "PAB" (Phish Alert Button) on this message, which was met with confusion by the impersonator.

To further verify, David asked about a dinner plan in Singapore, knowing Ani’s love for a local dish, but the impersonator could not respond appropriately. David then confirmed with Ani through Slack that he had not made the request, ending the conversation with the scammer, and reporting the incident to WhatsApp.

whatsapp-attack
Thanks to the security awareness training David received at KnowBe4, he was able to recognize and avoid this social engineering  attack.

Stop Being a Target for Social Media Exploits

Social media is the new frontier for targeted spear phishing and credential theft. Use our Free Social Media Phishing Test to identify which users are likely to click malicious links or leak data on platforms like LinkedIn and X, and get your results in just 24 hours.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.