KnowBe4 Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts

The US Federal Bureau of Investigation (FBI) has warned that a new phishing-as-a-service (PhaaS) platform called “Kali365” is targeting OAuth tokens to gain direct access to users’ ...

The Silent Invitation: A Deep Dive into Calendar Invite Phishing

Lead Analysts: Jeewan Singh Jalal and Prabhakaran Ravichandhiran

Chinese-Language Phishing Kits Are Growing More Advanced

Google’s Threat Intelligence Group (GTIG) is tracking phishing-as-a-service offerings in the rapidly expanding Chinese cybercriminal ecosystem, noting that at least a dozen of these ...

Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers

Scammers are using legitimate hotel booking details to craft targeted phishing attacks, WIRED reports. Victims are far more likely to fall for a phishing attack if a message contains real ...

Warning: Scammers are Exploiting Geopolitical Unrest

Scammers are taking advantage of the conflicts in the Middle East and Ukraine to exploit people’s emotions, according to researchers at ESET.

Ransomware Attacks Drive a Surge in Cyber Insurance Claims

Cyber insurance claims surged by 40% over the past eighteen months, while ransomware payments have dropped by 44%, according to a new report from Cowbell Cyber. The three most common ...

Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys

Lead Analysts: Jeewan Singh Jalal, Dilsha Dines, Karthikeyan Dharmaraj

Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks

Researchers at Push Security have analyzed a phishing platform used by organized criminal threat actors like ShinyHunters and BlackFile, finding more than 400 domains linked to attacks ...

Report: Adversarial Use of AI is Evolving

Threat actors are increasingly augmenting their attacks with AI tools, according to researchers at Google’s Threat Intelligence Group (GTIG). For the first time, GTIG observed a threat ...

Report: The Tycoon 2FA Phishing Kit Has Evolved

The Tycoon 2FA phishing-as-a-service platform is now using OAuth device code phishing to compromise devices that are protected by multifactor authentication, according to eSentire’s ...