Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Mysterious “double kill” Word/IE zero-day allegedly in the wild as phishing attack

“Double kill” is a bragging term from the world of violent video gaming – it means you finished off two assailants with a single shot. In the world of cybercrime, it’s the name given by ...
Continue Reading

[NEW WHITEPAPER] 10 Best Practices for Protecting Against Phishing, Ransomware and Email Fraud

Organizations have been victimized by a wide range of threats and exploits, most notably phishing attacks that have penetrated corporate defenses, targeted email attacks launched from ...
Continue Reading

Ransomware, Phishing, and Pretexting in the Annual Verizon Databreach Report

Did you know, 43% of breaches result from social engineering attacks? What's more, according to a recent Verizon investigation, phishing emails account for 98% of all social engineering ...
Continue Reading

[Heads-Up] Phishing Scam Of The Week: Bad Guys Go Nuclear

So, this one is the next new criminal low. This particular phish spoofs a campus-wide security alert for a community college (confidential information blocked out) in Florida. Given that ...
Continue Reading

Major uptick in mobile phishing URL click rate

In a study of Lookout users, more than half clicked mobile phishing URLs that bypassed existing security controls. Since 2011, Lookout has observed this mobile phishing URL click rate ...
Continue Reading

Phishing Tops IRS List of Tax-Related Scams for 2018

Michael Trimarchi at the Bloomberg Bureau of National Affairs wrote an excellent article about the continued risk of phishing, as reported by the IRS: "The stealing of personal ...
Continue Reading

Scam Of The Week: Fiendishly Clever Gmail Phishing Scam You Need To Know About

Twitter user @_thp shared a recent phishing scam that they received; and it’s so fiendishly clever that it’s gone viral. They wrote: "This is the most clever phishing scam I've ever ...
Continue Reading

SAM.Gov Hackers Were Handed Spear Phishing, Spoofing & Credential Theft On A Gold Platter

Cybercrooks who stole federal payments by hacking contractor accounts on a GSA website used sophisticated spear phishing techniques to steal login credentials and then diverted payments ...
Continue Reading

SAM.gov hackers used spear phishing, email spoofing and credential theft

Cybercrooks who stole federal payments by hacking contractor accounts on a GSA website used sophisticated spear phishing techniques to steal login credentials and then diverted payments ...
Continue Reading

Scam Of The Week: 150 Million Under Armour MyFitnessPal Users Are Now Phishing Targets

BREAKING NEWS: Under Armour's health- and fitness-tracking app, MyFitnessPal, has been hit by a data breach. Roughly 150 million MyFitnessPal users are affected, Under Armour says. Under ...
Continue Reading

US Disrupts 'Massive And Brazen' Iranian Phishing Scheme, DOJ Says

Friday morning the US Department of Justice announced that it had indicted Iran's Mabna Institute and nine of the individuals who work for it. The charges include conspiracy to commit ...
Continue Reading

UK National Lottery hacked: Watch Out For Phishing Attacks On Millions Of Customers

The UK National Lottery has warned more than 10 million players with online accounts to change their passwords due to a security breach, The Telegraph reported.
Continue Reading

Microsoft: "Phishing still number one method for cyber-attacks"

Redmond states the obvious: "Hackers are going for the low-hanging fruit." Microsoft has just released their Security Intelligence Report (SIR), its annual cybersecurity summary, and it ...
Continue Reading

Scam Of The Week: Phishing Madness!

Beware of March Madness, criminal hackers are at it again, after Valentine's Day their phishing agenda has moved to the next topic. They are now spoofing popular March Madness websites, ...
Continue Reading

Phishing Is Culprit Behind Vast Majority of Data Exfiltration, Intelligence Official Says

Phil Goldstein at FedTech magazine had some concerning news. "A top federal counterintelligence official says agencies must do more to harden their cybersecurity defenses, even if that ...
Continue Reading

FTC Study: Millennials Are The Biggest Victims Of Social Engineering

A report from the FTC found that 40% of adults age 20-29 lost money to fraud, while only 18% of adults over the age of 70 did so, challenging the narrative of older adults falling victim ...
Continue Reading

[ALERT] A Really Difficult Phishing Scenario That's Very Hard To Beat

I was alerted by a customer about a really difficult scenario that’s becoming all the more frequent. While there’s probably little that can be done in terms of tuning your spam filters ...
Continue Reading

Phishing Via Social Media Up 100 Percent

Fabian Libeau at InformationSecurityBuzz wrote: "The most interesting trend to surface in Q4 of RiskIQ’s phishing report was a 100 percent increase in phishing campaigns leveraging social ...
Continue Reading

New Phishing Security Test - See How You Compare to Peers in Your Industry!

We've got something really cool for you: the new Phishing Security Test v3.0!
Continue Reading

W-2 information of Scottsboro City Schools employees compromised in phishing incident

SCOTTSBORO, Ala. - The information of Scottsboro City Schools employees became compromised after a phishing scam hit the payroll department. The superintendent issued a letter addressed ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews