Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Scam Of The Week: Fortnite And League of Legends Phishing Attacks

This is an excellent opportunity to sit down with your young'uns and explain the risks of online scams.

Phishing Scam Is Targeting League of Legends Players

A phishing scam is using fake login pages to target League of Legends players, according to Avast Blog. At the moment, the attacks are taking place primarily in western Europe, mainly ...

Got A Chinese Vishing Scam Call in Mandarin

Howard, KnowBe4's HackBusters Discussion Forum Moderator reported on this very interesting phone call he got:

Has Microsoft Office 365 Beat Phishing?

By Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist. Microsoft recently announced a big update to their Microsoft Office 365 (O365) anti-phishing technical capabilities. ...

School Daze: Clever Phishing Emails Target Educational Organizations

By Eric Howes, KnowBe4 Principal Lab Researcher. It will surprise few people to learn that during our daily review of suspicious emails forwarded to us by users of the Phish Alert Button ...

Replica Phishing Sites Prey on User Trust

Attacks leveraging look-alike federated logon pages are more dangerous than malware-laden attachments in email.

KnowBe4 Top-Clicked Phishing Email Subjects for Q3 2018 [INFOGRAPHIC]

The latest results of KnowBe4's quarterly top-clicked phishing email subjects is now available. We report on three different categories: general emails, social media related subjects, and ...

[Heads-up] U.S. Government: "Your Weak Cyber Security Violates Federal Law"

Reuters just made me aware of a U.S. Securities and Exchange Commission report about a recent SEC investigation of nine companies that had been victims of CEO fraud had sufficient ...

It Only Takes One Phish: 37K Records and a Month of Access

The attack on California-based Gold Coast Health Plan went undetected, allowing attackers access to healthcare data serving as fuel for fraud.

UK publishers warn of global phishing scams targeting manuscripts

A succession of global phishing scams targeting publishers and agents has prompted responses from several global publishers, reports the Bookseller.

Organizations Need to Prepare for the Aftermath of Phishing Attacks

Phishing campaigns are growing more sophisticated as industries become increasingly aware of the threat they pose. Some of these attacks are so clever and meticulously crafted that many ...

Vishing Scams are Increasingly Difficult to Detect

Phone scams are becoming more convincing as attackers devise new ways to sound legitimate. KrebsOnSecurity recently spoke with several readers who'd been targeted by voice phishing, or ...

KnowBe4's Phish Alert Button Now Works With Outlook Mobile!

Do your users know what to do when they receive a suspicious email? Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report ...

Bleeding Edge Phishing Attack Uses Decoy PDF with Microsoft-issued SSL Cert

TL,DR: A recent phishing attack posing as a PDF decoy from a Denver law firm was stealing clients' Office 365 credentials. The phishing bait was hosted in Azure blob storage and contained ...

Worry About Phishing, Not Malware!

With so many security strategies revolving around the detection of malware, organizations forget the primary source of all their worries – phishing.

Kevin Mitnick weighs in on Facebook's big security breach

It was all over the news, and CNBC interviewed KnowBe4's very own Chief Hacking Officer Kevin Mitnick (note the StreetCred box on the right).

[InfoGraphic] 20 Ways to Block Mobile Attacks

To start your National Cyber Security Awareness Month (NCSAM) here is a goodie for your users to kick things off.

Targeted Attacks Replace Spam Campaigns

Spam campaigns are all but dead. But lucrative targeted low-risk, high-yield cyber-attacks have risen to take their place, according to the European Union law enforcement agency Europol.

Brand-New Tool: Domain Doppelgänger Identifies Evil Twin Domains

I gave you a heads-up a few days ago, and now I'm excited to announce the actual release of a new tool to help protect your organization from cybercriminals.

Ewww. Password managers can be tricked into believing that malicious Android apps are legitimate

Ewww. Something else to watch out for. Will it ever stop?. Ummm, no.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.