Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

And Just When You Thought Locky Ransomware Had Disappeared...

Locky ransomware reappeared with a vengeance Friday, this time not using Office documents combined with social engineering to have the user enable macros, but with a PDF that has a Word ...
Continue Reading

[ALERT] Aaron Hernandez Death Phishing Scams

Low-life scum is exploiting the deaths of famous people, such as the suicide yesterday of former N.E. Patriots player Aaron Hernandez.
Continue Reading

First Quarter 2017 Top-Clicked Phishing Email Subjects [INFOGRAPHIC]

KnowBe4 customers run millions of phishing tests per year, and we report frequently on the top-clicked phishing topics so that our customers know what the highest-risk phishing templates ...
Continue Reading

Scammers Phishing for financial credentials on Twitter

Steve Ragan at CSO wrote: "Scammers are using Twitter as a vehicle to target people looking for customer support or asking general questions. They interject themselves into legitimate ...
Continue Reading

Cybersecurity IQ: Americans Have Trouble Recognizing Phishing Attacks

A new Pew Research Center survey titled "What the Public Knows about Cybersecurity." tallied responses from 1,055 adults last year about their understanding of concepts important to ...
Continue Reading

Which phishing emails fooled the most people? [INFOGRAPHIC]

Kevin Mitnick, our Chief Hacking Officer forwarded this great poster to me he found on Twitter today: "Which phishing emails fooled the most people?" Share it with your users!
Continue Reading

Scam Of The Week: The Evil Airline Phishing Attack

Our friends at Barracuda run their Email Threat Scanner over hundreds of thousands of customer mailboxes and discovered a highly effective phishing attack that tricks a whopping 90% of ...
Continue Reading

SecureWorks Exposes Phishing Russian Hacker Gang APT28

Atlanta-based SecureWorks has a Counter Threat Unit which has been closely watching the Russian hacker gang APT28 over the last few years and released brand new research. This group of ...
Continue Reading

Who Were The Two Big US Tech Companies That Lost $100 Million In CEO Fraud?

4/28/2017 UPDATE: Facebook and Google confirmed as victims of $100M phishing scam. Story at The Verge. In an update on an earlier post of April 2016, more detail came known about this ...
Continue Reading

Scam Of The Week: New FBI and IRS Alerts Against W-2 Phishing

There is a wave of W-2 phishing attacks going on. We see these coming in through thousands of reported scam attempts via our Phishing Alert Button. The FBI and the IRS have repeatedly ...
Continue Reading

SEC Phishing Emails Target Execs For Inside Info

A sophisticated phishing attack is trying to get confidential corporate information. Bad guys are sending spoofed emails claiming to be from the Security and Exchange Commission, and ...
Continue Reading

Scary new malware hides in memory, uses DNS to communicate, and spreads through phishing

Cisco has a separate threat research group called Talos. They just published a report on a scary new form of malware that’s hard to detect. They called it DNSMessenger, and the malicous ...
Continue Reading

Verizon: "Most Breaches Trace to Phishing, Social Engineering"

BankInfoSecurity wrote: "Ninety percent of data breaches seen by Verizon's data breach investigation team have a phishing or social engineering component to them. Not coincidentally, one ...
Continue Reading

2016 Exceeds All Records in Numbers of Phishing Attacks

Year over year sustained growth in phishing campaigns produces yet another record number of attacks The Anti-Phishing Working Group (APWG) observed that 2016 ended as the worst year for ...
Continue Reading

Which User Will Infect Your Network With Ransomware?

We've got something really cool for you: the new Phishing Security Test v2.0! It's got several great new features, and sending simulated phishing emails to train your employees is a fun ...
Continue Reading

Phishing Attack Uses Stuxnet Technology And Makes PCs Into Roombugs

Researchers have uncovered an advanced malware-based operation that siphoned more than 600 gigabytes from about 70 targets in a broad range of industries, including news media, and ...
Continue Reading

Survey: Most Hackers Break In Within Six Hours

A recent survey of 70 professional hackers and penetration testers found that 60% of them take a maximum of just six hours to compromise a target. The research titled The Black Report, ...
Continue Reading

Google: "Office Inbox Receives 6.2X More Phishing And 4.3X More Malware Than Your Inbox At Home".

Google Research analyzed over a billion emails passing through Gmail, and the results were presented yesterday at the RSA security conference in San Francisco. Extremely interesting ...
Continue Reading

Scam Of The Week: Valentine’s Day Phishing Attacks

It is time to remind your users that heartless con artists use social engineering tactics to trick people looking for love. The FBI's Internet Crime Complaint Center warns every year that ...
Continue Reading

Careless Licking Gets A Nasty Ransomware Phishing Infection: 1,000+ Machines Down

More than 1,000 government computer systems shut down. A county in Ohio, US, has had to shut down its entire IT infrastructure due to a ransomware infection. County Auditor Mike Smith ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews