Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Scam Of The Week: Phish With Hidden Sting

As you may have heard, KnowBe4 has released a no-charge Outlook Add-in that allows employees to report phishing attacks to their Incident Response team with just one click. It's called ...
Continue Reading

Scam Of The Week: Massive LinkedIn Spam Steals Passwords

"I feel like a complete idiot. I just got taken by a LinkedIn spam that may have just stolen my banking password." These words dropped in my inbox, written a while ago by Dan Tynan, ...
Continue Reading

ISIS "Celebrates" Paris With Video - Inoculate Users Against Phishing Attacks

OK, bad news first. The world is shocked and angry about the attacks in Paris. That often causes emotional reactions, which the bad guys on the Internet are exploiting. ISIS has released ...
Continue Reading

How to Phish Your Own Users And Why

Over the last few years, thousands of organizations in the U.S have started to phish their own users. IT pros have realized that doing this is urgently needed as an additional security ...
Continue Reading

WSJ Gives Powerful Ammo For More InfoSec Budget

A front page article in the Wall Street Journal describes the escalating arms race for a possible cyberwar. This article is a great way to get C-level execs a crash course about ...
Continue Reading

Teach your execs well: Stop phishing in the C-suite

J. Peter Bruzzese is an InfoWorld columnist and five-time-awarded Microsoft MVP (current technical expertise Office 365, previous four years Exchange). He is a technical speaker, author ...
Continue Reading

Postal employees fall to internal phishing sting

Aaron Boyd wrote: "Determined not to fall victim to another network breach, the U.S. Postal Service is phishing its own employees, testing their ability to recognize a scam before it's ...
Continue Reading

[INFOGRAPHIC] Men Twice As Likely To Fall For Phishing Attacks

In the never ending battle of the sexes, it looks as though women are winning the phishing fight according to new research from KnowBe4. In an analysis done by KnowBe4 of 201,755 phishing ...
Continue Reading

Men Are Twice As Likely To Fall For Phishing Attacks

In an analysis done by KnowBe4 of 201,755 phishing emails sent over the past 30 days, it was found men appear to be more prone to clicking on a phishing email than women. In further ...
Continue Reading

KnowBe4 got a CEO Fraud phishing attack. Wrong Mark!

KnowBe4 has been warning against "CEO Fraud" emails for a few months now, the FBI also calls them "Business Email Compromise" (BEC). I had been hoping we would get one of these ourselves, ...
Continue Reading

Report: Phishing costs average organization $3.7 million per year

If you extrapolate the total annual cost of phishing for the average organization it comes to more than $3.7 million. You could shave that down by $1.8 million though, with the right ...
Continue Reading

What Is Worse Than Ransomware? Business Email Compromise

You are getting your Scam Of The Week early. Yesterday, the FBI via their Internet Crime Complaint Center announced some shocking numbers. There is a 270 percent spike in victims and cash ...
Continue Reading

Phishing Alert: Warn Your Users Against Ashley Madison Scams Now

Your end-users saw this in the news yesterday, or will read about it today. The hackers who stole more than 36 million records from the Ashley Madison site (which makes it easy to cheat ...
Continue Reading

Tech Firm Ubiquiti Suffers $46M Cyberheist

Brian Krebs just reported on a massive $46M Cyberheist. Networking firm Ubiquiti Networks Inc. disclosed this week that cyber thieves recently stole $46.7 million using an increasingly ...
Continue Reading

Scam Of The Week: Microsoft Windows 10 Upgrade Installs Ransomware.

Major Operating System upgrades are usually a cause of confusion among end-users and the current Windows 10 upgrade is no exception. The bad guys exploit these confusions in several ways, ...
Continue Reading

AshleyMadison: Second Nightmare Phishing Problem

8/19/2015 UPDATE: Yesterday the full 10 Gigabyte database was released on the Internet, with all records including confidential files related to the company itself. People that registered ...
Continue Reading

Aggressive New Tech Support Social Engineering Scam

The Tech Support Scams are getting worse by the month. Here is a horror story that was just shared today. I suggest you read it, and keep alert for Red Flags like these! "My dad almost ...
Continue Reading

Spear Phishing Attack Results In $5.3 Million Bitcoin Cyberheist

"Newly leaked, confidential documents have revealed details into a cyberattack aimed at Bitstamp, a company that fundamentally deals as a cryptocurrency trader, according to a report in ...
Continue Reading

OPM Phishing Attack: "Your Data Was Hacked, How To Protect Yourself"

And yes, as we predicted, there are now phishing attacks that mimic Office of Personnel Management (OPM) data breach notifications. The breach has expanded to millions more records. It ...
Continue Reading

Magazine publisher loses $1.5M in phishing scam

Cyber-criminals have social engineered magazine publisher Bonnier Group out of at least $1.5m after hacking the CEO’s email. The total damage could be as much as $3.0 million. Bonnier ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews