Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Almost One Quarter Of Canadians Have Clicked On A Phishing Link

TORONTO, March 1, 2018 /CNW/ - Online payment fraud like phishing is a growing trend, and Canadians are worried about it. According to a new survey conducted by Interac Corp., Canadians ...

Financial phishing accounts for over 50% of all phishing attacks for the first time

In 2017 Kaspersky Lab’s anti-phishing technologies detected over 246 million user attempts to visit different kinds of phishing pages. Of those, over 53 per cent were attempts to visit a ...

Organizations Are Failing To Learn From Phishing And Ransomware Attacks

Warwick Ashford, security editor at ComputerWeekly had an interesting observation after reading CyberArk's latest cyber threat report: "Organisations are failing to learn from cyber ...

Which phishing messages have a near 100% click rate?

Zeljika at HelpnetSecurity had a great summary of Wombat's latest State of the Phish report: "Training employees to spot phishing emails, messages and phone calls can’t be done just once ...

PHISHING SCHEMES NET HACKERS MILLIONS OF DOLLARS FROM FORTUNE 500

IBM has uncovered sophisticated CEO Fraud campaigns—aka Business Email Compromise—which are successfully targeting Fortune 500 companies. On Wednesday, researchers from IBM's X-Force ...

Cryptojacking Scripts And Phishing Pages Could Soon Invade Your Word Documents

Let's open that doc file and watch the Matrix again. Catalin Cimpanu at Bleepingcomputer had the scoop on this concerning news: "Cryptojacking scripts that mine Monero via JavaScript code ...

Edward Snowden returns to U.S.! Oops, nope, it's a phishing scam

Bradley Barth at SCMedia nailed it when he wrote: "No, NSA whistleblower and U.S. fugitive Edward Snowden did not just purchase a 2 terabyte storage plan for iCloud, nor has he moved back ...

Trusted Sites Often Deliver Phishing Attacks: Study

Ray Schultz at MediaPost had a great summary of some troublesome news: "Some of the world’s most popular websites are also the most dangerous when in comes to phishing attacks, according ...

New Multi-Stage Word Phishing Attack Infects Users Without Using Macros

Spam distributors are using a new technique to infect users with malware, and while this phishing attack relies on having users open Word documents, it does not involve social engineering ...

Lazarus Hacking Group back with new phishing campaign targeting banks and bitcoin users

The North Korean Lazarus Hacking Group, suspected to be behind the WannaCry ransomware attack last year, has returned with a new crime spree, this time targeting financial institutions ...

KnowBe4 Attains SOC 2 Type I Compliance For The Hosted Phishing And Training Product Offerings

KnowBe4, Inc, the world's largest security awareness training and simulated phishing platform, this week announced it has successfully completed a Service Organization Controls (SOC) 2 ...

New Trend In Phishing: Conversation Hijacking

Researchers see a new trend in phishing. Hackers are inserting themselves into email conversations between parties known to and trusted by one another. Once in, they exploit that trust to ...

2018 Winter Olympics Phishing Campaign Hides Evil PowerShell Script In Image

Jonathan, at our friends at Barkly wrote: "Hi all, according to researchers at McAfee, a new malware campaign is targeting organizations associated with the upcoming 2018 Winter Olympics ...

The Simulated Phishing Market Enters Early Adolescence

By Perry Carpenter, KnowBe4 Chief Evangelist and Strategy Officer We certainly live in fun times: Barracuda acquiring PhishLine Microsoft adding limited phishing simulation to Office 365 ...

Microsoft Confirms: "Sending Simulated Phishing Attacks to Your Employees Is a Must"

Well, Microsoft just legitimized the whole new-school security awareness training market. I'm pleased to note that Microsoft has finally acknowledged that organizations need to send ...

Who's Behind This Massive Wave of DDoS and Phishing Attacks Targeting Dutch Banks?

Shortly after the Dutch Volkskrant newspaper story about Netherlands Intelligence agencies compromising the prominent Russsian Cozy Bear hacking group and providing the US with ...

Phishing Messages from the Dark: When the Bad Guys Write Back

By Eric Howes, KnowBe4 Principal Lab Researcher. For most users the experience of dealing with phishing emails is a solitary experience, whether they recognize that they are under attack ...

Scam of The Week: Wave Of Payroll Direct Deposit Phishing Attacks

Lexology had an excellent post from Ogletree Deakins by Rebecca J. Bennett and Danielle Vanderzanden, related to a crafty new phishing scam they warned for and that you should be aware ...

[PHISHING ALERT] "Hey Did You See That Fake AI Porn Movie Of Yourself?"

Heads-up. I am sorry to have to bring up a very distasteful topic, but in the very near future your users will get phishing emails with something close to the ultimate click-bait, luring ...

Look out for More SMiShing This Year

Our friends at Social-Engineer wrote a great post that we are cross-posting here, because we see the same problem happening more and more! "With the new year come new social engineering ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.