Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

New Trend In Phishing: Conversation Hijacking

Researchers see a new trend in phishing. Hackers are inserting themselves into email conversations between parties known to and trusted by one another. Once in, they exploit that trust to ...

2018 Winter Olympics Phishing Campaign Hides Evil PowerShell Script In Image

Jonathan, at our friends at Barkly wrote: "Hi all, according to researchers at McAfee, a new malware campaign is targeting organizations associated with the upcoming 2018 Winter Olympics ...

The Simulated Phishing Market Enters Early Adolescence

By Perry Carpenter, KnowBe4 Chief Evangelist and Strategy Officer We certainly live in fun times: Barracuda acquiring PhishLine Microsoft adding limited phishing simulation to Office 365 ...

Microsoft Confirms: "Sending Simulated Phishing Attacks to Your Employees Is a Must"

Well, Microsoft just legitimized the whole new-school security awareness training market. I'm pleased to note that Microsoft has finally acknowledged that organizations need to send ...

Who's Behind This Massive Wave of DDoS and Phishing Attacks Targeting Dutch Banks?

Shortly after the Dutch Volkskrant newspaper story about Netherlands Intelligence agencies compromising the prominent Russsian Cozy Bear hacking group and providing the US with ...

Phishing Messages from the Dark: When the Bad Guys Write Back

By Eric Howes, KnowBe4 Principal Lab Researcher. For most users the experience of dealing with phishing emails is a solitary experience, whether they recognize that they are under attack ...

Scam of The Week: Wave Of Payroll Direct Deposit Phishing Attacks

Lexology had an excellent post from Ogletree Deakins by Rebecca J. Bennett and Danielle Vanderzanden, related to a crafty new phishing scam they warned for and that you should be aware ...

[PHISHING ALERT] "Hey Did You See That Fake AI Porn Movie Of Yourself?"

Heads-up. I am sorry to have to bring up a very distasteful topic, but in the very near future your users will get phishing emails with something close to the ultimate click-bait, luring ...

Look out for More SMiShing This Year

Our friends at Social-Engineer wrote a great post that we are cross-posting here, because we see the same problem happening more and more! "With the new year come new social engineering ...

Scam Of The Week: The Most Sophisticated Netflix Phishing Yet

This Netflix phishing campaign goes after your login, credit card, mugshot and ID! Paul Ducklin at Sophos wrote: "Think of the big security stories of recent months. Security holes like ...

KnowBe4 2017 Top Clicked Phishing Test Analysis

Click on the Picture to download the full infographic in PDF format Looking at the whole of 2017, there were some interesting shifts on what phishing emails were clicked from quarter to ...

Forget Viruses or Ransomware—Is Your Biggest Cyberthreat Greedy Cryptocurrency Miners?

This week, cybersecurity firm Check Point published its regular Global Threat Index. Malware that hijacks workstations to mine cryptocoins has apparently become the most popular infection ...

Business Email Compromise Phishing Attacks Will Exceed $9 Billion This Year

Trend Micro reported that Business Email Compromise (BEC) is projected to skyrocket as attackers use more and more sophisticated social engineering tactics to trick their targets. The ...

Three-Quarters of Businesses Saw Phishing Attacks in 2017

Tara Seals at InfoSecurity Magazine had a good summary of Wombat Security Technologies' annual State of the Phish research report. "The war against phishing is still on, with 76% of ...

Google’s Confusing Gmail Security Alert Looks Exactly Like a Phishing Attempt

Note: I got this too and had a similar reaction last week. Security researchers say the legitimate email is training people to have bad email hygiene. Richard De Vere, a security ...

Spend One Minute And Look At These Phishing Graphs

In the first quarter of 2018, after 7 years of helping our customers to enable their employees to make smarter security decisions and having reached the milestone of 15,000 customers, we ...

[On-Demand Webinar] Phishing Attack Landscape and Benchmarking

The most persistent security challenge you face today is bad guys social engineering your users. Phishing campaigns continue to be hacker’s No.1 preferred attack vector to get your ...

SNAFU Some AV Tools Cause BSODs And Boot Failures After Meltdown Patches

Microsoft's patch to protect Windows computers from the Meltdown / Spectre "hardware bug" revealed the rootkit-like nature of many antivirus tools. Some AV products are incompatible with ...

One surprising statistic explains why phishing will remain the most common cyberattack for the next few years

Phishing will remain the primary email attack vector through 2020. A new report from Comodo Security Threat Lab's VP, Fatih Orhan, brings up an interesting statistic from Friedrich ...

Report: Most Government Agencies Vulnerable To Phishing

Nearly half of federal agency email domains have adopted policies to collect data on unauthorized emails, a move mandated by the Department of Homeland Security in October, according to a ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.