KnowBe4 Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Embedded Email Attacks Are on the Rise and Aren’t Being Detected by Security Solutions

This classic tactic is making a comeback and is elegantly simple to execute, yet sufficiently complex enough to keep email scanning solutions from seeing it as malicious.

[EYE OPENER] New EU Phishing Study Shows That Crowd-sourcing Phishing Defense Is Successful

A Swiss phishing study involving roughly 15,000 participants in a 15-month experiment produced some interesting results. The study was run by researchers at ETH Zurich, working together ...

Wall Street Journal article: "Shaming Employees For Phishing is Counterproductive"

Shaming employees for falling for phishing attacks is the wrong approach, according to Dr. Karen Renaud, a chancellor’s fellow at the University of Strathclyde. In an article for the Wall ...

The Unbearable Lightness of Phishing Pages

Researchers at Kaspersky have found that most phishing pages are active for less than one day, with many of them going offline after just a few hours. Most of these short-lived pages were ...

Credential-Harvesting Phishing Campaign Urges Review of Spam

Researchers at MailGuard have observed a phishing campaign that’s using phony “spam notification” emails that purport to come from Microsoft Office 365. The emails tell recipients that an ...

New Phishing Campaign has Fake DHL Shipping

Researchers at Avanan have spotted a new phishing campaign that’s impersonating DHL with phony shipping notifications. The emails inform the recipients that they need to update their ...

[Heads Up] First Omicron Phishing Attack Spotted In The UK

Bleepingcomputer had the scoop. Phishing actors have quickly started to exploit the emergence of the Omicron COVID-19 variant and now use it as a lure in their malicious email campaigns. ...

91% of All Baiting Attacks Use Gmail to Collect Intel on Potential Victims

This rudimentary form of phishing contains no malicious links or attachments but serves a very important purpose for cybercriminals and scammers looking to better target victims.

Holiday Shopping and Phishing-as-a-Service

Researchers at Egress observed a massive increase in phishing kits in the run-up to Black Friday, particularly those impersonating Amazon.

Phishing Attacks Smash All Records in Q3 2021 With the Highest Monthly Number of Attacks Ever

New data shows the business of phishing is moving “up and to the right” in nearly every way measurable, indicating a serious problem as threat actors continue to see growing success.