Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Phishing from the Middle: Social Engineering Refined

By Eric Howes, KnowBe4 Principal Lab Researcher. Phishing attacks have long been associated with malicious emails that spoof well-known institutions in order to trick users into coughing ...

Phishing Reply Tracking Is Now Available for All KnowBe4 Customers

Two of the big cybersecurity attacks are the CEO Fraud (aka Business Email Compromise) which has caused $3.4 billion in damages as well as the W-2 Scams which social engineer ...

Kaspersky: DDoS Often Smokescreen For Phishing Attack

Distributed denial of service attacks, also known as DDoS, are becoming a major threat. They can bring websites and networks down, and generally make a lot of noise demanding attention. ...

Phishing Attack Hits Saudi Govt Networks With Disk-Wiping Malware

Hackers penetrated six Saudi Arabian government agencies including its General Authority of Civil Aviation, and bricked thousands of computers with the well-known Shamoon disk-wiper ...

10 Ways To Avoid Holiday Scams

With the biggest cybercriminal hacking holidays of the year upon us, it's time for a reminder of red flags to pay attention to when shopping either online or in brick-and-mortar stores.

New Phishing Category: Controversial/NSFW*Offensive Language*

We get thousands of real phishing emails in, reported to us by customers using the free KnowBe4 Phish Alert Button. On a daily basis, these reported phishing emails get analyzed by the ...

KnowBe4’s Phish Alert Button Now Works With G Suite!

Do your users know what to do when they receive a suspicious email? Should they call the help desk, or forward it? Should they forward to IT including all headers? Delete and not report ...

The LinkedIn Phishing Attack: How They Did It

by Eric Howes (Principal Lab Researcher) & Ryann Falke (Sales Development Representative) Last week we documented several interesting credentials phishes delivered through LinkedIn ...

City Of El Paso Victim Of 3 Million Dollar Phishing Scam

During a news conference Wednesday afternoon, city officials revealed that cybercriminals pretending to be a vendor scammed the city's Accounts Receivable Department out of about $3 ...

Yes, that email is really from LinkedIn. And, yes, it's really malicious.

By Eric Howes, KnowBe4 Principal Lab Researcher. Several months ago we blogged about a startling discovery by threat researchers at Proofpoint: the bad guys had figured out a way to turn ...

How Podesta got hacked: HelpDesk said 'Password' phishing email was real

John Podesta, Chairman of the 2016 Hillary Clinton presidential campaign was a victim of social engineering and rushed advice from his IT helpdesk. It's a comedy of errors. The helpdesk ...

A Slick Phish with a Hidden Surprise

By Eric Howes, KnowBe4 Principal Lab Researcher. Yesterday one of our customers was hit with a highly targeted phishing attack -- one of the slicker attacks we've seen in a while. Once we ...

Brazen: Phishing Attacks The Bad Guys Send When No One's Looking

When we talk with folks outside the security industry about what we see from the bad guys on a daily basis, we often get the response, "Wow! That's really sneaky." And it's true. The bad ...

These 500 Million Hacked Yahoo Accounts Are A Phishing Paradise. Warn Your Users!

It's all over the press. Here is a quote from Reuters: "Yahoo Inc said on Thursday information associated with at least 500 million user accounts was stolen from its network in 2014 by ...

Scam Of The Week: Apple Store Phishing Attack Goes For Whole Enchilada

Phishing attacks using false Apple Store email messages, fake landing pages and sometimes fake login pages are still a very popular attack vector. They still make it through all the ...

Bad Guy FAIL! or, When a Simple Credentials Phish Goes Horribly Wrong

By Eric Howes, KnowBe4 Principal Lab Researcher. Anyone who works a job in the computer security industry inevitably develops a kind of dark appreciation for the mad skills so often ...

Reported Phishes of the Week

KnowBe4's Templates Mistress Katie has been busy again adding a new batch of phishing templates to the collection of "System Templates" available to active subscribers.

Targeted Lawsuit Phishing Attack With Sophisticated Payload

We are seeing a big phishing wave with a social engineering attack that threatens with a personalized lawsuit using the domain name of the targeted victim. This is an interesting payload ...

"But, But, But... I Didn't Click!" False Positives In Phishing Tests

The following question was posted in the SANS Securing The Human forum. I thought it was a very good point and asked our VP Product Greg Kras for his perspective. First the question:

Funny Phishing Story: Your Online Order Receipt

A customer sent us this: Hi, I wanted to share with you a funny story…. My boss calls me into her office, very serious like. She sits me down and asks “Did you use the company credit card ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.