Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

OPM Phishing Attack: "Your Data Was Hacked, How To Protect Yourself"

And yes, as we predicted, there are now phishing attacks that mimic Office of Personnel Management (OPM) data breach notifications. The breach has expanded to millions more records. It ...

Magazine publisher loses $1.5M in phishing scam

Cyber-criminals have social engineered magazine publisher Bonnier Group out of at least $1.5m after hacking the CEO’s email. The total damage could be as much as $3.0 million. Bonnier ...

Ransomware Resume Phishing Security Test Gets Monster Open Rate

Now here is a real IT Horror Story. A brand new KnowBe4 customer which had not yet trained their employees decided to test their staff with one of the new templates we had just released.

LastPass Hacked. Be Alert For Phishing Attacks

LastPass, the popular online password management service has been hacked and data was stolen, including the password hints, which is why you need to be alert for scams trying to exploit ...

Gone phishing: How I taught my users to stop clicking everything

Familiar with SpiceWorks? It's the world's largest IT Admin community. One user wrote the 392nd entry in their Spotlight on IT. This is the story. There is a link at the end to the ...

The Truth About The Massive OPMgate Hacking Scandal

The recent U.S. Government Office of Personnel Management hack is getting worse by the day. In Saturday's Wall Street Journal they revealed that apart from more than 4 million personal ...

Adult Friend Finder Hack Is Nightmare Phishing Problem

Guys, we have a real phishing problem with this Adult Friend Finder (AFF) hack. This particular adult site is one of the most heavily-trafficked websites in the U.S. and has 40 million ...

Researchers Observe SVG Files Being Used To Distribute Ransomware

Researchers with AppRiver have observed attackers sending out phishing emails with SVG files attached – these files, when downloaded and executed, open up websites that download what ...

Phishing in the C-Suite: 96% of Executives Vulnerable to Attacks

According to a recent survey, 96% of executives failed to tell the difference between a real email and a phishing email 100% of the time.

How Phishing Malware Rombertik Kills Your Hard Drives

InfoSec researchers at Cisco's TALOS group discovered a strain of malware that spreads through phishing. Attackers use social engineering tactics to entice users to download, unzip, and ...

What our customers are saying about our security awareness training

One of our customers sent us this today: "I wanted to give you an update on our security awareness training. When we did the baseline phishing campaign for 85 employees and we had a click ...

Your Antivirus Enduser Is Exposed To Phishing Attacks For 17.5 Hours

The 2015 Websense threat report is abundantly clear about it. "Websense detected 28 percent of malicious email messages before an antivirus signature became available, presenting AV users ...

10 Lessons Learned From Painful Ryanair $5M Cyberheist

Low-cost airline Ryanair shamefacedly came clean last week that they fell victim to a cyberheist which stole almost 5 million dollars out of its fuel bank account. The money was siphoned ...

Social Engineering Exploit Fools HR with Infected IT Resumes

Proofpoint threat researchers recently detected a clever email-based attack that combines phishing and social engineering techniques in order to trick users into opening a malicious ...

Scam Of The Week: Nepal Earthquake

More than 5,000 people dead and counting. And you can also count on cyber-criminals exploiting the disaster. What else is new. Disgusting. Scammers are now using the Nepal disaster to ...

How Criminals Exploit Gaps In Your Security Awareness Training

I was at RSA in San Francisco last week. Great show, with ~30,000 attendees and packed exhibit halls at the Moscone Center. We invited KnowBe4 customers who were attending RSA for a ...

90% of phishing incidents trace back to PEBKAC and ID10T errors

Don't have time to read through the massive Verizon's 2015 Data Breach Investigations Report? Here is a great summary; 90% of Security incidents are still caused by PEBKAC and ID10T ...

If You Think Security Awareness Training is Expensive, Try Ignorance

Facts surrounding spear phishing all point to employees as the most cited culprits and security awareness training as the most effective remedy. Yet all training programs are not equal. ...

KnowBe4 Offers White House Free Security Awareness Training

April 7, 2015 - CNN reported that The White House said it noticed suspicious activity in the unclassified network that serves the executive office of the president. The KnowBe4 Blog ...

Facebook sends simulated phishing attacks to their employees

Fortune reported: "Each fall, Facebook hosts an event called Hacktober in which its security experts attempt to trick employees into falling for common hacking tricks such as phishing ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.