Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Three Lessons from a Recent MegaCortex Ransomware Phishing Attack

The MegaCortex strain of ransomware has been used in criminal campaigns targeting businesses as opposed to private individuals. The QuickBooks cloud-hosting firm iNSYNQ, has sustained ...
Continue Reading

Varieties of Extortion Experience

We are all familiar with ransomware and its increasingly dangerous cousin, wiper malware. The first encrypts your files and demands ransom payments in exchange for the decryption key. The ...
Continue Reading

Business Email Compromise Doubles in Incidents and Triples in Cost

The latest data from the U.S. government’s Financial Crimes Enforcement Network (FinCEN) shows fraud via business email is changing tactics and becoming more effective.
Continue Reading

Email Attacks are Having A Major Impact on Business with Employees Seen as a Major Weak Link

With 82% of organizations facing an attempted email-based security threat in the past year, the impacts of these attacks are material and potentially harmful to the organization.
Continue Reading

CEO Fraud hits B.C. lawyers for $2 million

Two B.C. law firms were targets of so-called social engineering frauds causing almost $2 million in real estate and investment funds to be wired to people other than clients the firms ...
Continue Reading

Confirm Your Unsubscribe Request? Not So Fast

An email phishing campaign that BleepingComputer describes as “long-running” has shown a distinct uptick recently. The phishbait in the subject line will read something like this: ...
Continue Reading

Bad Guys Exploit CapitalOne Breach to Push Backdoor Trojan

The bad guys are now exploiting news of the CapitalOne breach to push a malicious backdoor trojan via a phishing email purporting to offer a Windows Security Update. See the attached ...
Continue Reading

Why Is Windows Defender The World's No. 1 Antivirus With More Than Half A Billion EndPoints?

Having been inside the AntiVirus software industry for quite a while, and building an AV tool from the ground up, when I saw Redmond start acquiring several small AV companies in 2008 and ...
Continue Reading

Engineering Licensing as Phishbait

Researchers at Proofpoint have observed a state-sponsored spearphishing campaign targeting three US utilities companies. The emails convincingly posed as exam results from the National ...
Continue Reading

Freight Forwarding Email Scams are Business Killers

The Australian Cyber Security Centre (ACSC) has warned that multiple Australian IT suppliers have permanently closed their doors after falling victim to procurement scams, CRN reports. ...
Continue Reading

Scam Of The Week: Equifax Settlement Phishing

Well, that did not take long! The Equifax Data Breach resulted in a settlement and those affected have a choice between free credit monitoring or a $125 payment.
Continue Reading

Buyers of Facebook’s Libra Cryptocurrency are the Latest Target in Phishing Scams

Scammers are impersonating Facebook to trick potential buyers of Facebook’s new cryptocurrency into parting with their money.
Continue Reading

Russian Phishing: Swiss-based Email Provider ProtonMail Hit By Cyber Attack

Reporters investigating Russian military intelligence have been targeted by highly sophisticated cyber attacks through their encrypted email accounts, with evidence suggesting Moscow was ...
Continue Reading

CEO Fraud Phishing Scams Versus The U.K. Solicitors

The UK’s Solicitors Regulation Authority (SRA) has warned of another email scam that impersonated a real law firm in order to hijack a real estate transaction, according to Martin Parrin ...
Continue Reading

15-year old MyDoom Remains a Common Phish Hook

The destructive email worm MyDoom is still very active more than fifteen years after it was first spotted, according to ZDNet. Researchers at Palo Alto Networks’ Unit 42 observed 663,000 ...
Continue Reading

Office 365 Administrators are the Target of the Latest String of Phishing Attacks

Using a mix of fake admin alerts and a spoofed logon page, this newest campaign leverages IT’s urgency in fixing critical issues before they impact users.
Continue Reading

Iranian Hacker Group APT34 Use New ‘Tonedeaf’ Malware over LinkedIn in Latest Phishing Campaign

Targeting several key industries, this new campaign likely seeks to aid the Iranian government with information that could be of use to further Iran’s economic and security goals.
Continue Reading

[Heads-up] Nationwide Bomb Threat Extortion Phishing Attack Campaign With A Twist

IN OFFICES AND universities all across the country Thursday, the same threat appeared in email inboxes: Pay $20,000 worth of bitcoin, or a bomb will detonate in your building. Police ...
Continue Reading

Schools In Both The US And UK Victim Of Recent Phishing Attacks

A number of educational institutions have recently fallen victim to cyberattacks, highlighting the need for increased awareness training for students and faculty. SC Media UK has ...
Continue Reading

Romanian Cybercriminals Sentenced for Phishing Campaign

Our friends at Phishlabs wrote: "This week, the Department of Justice for the U.S. Attorney’s Office for the Northern District of Georgia announced the final of three sentences to be ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews