Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Scammers Use a $100 Amazon Gift Card to Deliver the Banking Trojan Dridex to Their Victims

It appears the holidays aren’t without a cyber-grinch, as attackers use the lure of free money in the form of a gift card as an easy means to trick victims into infecting their own ...
Continue Reading

2020 Top Phishing and Vishing Attacks And Trends

It’s an extra challenging year, harder than most, to choose the most impactful cybersecurity events. The year ended with a bang – the Solarwinds supply chain attack – which possibly ...
Continue Reading

What You Need to Know About DMARC

It's true - not enough organizations utilize DMARC, SPF, and DKIM, global anti-domain-spoofing standards, which could significantly cut down on phishing attacks. But before you implement ...
Continue Reading

BEC Attacks Nearly Doubled in 2020

A new report from Barracuda Networks found that business email compromise (BEC) attacks have nearly doubled over the past year. These attacks made up 12% of all spear phishing attacks in ...
Continue Reading

Cybercriminals Attempt to Exploit Australian Fears on COVID-19

The bad guys are attempting to take advantage of Australian fears of COVID-19 in 2021. The National Identity and Cyber Support Service of Australia and New Zealand ID Care recently warned ...
Continue Reading

A Friend Needs Money Urgently? You're Probably Getting Scammed

People need to be on the lookout for phishing attacks sent from legitimate but compromised social media accounts, according to Paul Ducklin at Naked Security. Ducklin describes a scam ...
Continue Reading

How Can You Be More at Risk With MFA?

In my recent comment on the Solarwinds’ cyber attack, I made the claim that using multifactor authentication (MFA) can sometimes make you more at risk than using a simple login name and ...
Continue Reading

Private Online Shopping Risks Affect Businesses, Too

Consumers aren’t the only ones who can be victimized by social engineering attacks while shopping online, according to Arab News. Employees who use work devices for personal shopping are ...
Continue Reading

FireEye's Mandia on SolarWinds hack: 'This was a sniper round'

Joe Warminsky at Cyberscoop wrote: "The foreign espionage operation that breached several U.S. government agencies through SolarWinds software updates was unique in its methods and ...
Continue Reading

Just 8% of U.K. Firms Offer Regular Security Training

A majority of UK businesses are failing to adequately train their remote working employees to spot security threats, according to new research from iomart. The cloud services company ...
Continue Reading

[HACK ALERT] Here Is A Whole New Way Cyber Criminals Empty Out Your Bank Account

Researchers at IBM discovered a brand new type of massive banking fraud campaign that raked in millions of dollars over the course of a few days before it was put to a stop.
Continue Reading

No, it's not You in the Facebook Video... it's a Phishing Link

Scammers are using compromised Facebook accounts to circulate phishing attack to the hacked accounts’ friends, according to Paul Ducklin at Naked Security. The links are sent via Facebook ...
Continue Reading

New Office 365 Credential Scam Uses a Received Fax to Trick Victims

A clever mix of brand impersonation, a supposedly received message, a thumbnail preview, and new spoofed Office 365 logon pages are all that’s needed to trick victims into giving up ...
Continue Reading

[INFOGRAPHIC] Holiday Phishing Red Flags to Watch Out For

Phishing attacks never slow down during the holiday season. Experian reported that 1 in 4 victims fell victim to fraud during the holidays.
Continue Reading

Learning More on Social Engineering Tactics are the Key to Preventing Phishing Expeditions

Understanding social engineering attacks is the key to thwarting them, according to Juan Badell and Russell Petrich, content designers for Sophos’s phishing simulation service. Badell and ...
Continue Reading

University-themed Phishbait Angles for Students

Researchers at Zix have observed phishing emails sent from legitimate but compromised university email accounts, impersonating the university’s IT department. The emails notified users ...
Continue Reading

Facebook Describes APT32 Social Engineering Campaign

Facebook’s security team has taken action against a phishing operation run by APT32 (also known as OceanLotus), a threat actor associated with the Vietnamese government. Facebook says the ...
Continue Reading

[HEADS UP] New York DMV Warns of Phishing Attack

According to the Press Republican, the New York State Department of Motor Vehicles warned New Yorkers last Friday of ongoing SMS phishing (aka smishing) attack.
Continue Reading

Zoom Phishing is Still Rampant

Cybercriminals are still using Zoom and other conferencing platforms as phishbait, according to Zlati Meyer at Fast Company. This phishing theme isn’t likely to let up any time soon, so ...
Continue Reading

Shame! Shame! I Got Phished

I can’t be phished. At least that’s what I used to believe.
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews