Security Awareness Training Blog

Phishing Blog

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Office 365 Administrators are the Target of the Latest String of Phishing Attacks

Using a mix of fake admin alerts and a spoofed logon page, this newest campaign leverages IT’s urgency in fixing critical issues before they impact users.
Continue Reading

Iranian Hacker Group APT34 Use New ‘Tonedeaf’ Malware over LinkedIn in Latest Phishing Campaign

Targeting several key industries, this new campaign likely seeks to aid the Iranian government with information that could be of use to further Iran’s economic and security goals.
Continue Reading

[Heads-up] Nationwide Bomb Threat Extortion Phishing Attack Campaign With A Twist

IN OFFICES AND universities all across the country Thursday, the same threat appeared in email inboxes: Pay $20,000 worth of bitcoin, or a bomb will detonate in your building. Police ...
Continue Reading

Schools In Both The US And UK Victim Of Recent Phishing Attacks

A number of educational institutions have recently fallen victim to cyberattacks, highlighting the need for increased awareness training for students and faculty. SC Media UK has ...
Continue Reading

Romanian Cybercriminals Sentenced for Phishing Campaign

Our friends at Phishlabs wrote: "This week, the Department of Justice for the U.S. Attorney’s Office for the Northern District of Georgia announced the final of three sentences to be ...
Continue Reading

BEC = “Because it’s Easy Cash” Scammers Trick Employees Into Giving Away Customer Info

Business Email Compromise—also known as CEO Fraud—scammers are now targeting a company's customers using a new indirect attack method designed to collect information on future scam ...
Continue Reading

This Year, Phishing Causes Losses of $17,700 per minute And Ransomware Attacks Will Cost $22,184 Per Minute

Global losses to cybercrime total $1.5 trillion per year, which amounts to $2.9 million per minute, a new report by RiskIQ shows. Some of the largest companies are losing $25 each minute ...
Continue Reading

A Phishing Campaign Evades Email Gateways via WeTransfer

A phishing campaign is abusing the legitimate file hosting site WeTransfer to get malicious links through email filters, according to Jake Longden at Cofense. The attackers send real ...
Continue Reading

HoneyTrap, The Oldest In The World Now As Iranian Catphish on LinkedIn

Iranian state-sponsored hackers are increasing their targeting of civilian targets amid escalating tensions between the US and Iran, according to Zak Doffman at Forbes. Doffman cites a ...
Continue Reading

Q2 2019 Top-Clicked Phishing Email Subjects from KnowBe4 [INFOGRAPHIC]

KnowBe4 reports on the top-clicked phishing emails by subject lines each quarter in three different categories: subjects related to social media, general subjects, and 'In the Wild' - we ...
Continue Reading

[Scam of The Week] New 'US State Police' Phishing Extortion Scam Includes Contact Numbers

Our friend Larry Abrams at Bleeping computer warned: "A new extortion scam is underway that pretends to be from a US State Police detective who is willing to delete child porn evidence if ...
Continue Reading

U.S. Coast Guard Warns of Phishing Attacks Designed for Data Theft and Malware Infection

A new Marine Safety Information Bulletin from the U.S. Coast Guard demonstrates that cybercriminals aren’t just after land-based businesses.
Continue Reading

U.K. Sees an Increase in Sophisticated Phishing Attacks Targeting Educational Institutions

Using a mix of identity deception, domain spoofing, credential theft, and bank fraud, scammers are taking advantage of soft targets in the U.K.’s education sector.
Continue Reading

NSO spyware ‘targets Big Tech cloud services’

The Israeli company whose spyware hacked WhatsApp has told buyers its technology can surreptitiously scrape all of an individual’s data from the servers of Apple, Google, Facebook, Amazon ...
Continue Reading

Lateral Phishing Used To Attack Organizations On Global Scale

Warwick Ashford at ComputerWeekly reported: "Lateral phishing is a growing type of account takeover that has enabled attackers to target more than 100,000 people by hijacking just 154 ...
Continue Reading

Microsoft Notifies 10,000 Customers About Nation-state Cyber Attacks

In an article about cyber security related to voting machines, an interesting snippet of information surfaced: “Microsoft said it has notified almost 10,000 customers in the past year ...
Continue Reading

[INFOGRAPHIC] Employees receive nearly five phishing emails per work week, according to Avanan

One in every 99 work emails is a phishing attack, according to a recent Avanan report. With employees accustomed to a busy inbox, it's easy to fall victim to a phishing attack disguising ...
Continue Reading

Mimecast Identifies Brand New Phishing Tactic Called "SHTML"

In early April, the Mimecast Threat Center team discovered a rare type of server-parsed HTML (SHTML) based phishing attack emerging from the UK.
Continue Reading

UK Mid-Sized Firms Lost £30bn to CyberAttacks in 2018

Phil Muncaster at InfoSec Mag reported that "Cybersecurity incidents have cost UK mid-market firms a combined £30bn over the past year as automated attacks become the norm, according to ...
Continue Reading

NEW SANS Whitepaper: Automating Response to Phish Reporting

As part of his SANS Technology Institute Master's degree, Geoffrey Parker recently published a whitepaper called Automating Response to Phish Reporting that got an A, was made a gold ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews