Human Risk Management Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

A Phishing Campaign Evades Email Gateways via WeTransfer

A phishing campaign is abusing the legitimate file hosting site WeTransfer to get malicious links through email filters, according to Jake Longden at Cofense. The attackers send real ...

HoneyTrap, The Oldest In The World Now As Iranian Catphish on LinkedIn

Iranian state-sponsored hackers are increasing their targeting of civilian targets amid escalating tensions between the US and Iran, according to Zak Doffman at Forbes. Doffman cites a ...

Q2 2019 Top-Clicked Phishing Email Subjects from KnowBe4 [INFOGRAPHIC]

KnowBe4 reports on the top-clicked phishing emails by subject lines each quarter in three different categories: subjects related to social media, general subjects, and 'In the Wild' - we ...

[Scam of The Week] New 'US State Police' Phishing Extortion Scam Includes Contact Numbers

Our friend Larry Abrams at Bleeping computer warned: "A new extortion scam is underway that pretends to be from a US State Police detective who is willing to delete child porn evidence if ...

U.S. Coast Guard Warns of Phishing Attacks Designed for Data Theft and Malware Infection

A new Marine Safety Information Bulletin from the U.S. Coast Guard demonstrates that cybercriminals aren’t just after land-based businesses.

U.K. Sees an Increase in Sophisticated Phishing Attacks Targeting Educational Institutions

Using a mix of identity deception, domain spoofing, credential theft, and bank fraud, scammers are taking advantage of soft targets in the U.K.’s education sector.

NSO spyware ‘targets Big Tech cloud services’

The Israeli company whose spyware hacked WhatsApp has told buyers its technology can surreptitiously scrape all of an individual’s data from the servers of Apple, Google, Facebook, Amazon ...

Lateral Phishing Used To Attack Organizations On Global Scale

Warwick Ashford at ComputerWeekly reported: "Lateral phishing is a growing type of account takeover that has enabled attackers to target more than 100,000 people by hijacking just 154 ...

Microsoft Notifies 10,000 Customers About Nation-state Cyber Attacks

In an article about cyber security related to voting machines, an interesting snippet of information surfaced: “Microsoft said it has notified almost 10,000 customers in the past year ...

[INFOGRAPHIC] Employees receive nearly five phishing emails per work week, according to Avanan

One in every 99 work emails is a phishing attack, according to a recent Avanan report. With employees accustomed to a busy inbox, it's easy to fall victim to a phishing attack disguising ...

Mimecast Identifies Brand New Phishing Tactic Called "SHTML"

In early April, researechers discovered a rare type of server-parsed HTML (SHTML) based phishing attack emerging from the UK.

UK Mid-Sized Firms Lost £30bn to CyberAttacks in 2018

Phil Muncaster at InfoSec Mag reported that "Cybersecurity incidents have cost UK mid-market firms a combined £30bn over the past year as automated attacks become the norm, according to ...

NEW SANS Whitepaper: Automating Response to Phish Reporting

As part of his SANS Technology Institute Master's degree, Geoffrey Parker recently published a whitepaper called Automating Response to Phish Reporting that got an A, was made a gold ...

An Amazon Phishing Scam Hits Just In Time For Prime Day

Amazon has confirmed that Prime Day 2019 will begin at 12 a.m. PT on Monday, July 15 and conclude at 11:59 p.m. PT on Tuesday, July 16.

TrickBot Malware May Recently Have Hacked 250 Million Email Accounts

Endgadged reported that "TrickBot malware may recently have stolen as many as 250 million email accounts, including some belonging to governments in the US, UK and Canada. The malware ...

Homeland Security Warning About Phishing As A Threat to 2020 Elections

The US Department of Homeland Security is warning state election officials that phishing attacks are one of the greatest threats to watch out for as the 2020 elections approach.

Automated Tailored EBAY Spam Campaign Leads to Risky Sites

Automated spam on eBay is spreading tailored phishing messages offering to promote users’ products, and the links the spammers share can lead to dangerous websites, according to Paul ...

Phishing And Impersonation Attacks Balloon in South Africa

South African companies saw an increase in phishing attacks containing malicious links or attachments in the past year. E-mail attacks are cheap, easy, low risk and high reward for cyber ...

Discovered This Year: 5,334 Kits Offering Evasive Criminal Phishing-as-a-Service

Commodity phishing kits are making it easier for unskilled criminals to run sophisticated phishing campaigns for a low price, according to a report from cloud security provider Cyren.

80% of all Brand Deception Phishing Scams Targeting Execs Pretend to be Microsoft

The prevalence of Office 365 and the Windows OS has caused cybercriminals to choose the software titan as their primary brand used in identity deception phishing scams.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.