Human Risk Management Blog

Security Awareness Training

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

You Should Be Scared of the Latest Strains of Phobos Ransomware

In an unusual twist, it’s not actually the ransomware itself that makes the newer forms of Phobos so frightening; it’s the people behind the attacks that will have you worried.

Happy Hotel With a Sad Ending

Tokyo, Japan-based Almex which operates the Japanese Happy Hotels announced it has been hacked and that customer data including email address, birth date, gender, phone number, log in, ...

Nobel Laureates Get Scammed, Too

Nobel Prize-winning economist and New York Times Opinion columnist Paul Krugman appears to have been taken in by a phishing scam, Business Insider reports. In a tweet that’s since been ...

Hackers Target the Special Olympics of New York and Use them to Launch Phishing Attacks

This latest attack demonstrates how cybercriminals can leverage one organization as merely a part of a larger phishing campaign to scam countless individuals out of credentials or money.

Fast Work By Cops Recovers $710,000 After CEO Fraud Attack Hits Long Island County Government

Finally some good news. Newsday reports that in record time, Nassau County, New York, recovered $710,000 that was transferred to scammers who were impersonating an existing county vendor.

Auto Dealership Becomes Latest Victim of Ransomware Attack Costing Up to $500,000

The opening of a seemingly benign email from a coworker by an unsuspecting employee set in motion an attack that brought operations to a halt and resulted in some costly remediation. The ...

Microsoft Sues Hacker Group for Data Theft of Highly Sensitive Information

A new recently unsealed lawsuit against a North Korean hacker group shows how even the largest companies can be successfully attacked by phishing.

An Overview of Phishing from the Accounting Sector

Employee training is an essential long-term defense against phishing attacks, according to David Barton and Kimberly Anderson at UHY Advisors. In an article for Accounting Today, Barton ...

[Scam Of The Week] Don't Fall For This Tricky: “Start your 2020 with a gift from us”

Paul Ducklin at Naked Security warned us about a scam that just surfaced and promises a gift by courier from overseas where the other person hasn’t told you what they’re sending – the ...

Cybercriminal Offers a “How To” Guide for Robbing Banks; Uses Cayman National Bank as the Example

This latest document from notorious hacker Phineas Phisher, along with a leaked report from PwC, shows how easy it is for a bank to be hacked and defrauded.

The Top 5 Eyeopener Strategies To Improve Your IT Defenses And Keep Bad Guys Out Of Your Network

Last year, in 2019 according to CVEdetails, there were 12,174 new, publicly announced vulnerabilities. If that sounds like a high number, it’s a lot less than the previous two years. We ...

New Office 365 Phishing Attack Targets OAuth Apps Instead of Credentials

Trying to steal your username and password is so “yesterday.” The 2020 Hacker is now leveraging Office 365 OAuth APIs to gain control over user mailboxes with phishing tactics.

The Better the Phishing Protection Gets, the More Sophisticated Phishing Attacks Are Getting

Microsoft’s review of how phishing has evolved over the last year highlights some of the great lengths attackers will go to in order to avoid being detected as a phishing campaign.

Scammer Who Tricked Facebook and Google Out of $120 Million Gets 5 Years in Jail

The Lithuanian hacker who ran the most notorious, simplest, and most lucrative email-based social engineering fraud scam has been brought to justice and will be serving time and paying ...

Of Course, Scammers Exploit Fears of Iranian Hacking

A new phishing campaign is attempting to frighten people into handing over their credentials by claiming Microsoft was hacked by Iran, BleepingComputer reports. The campaign is ...

JudicialWatch: "Epidemic of Government Employees Watching Porn on Taxpayer Time"

I'd like to point at a type of security behavior that is enormously risky. Judicial Watch just released a post that's a major heads-up for anyone: "An epidemic of federal employees ...

December Content Update: Includes New Versions of Email Exposure Check Pro and Phishing Security Test Tools

Here are a few important updates to share with you from the month of December.

Smishing Examples & Defenses

Smishing is phishing via Short Message Service (SMS) on a participating device, usually a cell phone. Long neglected by phishers and spammers, smishing has recently become a very common ...

Mobile Threats Shouldn't be Overlooked

Phishing attacks against mobile devices can be just as damaging to an organization as attacks targeting workstations and laptops, according to a market report by Cyber Security Hub. ...

Encryption Isn’t Your Only Ransomware Problem - There Are Some Other Nasty Issues

Ransomware has become one of the most dreaded problems in the cyber world and it’s only getting worse. Much worse!


Get the latest insights, trends and security news. Subscribe to CyberheistNews.