Human Risk Management Blog

Security Awareness Training

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

Real Estate Transactions are Increasingly Vulnerable to CEO Fraud

The real estate industry is a particularly attractive target for BEC (Business Email Compromise—also known as CEO Fraud—attacks, according to FBI spokesman David Fitz. Fitz told The ...

UK Companies Cite a Lack of Cybersecurity Support from the Government

With cyberattacks occurring at such a regular frequency, UK organizations are desiring for the government to provide guidance and support on how to prepare for and address attacks.

These Incredibly Realistic Fake Faces Show How AI Can Now Mess With Us

This starts to be more than a bit concerning. The faces in this post look like pretty normal humans. They could be social media shots. However, they were generated by a recent type of ...

Ransomware Recovery Expert Scams Victims and Turns Out to be Nothing More than a Bitcoin Middleman

Organizations falling victim to ransomware look for any way to ensure they get their files back. One Belasurian businessman promises decryption but is merely conning victims out of more ...

WARNING: Your Head of Finance May Be 1 of 50,000 Execs Targeted in BEC Scams

According to a report from email security & protection vendor Agari, the cybercriminal group dubbed London Blue are directing their latest scams at very specific finance execs.

Giveaway Scam Offers Free Volkswagens to Generate Ad Revenue

A scam campaign is promising free Volkswagen car giveaways to trick social media users into visiting third-party ad servers, according to researchers at Sucuri.

A Call for More Consumer Privacy Laws Could Spell Penalties in Your Future

In the wake of the Marriott data breach, U.S. senators are calling for tougher privacy laws and stiff fines for organizations that do not properly protect consumer data.

Scammers are Posing as Huawei’s Captive CFO

An advance fee scam is targeting individuals in China following the arrest of Huawei’s CFO, Meng Wanzou, according to the SANS Internet Storm Center. Ms. Meng, who is also the daughter of ...

Half of Management Teams Don’t Understand Business Process Compromise

A new survey by Trend Micro reveals that 43% of organizations in twelve countries have been affected by Business Process Compromise (BPC) attacks. In spite of this, 50% of management ...

Employee Education and Training is a Key Component of a Culture of Security

Organizations need to focus on education and training rather than blaming employees for security gaffes, according to the speakers in a panel debate at Computing′s Enterprise Security and ...

Cybercriminals Use 1.7 Million Compromised PCs in Botnet Advertising Fraud Scam

The Russian-born, botnet-driven advertising fraud scam, 3ve, generated over $29 million in revenue using fileless malware variant Kovter, botnets, and unsuspecting users.

Google Maps’ Bank Listings Updated by Scammers

Scammers are taking advantage of Google Maps by modifying the contact information of the service’s bank listings. After replacing banks’ legitimate phone numbers with numbers of their ...

GreyEnergy Malware Spreads Through Phishing Emails

The GreyEnergy APT primarily uses phishing emails as its initial infection method, according to analysis by Nozomi Networks. The malware has been targeting industrial control systems in ...

Phishing Emails are Targeting Spotify Users

A phishing campaign is attempting to steal login credentials from Spotify users, according to researchers at AppRiver. The emails ask users to click a hyperlink to confirm their accounts, ...

Why You Need To Make Security Awareness Training Mandatory. Read This Horror Story.

OK, so here is a horror story that you can prevent from happening in your own organization. Now and then we hear that KnowBe4 customers do not make the security awareness training ...

Learning a 120K Lesson the Hard Way

The bank isn’t always responsible for making you whole after a business email compromise. Indiana’s Lake Ridge Schools lost more than $120,000 from a seven-million-dollar construction ...

Attackers Impersonate CEOs to Scam Employees into Sending Gift Cards for the Holidays

A crafty mix of social engineering, great timing, and context act as the perfect ingredients to trick unwitting users into buying gift cards and placing them into the hands of the ...

[Heads-up] Bad Guys Love Marriott: 500 Million Data Breach Is Phishing Heaven

So I guess we have just reached the tipping point, it's "privacy game over" for business travelers.

KnowBe4 Fresh Content Update & New Features November 2018

We've got a few content updates in the KnowBe4 Modstore to share with you for the month of November!

Employers Are Liable If They Don't Protect Employees' Sensitive Personal Information from Attack

A recent ruling from the Pennsylvania Supreme Court on an employee lawsuit against the University of Pittsburgh Medical Center stemming from a data breach should put all employers on ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.