KnowBe4 Blog

Social Engineering

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception

In just a couple years, deepfakes have gone from cartoonishly silly and largely academic exercises to sophisticated audio and video creations with the potential to trick just about anyone ...

Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys

Lead Analysts: Jeewan Singh Jalal, Dilsha Dines, Karthikeyan Dharmaraj

When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks

When geopolitical tensions rise, whether due to conflicts like the current one involving Iran or other global flashpoints, many organizations focus on physical security, supply chains, or ...

Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks

Researchers at Push Security have analyzed a phishing platform used by organized criminal threat actors like ShinyHunters and BlackFile, finding more than 400 domains linked to attacks ...

Report: The Tycoon 2FA Phishing Kit Has Evolved

The Tycoon 2FA phishing-as-a-service platform is now using OAuth device code phishing to compromise devices that are protected by multifactor authentication, according to eSentire’s ...

KnowBe4 CEO Bryan Palma Q&A From KB4-CON 2026

By Bree Fowler, contributor Artificial intelligence is dramatically changing the digital threat landscape and how security professionals fight back against the cybercriminals that use ...

How Agentic AI and Automation Are Changing Cybersecurity

There is no question that AI is changing cybersecurity in a massive way. In many respects, its impact is comparable to the rise of the internet. AI tools are helping organizations improve ...

AI Alone Won’t Stop the Breach: Why Email Security Needs Humans-on-the-Loop

2026 has officially become the year of speed, scale and support. The delta between a phishing email landing and a full organizational compromise has shrunk to mere seconds.

[Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets

GitHub disclosed that attackers accessed its internal repositories after compromising an employee device through a poisoned Visual Studio Code extension. The company said the activity ...

Robinhood Glitch Allowed Attackers to Send Phishing Emails to Customers

A phishing campaign exploited a glitch in Robinhood’s account creation process to send phishing emails from the investment platform’s own systems, SecurityWeek reports.