Security Awareness Training Blog

Social Engineering Blog

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Even Law Firms Suffer from Social Engineering

They may not fall for an advance fee scam from an emailer claiming to be the widow of a Nigerian prince, but law firms have their issues with social engineering, too.
Continue Reading

The Con of Social Engineering: Law Firms are Easy Prey

Excellent article at www.law.com about social engineering! A discussion of the threat that social engineering (aka the "human side of hacking") poses to law firms, and some tips and ...
Continue Reading

Hacking Humans—a new CyberWire podcast covering social engineering launched this week

Each week the CyberWire’s Hacking Humans podcast looks behind the social engineering scams, phishing schemes, and criminal exploits that make headlines and take a heavy toll on ...
Continue Reading

Here is a Spam Message from 1864, as Old as the Victorian Internet

If you thought spam was just a twenty-first-century thing, think again. As usual, most things that seem new have pretty deep roots. Most of us can see spam's ancestry in junk mail, but it ...
Continue Reading

[Heads-up] New Exploit Hacks LinkedIn 2-factor Auth. See This Kevin Mitnick VIDEO

OK, here is something really scary. KnowBe4's Chief Hacking Officer Kevin Mitnick now and then calls me with some chilling news. This time, Kuba Gretzky, a white hat hacker friend of ...
Continue Reading

[On-Demand Webinar] The Science and Methodology Behind Social Engineering

No matter how much security technology we purchase, we still face a fundamental security problem: people. Our CEO Stu Sjouwerman was interviewed by Information Security Media Group at RSA ...
Continue Reading

Positive Technologies Social Engineering Report: 17 Percent Fall Foul To “Attacks”

Employees download malicious files, click phishing links, correspond with hackers, and even share contact information for their colleagues. Positive Technologies has released a new report ...
Continue Reading

Scam Of The Week: Fiendishly Clever Gmail Phishing Scam You Need To Know About

Twitter user @_thp shared a recent phishing scam that they received; and it’s so fiendishly clever that it’s gone viral. They wrote: "This is the most clever phishing scam I've ever ...
Continue Reading

Social Engineering Fraud and Cyber Insurance – Are You Covered?

We’ve covered this before but here’s another article on exclusionary clauses. The loophole: "No unauthorized use of the victims Computer System". Excellent reminder by Drinker Biddle ...
Continue Reading

Why Social Engineering Works And How To Arm Yourself Against "Human Hacking"

Let me share some observations after 7 years of building KnowBe4 from scratch into a 100 million dollar company. We train your employees to recognize social engineering attacks and not ...
Continue Reading

How To: Social Engineering A Whole Country During An Election

Check out this fascinating 13 min interview with Christopher Wylie, a former research director at Cambridge Analytica, who had a copy of a dataset with 50 million Facebook profiles. He ...
Continue Reading

FTC Study: Millennials Are The Biggest Victims Of Social Engineering

A report from the FTC found that 40% of adults age 20-29 lost money to fraud, while only 18% of adults over the age of 70 did so, challenging the narrative of older adults falling victim ...
Continue Reading

Now *HERE* Is A Devious Combo pretexting / vishing / SMS Social Engineering Attack!

Someone on Reddit described how he was the victim of a very sophisticated social engineering attack. Wow, this is crafty. This is the story!: "I have different passwords for every website ...
Continue Reading

Phishing Messages from the Dark: When the Bad Guys Write Back

By Eric Howes, KnowBe4 Principal Lab Researcher. For most users the experience of dealing with phishing emails is a solitary experience, whether they recognize that they are under attack ...
Continue Reading

Spend One Minute And Look At These Phishing Graphs

In the first quarter of 2018, after 7 years of helping our customers to enable their employees to make smarter security decisions and having reached the milestone of 15,000 customers, we ...
Continue Reading

How One of Australia's Richest Men Lost $1 Million in Email Scam

The multi-millionaire founder of Twynam Agricultural Group Pty Ltd. lost $1 million in an email fraud, a London court heard Thursday. The British man who facilitated the theft says he’s a ...
Continue Reading

KnowBe4 Prevents Customer From Becoming Social Engineering Victim Of Duke Energy Vendor’s Hack

A customer just sent us this: "Stu, the company who processes payments for Duke Energy’s walk in payments was hacked and as a result about 375,000 bank accounts may have been stolen. "We ...
Continue Reading

Phishing Schemes Are Using Encrypted Sites To Seem Legit

WIRED wrote: "A MASSIVE EFFORT to encrypt web traffic over the last few years has made green padlocks and "https" addresses increasingly common; more than half the web now uses internet ...
Continue Reading

Your Cybercrime Insurance Policy May Not Cover You For Social Engineering Fraud

I have talked about this potentially extremely expensive and very disappointing "CEO fraud" or "Business Email Compromise" problem many times before. Your cybercrime policy may not ...
Continue Reading

Google Kicks Harmful Apps Out Of Google Play And Offers 5 Steps Against Social Engineering

You're always better off getting apps from reputable stores like Google Play than you are from potentially dodgy, at best unknown, third-party sites. But even Google Play isn't immune ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews