Security Awareness Training Blog

Social Engineering Blog

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Social Engineering Heaven: Combine AshMad Hack With OPM Data

The Office of Personnel Management has just closed a 133 million dollar contract to protect 21.5 million OPM data breach victims for three years. Wow, "Barn, Horse" anyone? This is an ...
Continue Reading

Off With Their Heads! Execs get the ax for data breaches

Until last year, executives were able to pass the buck to IT in case a data breach hit the organization. However, several recent high-profile resignations are now putting the focus on ...
Continue Reading

IT Confessions: The Deadly Six Sins Of Data Security

Massive hacks continue to fill the front page of major media outlets. The recent hack of the Federal Office of Personnel Management (OPM) by Chinese state-sponsored hackers again showed ...
Continue Reading

Leaked NSA slides: Chinese hackers wreaking havoc on USA

I have been talking for years at this blog about the Chinese hacking into the U.S. for mainly espionage, using highly sophisticated social engineering and spear-phishing attacks. This ...
Continue Reading

AshleyMadison: Second Nightmare Phishing Problem

8/19/2015 UPDATE: Yesterday the full 10 Gigabyte database was released on the Internet, with all records including confidential files related to the company itself. People that registered ...
Continue Reading

Blackhat 2015 Survey: End-User Wins Easily As IT's Big Worry

According to the 2015 Black Hat Attendee Survey, nearly three quarters (73 percent) of top security professionals think it likely that their organizations will be hit with a major data ...
Continue Reading

U.K.-hedge fund loses a million dollars in social engineering attack

A British hedgefund lost more than a million dollars in a social engineering attack on their Chief Financial Officer Thomas Meston, and there is an expensive court case going on because ...
Continue Reading

Scam Of The Week: Internet Capacity Warning

OK, so here is the latest scam of the week, possibly fueled by the recent news that we have run out of IPv4 addresses in the U.S. Employees receive an email which claims to be from the ...
Continue Reading

A New, Innovative Ransomware Attack Spreads Using Google Drive

An Eastern European cybercrime gang has started a new TorrentLocker ransomware campaign where whole websites of energy companies, government organizations and large enterprises are being ...
Continue Reading

Spear Phishing Attack Results In $5.3 Million Bitcoin Cyberheist

"Newly leaked, confidential documents have revealed details into a cyberattack aimed at Bitstamp, a company that fundamentally deals as a cryptocurrency trader, according to a report in ...
Continue Reading

OPM Phishing Attack: "Your Data Was Hacked, How To Protect Yourself"

And yes, as we predicted, there are now phishing attacks that mimic Office of Personnel Management (OPM) data breach notifications. The breach has expanded to millions more records. It ...
Continue Reading

The Seven Deadly Social Engineering Vices Updated

You may not be aware that there is a scale of seven deadly vices connected to social engineering (SE). The deadliest SE attacks are the ones that have the highest success rates, often ...
Continue Reading

Annoying New Ransomware Attack Uses Girl Resumes

The SANS InfoSec Forums noted that since Monday May 25th a new version of CryptoWall 3.0 ransomware started, using both malicious spam and the Angler exploit kit (EK). The attack wave has ...
Continue Reading

Some Interesting Security Awareness Computer-Based Training Numbers

You may know Gartner, the 800-pound gorilla in the IT Analyst space. When a market is mature enough they create their so-called Magic Quadrant (MQ) with the leading vendors in that ...
Continue Reading

Adult Friend Finder Hack Is Nightmare Phishing Problem

Guys, we have a real phishing problem with this Adult Friend Finder (AFF) hack. This particular adult site is one of the most heavily-trafficked websites in the U.S. and has 40 million ...
Continue Reading

Tesla Attack Caused By Social Engineering

A few days ago, you may have read the news that Tesla Motors had their website and Twitter accounts hijacked by pranksters. OpenDNS has a blog post that goes into great technical detail.
Continue Reading

So, What Is The Real Reason The White House Got Hacked?

According to a new CyberEdge research survey of 19 sectors, including government, spearphishing is the biggest concern to IT security pros, more worrisome than even malware. And only 20 ...
Continue Reading

New Ransomware CrypVault Makes Files Look Like They Are Quarantined

New Ransomware CrypVault Evades AV With Simple Batch Scripts A new ransomware strain dubbed CRYPVAULT by Trend Micro is being spread as an email attachment. It's currently focusing on ...
Continue Reading

KnowBe4 Offers White House Free Security Awareness Training

April 7, 2015 - CNN reported that The White House said it noticed suspicious activity in the unclassified network that serves the executive office of the president. The KnowBe4 Blog ...
Continue Reading

Facebook sends simulated phishing attacks to their employees

Fortune reported: "Each fall, Facebook hosts an event called Hacktober in which its security experts attempt to trick employees into falling for common hacking tricks such as phishing ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews