Human Risk Management Blog

Social Engineering

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

IT Confessions: The Deadly Six Sins Of Data Security

Massive hacks continue to fill the front page of major media outlets. The recent hack of the Federal Office of Personnel Management (OPM) by Chinese state-sponsored hackers again showed ...

Leaked NSA slides: Chinese hackers wreaking havoc on USA

I have been talking for years at this blog about the Chinese hacking into the U.S. for mainly espionage, using highly sophisticated social engineering and spear-phishing attacks. This ...

AshleyMadison: Second Nightmare Phishing Problem

8/19/2015 UPDATE: Yesterday the full 10 Gigabyte database was released on the Internet, with all records including confidential files related to the company itself. People that registered ...

Blackhat 2015 Survey: End-User Wins Easily As IT's Big Worry

According to the 2015 Black Hat Attendee Survey, nearly three quarters (73 percent) of top security professionals think it likely that their organizations will be hit with a major data ...

U.K.-hedge fund loses a million dollars in social engineering attack

A British hedgefund lost more than a million dollars in a social engineering attack on their Chief Financial Officer Thomas Meston, and there is an expensive court case going on because ...

Scam Of The Week: Internet Capacity Warning

OK, so here is the latest scam of the week, possibly fueled by the recent news that we have run out of IPv4 addresses in the U.S. Employees receive an email which claims to be from the ...

A New, Innovative Ransomware Attack Spreads Using Google Drive

An Eastern European cybercrime gang has started a new TorrentLocker ransomware campaign where whole websites of energy companies, government organizations and large enterprises are being ...

Spear Phishing Attack Results In $5.3 Million Bitcoin Cyberheist

"Newly leaked, confidential documents have revealed details into a cyberattack aimed at Bitstamp, a company that fundamentally deals as a cryptocurrency trader, according to a report in ...

OPM Phishing Attack: "Your Data Was Hacked, How To Protect Yourself"

And yes, as we predicted, there are now phishing attacks that mimic Office of Personnel Management (OPM) data breach notifications. The breach has expanded to millions more records. It ...

The Seven Deadly Social Engineering Vices Updated

You may not be aware that there is a scale of seven deadly vices connected to social engineering (SE). The deadliest SE attacks are the ones that have the highest success rates, often ...

Annoying New Ransomware Attack Uses Girl Resumes

The SANS InfoSec Forums noted that since Monday May 25th a new version of CryptoWall 3.0 ransomware started, using both malicious spam and the Angler exploit kit (EK). The attack wave has ...

Some Interesting Security Awareness Computer-Based Training Numbers

You may know Gartner, the 800-pound gorilla in the IT Analyst space. When a market is mature enough they create their so-called Magic Quadrant (MQ) with the leading vendors in that ...

Adult Friend Finder Hack Is Nightmare Phishing Problem

Guys, we have a real phishing problem with this Adult Friend Finder (AFF) hack. This particular adult site is one of the most heavily-trafficked websites in the U.S. and has 40 million ...

Tesla Attack Caused By Social Engineering

A few days ago, you may have read the news that Tesla Motors had their website and Twitter accounts hijacked by pranksters. OpenDNS has a blog post that goes into great technical detail.

So, What Is The Real Reason The White House Got Hacked?

According to a new CyberEdge research survey of 19 sectors, including government, spearphishing is the biggest concern to IT security pros, more worrisome than even malware. And only 20 ...

New Ransomware CrypVault Makes Files Look Like They Are Quarantined

New Ransomware CrypVault Evades AV With Simple Batch Scripts A new ransomware strain dubbed CRYPVAULT by Trend Micro is being spread as an email attachment. It's currently focusing on ...

KnowBe4 Offers White House Free Security Awareness Training

April 7, 2015 - CNN reported that The White House said it noticed suspicious activity in the unclassified network that serves the executive office of the president. The KnowBe4 Blog ...

Facebook sends simulated phishing attacks to their employees

Fortune reported: "Each fall, Facebook hosts an event called Hacktober in which its security experts attempt to trick employees into falling for common hacking tricks such as phishing ...

10 Hacking Facts / How They Impact You [Infographic]

Cybersecurity is one of the most pressing concerns for business and consumers, especially when it comes to social media. So much personal identifiable information (PII) exists across the ...

IBM: 'Dyre Wolf' Cyber Gang Uses Spear Phishing For $1 Million Cyberheists

Last week, IBM Security reported on an active cyberheist campaign using a variant of the Dyre Trojan that has successfully stolen more than $1 million at a time from targeted enterprise ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.