Human Risk Management Blog

Social Engineering

Latest social engineering news, analysis, tactics the bad guys are using and what you can do to defend your organization.

Homeland Security: Security Education Deterred Cybercrime

Homeland Security Today has a good article which explains that cybersecurity education, including employee training and awareness programs, is vital in deterring cybercrime. The ...

Software Support Cybercrime Scam

This week the FTC shut down a $120M tech support scam that consumer software buyers should be aware of. Two telemarketing firms were at the center of this FTC investigation, but there are ...

STATE DEPT COMPUTERS HACKED, EMAIL SHUT DOWN

Associated Press just reported that the State Department has taken the unprecedented step of shutting down its entire unclassified email system as technicians repair possible damage from ...

New Flavor of Ransomware Is More User Friendly

It's been more than a year since the first vicious ransomware stuck up its ugly head.

SCAM of the Week: Free Pizza Delivers Malware

There is a current, active cybercrime campaign going, using the tempting lure of free pizza, researchers at Cloudmark warned. They spotted new spam emails claiming to be a campaign from ...

PCI Publishes Guidance On Security Awareness Training

The Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of ...

Scam Of The Week: Ebola Phishing Grows In Volume

I have been warning here before that Ebola phishing attacks would be more and more prevalent, as a result of the mass-media spending increasing amounts of time covering this threat.

Poll: Employees Clueless About Social Engineering

Fresh from Dark reading: "When it comes to social engineering, Pogo, the central character of a long-running American comic strip, said it best. "We have met the enemy and he is us."

New Android Ransomware Strain Locks The Device Twice

Researchers in Russia discovered a new Android ransomware strain which does not lock the device just once but twice. It spreads by using a social engineering trick, disguising itself as a ...

Home Depot, Target Breaches Exploited Old WinXP Flaw

The massive security breaches and theft of credit card information at The Home Depot and Target have something in common. They were both allowed by a vulnerability in XP embedded that was ...

Regular Facebook Users Are More Likely To Fall For Phishing Scams

Techcrunch was the first one to report on some very interesting findings:

New KnowBe4 Whitepaper: A Short History of Ransomware

Cyber Criminals Use AEA-256 Crypto To Obfuscate Phishing Sites

The Register said: "Well, at least someone listened to Snowden about privacy... Phishing fraudsters have begun using industry-standard AES-256 encryption to disguise the content of ...

Five Reasons Why Clicking "Unsubscribe" May Be A Bad Idea

When you get on a mailing list you don't want to be on, it's easy to get off – just click on the "unsubscribe" link. But should you? Sophos Naked Security says maybe not. When you ...

Scam Of The Week: Jennifer Lawrence Nude Pictures Phishing

There is a new (true) Current Event which unfortunately is the ultimate click bait. A hacker got into the Apple iCloud and hacked the account of Jennifer Lawrence and many other celebs.

Chase Is Asking For Phishing Trouble

Chase bank says to click links if you suspect phishing. Huh? Yup, they do. Check out this email from Chase, scratch your head, and do not make this error in your own organization. If you ...

J.P. Morgan Hacked Because Malware Infects Employee PC

This morning, the Wall Street Journal reported on the front page that J.P. Morgan was hacked and suffered a cyberheist called "a significant breach of corporate computer security".

Bitcoin Phishing Click Rate Higher Than Regular Scams

The Proofpoint Threatinsight blog reported on something curious. They called their posting "Curiosity Clicks: Using Bitcoin’s hype for phishing fun" and came up with some interesting ...

Not news: Windows Store is full of scam apps

Paul Thurrott over at WindowsIT Pro wrote:

Workers At U.S. Nuclear Regulator Fooled By Phishing

Antone Gonsalves at CSO reported something that worries me, and this SHOULD NOT BE at this day and age.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.