Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

What Are The Key Components Of A Successful Human Risk Management Program?

Fake MFA Reset Warning Message

FBI Alert: Extortion Gang Targets Law Firms With Social Engineering Attacks

Copyright-Themed Phishing Lures Target Europe

The Worsening Landscape of Educational Cybersecurity

New Unrestricted AI Tool Can Assist in Cybercrime

CyberheistNews Vol 15 #22 If I Had Only 20 Seconds To Teach People How To Avoid Scams

Your KnowBe4 Compliance Plus Fresh Content Updates from May 2025

Beyond Credentials: When Every Data Point Becomes a Weapon

French Users Targeted by Major Phishing Campaign

Your KnowBe4 Fresh Content Updates from May 2025

Scammers Exploit Uncertainty Surrounding US Tariffs

Capital One Customers Targeted By Credential Harvesting Phishing Campaign

CyberheistNews Vol 15 #21 I Got This Coinbase-Related Scam in My Personal Inbox Last Week

Threat Actors Are Using AI-Generated Audio to Impersonate U.S. Officials

If I Had Only 20 Seconds To Teach People How To Avoid Scams

The Lost Art of Writing Things Down

Impersonating Meta, Powered by AppSheet: A Rising Phishing Campaign Exploits Trusted Platforms to Evade Detection

Phishing Campaign Targets International Students in the US

The Ransomware Threat: Still Alive and Kicking

CyberheistNews Vol 15 #20 How to Protect Your Business from Scattered Spider's Latest Attack Methods

Beware of Coinbase Scams

Warning: Phishing Kits Can Auto-Generate Tailored Login Pages

Agentic AI Ransomware Is On Its Way

Email-based Attacks Accounted for Most Cyber Insurance Claims Last Year

KnowBe4 Leads the Charge Against Cybersecurity Threats with Unmatched AI Capabilities

How to Protect Your Business from Scattered Spider's Latest Attack Methods

The Clock Is Ticking: Why Phishing Remains The Fastest-Moving Cyber Threat in 2025

CyberheistNews Vol 15 #19 [Heads Up] Talos Report Shows Phishing Attacks Surged in Q1 2025

Cybercriminals Use Telegram Bots to Exfiltrate Data In Phishing Kit Campaign

You Are Still Vulnerable to Password Attacks When Using Passkeys

Phishing Kits Are Growing More Sophisticated; Focused on Bypassing MFA

Talos Report: Phishing Attacks Surged in Q1 2025

Warning: Phishing Campaign Impersonates the US Social Security Administration

CyberheistNews Vol 15 #18 [Eye Opener] Sneaky New Attack. What is Device Code Phishing?

Your KnowBe4 Compliance Plus Fresh Content Updates from April 2025

Your KnowBe4 Fresh Content Updates from April 2025

Exciting Leadership Updates at KnowBe4

Xfinity Scam Might Explain Similar Scams

Email Remains the Top Attack Vector for Cyberattacks

Hundreds of Fortune 500 companies have hired North Korean operatives.

Cybercriminals Impersonate DHS Amid Deportation Efforts

A Sneaky T-Mobile Scam and Lessons That Were Learned

Researchers Warn of Surge in Infostealers Delivered Via Phishing

What Is Device Code Phishing?

Criminals Exploit the Death of Pope Francis to Launch Scams

AJ from The Inside Man Now Coaching Your Users Real-time with Security Coach

CyberheistNews Vol 15 #17 [Warning] The Cyber "Broken Windows Theory" You Can't Afford to Ignore

Introducing the KnowBe4 Academy: Your Path to Mastering Human Risk Management

Social Engineering Campaign Abuses Zoom to Install Malware

Half of Organizations Lack Protection Against Email Spoofing

How Organizational Culture Shapes Cyber Defenses

Warning: Ransomware Remains a Top Threat for SMBs

Breaking the Stigma: 90% of Employees Agree that Phishing Simulations Improve their Security Awareness

Broken Cyber Windows Theory

Threat Actors Are Increasingly Abusing AI Tools to Help With Scams

CyberheistNews Vol 15 #16 [Scary] A New Real Cash Scam Sweeps Across the U.S. Warn Your Family and Friends!

Powering Down Vulnerability: Securing the Energy Sector's Supply Chain

China Cybercriminals Behind Toll-Themed Smishing Attacks Surge in the US and UK

[Scary] A New Real Cash Scam Sweeps Across the U.S. Warn Your Family and Friends!

Lack of Security Awareness Tops List of Obstacles to Cyber Defense

The Continued Abuse of Legitimate Domains: A Spike in the Exploitation of Google Drive to Send Phishing Attacks

How Does Human Risk Management Differ from Security Awareness Training?

AI-Powered Spear Phishing Can Now Outperform Human Attackers

UK Organizations Cite Phishing as the Most Disruptive Type of Cyberattack

CyberheistNews Vol 15 #15 [HEADS UP] North Korea Expands Its Fraudulent IT Worker Operations

Hidden Threats in Our Power Grid: The Chinese Transformer Backdoor Scandal

Warning: QuickBooks Phishing Campaign Targets Taxpayers

Europe's Energy Sector at Risk: The Critical Need for Cybersecurity

Beware the Tax Trap: Seasonal Urgency Drives a Spike in Tax-Related Phishing Scams

Shadow AI: A New Insider Risk for Cybersecurity Teams to Tackle Now

64% of Australian Organizations Hit by Ransomware Were Forced to Halt Operations

Seeing (and Hearing) Isn’t Believing: My SEC Presentation on AI-Driven Scams

Securing Employee Identities: Expert Tips for Identity Management Day 2025

Russian Threat Actor Launches Spear-Phishing Campaign Against Ukrainians

[HEADS UP] North Korea Expands Its Fraudulent IT Worker Operations

The Real Deal: How Cybercriminals Exploit Legitimate Domains

CyberheistNews Vol 15 #14 [Heads Up] QR Code Phishing is Getting More Stealthy Fast

Your KnowBe4 Compliance Plus Fresh Content Updates from March 2025

Upgraded Phishing-as-a-Service Platform Drives a Wave of Smishing Attacks

Online Gaming Platform Steam Tops List of Most Imitated Brands For the First Time

Your KnowBe4 Fresh Content Updates from March 2025

Phishing Attacks Lead to Theft in the Shipping Industry

[Heads Up] QR Code Phishing is Getting More Stealthy Fast

Malicious Memes: How Cybercriminals Use Humor to Spread Malware

Compliance Plus Library Reaches 800 Pieces of Content

The State of NIS2: A Fragmented Implementation Across the EU

Exploring the Implications of DORA: A New Global Standard For Financial Cybersecurity

Most Phishing Emails Rely Purely on Social Engineering

CyberheistNews Vol 15 #13 Why Password Security Matters: The Danish and Swedish Password Problem

Report: Phishing Remains the Most Prevalent Cyber Threat

Surge in Phishing Attacks Hijacking Legitimate Microsoft Communications

Amount of Money Requested In BEC Attacks Nearly Doubled in Q4 2024

CyberheistNews Vol 15 #12 Key Takeaways from the KnowBe4 2025 Phishing Threat Trends Report

The Human Element: Addressing Cybersecurity Risk in Danish and Swedish Organizations

Act Now: Phishing-as-a-Service Attacks are on the Rise

Why Password Security Matters: The Danish and Swedish Password Problem

Hundreds of Malicious Android Apps Received 60 Million Downloads

Key Takeaways from the KnowBe4 2025 Phishing Threat Trends Report

Scammers Can Be Victims Too

Phishing Attacks Abuse Microsoft 365 to Bypass Security Filters

Be Vigilant: BEC Attacks Are on the Rise

Agentic AI: Why Cyber Defenders Finally Have the Upper Hand

The Cybersecurity Confidence Gap: Are Your Employees as Secure as They Think?

Booking.com Phishing Scam Targets Employees in the Hospitality Sector

CyberheistNews Vol 15 #11 [Heads Up] 245% Increase in SVG Files Used to Obfuscate Phishing Payloads

98% Spike in Phishing Campaigns Leveraging Russian (.ru) Domains

Make Your Real Emails Less Phishy

Protect Yourself: Social Engineering Fuels SIM Swapping Attacks

245% Increase in SVG Files Used to Obfuscate Phishing Payloads

AI and AI-agents: A Game-Changer for Both Cybersecurity and Cybercrime

Beware: Malvertising Campaign Hits Nearly a Million Devices

U.S. Justice Department Charges China’s Hackers-for-Hire Working IT Contractor i-Soon

The Myth of Geographic Immunity in Cybersecurity

CyberheistNews Vol 15 #10 [Heads Up] Sophisticated Phishing Attack Uses New JavaScript Obfuscation Trick

Your KnowBe4 Compliance Plus Fresh Content Updates from February 2025

Autonomous Agentic AI-Enabled Deepfake Social Engineering Malware is Coming Your Way!

Your KnowBe4 Fresh Content Updates from February 2025

Warning: Ransomware Threats Increased Fourfold in 2024

Software Will Become Agentic and the Security Lessons We Need To Learn

Invoice or Impersonation? 36.5% Spike in Phishing Attacks Leveraging QuickBooks’ Legitimate Domain in 2025

AI Literacy: A New Mandate Under the EU AI Act - What Your Organization Needs to Know

Data at Risk: 96% of Ransomware Attacks Involve Data Theft

[Heads Up] Sophisticated Phishing Attack Uses New JavaScript Obfuscation Trick

Q&A with Martin Kraemer on Information Sharing in Cybersecurity

Primary Refresh Tokens Aren’t Your Parent’s Browser Token

School is in Session: Surge in Phishing Attacks Targeting the Education Sector

CyberheistNews Vol 15 #09 [NEW] KnowBe4 Interviews a Fake North Korean Employee

Announcing: Audiocasts - A New Podcast-Like Training Content Type

Protect Yourself from Job Termination Scams

Protect Your Devices: Mobile Phishing Attacks Bypass Desktop Security Measures

KnowBe4 Named #1 Security Product and #2 Overall Software Product in G2’s 2025 Best Software Awards

Chinese Hackers Target Hospitals by Spoofing Medical Software

Phishing Attack Leads to Lateral Movement in Just 48 Minutes

Viral but Vulnerable: The Hidden Risks of Cybersecurity Misinformation on Social Media

Warning: Russian Threat Actors Are Targeting Signal Accounts With Malicious QR Codes

CyberheistNews Vol 15 #08 Protect Your Data: Russian Spear-Phishing Targets Microsoft 365 Accounts

[NEW] KnowBe4 Interviews a Fake North Korean Employee

Phishing Kit Abuses Open Graph to Target Social Media Users

Phishing Attacks Increased by Nearly 200% in H2 2024

Spear Phishing is the Top Cyber Threat to the Manufacturing Sector

CyberheistNews Vol 15 #07 Facebook Business Users Beware: Thousands Hit by New Phishing Scam

Scanning for Trouble: Behind the Scenes of Our QR Code Phishing Demo

Protect Your Data: Russian Spear-Phishing Targets Microsoft 365 Accounts

Phishing for Love: A Sharp Surge in Valentine’s Day-Themed Scams

New Research: Ransomware Data Extortion Skyrocketing

[POLL] Sam Altman: "I don't do Google searches anymore." How about you?

New Phishing Campaign Targets The X Accounts of Politicians, Tech Companies, Cryptocurrency, And More

Facebook Business Users Beware: Thousands Hit by New Phishing Scam

CyberheistNews Vol 15 #06 Phishing Up 76% – Deepfake Attacks Surge: Is Your Org the Next Target?

2024 Was a Record-Breaking Year For Ransomware

Cybersecurity Resilience and Culture Matters to Face the Growing Frequency and Sophistication of Cybercrime

From Madison Avenue to Malware

Don’t Fall Victim: DeepSeek-Themed Scams Are on the Rise

Make-Shift Brand Impersonation: Abusing Trusted Domains with Open Redirects

Warning: Organizations Need to Prep For AI-Powered Ransomware Attacks

From Firewalls to Digital Well-Being: A Whole-School Approach to Online Safety

Phishing Up 76% – Deepfake Attacks Surge: Is Your Org the Next Target?

CyberheistNews [Vol 15 #05 Eye Opener] Is DeepSeek The Next Threat in Social Engineering?

Warning: Phishing Campaign Targets Germany with New Malware

Your KnowBe4 Compliance Plus Fresh Content Updates from January 2025

Your KnowBe4 Fresh Content Updates from January 2025

Beware: Mobile Phishing Mimicking the USPS Is On the Rise

The Rising Tide of Cybercrime Concerns in Africa

Using Genuine Business Domains and Legitimate Services to Harvest Credentials

Tips for Detecting Real-time Deepfakes: A Guide to Staying One Step Ahead

Microsoft is Still the Most Commonly Impersonated Brand in Phishing Attacks

CyberheistNews Vol 15 #04 [HEADS UP] Bad Actors Abuse Google Translate to Craft Phishing Attacks

[Eye Opener] Is DeepSeek The Next Threat in Social Engineering?

Beware of Toll Scam Texts: How Cybercriminals are Targeting U.S. Drivers

Nearly Three-Quarters of UK Education Orgs Have Sustained Cyberattacks

Phishing is the Top Security Threat For Smartphone Users

84% of Healthcare Organizations Sustained Cyberattacks Last Year

4 Ways to Mature Your Human Risk Management Program

Russian Spear-Phishing Campaign Targets WhatsApp Accounts

Malvertising Campaign Abuses Google Ads to Target Advertisers

CyberheistNews Vol 15 #03 Waging War on Explicit Deepfakes. The Real Problem Behind the UK Crackdown.

Threat Actors Abuse Google Translate to Craft Phishing Links

Phishing Campaign Attempts to Bypass iOS Protections

From Pig Butchering to People Talking

Effective Security Awareness Training Really Does Reduce Data Breaches

Your KnowBe4 Compliance Plus Fresh Content Updates from December 2024

Ransomware Gangs Claimed More Than 5,000 Attacks in 2024

Brad Pitt Romance Scams Pushed By AI-Enabled Deepfakes

First Ever Magic Quadrant™ for Email Security Platforms by Gartner®

Your KnowBe4 Fresh Content Updates from December 2024

Japan Attributes More Than 200 Cyberattacks to China Threat Actor "MirrorFace"

CyberheistNews Vol 15 #02 [HEADS UP] Credential Phishing Increased by 703% in H2 2024

Waging War on Explicit Deepfakes. The Real Problem Behind the UK Crackdown

Phishing Campaign Abuses Legitimate Services to Send PayPal Requests

Malicious WordPress Plugin Assists in Phishing Attacks

[BUDGET AMMO DEPT] WSJ: "Cybersecurity Is the King of Business Worries"

Phishing for Gamers: Fake Offers Invite Gamers to Test New Gaming Titles

CyberheistNews Vol 15 #01 [No Time to Waste] The 2025 Cybersecurity Tightrope: What's Next for The World?

Credential Phishing Increased by 703% in H2 2024

Tax-Themed Phishing Campaign Delivers Malware Via Microsoft Management Console Files

FTC Warns Immigrants About Rising Social Media Immigration Scams

CyberheistNews Vol 14 #52 [Heads Up] Bad Actors Use Voice Phishing in Microsoft Teams To Spread Malware

Russia’s APT29 Launches Major Spear Phishing Campaign

"Get Beyond Security Awareness Training" Does Not Mean Forgetting About It


Get the latest about social engineering

Subscribe to CyberheistNews