BleepingComputer warns that cybercriminals are using calendar invites to send phishing links to Wells Fargo customers. Researchers at Abnormal Security discovered this phishing campaign in mid-June, and it’s targeted more than 15,000 people. The attackers are sending emails purporting to come from Wells Fargo that inform the recipient that they need to update their security […]
WARNING: The List of Ransomware-Turned-Data Breach Operators is Getting Long
Seeing a better opportunity to generate more “revenue” from their victims, the idea of ransomware also exfiltrating data to be used to extort the payment is gaining steam. Ransomware started as little more than a nuisance, impacting just a few endpoints. Then the idea of spreading throughout a network to infect as many machines as […]
Pyongyang’s Phishing with Job Offers
An attack campaign with possible ties to North Korea’s Lazarus Group targeted aerospace and military companies in Europe and the Middle East with spear phishing attacks late last year, according to researchers at ESET. The campaign, which the researchers call “Operation In(ter)ception,” used social engineering attacks on LinkedIn to trick employees into opening malware-laden documents. […]
Prediction: Ransomware Attacks to Spike as Employees Return to the Office
Because of the nature of ransomware attacks and the mass numbers of workers at home, anti-malware vendor Emisoft believes we’re going to see a rise once work returns to normal. Ransomware is a numbers game: launch enough attacks and a percentage of them will return revenue back to you. This rings true regardless of whether […]
Why People Don’t Learn (It’s Not Always Their Fault)
IT and security managers often fail to understand how well their employees actually absorb cybersecurity training, according to a survey from Mimecast and Forrester Consulting. The survey gathered responses from 120 senior IT and cybersecurity managers at companies in Australia, Hong Kong, New Zealand, and Singapore, as well as from 240 employees that worked within […]
COVID-19 Security Hints & Tips Email Templates In 10 Additional Languages
KnowBe4’s Product Content team is happy to announce that their 9 COVID-19 Security Hints and Tips email templates are now available in 10 additional languages. The new emails are available in: German (DE-DE) French – Canada (FR-CA) French – France (FR-FR) Japanese (JP-JP) Dutch (NL-NL) Portuguese – Brazil (PT-BR) Spanish – Latin America (ES-LA) Spanish […]
Cybercriminals Lean Heavily on Social Engineering Tactics to Gain Access to Bank Accounts
A series of attack anecdotes shared by Brian Krebs shows how persistent and sophisticated scammers are in using social engineering tactics to gain access to their victim’s bank account details. It all starts with a bit of information about their next potential victim; using credit card records for sale on the dark web, scammers begin […]
Fake Zoom Downloader is the Latest Method of Attack on Remote Workers
Riding on the coattails of the massive rise in popularity in the video conference solution, remote workers new to Zoom need to be wary of where they download the installer. We’ve written before about the various types of Zoom-related attacks that have sprouted up over the last two months. The latest chapter in this saga […]
It Starts with a Phish: Employee PII at Risk When Pipeline Development Outsourcer Falls Victim to Ransomware Attack
The latest example of a modern-day ransomware attack demonstrates how data encryption and ransom can no longer be the assume extent of an attack. Two weeks ago, outsourcing service provider ExecuPharm released a notice of data breach to their consumers. In it, ExecuPharm noted experiencing a ransomware attack in March of this year where “employees […]
Can COVID-19 Related Data Breach Worries Stop Your Mergers Or Acquisitions?
The WSJ just reported that the new coronavirus has thrown the M&A dealmaking into disarray. They said: “cybersecurity experts say the workplace upheaval caused by the pandemic will complicate mergers and acquisitions when activity picks up. Countless employees are working remotely on networks that might be vulnerable to attack, while others with access to confidential […]