Cyber Risk Aware Blog

New Phishing Tactics Used by Threat Agents in 2019  and How to Get Around Them

[fa icon="calendar'] 17-May-2019 11:36:56 / by Jennifer Nwaigwe M posted in Phishing, Social Engineering, phishing email, vishing, phishing attacks, phishing scams

As internet security infrastructure becomes smarter and more difficult to penetrate, hackers have made the migration toward phishing attacks as the cyber-criminal weapon of choice because they exploit the seeming weakest part of any security system – humans!

Read More [fa icon="long-arrow-right"]

Security Awareness Training for Schools and Educational Institutions

[fa icon="calendar'] 10-Apr-2019 16:59:34 / by Jennifer Nwaigwe M posted in Phishing, Spear Phishing, security awareness training, Cyber Risk as a Human Risk, Security Compliance

In our data-driven world, most organisations are at least partially dependent on a measure of electronic storage and networking. Perhaps out of experience, large organisations are generally aware of the need for effective cyber security frameworks including firewalls, access and awareness training, and anti-malware systems. Educational institutions, however, tend to be somewhat behind the curve, when it comes to tightly securing their data-verse. Recently, ethical hackers while testing the computer security of university networks discovered that they were able to successfully breach networks in less than 2 hours by using spear-phishing attacks to gain access to sensitive information. Well over 50 universities across the UK were a part of the test and in almost every case, testers were able to acquire domain-level administrator access used to control systems and gain complete unauthorised access to system information.

Read More [fa icon="long-arrow-right"]

The Cost of FREE Public WiFi

[fa icon="calendar'] 15-Mar-2019 14:43:40 / by Jennifer Nwaigwe M posted in CyberCrime, Phishing, Security awareness, Social Engineering, Accidental Cybersecurity Leaks

Everything has a cost, and that does not exclude free public WiFi connections.

Read More [fa icon="long-arrow-right"]

Tis the Season To Stay Safe Online!

[fa icon="calendar'] 20-Nov-2018 10:09:47 / by Stephen Burke posted in Phishing, securty awareness training, smishing

It is true that with the onset of the holiday shopping season there is a dramatic up-tick in activity in both the eCommerce world and the cybercriminal.   Black Friday and Cyber Monday have now become international shopping events and they are no longer one weekend but seem to go on for three to four weeks.  So, with consumers seeing increases in offers, promotions and coupons coming out in emails or SMS messages (SMiShing is the growing threat) as well as all those order confirmations, payment requests and shipping messages there are rich pickings for the cybercriminal who wants to swim in tide of communications hoping to de-fraud some unsuspecting consumers.

Read More [fa icon="long-arrow-right"]

Phishing Template Upgrade - Introducing New Sophistication Rankings

[fa icon="calendar'] 19-Apr-2018 08:44:21 / by Julie Lhanang posted in Phishing, Phishing Simulation, phishing email

Getting to know the new lure sophistication classifications, and how they can help your next campaign.

 

In 2017, Symantec reported that phishing rates had increased across most industries and organisation sizes. News sites consistently report on the biggest and scariest malware attacks and data breaches, and then ultimately attribute the increased susceptibility to one of many new phishing trends. But what in fact constitutes a highly-sophisticated phishing message? And how can this knowledge help you strategically plan and execute your next test campaigns.

Read More [fa icon="long-arrow-right"]

Phishing Alert: Hurricane Harvey Disaster Relief Fraud

[fa icon="calendar'] 28-Aug-2017 11:59:00 / by Stephen Burke posted in Phishing, Disaster Relief fraud, Social Media Scam

 

Hurricane Harvey has hit the U.S. State of Texas hard, the most powerful storm to make landfall in the U.S. for over a decade and create what has been described as a 500 year flood. At times like this decent human beings want to help each other. However, for others in society namely "cyber-scum" they are exploiting this disaster and human goodness. 

Read More [fa icon="long-arrow-right"]

Ransomware Phishing: An Ounce of Prevention

[fa icon="calendar'] 27-Jun-2017 21:45:11 / by Stephen Burke posted in Phishing, Spear Phishing, Phish prone, Ransomware, security awareness training, wannacry, petrwrap

Phishing has been in the news lately, not only because it was the intrusion technique allegedly used by Russian hackers to access U.S. voter registrations, but also because it is becoming more prevalent, especially in the UK.  You only have to look at the recent NHS "Wannacry" and the latest "Petrwrap" ransomware incidents both starting with curious staff opening phishing emails to understand the risks.

Read More [fa icon="long-arrow-right"]

Will Your Employees Take the Bait?

[fa icon="calendar'] 26-May-2017 09:13:29 / by Stephen Burke posted in CEO Fraud, Phishing, Spear Phishing, security awareness training

Do your employees know enough about phishing? Can they explain what spear phishing is? Do you have a policy in place to help prevent CEO fraud?

If the answer to any of these questions is ‘no’, then you are not alone. Employees remain the weakest link in the battle against cybercrime and are criminals number one target.

Read More [fa icon="long-arrow-right"]

HSE Could Be a 'Sitting Duck' for a Cyber Attack

[fa icon="calendar'] 14-May-2017 12:51:49 / by Stephen Burke posted in Phishing, Staff Awareness, Ransomware

 The content of this article was originally published by Mark O'Regan - Sunday Independent

The HSE could be a 'sitting duck' for a cyberattack unless it radically beefs up security to protect highly sensitive data which may be sold by criminals on the Dark Web.

Read More [fa icon="long-arrow-right"]

Ransomware Prevention!

[fa icon="calendar'] 13-May-2017 12:41:13 / by Stephen Burke posted in CyberCrime, Phishing, Ransomware, Data Protection, Phishing Simulation, securty awareness training

A widespread cyber attack has been coming folks, and many security professionals are attempting to increase awareness for staff and companies.

Two days ago I shared an article from AIG that stated "systemic cyber attacks" were expected this year across several sectors, including healthcare.

Read More [fa icon="long-arrow-right"]