Cloud Services Abused by Clever Phishing Campaign
Security researchers detected a clever new phishing campaign that abused three enterprise cloud services in an attempt to steal victims’ credentials. On July 18, Bleeping Computer revealed that the phishing campaign’s attack ...
Business Email Compromise (BEC) Criminal Ring
A criminal group called Cosmic Lynx seems to be based in Russia: Dubbed Cosmic Lynx, the group has carried out more than 200 BEC campaigns since July 2019, according to researchers from ...
Nigerian National Extradited to United States on BEC Scam Charges
A Nigerian national entered into the custody of the FBI to face charges of having targeted several U.S. companies with business email compromise (BEC) scams. On July 3, the U.S. Attorney’s Office ...
Employees’ Reasons for Not Using Secure Communications
How heavily do you invest in cybersecurity? How much of that is in your communications infrastructure? Regulations and compliance requirements, customer or client demand and simply maintaining your business’s reputation all contribute ...
Assessing an Email’s Legitimacy
I recently received an email sporting “Wells Fargo” logos. It asked me to do a survey. It was actually sent from the domain ‘morpace.com,’ which used to belong to a product survey ...
Beware of Phone Phishing
Just because the email (or letter) directs you to a phone number doesn’t mean you aren’t being phished. The nearby image shows part of a recent phishing email. It claims that I ...
New Trickbot Campaign Uses Fake Emails from U.S. Department of Labor
A new campaign is targeting people with messages that seem to come from the U.S. Department of Labor (DoL), trying to trick them into opening a DOC file, enabling macros, and eventually ...
Digital Fraudsters Masquerading as FINRA in Phishing Emails
The Financial Industry Regulatory Authority (FINRA) warned that digital fraudsters are impersonating it in an ongoing phishing email campaign. In a regulatory notice published on its website, FINRA revealed that malicious actors ...
COVID Email Attack or Email Harvesting?
The well-publicized publishing of 25,000+ emails and passwords allegedly associated with the World Health Organization, the Gates Foundation and the National Institutes of Health has captured the attention of both infosec practitioner ...
Detecting a Phish on an iPhone
In their obsession with simplifying the phone interface, the iPhone designers make it a bit harder to detect dangerous emails. Here is an email claiming to be from “Humana Health” asking me ...
