CyberheistNews Vol 15 #16 | April 22nd, 2025
[Scary] A New Real Cash Scam Sweeps Across the U.S. Warn Your Family and Friends!
By Roger Grimes.
Right now, today, thousands of people are being tricked into going to their banks or credit unions to withdraw large sums of cash and will give or send it to a complete stranger, never to see it again.
Many of the victims are in the prime of their lives, intelligent and consider themselves to be of above-average ability in spotting scams and scammers.
Each victim unknowingly gave large sums of their life savings to people they had never met. They were instructed to lie. They were instructed not to tell their spouses what they were doing. They were instructed not to trust any other law enforcement.
They were told their phones and even houses could be bugged. In their moment of personal weakness, it was them and the stranger on the phone against the world. They were convinced that what they were doing was needed to protect not only themselves and their families, but the entire world!
It is similar to the climactic ending of nearly every Hollywood action film…and for a little while…the victim accidentally gives themselves a starring role in the opposite of a feel-good movie.
Cash Bag Scamming
I'll call this type of social engineering attack "cash bag scamming" because the defining characteristic is that the scammer gets a big bundle of physical cash. The scam starts like this.
The victim is usually first contacted by a person pretending to be a legal representative of a prominent retail vendor, like Amazon. They will tell the victim a wild story like that their vendor account was compromised by terrorists and is being used by terrorists to facilitate terrorism.
The representative will make up some bogus transactions and ask the potential victim to confirm that these purported transactions were not really theirs.
Of course, they were not. They were made up.
The representative claims the transactions are not being charged to the victim, but says that the FBI, CIA, FTC, IRS or Secret Service (or some authoritative sounding federal law enforcement service) would like to talk to them and would it be OK for the representative to transfer them into the call. The victim agrees.
[CONTINUED] At the KnowBe4 Blog
https://blog.knowbe4.com/scary-a-new-real-cash-scam-sweeps-across-the-u.s.-warn-your-family-and-friends
Agentic AI Ransomware: What You Need to Know
Brace yourself for agentic AI ransomware — a terrifying fusion of cutting-edge tech and malicious intent that's set to redefine cyber threats as we know them. Unlike traditional ransomware, which follows pre-programmed rules, agentic AI ransomware can adapt its behavior in real time based on its environment and the defenses it encounters. Is your organization prepared?
Join us for this mind-blowing webinar where Roger A. Grimes, KnowBe4's Data-Driven Defense Evangelist, pulls back the curtain on the looming threat of AI-powered ransomware. Don't let your organization become a case study in what NOT to do when faced with this new breed of ransomware!
You'll discover:
- Agentic AI and why it's keeping cybersecurity experts up at night
- A glimpse into the future: what agentic AI malware looks like and how it operates
- The terrifying mechanics behind agentic AI ransomware
- Battle-tested strategies to fortify your defenses against this AI-driven attack
- How to stay one step ahead with next-generation defense tactics against evolving AI threats
Don't be caught with your defenses down. Join us and arm yourself with strategies you need to protect your organization in this new era of AI-powered cyber warfare and earn CPE credit for attending!
Date/Time: TOMORROW, Wednesday, April 23 @ 2:00 PM (ET)
Can't attend live? No worries — register now and you will receive a link to view the presentation on-demand afterwards.
Save My Spot:
https://info.knowbe4.com/agentic-ai-ransomware?partnerref=CHN2
How Does Human Risk Management Differ from Security Awareness Training?
In today's cybersecurity landscape, organizations face an ever-present and often underestimated threat: human risk.
Despite significant advancements in technological defenses, human error remains a leading cause of data breaches and security incidents. Multiple industry studies and research reports consistently show that between 70% and 90% of data breaches involve some form of human related cause — whether through social engineering, errors or misuse. It's why a recent study revealed that 74% of CISOs now consider human error their top cybersecurity risk.
SAT has been a long-held, well-established approach that has focused on education, awareness, testing and best practices. HRM, on the other hand, is a more comprehensive approach that aims to identify, quantify and mitigate risks associated with human behavior in a cybersecurity context.
And, while the term "Human Risk Management" may be relatively new, the concept itself represents years of evolution in understanding how to effectively address human-related security risks.
While some still use SAT and HRM interchangeably, these strategies are fundamentally different—and understanding how human risk management (HRM) is different from security awareness training (SAT) is key to building a more secure organization.
Security Awareness Training
SAT is a well-established approach that focuses on educating employees about cyber threats, organizational policies and best practices. SAT programs aim to raise awareness of risks like phishing, malware and social engineering attacks. These initiatives typically include video modules, quizzes and simulated phishing emails to test employee readiness.
SAT plays a critical role in establishing a security baseline. It ensures employees are informed about the threats they may encounter and the appropriate steps to respond. However, SAT alone doesn't always result in lasting behavior change. It often follows a one-size-fits-all model, delivering the same content to all employees regardless of their individual risk levels, job roles or digital behaviors.
As a result, while employees may know what to do, that knowledge doesn't always translate into action or different behavior. The gap between awareness and behavior is where SAT's limitations become evident, and represents the primary difference between SAT and HRM.
Human Risk Management: A Paradigm Shift
HRM represents a next-generation approach to managing human-related cybersecurity risks. Rather than simply educating employees, HRM aims to identify, quantify and mitigate those risks through a holistic, data-driven lens.
HRM has evolved over years of learning and iteration. Leading organizations like KnowBe4 were among the first to recognize that employees are not the "weakest link" in cybersecurity—they are a critical layer of defense. This shift in thinking marks a profound departure from traditional SAT, which sometimes unintentionally placed blame on users for mistakes.
How Is Human Risk Management Different from Security Awareness Training?
Let's break down some of the core differences between HRM and SAT across these topics, which are expanded on the blog.
- From Awareness to Measurable Risk Reduction
- From One-Size-Fits-All to Personalized Learning
- From Static Training to Dynamic Defense
- From Compliance-Driven to Behavior-Focused
- From Reactive to Proactive Security Culture
[CONTINUED] at the KnowBe4 blog:
https://blog.knowbe4.com/how-does-human-risk-management-differ-from-security-awareness-training
The Outstanding ROI of KnowBe4's Human Risk Management Platform
Reducing the risk of a data breach is paramount, and the overwhelming majority of data breaches are due to human error. According to Verizon's Data Breach Investigations Report, 74% of all data breaches involved the human element.
It's why security awareness training and security orchestration platforms are critical at reducing risk, protecting data and ensuring regulatory compliance. They now represent one of the best return on investments for your organization's infosec budget.
Download this guide to understand:
- The cost savings and productivity gains of KnowBe4's SAT, Compliance Plus and PhishER Plus products
- The overall risk reduction of a data breach or ransomware attack
- How you can decrease your cyber insurance premiums
- The 3-year ROI and annual benefits
Download Now:
https://info.knowbe4.com/hobson-outstanding-roi-knowbe4-hrm-platform-chn
AI-Powered Spear Phishing Can Now Outperform Human Attackers
Researchers at Hoxhunt have found that AI agents can now outperform humans at creating convincing phishing campaigns.
The researchers state that in 2023, AI-powered phishing was 31% less effective than humans. In November 2024, it was 10% less effective than humans. Then in March 2025, the AI was 24% more effective than humans.
"This public finding could be considered an inflection point for the threat landscape," the researchers state. "AI's superiority in social engineering will transform cybersecurity risks, attacks and defenses. Advances in AI Large Language Models are simultaneously disrupting the social engineering landscape and the cybersecurity training category.
"The co-evolution of attacks and protections must be considered when evaluating the rising threat of blackhat generative AI applications."
Currently, these types of sophisticated AI-powered attacks are limited to targeted spear phishing campaigns. However, commodity phishing kits will likely incorporate these features at some point in the near future.
"It is only a matter of time until AI agents disrupt the phishing landscape," the researchers write. "For now, there are many anecdotal media accounts of highly targeted, sophisticated AI spear phishing attacks that leveraged AI. These are typically bespoke campaigns.
"Soon, the phishing-as-a-service market will shift to mass adoption of AI Spear Phishing Agents. Once that happens, the baseline quality and effectiveness of mass phishing campaigns will rise to a level we currently equate with targeted spear phishing attacks."
Organizations should begin preparing now for unskilled cybercriminals to gain access to these sophisticated AI capabilities.
"Disruption happens gradually and then all at once, to paraphrase Clayton Christensen," the researchers write. "We must be prepared for when the inevitable disruption to the phishing-as-a-service market occurs, as AI-generated phish become more effective, easier to adopt and ultimately more lucrative for criminals."
New-school security awareness training can help your employees keep up with evolving social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Blog post with links here:
https://blog.knowbe4.com/ai-powered-spear-phishing-can-now-outperform-human-attackers
Can You Be Spoofed?
Are you aware that one of the first things hackers attempt is whether or not they can spoof the email address of someone in your domain?
This is how "CEO fraud" spear-phishing attacks are launched on your organization. Such attacks are hard to defend against, unless your users know what to look for.
Are your email servers vulnerable to spoofing? KnowBe4 can help you find out with our free Domain Spoof Test. It's quick, easy and often a shocking discovery.
Find out now if your email server is configured correctly, many are not!
- This is a simple, non-intrusive "pass/fail" test
- We will send a spoofed email "from you to you"
- If it makes it through into your inbox, you know you have a problem
- You'll know within 48 hours!
Try to Spoof Me!
https://info.knowbe4.com/domain-spoof-test-1-chn
Let's stay safe out there.
Warm Regards,
Stu Sjouwerman, SACP
Founder and CEO
KnowBe4, Inc.
PS: Five Potential Risks Of Autonomous AI Agents Going Rogue via Forbes:
https://www.forbes.com/councils/forbestechcouncil/2025/04/17/five-potential-risks-of-autonomous-ai-agents-going-rogue/
PPS: "5 ways Agentic AI promises to improve security ops":
https://www.scworld.com/perspective/5-ways-agentic-ai-promises-to-improve-security-operations
- Jamie Paolinetti - Actor (born 1964)
- Sir Winston Churchill (1874 – 1965)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-15-16-scary-a-new-real-cash-scam-sweeps-across-the-us-warn-your-family-and-friends
Ransomware Surged by 126% in the First Quarter of 2025
Cyberattacks per organization increased by 47% during Q1 2025, with 1,925 attacks per week, according to researchers at Check Point. Ransomware attacks rose by 126%, with 62% of incidents occurring in North America. Organizations in the education, government and telecommunications sectors were the most frequently targeted last quarter.
"While no market sector is immune from cyber attack, the education sector was the hardest hit in Q1 2025, averaging 4,484 attacks per organization each week—a staggering 73% increase from the previous year," Check Point says.
"The government sector followed closely, with 2,678 attacks per organization per week, a 51% increase, while the telecommunications sector experienced the highest percentage increase, with a 94% jump, reaching 2,664 attacks per organization weekly.
"The growing reliance on digital infrastructure in these industries, coupled with their public-facing nature, makes these critical infrastructure sectors prime targets for cyber criminals looking to exploit vulnerabilities."
Organizations need to have a defense-in-depth strategy to protect themselves against this onslaught of threats. Check Point offers the following recommendations:
- "Enhance Security Posture: Regularly update and patch systems to close vulnerabilities. Multi-layered security measures, including firewalls and endpoint protection, are essential.
- "Employee Training and Awareness: Regular training sessions can educate employees about the latest cyber threats and phishing tactics, fostering a culture of vigilance.
- "Advanced Threat Prevention: Utilize technologies such as sandboxing and anti-ransomware tools to detect and block sophisticated attacks.
- "Adopt Zero Trust Architecture: Implement strict identity verification for every person and device attempting to access network resources. This is particularly important to maintain hybrid cloud security.
- "Regular Backups and Incident Response Planning: Ensure regular backups of critical data and develop comprehensive response plans to quickly address and mitigate the impact of attacks.
- "Network Segmentation: Isolate critical systems to limit the spread of attacks and protect sensitive information.
- "Vulnerability Management: Conduct regular vulnerability assessments and penetration testing, prioritizing remediation efforts based on potential impact."
Check Point has the story:
https://blog.checkpoint.com/research/q1-2025-global-cyber-attack-report-from-check-point-software-an-almost-50-surge-in-cyber-threats-worldwide-with-a-rise-of-126-in-ransomware-attacks/
Lack of Security Awareness Tops List of Cyberdefense Obstacles
Most organizations cite low security awareness among employees as the biggest barrier to defending against cyberattacks, according to a new survey by CyberEdge Group.
"This result reinforces the idea that in cybersecurity, as in so many other areas of business and life, people challenges trump technology issues every time," the researchers write. "Without doubt, although computers speed up every year, people don't (and some days we suspect they are getting slower).
"But the data serves as a reminder that we should be investing more in educating end users and training our cybersecurity teams."
The top four threats cited by organizations were malware, phishing, ransomware and account takeovers. These threats often overlap—for example, most ransomware incidents begin with phishing attacks and involve preliminary malware staging.
The report also found that the number of organizations hit by ransomware declined, although the average ransom demand increased. Additionally, only half of the orgs that paid the ransom were able to recover their data. The researchers note, "the reduction in the number of organizations victimized by ransomware has been partially offset by a trend toward targeting larger enterprises that can afford larger ransom payments."
Notably, the survey found that 82% of organizations were hit by cyberattacks last year, but only 64% expect to be hit in 2025, suggesting a false sense of confidence.
Additionally, IT teams cited employees' mobile devices as the most difficult assets to secure. "Threat actors employ web and mobile application attacks to steal credentials and personal information, which they can then use to impersonate victims to carry out data breaches, identity theft and other crimes," the researchers write.
"The problem is made worse when people reuse the same passwords for multiple personal and work accounts." New-school security awareness training gives your organization an essential layer of defense against cyberattacks.
CyberEdge Group has the story:
https://www.businesswire.com/news/home/20250415839378/en/Only-Half-of-Ransomware-Victims-Recover-Data-After-Paying-Finds-CyberEdge-Groups-2025-Cyberthreat-Defense-Report
What KnowBe4 Customers Say
"Hi Stu, Thanks for reaching out. I'm absolutely a happy camper here with KnowBe4. This has been my third company that I've launched and advocated the use of KnowBe4. Keep up the great work!"
- F.J., Sr. Security Manager
- The (scary) AI 2027 scenario is the first major release from the AI Futures Project:
https://ai-2027.com/summary - Midnight Blizzard deploys new GrapeLoader malware in embassy phishing:
https://www.bleepingcomputer.com/news/security/midnight-blizzard-deploys-new-grapeloader-malware-in-embassy-phishing/ - China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents:
https://www.reuters.com/technology/cybersecurity/chinas-harbin-says-us-launched-advanced-cyber-attacks-winter-games-2025-04-15/ - Cozy Bear targets EU diplomats with wine-tasting invites (again):
https://www.helpnetsecurity.com/2025/04/16/cozy-bear-targets-eu-diplomats-with-wine-tasting-invites-again/ - GPS Spoofing Attacks Spike in Middle East, Southeast Asia:
https://www.darkreading.com/cyberattacks-data-breaches/gps-spoofing-attacks-spike-middle-east-southeast-asia? - "I sent you an email from your email account," sextortion scam claims:
https://www.malwarebytes.com/blog/news/2025/04/i-sent-you-an-email-from-your-email-account-sextortion-scam-claims - CISA extends CVE program contract with MITRE for 11 months amid alarm over potential lapse:
https://therecord.media/cisa-extends-cve-program-contract-with-mitre - New FTC Data Show Top Text Message Scams of 2024; Overall Losses to Text Scams Hit $470 Million:
https://www.ftc.gov/news-events/news/press-releases/2025/04/new-ftc-data-show-top-text-message-scams-2024-overall-losses-text-scams-hit-470-million - Google warns of increase in AI-generated malicious content:
https://www.bleepingcomputer.com/news/google/google-blocked-over-5-billion-ads-in-2024-amid-rise-in-ai-powered-scams/ - Malicious bots account for 37% of all internet traffic:
https://www.imperva.com/resources/resource-library/reports/2025-bad-bot-report/
- Virtual Vaca #1 to Top 10 Places To Visit in Chile - Travel Guide:
https://youtu.be/CeRh5Epg-3c - Virtual Vaca #2 to Canada in 4K - Incredible Scenes & Uncovering Hidden Gems:
https://youtu.be/oSPoGIhp9E8 - I Crashed Into A Tree during my Wingsuit Flight in South Africa:
https://youtu.be/rIr7NMd12dg - Humanoid Robot Atlas Takes on a New Role as a Camera Operator:
https://youtu.be/yfCWhmK5Yo4?si=nQpmYsAvE2zKCQzn - [WORLD FIRST] Driving Upside Down in McMurtry Spéirling Electric Hypercar:
https://www.youtube.com/watch?v=g6LYcgaQ46c - Bounce Level: Expert. The Ultimate Trampoline Compilation:
https://youtu.be/kJ_66qnt970?si=wDqcoWwYaynM4yox - [ANIMATED GRAPHICS] China's car exports have skyrocketed, soaring past the world's biggest auto powerhouses:
https://www.youtube.com/watch?v=tqk4_K09ZZk - This "bird" robot uses its butt to stay in balance:
https://www.youtube.com/watch?v=5iV_hB08Uns - World Order Is back with 'Neo Samurai' - a vibrant call to reclaim tradition and forge new paths as modern samurai:
https://www.flixxy.com/neo-samurai-rising-world-orders-epic-return.htm?utm_source=4 - The Tube Station That Threatened Big Ben:
https://youtu.be/O0ZkVFmHUNA - [SUPER COOL] Early Color Autochromes Brought to Life c.1910
https://youtu.be/fsbiBoQB88E - German Champion of Magic Alana brings her revolutionary fashion magic act to the Fool Us stage, seamlessly blending elegance with astonishing illusion:
https://www.flixxy.com/the-five-handed-enchantress-alanas-fashion-magic.htm?utm_source=4 - Imagine Having a Private Sauna Overlooking the Alps at BBC Earth Explore:
https://youtu.be/g_IRlerZVTg - For Da Kids #1 - Abandoned Dog Becomes Fluffiest Poodle Mix:
https://youtu.be/2hwOOs80X_w - For Da Kids #2 - Little Dog Chases Marathon Runner For Miles Until Finally Catches Up:
https://youtu.be/tU6YdUu20Xs - For Da Kids #3 - Baby Elephant Is Freed From Chains And Gets A New Mom 💙:
https://youtu.be/h2Yz5ZAO4bk - For Da Kids #4- Baby Hyena Chews Shoes Instead of Toys And Plays Catch:
https://youtu.be/hfXdMF_vFbk - For Da Kids #5 - Tiny Baby Lambs Don't Leave Lady's Side After She Saved Them:
https://youtu.be/yLgTi7lvayk