KnowBe4 says attackers are abusing trusted services like DocuSign, SharePoint, Adobe…

· in brief

KnowBe4 says attackers are abusing trusted services like DocuSign, SharePoint, Adobe Sign, Dropbox and Google Drive to send phishing emails that look legitimate. In its analysis of 544,000 threat emails between June and August 2026, LOTS techniques accounted for 53,000 emails, with DocuSign and QuickBooks making up nearly two-thirds of that volume. The post says these emails can bypass security gateways because they come from real platforms. Windows users and small offices should be careful with document-share and payment messages, even when the sender looks trustworthy.

KnowBe4The Rise of Legitimate-Service Phishing: 1 in 10 Phishing Emails Now Comes From a Platform You Trust

Source: blog.knowbe4.com

More in this rubric
all →
· in brief

Hackread.com reports that the DOJ has charged MonsterCloud CEO Zohar Pinhasi with wire fraud and conspiracy to commit wire fraud. Prosecutors say he claimed the company could recover encrypted files without paying a ransom, but instead paid attackers for decryption keys and charged victims much higher fees. The FBI and CISA advise against paying ransoms, since payment does not guarantee files will be recovered or stolen data will not be leaked.

hackread.comMonsterCloud CEO Zohar Pinhasi Accused of Paying Hackers, Defrauding Victims

Source: hackread.com

· in brief

The CyberScoop reports that authorities have indicted MonsterCloud owner Zohar Pinhasi, accusing him of charging ransomware victims inflated fees while claiming to use proprietary recovery tools that did not exist. Prosecutors say he paid cybercriminals to recover data without telling clients, and that the company drew in hundreds of clients with false promises. Windows users and small offices hit by ransomware should be careful about who they trust for recovery and verify any claims before paying.

cyberscoop.comRansomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Source: cyberscoop.com

· in brief

Graham Cluley reports that UK losses from hacked email and social media accounts have risen by 417%, with scammers posing as your friends to sell tickets to gigs that do not exist. The post says this is part of a big rise in cyber scams stealing social media accounts. Home users should be careful with messages from friends that ask for money or tickets, and check requests through another channel before paying.

grahamcluley.comSmashing Security podcast #487: Clippy’s crypto comeback

Source: grahamcluley.com

5,454 members already hereReading, writing, commenting and voting. 0 verified · 179 joined this year