Skip to main content

Social Engineering

MuddyWater Exclusive: Dangerous Global Phishing Campaign

MuddyWater Exclusive: Dangerous Global Phishing Campaign

Get an exclusive look at the dangerous global MuddyWater phishing campaign—how it operates, who it targets, and simple, practical steps you can take today to stay protected.

Analyst 207
MuddyWater Exclusive: Dangerous Mailbox Phishing Surge

MuddyWater Exclusive: Dangerous Mailbox Phishing Surge

Think your inbox is safe? MuddyWater’s latest phishing wave shows how compromised mailboxes let attackers steal credentials and session tokens, impersonate colleagues, and turn a single click into long‑term espionage across organizations.

Analyst 207
Singapore Officials Impersonated in Exclusive Costly Scam

Singapore Officials Impersonated in Exclusive Costly Scam

Singapore officials impersonated in a sophisticated, costly scam—learn how it works and simple steps to protect yourself before you become a target.

Analyst 207
Singapore Officials Impersonated in Stunning, Damaging Scam

Singapore Officials Impersonated in Stunning, Damaging Scam

Think twice before trusting top search results: criminals are buying Google ads to surface near‑perfect clones of Singapore government sites and using AI-generated deepfakes of real officials to trick investors into wiring funds or handing over credentials.

Analyst 207
Singapore Officials Targeted in Stunning Damaging Scam

Singapore Officials Targeted in Stunning Damaging Scam

A stunning Singapore officials scam has exposed shocking vulnerabilities—discover how the damaging scheme unfolded and what it means for public trust.

Analyst 207
Smishing Triad Exclusive: Dangerous 194K Domains Revealed

Smishing Triad Exclusive: Dangerous 194K Domains Revealed

Think a text cant hurt you? Researchers say a single smishing campaign has spawned over 194,000 malicious domains, turning routine SMS alerts into localized lookalike sites and clever redirect chains that steal credentials or deliver malware worldwide.

Analyst 207
North Korean Hackers: Exclusive Dangerous Drone Job Scam

North Korean Hackers: Exclusive Dangerous Drone Job Scam

North Korean hackers are posing as recruiters for “exclusive” drone jobs that could put applicants in real danger — here’s how to spot the scam and protect yourself.

Analyst 207
North Korean Hackers Exclusive Drone Espionage Threat

North Korean Hackers Exclusive Drone Espionage Threat

Imagine a calendar invite from a colleague that’s actually a spy. North Korean threat actors are exploiting trusted collaboration tools and clever social engineering to steal drone designs and supplier data from European defense contractors.

Analyst 207
Ukraine Aid Groups Hit by Exclusive Fake Zoom PDF Attacks

Ukraine Aid Groups Hit by Exclusive Fake Zoom PDF Attacks

Who do you trust when the envelope itself is the weapon? A campaign called PhantomCaptcha disguised malware inside a Zoom-related PDF, giving attackers stealthy, long-term access to Ukraine aid groups and risking donor data, credentials and field operations.

Analyst 207
Spotlight shines on minimalist podium with glowing laptop in empty auditorium.

Upcoming Speaking Engagements: Schedule and Key Takeaways

How do you change a system that amplifies its own noise? Join Bruce Schneier and Nathan E. Sanders on Oct 22–23, 2025 as they turn insights from Rewiring Democracy into practical prescriptions across three public events — a policy talk at Harvard’s Ash Center, a community conversation and book signing at Cambridge Public Library, and a wide-ranging virtual session with Data & Society.

Analyst 207
Hand replacing old light switch with modern smartphone against Cambridge cityscape at dusk, symbolizing change and diversity.

Rewiring Democracy: Must-See Cambridge Events Best

Join Bruce Schneier and Nathan E. Sanders in Cambridge and online as they unpack Rewiring Democracy—three public events (a Harvard book talk, an evening signing at Cambridge Public Library, and a Data & Society virtual conversation) that turn technical diagnosis into practical civic solutions.

Analyst 207
AI-driven social engineering: Must-Have Risk Fix

AI-driven social engineering: Must-Have Risk Fix

ISACA’s new survey sounds a wake-up call: only 1 in 10 cybersecurity pros feel “very prepared” as AI-powered social engineering tops the threat list for 2026, so organizations must sharpen playbooks, training, and verification now before attackers exploit the gap.

Analyst 207
copy-paste attacks: Dangerous, Must-Have Fixes

copy-paste attacks: Dangerous, Must-Have Fixes

When a site tells you “paste this into your console” it may seem like helpful tech support, but ClickFix attacks are a fast‑growing social‑engineering scam that trick users into running scripts that steal tokens, clipboard data, or install persistent browser malware. Learn why low technical barriers, defenses that can be bypassed by user interaction, and high‑value browser tokens make copy‑paste attacks especially dangerous — and what can be done to stop them.

Analyst 207
phishing emails: Urgent Warning—Must-Have Best Tips

phishing emails: Urgent Warning—Must-Have Best Tips

Don’t panic — LastPass says it wasn’t hacked; those alarming emails are a phishing scam. Pause, verify updates through the official app or website, and report any suspicious messages.

Analyst 207
Whisper 2FA: Exclusive Risky Phishing Threat

Whisper 2FA: Exclusive Risky Phishing Threat

Think 2FA is foolproof? Researchers warn Whisper 2FA — a phishing‑as‑a‑service tool tied to roughly one million credential‑theft attempts since July 2025 — shows attackers can cheaply scale real‑time relay attacks, so phishing‑resistant authentication and layered defenses are now essential.

Analyst 207
extortion attempt: Exclusive Risky Refusal Shakes Trust

extortion attempt: Exclusive Risky Refusal Shakes Trust

When an extortionist claimed nearly a billion Salesforce records were stolen, the company made a bold choice: no negotiation, no payment. That stance forces customers and the industry to balance short-term harm against the long-term need to deter cybercrime.

Analyst 207
Scattered Lapsus$ Hunters: Risky Stunning Extortion

Scattered Lapsus$ Hunters: Risky Stunning Extortion

Believe it or not, a loose group offering just $10 in Bitcoin is recruiting crowds to harass executives — a novel, low-cost form of extortion that trades big payouts for mass nuisance and could be dangerously scalable.

Analyst 207
subpoena management platform Stunning Risky Outage Exposes

subpoena management platform Stunning Risky Outage Exposes

When Kodex — the subpoena-tracking platform trusted by police and big tech — went dark after its domain was frozen over a forged legal order, agencies were left scrambling and the outage revealed how social engineering against registrars and cloud providers can cripple critical legal services without touching any code. It’s a wake-up call to strengthen verification, add redundancy, and treat DNS and registrar governance as core security, not an afterthought.

Analyst 207
phishing Warning: Exclusive Risky Threat & Must-Have Fixes

phishing Warning: Exclusive Risky Threat & Must-Have Fixes

ENISA warns that simple phishing emails and unpatched systems were behind most EU cyber intrusions last year, turning tiny mistakes into big national-security headaches. It’s a wake-up call to harden the basics—MFA, patching, email defenses, and smarter user training—before the next click becomes a crisis.

Analyst 207
Windows shortcuts: Stunning, Risky DLL Lures

Windows shortcuts: Stunning, Risky DLL Lures

A single innocent-looking Windows shortcut in a ZIP can quietly trigger PowerShell to fetch a DLL implant and let attackers run code inside trusted processes — turning everyday convenience into a stealthy compromise. Stay skeptical of unexpected archives and treat shortcut icons as potentially dangerous until verified.

Analyst 207
Generative AI: Stunning, Dangerous Scam Surge

Generative AI: Stunning, Dangerous Scam Surge

When a convincing video or familiar voice asks for money, generative AI makes the split-second choice to trust or verify riskier than ever; Bruce Schneier’s “Scam GPT” reveals how cheap, scalable synthetic text, images and voices are automating old cons and spawning new ones. We’ll need smarter tech, clearer rules and stronger community safeguards to keep deception from becoming the new normal.

Analyst 207
Milesight routers: Exclusive Dangerous Smishing Threat

Milesight routers: Exclusive Dangerous Smishing Threat

Imagine your factory router moonlighting as a scammer — attackers have been hijacking Milesight industrial cellular routers to send believable phishing SMS from legitimate device numbers. Change default passwords, patch firmware, and disable unused SMS APIs before your edge devices start ringing alarm bells.

Analyst 207
North Korean IT personas: Exclusive Risky Threat Revealed

North Korean IT personas: Exclusive Risky Threat Revealed

You won’t believe it until you see it: Okta uncovered convincing fake North Korean IT personas applying, interviewing, and even landing roles across tech, healthcare, finance and AI—using hiring pipelines as a stealthy route for espionage and exploitation. The takeaway: identity is the new perimeter, and companies must tighten onboarding, vetting and access controls before attackers turn routine hiring into a backdoor.

Analyst 207
social engineering: Risky Tricks Exposed

social engineering: Risky Tricks Exposed

A clear, reader-friendly breakdown of a convincing phone scam that shows how faux authority, fake case numbers and offers of a “supervisor” trick people — plus the timeline, red flags, and simple steps you can use to avoid being fooled. Learn what habits and tech fixes really stop these attacks before they cost you time or money.

Analyst 207