Clearwater, FL, USA
2010
  |  By KnowBe4 Team
Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.
  |  By KnowBe4 Team
A recent survey from Experian found that 60% of companies report fraud losses that are “somewhat or significantly higher” than in previous years, with a majority of respondents citing AI-generated phishing attacks as their top AI-related fraud concern. “Businesses identify AI-generated phishing as the most common AI-enabled fraud risk at 53%,” the report says.
  |  By KnowBe4 Team
The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.” OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.
  |  By KnowBe4 Threat Lab
An employee at your company receives an email from hr@yourcompany.com. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required.
  |  By KnowBe4 Team
With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce. Voice is the fastest-growing attack vector, and it’s because it’s dangerously effective. According to Verizon’s 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.
  |  By Dr. Kawin Boonyapredee
Quantum Readiness Day on 24 September is a useful reminder that the security work we do today is not only about preventing breaches tomorrow. It is about protecting data and digital trust for years to come.
  |  By KnowBe4 Team
Researchers at ZeroBEC are tracking a phishing platform called “Greatness” that’s been significantly upgraded since it surfaced in 2023. “Since its initial discovery, the platform has evolved significantly,” the researchers write.
  |  By KnowBe4 Threat Lab
In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this.
  |  By KnowBe4 Team
A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.
  |  By KnowBe4 Team
Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.
  |  By KnowBe4 | Securing Humans & Agents
The Sack Company implemented KnowBe4 to eliminate "click happy" employee behavior and streamline phishing campaign management across its family of companies. By leveraging KnowBe4’s AI Defense Agents (AIDA) and gamified phishing security awareness training, The Sack Company reduced organizational risk scores while saving 50 to 60 hours per week in IT monitoring time. KEY HIGHLIGHTS & RESULTS: TIMESTAMPS / CHAPTERS.
  |  By KnowBe4 | Securing Humans & Agents
Overrated and underrated AI hot takes.
  |  By KnowBe4 | Securing Humans & Agents
Still forcing yourself to remember random passwords? Dr. Martin Kraemer shares a memory-based formula to craft secure, super-memorable passphrases.
  |  By KnowBe4 | Securing Humans & Agents
When high-stakes attackers target you, they aren't playing the cards — they’re playing the player. For National Social Engineering Day, Erich Kron reveals modern social engineering's biggest tell.
  |  By KnowBe4 | Securing Humans & Agents
AI tools state false information with just as much credibility as the truth. Here’s what you need to know about AI hallucinations.
  |  By KnowBe4 | Securing Humans & Agents
More summer screen time means more opportunities for gaming scammers. Watch out for fake "Free Robux" scams targeting kids online, and learn the easy red flags to teach your family today.
  |  By KnowBe4 | Securing Humans & Agents
What is the single best piece of security advice? Pausing.
  |  By KnowBe4 | Securing Humans & Agents
AI add-ons can automate everything from travel to banking—but are they opening backdoors to your private data? Here is what to look for before granting permissions.
  |  By KnowBe4 | Securing Humans & Agents
What if you could build a complete, personalized security awareness course from a single prompt — in seconds? KnowBe4's AIDA Content Creation Agent does exactly that. Powered by our decade of AI innovation, it generates e-learning modules instantly — and goes far beyond basic content generation: Deepfake Face Injection — Insert real members of your team into training visuals using safe, consensual deepfake synthesis. Your people, your culture, your training.
  |  By KnowBe4 | Securing Humans & Agents
Unexpected delivery texts are one of the most common smishing tricks out there. Here is why you should never click the link, and what to do instead!
  |  By KnowBe4
Your employees are your largest attack surface. For too long the human component of cybersecurity has been neglected, leaving employees vulnerable and creating an easy target for cybercriminals to exploit. But your users want to do the right thing. Rather than a hurdle to be overcome, organizations need to think of their employee base as an asset, once properly equipped.
  |  By KnowBe4
Want to read this bestseller? Register now for your free (instant 240-page PDF download) Cyberheist e-book and learn how to not be the next victim! Cyberheist was fully updated and written for the IT team and owners / management of Small and Medium Enterprise, which includes non-profits, local and state government, churches, and any other organization with more than a few thousand dollars in their bank operating account.
  |  By KnowBe4
Hackers have become increasingly savvy at launching specialized attacks that target your users by tapping into their fears, hopes, and biases to get access to their data. Cybersecurity is not just a technological challenge, but increasingly a social and behavioral one. People, no matter their tech savviness, are often duped by social engineer scams, like CEO fraud, because of their familiarity and immediacy factors.
  |  By KnowBe4
Spear phishing emails remain a top attack vector for cybercriminals, yet most companies still don't have an effective strategy to stop them. This enormous security gap leaves you open to business email compromise, session hijacking, ransomware and more. Don't get caught in a phishing net! Learn how to avoid having your end users take the bait. Roger Grimes, KnowBe4's Data-Driven Defense Evangelist, will cover techniques you can implement now to minimize cybersecurity risk due to phishing and social engineering attacks.
  |  By KnowBe4
Anything but 100% completion on your employee compliance training is often more than simply frustrating. Compliance audits and regulatory requirements can make anything less than 100% feel like a failure. But, getting compliance on your compliance training is possible! Organizations have struggled for years with getting everyone to complete their required compliance training. This puts organizations at risk of more incidents occurring, fines or reputational damage if an employee is non-compliant.
  |  By KnowBe4
All multi-factor authentication (MFA) mechanisms can be compromised, and in some cases, it's as simple as sending a traditional phishing email. Want to know how to defend against MFA hacks? This eBook covers over a dozen different ways to hack various types of MFA and how to defend against those attacks.

KnowBe4 is the provider of the world's largest integrated platform for security awareness training combined with simulated phishing attacks. Join our more than 56,000 customers to manage the continuing problem of social engineering.

The KnowBe4 platform is user-friendly and intuitive, and powerful. It was built to scale for busy IT pros that have 16 other fires to put out. Our goal was to design a full-featured, yet easy-to-use platform.

Find Out How Effective Our Security Awareness Training Is:

  • Train Your Users: The world’s largest library of security awareness training content. Automated training campaigns with scheduled reminder emails.
  • Phish Your Users: Best-in-class, fully automated simulated phishing attacks, thousands of templates with unlimited usage, and community phishing templates.
  • See The Results: Enterprise-strength reporting, showing stats and graphs for both training and phishing, ready for management. Show the great ROI!

Human Error. Conquered.