In 2020 Toll Group went twice through a ransomware attack, now Sophos which acted as a response and investigation team for the events, announces that the entry point was an account of an employee who died but remained active in the system.

Nefilim Ransomware Attack Used “Ghost” Credentials.

According to the report by Sophos, the Nefilim group responsible for the infidelity attack that was on the company’s network for about a month without the defense systems identifying suspicious activity, the user used by the attack group belonged to a deceased employee but his account was locked/deleted due to being integrated into various services. 

Read more about Examples and Numbers of Social Engineering attacks  ›

Save Your Company from Social Engineering Attacks Like that

 

Register and Get your Personalized Free Exposure Report NOW
and See your where your Company is Exposed to Hackers

Recently Published on our Blog

The Hidden Insider Threat You’re Probably Ignoring – Ex-Employee Password Access

🔑 Ex-Employees Still Have Your Passwords – And They’re Using Them

🚨 Many workers admit they’ve logged in to former employers’ accounts after leaving – and sometimes months later.

💥 It’s a silent insider threat that bypasses firewalls and phishing filters entirely.

🕵️ The real danger? Credentials that stay active long after offboarding, often with access to sensitive systems, customer data, or financial platforms.

⚠️ In some cases, ex-staff under strained exits can exploit this for sabotage or even sell access on the dark web.

📊 Even “friendly” departures can lead to accidental leaks if accounts aren’t properly closed.

🔍 The fix? Immediate credential deactivation, MFA, and ongoing account audits to spot dormant access before it’s abused.

📢 Your next security breach could come from someone who already knows your systems. Book your AUMINT.io consultation today.

#CyberSecurity #InsiderThreats #AccessControl #FraudPrevention #RiskManagement #CISOs #ITSecurity #DataProtection

read more

📢 CISOs: Best Free Resources to Manage Security Awareness Campaigns 📢

Security awareness campaigns are your frontline defense against social engineering attacks. But managing them effectively without a budget can be tough.

Here’s a carefully curated list of free resources every CISO can use to plan, run, and measure impactful security awareness programs:

1️⃣ SANS Security Awareness Planning Toolkit – Ready-made templates, calendars, and communication guides.
https://www.sans.org/security-awareness-training/resources/planning-toolkit

2️⃣ CISA Security Awareness Materials – Posters, videos, and tip sheets designed for wide audiences.
https://www.cisa.gov/security-awareness-resources

3️⃣ NIST Security Awareness and Training Guide (SP 800-50) – Framework for building and improving awareness programs.
https://csrc.nist.gov/publications/detail/sp/800-50/final

4️⃣ Infosec IQ Free Awareness Campaign Templates – Email and social media content to engage employees.
https://www.infosecinstitute.com/skills/awareness-free-resources/

5️⃣ Cyber Aware UK – Free resources and monthly campaign toolkits from the UK government.
https://www.ncsc.gov.uk/cyberaware/home

6️⃣ Phishing Quiz by KnowBe4 – Interactive tool to educate employees on phishing red flags.
https://www.knowbe4.com/phishing-security-test

7️⃣ Awareness Campaign Scorecard (by Gartner) – Measure campaign effectiveness and engagement.
https://www.gartner.com/en/documents/

Security awareness is not just about info – it’s about culture change.

Want to see how AUMINT.io’s targeted social engineering simulations can boost your campaign results and give you actionable insights?

📅 Book your free intro call now: Schedule here

💾 Save this post and transform your awareness campaigns today!

#CISO #SecurityAwareness #PhishingPrevention #HumanRisk #AUMINT

read more

The Coming Wave of Social Engineering Attacks No One is Ready For

🛑 The AI-Powered Social Engineering Storm Is Coming

💡 Imagine getting a voice call from your CEO – but it’s not them. It’s a deepfake, paired with a perfectly written urgent email.

⚠️ That’s the next generation of phishing – faster, smarter, and terrifyingly convincing.

🤖 AI can now scrape your social media, corporate bios, and leaked data in seconds to create hyper-personalized attacks that feel 100% real.

🎯 This means your staff won’t just get generic spam. They’ll get messages with insider details, references to real projects, and even personal anecdotes.

🛡️ The solution isn’t just more training – it’s proactive intelligence. Dark web monitoring, deepfake detection, and continuous behavioral awareness are now mission-critical.

📉 Without them, even experienced executives will fall for scams that feel like direct conversations with trusted contacts.

📢 The attackers aren’t waiting – and neither should you. Book your AUMINT.io strategy session today to get ahead of the threat curve.

#CyberSecurity #SocialEngineering #FraudPrevention #DeepfakeThreats #CISOs #RiskManagement #DataSecurity #BusinessContinuity

read more