MORE POSTS
March 22, 2021 4:33 PM
Annual March Hackness: The Opener — What a Difference a Year Makes in the World of Phishing Attacks
Area 1 has been doing our own Phishing brackets over the past five years. We took a hiatus in 2020 (as did the NCAA), so today, we proudly introduce the 5th Annual March Hackness: The Phishing Tournament....
March 18, 2021 3:35 PM
Sophisticated Microsoft Spoof Targets Financial Departments
A sophisticated Microsoft Office 365 credential harvesting campaign targets financial departments at companies across multiple industries, as well as newly-appointed CEOs and executive assistants....
January 27, 2021 11:37 AM
Count yourself in for a vaccine phish: new phishing campaign exploits concern over COVID-19 vaccine availability
Area 1 has uncovered a coronavirus vaccine-themed campaign spoofing the CDC. The attack, which originally bypassed Office 365’s email security, uses a number of techniques to bypass normal anti-spoofing and email authentication methods....
December 11, 2020 12:03 PM
Phishpoint back in full swing: an infamous Microsoft SharePoint spoof resumes with new tactics
Our researchers detected an updated wave of Microsoft SharePoint phish that are leveraging new COVID-19 restrictions to steal victims’ login information....
November 10, 2020 2:49 PM
What is an Integrated Email Security solution? And is it right for your organization?
Gartner has named Area 1 Security as a Representative Vendor for IESS. We believe, Area 1 Security, as an IESS, provides the core functionalities of a SEG, but has the advantage of being very quick and easy to deploy, without requiring changes to the email flow at the gateway....
November 09, 2020 3:09 PM
Phishing campaign threatens job security, drops Bazar and Buer Malware
A phishing campaign is threatening targets with false claims of employment termination. The goal of the attacker is to intimidate employees into clicking on a link that will ultimately lead to Bazar or Buer malware infections by way of Trickbot....
October 20, 2020 9:45 AM
With 14 days to go, we haven’t nailed the basics: election security risks from expired domains
Failure for any organization to properly register their domains poses several key risks. For example, anyone who might register an election-sensitive domain would be able to assume the identity of elections officials and send phishing emails....
October 13, 2020 2:33 PM
Spike in Amazon phishing for Prime Day: a new day of deals means new phishing campaigns
Cyber criminals target Amazon Prime members. 2020 Prime Day phishing attacks attempt to steal credit card details, PII data....
October 06, 2020 10:48 AM
PAC spoof drops Emotet: phishing campaign leverages stolen PAC content to drop Emotet
President Donald Trump, election fundraising, Microsoft Office 365 used to send Emotet malware in fake Political Action Committee phishing email....
September 23, 2020 10:57 AM
Are you GDPR-compliant? New phishing message harvests credentials with GDPR lure
Credential harvesting phishing emails leverage GDPR compliance and exploits cloud-based services, Virtual Private Servers, to target sales executives....
September 09, 2020 11:17 AM
Latest SBA phishing attempt: stealthy social engineering phish using newly registered domains attempts to gain bank details
Area 1 blocks social engineering, COVID-19 phishing emails impersonating Small Business Administration, using Newly Registered Domains, PDF attachments....
August 27, 2020 12:02 PM
“Face mask manufacturer” supplies Agent Tesla Malware: campaign employs Covid-19 lures and sophisticated evasion techniques
Covid-19 phishing attack exploits need for face masks, thermometers to launch Agent Tesla malware (advanced Remote Access Trojan); bypasses gateways, DMARC....
August 17, 2020 12:43 PM
July bonus Microsoft spear phishing
The creators of two Microsoft phishing campaigns, that Area 1 has dubbed “Summer Bonus”, are attempting to lure unsuspecting employees into divulging their Microsoft credentials....
July 26, 2020 12:52 PM
New Area 1 security study shows that U.S. State & local election administrators remain vulnerable to phish
With only 100 days until Election Day, Area 1 Security’s new “Phishing Election Administrators” report assesses the depth of current email security controls used by 10,000 U.S. state and local election administrators....