Author name: POPP3R

What Ransomware Awareness Training Misses About Vishing

Most ransomware awareness training programs teach employees to recognise malicious attachments, suspicious links, and spoofed sender addresses. That coverage is necessary but no longer sufficient. The ShinyHunters campaign targeting healthcare organisations, reported by HealthSystemCIO on September 10, 2026, reveals the gap: ransomware actors now routinely begin their attack with a phone call, not an email,

What Ransomware Awareness Training Misses About Vishing Read More »

Behaviour Change Cybersecurity: Beating Voice Phishing

Voice phishing has quietly overtaken email as the preferred entry point for attackers targeting organisations, and no amount of technical filtering closes that gap without genuine behaviour change. According to Google Cloud’s Mandiant M-Trends 2026 report, vishing accounted for 11 per cent of all confirmed initial access methods observed across more than 500,000 hours of

Behaviour Change Cybersecurity: Beating Voice Phishing Read More »

The Phishing Simulation Your Marketing Team Is Missing

A phishing campaign that has been quietly running for at least five months just exposed a hard truth about employee training programs. When threat researchers at CTM360 published their RecruitTrap findings in August 2026, they mapped more than 3,000 phishing URLs impersonating recruiters from over 50 real organizations. The primary victims were marketing professionals, and

The Phishing Simulation Your Marketing Team Is Missing Read More »

Behaviour Change Cybersecurity: The Starbucks Portal Lesson

In January 2026, attackers gained access to the personal and financial records of 889 Starbucks employees without ever penetrating the company’s core infrastructure. The method was precise: a convincing replica of Starbucks’ Partner Central, the internal portal workers use to manage payroll, benefits, and employment details, was built to harvest credentials. Workers who entered their

Behaviour Change Cybersecurity: The Starbucks Portal Lesson Read More »

Ransomware Awareness Training: Gunra Targets Nonprofits

On August 10, 2026, CISA, the FBI, the National Security Agency, and South Korea’s National Police Agency issued a joint advisory warning organizations worldwide about Gunra ransomware, a fast-growing criminal operation that has already claimed Canadian victims. Advisory AA26-222A names healthcare providers, nonprofit services, financial institutions, and government agencies as active targets and describes an

Ransomware Awareness Training: Gunra Targets Nonprofits Read More »