Generated by All in One SEO Pro v4.9.10, this is an llms.txt file, used by LLMs to index the site. # POPP3R CYBERSECURITY We specialize in cybersecurity for small-medium businesses, municipalities and non-profit organizations. ## Sitemaps - [XML Sitemap](https://popp3r.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [News](https://popp3r.com/news/) - [Pink Vishing: Security Awareness for Canadian Organizations](https://popp3r.com/pink-vishing-security-awareness-canadian-organizations/) - Your employees can spot a suspicious email. Fewer of them are prepared for the phone call that follows: someone claiming to be from IT, asking them to register a new passkey, and in minutes the attacker has their Microsoft 365 credentials. This is the active O-UNC-066 campaign, and it targets sectors that form the backbone - [Ransomware Awareness Training: The July Imperative](https://popp3r.com/ransomware-awareness-training-july-imperative/) - A single compromised employee account was all it took for ShinyHunters to access 70,000 Canadians' personal records at Canada Life in April 2026. No exotic vulnerability, no extended campaign: one credential, one door left unlocked, and a major Canadian financial services provider was facing a data breach notification and an extortion deadline simultaneously. For the - [Your Security Awareness Program Needs an In-Person Clause](https://popp3r.com/security-awareness-program-it-impersonation-silent-ransom-group/) - When a stranger walks into your office, identifies themselves as IT support, and plugs a USB drive into a workstation while your employee watches, every firewall you own is irrelevant. That is not a hypothetical. On May 26, 2026, the FBI issued a FLASH alert about the Silent Ransom Group (SRG), a Russia-linked extortion operation - [Why Behaviour Change Cybersecurity Beats SSO Vishing](https://popp3r.com/why-behaviour-change-cybersecurity-beats-sso-vishing/) - When an employee picks up the phone and hears what sounds like internal IT asking them to re-enrol a multifactor token, the firewall is already irrelevant. That is the quiet truth behind the latest wave of voice phishing attacks that Google's Mandiant team documented in January 2026, and it is why every Canadian organisation relying - [The SharePoint Zero-Day and Employee Security Training](https://popp3r.com/sharepoint-zero-day-employee-security-training/) - Every second Tuesday of the month, Microsoft releases security updates, and IT teams across the country quietly begin a race against exploitation. This month, the stakes are higher than usual. Microsoft’s April 2026 Patch Tuesday addressed 167 vulnerabilities, including eight rated critical and two zero-days, one of which is already being actively exploited in the - [Booking.com Breach Is a Social Engineering Defence Lesson](https://popp3r.com/booking-com-breach-social-engineering-defence/) - Booking.com confirmed on April 13, 2026 that unauthorized parties accessed customer reservation data through a third-party compromise. The stolen information included names, email addresses, phone numbers, postal addresses, and messages guests had exchanged with hotels through the platform. Financial data was not exposed, but the immediate weaponization of that booking data in follow-up attacks tells - [$500 Phishing Kits Demand a Cybersecurity Culture Shift](https://popp3r.com/500-phishing-kits-cybersecurity-culture-shift/) - Last week, the FBI and Indonesia's National Police dismantled the W3LL phishing network, arresting the alleged developer and seizing the platform's infrastructure. It was a meaningful enforcement milestone: the first coordinated action between American and Indonesian authorities targeting a phishing kit developer. But the headline about the arrest misses the more important story. The W3LL - [Payroll Pirates Reveal Canada's Human Risk Gap](https://popp3r.com/payroll-pirates-human-risk-management-canada/) - On April 9, 2026, Microsoft's security researchers published their investigation into Storm-2755, a financially motivated threat actor running what they are calling "payroll pirate" attacks against Canadian employees. The campaign does not rely on malware, ransomware, or headline-grabbing intrusions. It relies on two things that are already inside your organization: a staff member who Googled - [When Teams Is the Trap: Rethinking Phishing Prevention](https://popp3r.com/when-teams-is-the-trap-phishing-prevention/) - The attack unfolded through tools that would look routine to any working professional: a LinkedIn connection from a credible-seeming contact, an invitation to a Slack workspace that appeared genuinely company-branded, and then a Microsoft Teams video call that stalled with a familiar-looking technical error. The suggested fix was a software update. One developer clicked, and - [Why Contextual Security Awareness Training Works Better](https://popp3r.com/contextual-security-awareness-training/) - A new integration announced this week between Dashlane and KnowBe4 points to a fundamental shift in how effective contextual security awareness training actually works. Rather than delivering training on a quarterly schedule, the two companies have built a system that triggers learning the moment a credential risk is detected in the browser. The announcement offers - [Tax Season Phishing: The Security Training Blind Spot](https://popp3r.com/tax-season-phishing-security-training/) - Proofpoint researchers identified more than 100 malicious tax-themed phishing campaigns in early 2026, and Canadian organizations are among the primary targets. With April representing the peak filing period for most Canadians, attackers are exploiting the urgency, distraction, and financial stress that tax season reliably produces. Most organizations have not updated their security awareness training to - [AI Voice Cloning Phishing: What Security Training Misses](https://popp3r.com/ai-voice-cloning-phishing-security-awareness-training/) - Picture this: your company’s CFO calls your finance manager to approve an urgent wire transfer before end of day. The voice is familiar, the cadence right, even the slight impatience is typical of how she sounds under deadline pressure. The call is also completely fake. AI voice cloning phishing attacks have matured to the point - [ClickFix: The Fake CAPTCHA That's Tricking Employees](https://popp3r.com/clickfix-fake-captcha-social-engineering-employees/) - A social engineering technique called ClickFix is now the leading way cybercriminals break into organizations, and it asks nothing more from victims than pressing three keys on a keyboard. According to Microsoft’s 2025 Digital Defense Report, ClickFix has become the number one initial access method, responsible for 47% of all attacks observed by Microsoft Defender - [Why QR Code Phishing Is Beating Employee Security Training](https://popp3r.com/qr-code-phishing-employee-security-training/) - The FBI issued a public alert in January 2026 warning that North Korean state-sponsored hackers have been embedding malicious QR codes in spear-phishing emails to bypass corporate security controls and steal credentials from government agencies, universities, and think tanks. This technique, called quishing, is no longer a fringe attack method. QR code phishing emails surged - [Device Code Phishing Hits Microsoft 365: What to Know](https://popp3r.com/device-code-phishing-microsoft-365/) - A sophisticated phishing campaign is actively targeting Microsoft 365 accounts at more than 340 organizations across Canada, the United States, Australia, New Zealand, and Germany, using a technique called device code phishing to capture authentication tokens that persist even after a password reset. Security researchers first detected the attacks on February 19, 2026, and the - [Device Code Phishing: The Attack MFA Can't Stop](https://popp3r.com/device-code-phishing-attack-mfa/) - A new device code phishing attack campaign has compromised over 340 organizations across five countries, including Canada, since February 19, 2026, and the pace is accelerating. Researchers at Huntress, who published their analysis this week, found that multi-factor authentication provides no protection against this attack class. Employees who complete MFA challenges believe they are signing - [Quishing: Why QR Code Phishing Needs a Training Response](https://popp3r.com/quishing-qr-code-phishing-employee-training/) - A new variant of phishing is bypassing email filters, evading mobile defenses, and landing in employee inboxes with almost no friction. QR code phishing, known in the security industry as quishing, has grown at a pace that most security awareness training programs have not kept up with. If your team does not know how to - [CIRO Breach: Financial Sector Phishing Attack Exposes 750K](https://popp3r.com/financial-sector-phishing-attack-ciro-breach/) - A financial sector phishing attack on Canada's investment regulator has exposed the sensitive data of 750,000 investors, including social insurance numbers, annual income figures, government-issued IDs, and detailed account statements. The Canadian Investment Regulatory Organization (CIRO) confirmed in January 2026 that a targeted email delivered in August 2025 gave an attacker unauthorized access to records - [Spear Phishing Beats DMARC as Identity Attacks Surge](https://popp3r.com/spear-phishing-bypasses-dmarc-identity-attacks/) - Spear phishing attacks bypassed DMARC email authentication in 70 percent of cases detected last year, according to Darktrace's newly released 2025 annual report. The figure is striking enough on its own. But the broader picture reveals something more unsettling: the technical filters most organizations rely on are being outpaced by attackers who have shifted their - [Vishing Attack on One Employee Exposed 900,000 Records](https://popp3r.com/vishing-attack-employee-data-breach/) - When an identity protection company falls victim to a targeted phone scam, the lesson lands harder. On March 19, 2026, Aura confirmed that a vishing attack on one of its employees had exposed nearly 900,000 contact records. For security awareness training professionals and the teams they protect, the incident is not just another breach headline. - [Why Email Urgency Is Now the Top Phishing Red Flag](https://popp3r.com/email-urgency-phishing-red-flag/) - For years, the advice was simple: check for typos, look for a suspicious sender address, and watch out for requests for sensitive information. But new research published this week signals a significant shift in how employees are identifying phishing threats. According to a KnowBe4 poll, the top email urgency phishing red flag today is not - [Supply Chain Credential Theft and the TELUS Breach](https://popp3r.com/supply-chain-credential-theft-telus-breach/) - When TELUS Digital confirmed a cyberattack on March 12, 2026, the headline was about scale: nearly one petabyte of stolen data, a $65 million ransom demand, and one of Canada's largest telecoms facing a months-long silent intrusion. But the detail security teams should focus on is how the attack started. The ShinyHunters group did not - [Human Risk Management: Beyond Security Awareness Training](https://popp3r.com/human-risk-management-awareness-training/) - Nearly 70% of organizations believe their employees lack fundamental cybersecurity awareness, even at organizations that already run formal training programs. That finding, from Fortinet's 2024 Security Awareness and Training Global Research Report, captures a frustration that many security leaders recognize immediately: completing a course is not the same as being prepared. In 2026, the industry's - [Why Phishing Simulations Are Failing Your Team in 2026](https://popp3r.com/phishing-simulation-best-practices-2026/) - Most organizations run phishing simulations a few times a year and feel reassured when pass rates look good. But new research from ISACA and findings from Gartner's March 2026 Security and Risk Management Summit in Sydney paint a more troubling picture: the simulations themselves may be the problem. Outdated templates, unrealistic scenarios, and a compliance-first - [When Phishing Bypasses MFA: Lessons from Tycoon 2FA](https://popp3r.com/phishing-bypasses-mfa-tycoon-2fa-takedown/) - On March 4, 2026, Microsoft, Europol, and a coalition of industry partners announced the disruption of Tycoon 2FA, one of the most prolific phishing-as-a-service platforms ever documented. The takedown is a meaningful win for defenders, but the story it tells about how phishing bypasses MFA should be required reading for anyone building a security awareness - [When the Boss Calls: AI Voice Scams Target Employees](https://popp3r.com/ai-voice-scam-employee-training/) - AI voice scam employee training is no longer a future concern for Canadian organizations. On March 9, 2026, Canada's Competition Bureau issued a public alert warning that scammers are using artificial intelligence to impersonate government officials, politicians, and other trusted figures with a level of realism that makes these calls remarkably difficult to detect. The - [Retail Data Breach: Phishing Awareness Training Gap](https://popp3r.com/retail-data-breach-phishing-awareness-training/) - Retail Data Breach: Phishing Awareness Training Gap By POPP3R Cybersecurity | March 20, 2026 Table of Contents What Happened at Loblaw Why Exposed PII Fuels Phishing Campaigns Retail Data Breach Phishing Awareness Training: The Missing Layer Key Steps for Canadian Retailers What Happened at Loblaw On March 10, 2026, Loblaw Companies Limited confirmed that a - [Cybersecurity firm POPP3R announces strategic partnerships for disruptive Gamified Awareness solutions at NCA Convene](https://popp3r.com/cybersecurity-firm-popp3r-announces-strategic-partnerships-for-disruptive-gamified-awareness-solutions-at-nca-convene/) - Cybersecurity firm POPP3R announces strategic partnerships for disruptive Gamified Awareness solutions at NCA Convene - IssueWire ## Pages - [Home](https://popp3r.com/) - We protect your reputation, assets and people. We are a Canadian consulting firm, specializing in SME, municipalities and non-profit organizations. - [securedbytes](https://popp3r.com/securedbytes/) - [Ransomware attacks in Canada](https://popp3r.com/ransomwareca/) - Recent Ransomware Attacks in Canada Loading... - [IRAP SME Cybersecurity Program](https://popp3r.com/irapsme/) - SME Cyber Security Support Program IRAP by Hernán Popper - [Videos](https://popp3r.com/videos/) - Cybersecurity Videos Self Assessment Gap Analysis - [Tools](https://popp3r.com/tools/) - Has your email been breached? https://p3.ar/breachedIncident Response Plan Generator: https://p3.ar/irpSecurity Awareness Training Program Generator: https://p3.ar/ASAPCybersecurity Posture Checklist: https://p3.ar/checklist BETAEmail Server Configuration Checker: Coming soon!Email Breach Monitor: Coming soon! - [Cybersecurity Assessment](https://popp3r.com/assessment/) - Cybersecurity Posture Assessment 60% of small businesses and non-profits will fold within 6 months of an incident. Do you even know where you stand? We make it simple. We help you understand your current posture, your risks, what is urgent and what is important. And how to fix it, step by step. Included in your - [FAQ](https://popp3r.com/faq/) - How can we help? Frequently Asked Questions What is Cybersecurity? Cybersecurity is the protection of data, information, computers, devices and networks from cyber threats and attacks.In plain English, it is all about protecting our data, devices, and networks so we can use them with no issues. It implies that only authorized users within the organization can - [Phishing Simulations](https://popp3r.com/phishing-simulations/) - Phishing Simulations 95% of cyberattacks start with an email All that hackers need is a single “click” on the wrong link. Just one. How many of your employees will click?Evaluate your workforce readiness with customized phishing simulations and social engineering attacks. Managed phishing reveals risk by identifying vulnerable staff so you can improve training and policies. Phishing tests - [Consulting](https://popp3r.com/consulting/) - Consulting Every need is different when a specific requirement or need arises, or simply when you don't know where to start, you need a trusted advisor. We are experts in providing a wide range of services to help organizations protect their sensitive information and systems from cyber threats. We can help you identify vulnerabilities in your - [Privacy Policy/Terms of Use](https://popp3r.com/privacy-policy/) - Privacy Policy This privacy policy outlines what personal information we collect about you, how we use it, and who we share it with when you visit or purchase from https://www.popp3r.com. It also explains your rights regarding your personal information and who you can contact if you have any questions. Personal information we collect When you visit the Site, we automatically collect - [Cybersecure Canada Certification](https://popp3r.com/cybersecure-canada-certification/) - Cybersecure Canada Certification About cybersecure canada CyberSecure Canada is the nation's cybersecurity certification program for small and medium-sized organizations. By taking steps to improve your organization’s cyber security posture you will: limit the impacts of cyber incidents enhance your competitive advantage and attract new business reassure your customers and investors that their information is protected - [Human Risk Management Innovation](https://popp3r.com/innovation/) - Human Risk Management Innovation Traditional Security Awareness Training is not working. Yes, you phish your users. Yes, you might be compliant. But… Are behaviors changing?Save your staff from “Death from LMS”… Let them have fun!We are proud to introduce to the north American market two revolutionary concepts, based on the principles of gamification and experiential learning. - [Canadian Program for Cyber Security Certification (CPCSC)](https://popp3r.com/cpcsc/) - Canadian Program for Cyber Security Certification (CPCSC) About the Canadian Program for Cyber Security Certification (CPCSC) Canadian defense suppliers can now prepare for the upcoming CPCSC certification requirements with our streamlined compliance solutions, ensuring your business meets all mandatory cyber security standards without disrupting operations. Starting your CPCSC compliance journey now secures your competitive advantage - [vCiso](https://popp3r.com/vciso/) - Virtual CISO Services Protect your organization with the expertise of a Chief Information Security Officer (CISO) without having to hire a full-time resource Cyberthreats are growing and can pose a significant threat to your business. 65% of small and medium sized businesses and enterprises have experienced a cyberattack in the last year. Regulatory demands and cyber - [In The News](https://popp3r.com/about-us/in-the-news/) - in the news https://www.isstories.com/2024/11/04/pioneering-partnership-combines-human-risk-management-with-mindful-security-to-transform-enterprise-cybersecurity/ https://www.channelinsider.com/news-and-trends/us/vciso-expands-channel-providers-enhances-enterprise-security/ Learning from the UofW cyberattack POPP3R Cybersecurity Wins Major Contract with TransLink for Security Awareness Training in Partnership with KnowBe4 Homegrown Cyber Awareness Partner Selected by National Public Broadcaster Police warn Manitobans about Interac e-transfer scam U of W cyberattack a lesson for province: experts ‘A problem for life’: Students - [Services](https://popp3r.com/services/) - Services Human Risk ManagementSecurity awareness should be ongoing within every organization; hence a security plan is necessary. From simply fulfilling a compliance requirement to a comprehensive culture change program to manage your human risk, our team will design, implement and manage a solution that fits your needs. Learn more Compliance & CertificationsCompleting a certification process - [CDAP Cybersecurity Assessment](https://popp3r.com/cdap-assessment/) - CDAP Cybersecurity Assessment You are an approved CDAP advisor, and an expert in your field. We are too. We help you enhance your Digital adoption plans with an ISED approved cybersecurity assessment and personalized plan for your client. As of January 17, 2024, ISED recommends including a Cybersecurity Assessment as part of any CDAP plan. - [About Us](https://popp3r.com/about-us/) - About Us Popp3r cybersecurity POPP3R CYBERSECURITY is a Canadian boutique firm based in Winnipeg, Manitoba. We are located at University of Manitoba’s Innovation Hub.We specialize in cybersecurity for small-medium businesses, municipalities and non-profit organizations. We strategically partner with several of the most respected security technology firms in Canada and abroad, offering our clients access to a broad - [October Cybersecurity Awareness Month 2023](https://popp3r.com/october2023/) - [Contact Us](https://popp3r.com/contact-us/) - Contact us Book a Meeting Every company is different, right? We get that. So we’ll take a look at what you need and make sure the cybersecurity program we set up for you fits your company just right. No one-size-fits-all approach here. Book Now Get in Touch Don’t wait, take the first step towards a - [Has your account been breached](https://popp3r.com/has-your-account-been-breached/) - Check your email and find out if it has been breached Email Verify has your account been breached? If “No”, congratulations! You are safe for now. It might be worth it to continue reading below and use some best email practices.If your email is listed in any data breach, immediately change your password! A safer - [Education & Training](https://popp3r.com/training/) - Training & Certifications Comprehensive Cybersecurity Training for Your Team Give your employees the must-have cyber skills to protect your organization and advance their careers with industry-recognized certifications. Invest in security talent tailored to your needs. The world is advancing faster than ever before. New technologies and the expansive internet are fundamentally reshaping how we live, learn, - [Human Risk Management](https://popp3r.com/human-risk-management/) - Human Risk Management Security Awareness is much more than a once-a-year event or being compliant traditional Security Awareness approach is failing. An effective Security Awareness Training program educates the user about the cyber security risks like phishing, social engineering through games and practical simulation to know the cyber security risks in real world scenarios. It ## Elementor Header & Footer Builder - [Footer](https://popp3r.com/elementor-hf/footer/) - 100 Innovation Dr #441Winnipeg, MB R3T 6G2Canada +1 204.202.3005 +1 844.5.POPP3R Quick Links Menu Home Services About Us Contact Us FAQ Privacy Policy/Terms of Use Services Menu Cybersecurity Posture Assessments Human Risk Management Phishing Simulations vCISO Services Consulting ## Categories - [News](https://popp3r.com/category/news/) ## Tags - [security awareness training](https://popp3r.com/tag/security-awareness-training/) - [phishing](https://popp3r.com/tag/phishing/) - [retail data breach](https://popp3r.com/tag/retail-data-breach/) - [human risk management](https://popp3r.com/tag/human-risk-management/) - [Canada cybersecurity](https://popp3r.com/tag/canada-cybersecurity/) - [vishing](https://popp3r.com/tag/vishing/) - [deepfake](https://popp3r.com/tag/deepfake/) - [AI voice scam](https://popp3r.com/tag/ai-voice-scam/) - [social engineering](https://popp3r.com/tag/social-engineering/) - [MFA bypass](https://popp3r.com/tag/mfa-bypass/) - [phishing simulation](https://popp3r.com/tag/phishing-simulation/) - [phishing simulations](https://popp3r.com/tag/phishing-simulations/) - [employee behavior](https://popp3r.com/tag/employee-behavior/) - [cybersecurity culture](https://popp3r.com/tag/cybersecurity-culture/) - [employee security training](https://popp3r.com/tag/employee-security-training/) - [Canadian cybersecurity](https://popp3r.com/tag/canadian-cybersecurity/) - [data breach](https://popp3r.com/tag/data-breach/) - [supply chain security](https://popp3r.com/tag/supply-chain-security/) - [credential theft](https://popp3r.com/tag/credential-theft/) - [email security](https://popp3r.com/tag/email-security/) - [human risk](https://popp3r.com/tag/human-risk/) - [voice phishing](https://popp3r.com/tag/voice-phishing/) - [cybersecurity training program](https://popp3r.com/tag/cybersecurity-training-program/) - [social engineering defense](https://popp3r.com/tag/social-engineering-defense/) - [spear phishing](https://popp3r.com/tag/spear-phishing/) - [DMARC](https://popp3r.com/tag/dmarc/) - [identity attacks](https://popp3r.com/tag/identity-attacks/) - [phishing awareness](https://popp3r.com/tag/phishing-awareness/) - [financial sector](https://popp3r.com/tag/financial-sector/) - [Canada](https://popp3r.com/tag/canada/) - [CIRO](https://popp3r.com/tag/ciro/) - [quishing](https://popp3r.com/tag/quishing/) - [QR code phishing](https://popp3r.com/tag/qr-code-phishing/) - [device code phishing](https://popp3r.com/tag/device-code-phishing/) - [Microsoft 365](https://popp3r.com/tag/microsoft-365/) - [OAuth](https://popp3r.com/tag/oauth/) - [MFA](https://popp3r.com/tag/mfa/) - [mobile security](https://popp3r.com/tag/mobile-security/) - [ClickFix](https://popp3r.com/tag/clickfix/) - [employee training](https://popp3r.com/tag/employee-training/) - [AI voice cloning](https://popp3r.com/tag/ai-voice-cloning/) - [CRA scam](https://popp3r.com/tag/cra-scam/) - [tax season phishing](https://popp3r.com/tag/tax-season-phishing/) - [contextual training](https://popp3r.com/tag/contextual-training/) - [phishing prevention](https://popp3r.com/tag/phishing-prevention/) - [behaviour change cybersecurity](https://popp3r.com/tag/behaviour-change-cybersecurity/) - [payroll fraud](https://popp3r.com/tag/payroll-fraud/) - [AiTM](https://popp3r.com/tag/aitm/) - [Storm-2755](https://popp3r.com/tag/storm-2755/) - [phishing as a service](https://popp3r.com/tag/phishing-as-a-service/) - [W3LL](https://popp3r.com/tag/w3ll/) - [behaviour change](https://popp3r.com/tag/behaviour-change/) - [social engineering defence](https://popp3r.com/tag/social-engineering-defence/) - [vendor risk](https://popp3r.com/tag/vendor-risk/) - [SharePoint](https://popp3r.com/tag/sharepoint/) - [Patch Tuesday](https://popp3r.com/tag/patch-tuesday/) - [zero-day vulnerability](https://popp3r.com/tag/zero-day-vulnerability/) - [Microsoft](https://popp3r.com/tag/microsoft/) - [security awareness program](https://popp3r.com/tag/security-awareness-program/) - [callback phishing](https://popp3r.com/tag/callback-phishing/) - [Silent Ransom Group](https://popp3r.com/tag/silent-ransom-group/) - [IT impersonation](https://popp3r.com/tag/it-impersonation/) - [law firm cybersecurity](https://popp3r.com/tag/law-firm-cybersecurity/) - [ransomware awareness training](https://popp3r.com/tag/ransomware-awareness-training/) - [ransomware](https://popp3r.com/tag/ransomware/) - [security awareness](https://popp3r.com/tag/security-awareness/) - [security awareness for Canadian organizations](https://popp3r.com/tag/security-awareness-for-canadian-organizations/) - [Microsoft 365 security](https://popp3r.com/tag/microsoft-365-security/)