# POPP3R CYBERSECURITY > Generated by All in One SEO Pro v5.0.2, this is an llms.txt file, used by LLMs to index the site. We specialize in cybersecurity for small-medium businesses, municipalities and non-profit organizations. ## Sitemaps - [XML Sitemap](https://popp3r.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [News](https://popp3r.com/news/) - [EvilTokens: Security Awareness for Canadian Organizations](https://popp3r.com/eviltokens-security-awareness-canadian-organizations/): On September 22, 2026, Microsoft and a coalition of technology partners dismantled EvilTokens, an AI-powered phishing service that had compromised more than 12,000 Microsoft 365 inboxes across 10,000 organizations worldwide. Canada was among the countries specifically named as a victim zone. If your organization uses Microsoft 365, this story concerns you directly.How Device-Code Phishing WorksEvilTokens - [EvilTokens: AI-Powered Business Email Compromise at Scale](https://popp3r.com/eviltokens-ai-business-email-compromise-mfa-bypass/): On September 22, 2026, Microsoft's Digital Crimes Unit seized 50 websites and disabled more than 150 domains tied to EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 inboxes across more than 10,000 organisations worldwide. Two men, aged 32 and 38, were arrested by British police earlier this month in connection with the operation. Canada - [Fake Job Interviews Expose Security Awareness Training Gaps](https://popp3r.com/fake-job-interviews-security-awareness-training-gaps/): On September 18, 2026, the FBI, Japan's National Police Agency, Australia's Australian Cyber Security Centre, and Germany's federal security agencies issued a joint advisory about a North Korean state-sponsored group called WaterPlum. Between December 2025 and July 2026, the group infected more than 30,000 devices across 100 countries and stole $10.71 million from roughly 7,000 - [Vishing Awareness: When SaaS Becomes the Attack Surface](https://popp3r.com/vishing-awareness-saas-attack-surface/): When a call comes in from someone claiming to be your IT help desk, urging you to update your passkey or risk losing access to your Microsoft 365 account, most employees comply. That instinct is precisely the entry point that threat actors are targeting. In advisory AL26-010, published this year, the Canadian Centre for Cyber - [Smishing Prevention in the Age of AI Voice Cloning](https://popp3r.com/smishing-prevention-ai-voice-cloning-canadian-organizations/): A text message arrives on the phone of a Canadian nonprofit's finance manager, appearing to be from a trusted bank contact with the right account details, asking for a wire transfer before end of day. The manager complies. The message was not from the bank. Across every sector, Canadian organizations are encountering this scenario at - [What Ransomware Awareness Training Misses About Vishing](https://popp3r.com/what-ransomware-awareness-training-misses-about-vishing/): Most ransomware awareness training programs teach employees to recognise malicious attachments, suspicious links, and spoofed sender addresses. That coverage is necessary but no longer sufficient. The ShinyHunters campaign targeting healthcare organisations, reported by HealthSystemCIO on September 10, 2026, reveals the gap: ransomware actors now routinely begin their attack with a phone call, not an email, - [Behaviour Change Cybersecurity: Beating Voice Phishing](https://popp3r.com/behaviour-change-cybersecurity-beating-voice-phishing/): Voice phishing has quietly overtaken email as the preferred entry point for attackers targeting organisations, and no amount of technical filtering closes that gap without genuine behaviour change. According to Google Cloud's Mandiant M-Trends 2026 report, vishing accounted for 11 per cent of all confirmed initial access methods observed across more than 500,000 hours of - [Vishing Awareness Lessons from the Apollo Data Breach](https://popp3r.com/vishing-awareness-apollo-data-breach/): On 21 August 2026, Apollo Global Management disclosed a data breach: between 6 and 10 July, attackers had gained unauthorised access to several of the firm's cloud platforms and exposed names, dates of birth, home addresses, and Social Security numbers belonging to an unknown number of people. Apollo manages more than one trillion dollars in - [Social Engineering Defence in the Age of Vishing](https://popp3r.com/social-engineering-defence-vishing-reliaquest/): On August 22, 2026, an employee at ReliaQuest, a cybersecurity firm, received a phone call from someone claiming to be a named member of the company's own security team. The caller directed the employee to authenticate through what appeared to be the company's single sign-on portal. The employee did. The site was a fake, the - [The Phishing Simulation Your Marketing Team Is Missing](https://popp3r.com/phishing-simulation-marketing-team-recruiter-trap/): A phishing campaign that has been quietly running for at least five months just exposed a hard truth about employee training programs. When threat researchers at CTM360 published their RecruitTrap findings in August 2026, they mapped more than 3,000 phishing URLs impersonating recruiters from over 50 real organizations. The primary victims were marketing professionals, and - [Behaviour Change Cybersecurity: The Starbucks Portal Lesson](https://popp3r.com/starbucks-breach-behaviour-change-cybersecurity/): In January 2026, attackers gained access to the personal and financial records of 889 Starbucks employees without ever penetrating the company's core infrastructure. The method was precise: a convincing replica of Starbucks' Partner Central, the internal portal workers use to manage payroll, benefits, and employment details, was built to harvest credentials. Workers who entered their - [Ransomware Awareness Training: Gunra Targets Nonprofits](https://popp3r.com/gunra-ransomware-awareness-training-nonprofits/): On August 10, 2026, CISA, the FBI, the National Security Agency, and South Korea's National Police Agency issued a joint advisory warning organizations worldwide about Gunra ransomware, a fast-growing criminal operation that has already claimed Canadian victims. Advisory AA26-222A names healthcare providers, nonprofit services, financial institutions, and government agencies as active targets and describes an - [Behaviour Change Cybersecurity: 4 Lessons from Black Hat](https://popp3r.com/behaviour-change-cybersecurity-lessons-black-hat-2026/): The message from Black Hat USA 2026, which concluded in Las Vegas on August 7, was directed squarely at organizations still running annual click-training programs: the attackers have moved on, and so must you. Researchers documented a threat landscape in which AI tools produce flawless phishing emails at 95 percent lower cost than manual campaigns, - [Security Awareness for Schools: A Social Engineering Lesson](https://popp3r.com/security-awareness-for-schools-dfe-breach-social-engineering/): The staff at the UK Department for Education did not hand attackers a password. They answered a help desk request, clicked a link, and responded to what looked like a legitimate internal process. On July 30, 2026, a threat group calling itself ExfilSquad confirmed they had used exactly that approach to steal 607,000 records from - [Security Awareness Metrics: Canada's $7M Breach Cost](https://popp3r.com/security-awareness-metrics-canada-breach-cost/): Canadian organizations are paying an average of CA$7.11 million every time a data breach occurs, according to IBM's 2026 Cost of a Data Breach Report released July 29. That figure is the highest ever recorded since IBM began tracking breach costs in Canada, and it should prompt every security leader in the country to ask - [When Business Email Compromise Survives the Takedown](https://popp3r.com/business-email-compromise-kratos-phaas-canada/): Law enforcement took down Kratos. But the 1,800 criminal subscribers who paid for that phishing-as-a-service platform still have the kit code, and security researchers confirm they are already adapting it. For Canadian finance teams and executives, the practical question is not whether criminals will continue using these techniques; it is whether your organization is ready - [Vishing Awareness: Canada's IT Help Desks Under Attack](https://popp3r.com/vishing-awareness-canada-it-help-desks-under-attack/): The phone rings at a Canadian IT help desk. The caller identifies themselves as someone from the security team, explains that an account is about to be locked out, and asks the agent to quickly reset the user's MFA credentials. The call is convincing, the urgency feels real, and the agent has been trained to - [Security Awareness for Nonprofits: The Interlock Problem](https://popp3r.com/security-awareness-for-nonprofits-interlock-breach/): The clients of the Centre for Newcomers came to Calgary for a fresh start. On July 17, 2026, they got something else: their personal records, immigration files, and sensitive status documents became part of a 380 GB haul claimed by the Interlock ransomware group. The organisation, a Calgary-based nonprofit providing immigration and settlement services across - [Pink Vishing: Security Awareness for Canadian Organizations](https://popp3r.com/pink-vishing-security-awareness-canadian-organizations/): Your employees can spot a suspicious email. Fewer of them are prepared for the phone call that follows: someone claiming to be from IT, asking them to register a new passkey, and in minutes the attacker has their Microsoft 365 credentials. This is the active O-UNC-066 campaign, and it targets sectors that form the backbone - [Ransomware Awareness Training: The July Imperative](https://popp3r.com/ransomware-awareness-training-july-imperative/): A single compromised employee account was all it took for ShinyHunters to access 70,000 Canadians' personal records at Canada Life in April 2026. No exotic vulnerability, no extended campaign: one credential, one door left unlocked, and a major Canadian financial services provider was facing a data breach notification and an extortion deadline simultaneously. For the - [Your Security Awareness Program Needs an In-Person Clause](https://popp3r.com/security-awareness-program-it-impersonation-silent-ransom-group/): When a stranger walks into your office, identifies themselves as IT support, and plugs a USB drive into a workstation while your employee watches, every firewall you own is irrelevant. That is not a hypothetical. On May 26, 2026, the FBI issued a FLASH alert about the Silent Ransom Group (SRG), a Russia-linked extortion operation - [Why Behaviour Change Cybersecurity Beats SSO Vishing](https://popp3r.com/why-behaviour-change-cybersecurity-beats-sso-vishing/): When an employee picks up the phone and hears what sounds like internal IT asking them to re-enrol a multifactor token, the firewall is already irrelevant. That is the quiet truth behind the latest wave of voice phishing attacks that Google's Mandiant team documented in January 2026, and it is why every Canadian organisation relying - [The SharePoint Zero-Day and Employee Security Training](https://popp3r.com/sharepoint-zero-day-employee-security-training/): Every second Tuesday of the month, Microsoft releases security updates, and IT teams across the country quietly begin a race against exploitation. This month, the stakes are higher than usual. Microsoft’s April 2026 Patch Tuesday addressed 167 vulnerabilities, including eight rated critical and two zero-days, one of which is already being actively exploited in the - [Booking.com Breach Is a Social Engineering Defence Lesson](https://popp3r.com/booking-com-breach-social-engineering-defence/): Booking.com confirmed on April 13, 2026 that unauthorized parties accessed customer reservation data through a third-party compromise. The stolen information included names, email addresses, phone numbers, postal addresses, and messages guests had exchanged with hotels through the platform. Financial data was not exposed, but the immediate weaponization of that booking data in follow-up attacks tells - [$500 Phishing Kits Demand a Cybersecurity Culture Shift](https://popp3r.com/500-phishing-kits-cybersecurity-culture-shift/): Last week, the FBI and Indonesia's National Police dismantled the W3LL phishing network, arresting the alleged developer and seizing the platform's infrastructure. It was a meaningful enforcement milestone: the first coordinated action between American and Indonesian authorities targeting a phishing kit developer. But the headline about the arrest misses the more important story. The W3LL - [Payroll Pirates Reveal Canada's Human Risk Gap](https://popp3r.com/payroll-pirates-human-risk-management-canada/): On April 9, 2026, Microsoft's security researchers published their investigation into Storm-2755, a financially motivated threat actor running what they are calling "payroll pirate" attacks against Canadian employees. The campaign does not rely on malware, ransomware, or headline-grabbing intrusions. It relies on two things that are already inside your organization: a staff member who Googled - [When Teams Is the Trap: Rethinking Phishing Prevention](https://popp3r.com/when-teams-is-the-trap-phishing-prevention/): The attack unfolded through tools that would look routine to any working professional: a LinkedIn connection from a credible-seeming contact, an invitation to a Slack workspace that appeared genuinely company-branded, and then a Microsoft Teams video call that stalled with a familiar-looking technical error. The suggested fix was a software update. One developer clicked, and - [Why Contextual Security Awareness Training Works Better](https://popp3r.com/contextual-security-awareness-training/): A new integration announced this week between Dashlane and KnowBe4 points to a fundamental shift in how effective contextual security awareness training actually works. Rather than delivering training on a quarterly schedule, the two companies have built a system that triggers learning the moment a credential risk is detected in the browser. The announcement offers - [Tax Season Phishing: The Security Training Blind Spot](https://popp3r.com/tax-season-phishing-security-training/): Proofpoint researchers identified more than 100 malicious tax-themed phishing campaigns in early 2026, and Canadian organizations are among the primary targets. With April representing the peak filing period for most Canadians, attackers are exploiting the urgency, distraction, and financial stress that tax season reliably produces. Most organizations have not updated their security awareness training to - [AI Voice Cloning Phishing: What Security Training Misses](https://popp3r.com/ai-voice-cloning-phishing-security-awareness-training/): Picture this: your company’s CFO calls your finance manager to approve an urgent wire transfer before end of day. The voice is familiar, the cadence right, even the slight impatience is typical of how she sounds under deadline pressure. The call is also completely fake. AI voice cloning phishing attacks have matured to the point - [ClickFix: The Fake CAPTCHA That's Tricking Employees](https://popp3r.com/clickfix-fake-captcha-social-engineering-employees/): A social engineering technique called ClickFix is now the leading way cybercriminals break into organizations, and it asks nothing more from victims than pressing three keys on a keyboard. According to Microsoft’s 2025 Digital Defense Report, ClickFix has become the number one initial access method, responsible for 47% of all attacks observed by Microsoft Defender - [Why QR Code Phishing Is Beating Employee Security Training](https://popp3r.com/qr-code-phishing-employee-security-training/): The FBI issued a public alert in January 2026 warning that North Korean state-sponsored hackers have been embedding malicious QR codes in spear-phishing emails to bypass corporate security controls and steal credentials from government agencies, universities, and think tanks. This technique, called quishing, is no longer a fringe attack method. QR code phishing emails surged - [Device Code Phishing Hits Microsoft 365: What to Know](https://popp3r.com/device-code-phishing-microsoft-365/): A sophisticated phishing campaign is actively targeting Microsoft 365 accounts at more than 340 organizations across Canada, the United States, Australia, New Zealand, and Germany, using a technique called device code phishing to capture authentication tokens that persist even after a password reset. Security researchers first detected the attacks on February 19, 2026, and the - [Device Code Phishing: The Attack MFA Can't Stop](https://popp3r.com/device-code-phishing-attack-mfa/): A new device code phishing attack campaign has compromised over 340 organizations across five countries, including Canada, since February 19, 2026, and the pace is accelerating. Researchers at Huntress, who published their analysis this week, found that multi-factor authentication provides no protection against this attack class. Employees who complete MFA challenges believe they are signing - [Quishing: Why QR Code Phishing Needs a Training Response](https://popp3r.com/quishing-qr-code-phishing-employee-training/): A new variant of phishing is bypassing email filters, evading mobile defenses, and landing in employee inboxes with almost no friction. QR code phishing, known in the security industry as quishing, has grown at a pace that most security awareness training programs have not kept up with. If your team does not know how to - [CIRO Breach: Financial Sector Phishing Attack Exposes 750K](https://popp3r.com/financial-sector-phishing-attack-ciro-breach/): A financial sector phishing attack on Canada's investment regulator has exposed the sensitive data of 750,000 investors, including social insurance numbers, annual income figures, government-issued IDs, and detailed account statements. The Canadian Investment Regulatory Organization (CIRO) confirmed in January 2026 that a targeted email delivered in August 2025 gave an attacker unauthorized access to records - [Spear Phishing Beats DMARC as Identity Attacks Surge](https://popp3r.com/spear-phishing-bypasses-dmarc-identity-attacks/): Spear phishing attacks bypassed DMARC email authentication in 70 percent of cases detected last year, according to Darktrace's newly released 2025 annual report. The figure is striking enough on its own. But the broader picture reveals something more unsettling: the technical filters most organizations rely on are being outpaced by attackers who have shifted their - [Vishing Attack on One Employee Exposed 900,000 Records](https://popp3r.com/vishing-attack-employee-data-breach/): When an identity protection company falls victim to a targeted phone scam, the lesson lands harder. On March 19, 2026, Aura confirmed that a vishing attack on one of its employees had exposed nearly 900,000 contact records. For security awareness training professionals and the teams they protect, the incident is not just another breach headline. - [Why Email Urgency Is Now the Top Phishing Red Flag](https://popp3r.com/email-urgency-phishing-red-flag/): For years, the advice was simple: check for typos, look for a suspicious sender address, and watch out for requests for sensitive information. But new research published this week signals a significant shift in how employees are identifying phishing threats. According to a KnowBe4 poll, the top email urgency phishing red flag today is not - [Supply Chain Credential Theft and the TELUS Breach](https://popp3r.com/supply-chain-credential-theft-telus-breach/): When TELUS Digital confirmed a cyberattack on March 12, 2026, the headline was about scale: nearly one petabyte of stolen data, a $65 million ransom demand, and one of Canada's largest telecoms facing a months-long silent intrusion. But the detail security teams should focus on is how the attack started. The ShinyHunters group did not - [Human Risk Management: Beyond Security Awareness Training](https://popp3r.com/human-risk-management-awareness-training/): Nearly 70% of organizations believe their employees lack fundamental cybersecurity awareness, even at organizations that already run formal training programs. That finding, from Fortinet's 2024 Security Awareness and Training Global Research Report, captures a frustration that many security leaders recognize immediately: completing a course is not the same as being prepared. In 2026, the industry's - [Why Phishing Simulations Are Failing Your Team in 2026](https://popp3r.com/phishing-simulation-best-practices-2026/): Most organizations run phishing simulations a few times a year and feel reassured when pass rates look good. But new research from ISACA and findings from Gartner's March 2026 Security and Risk Management Summit in Sydney paint a more troubling picture: the simulations themselves may be the problem. Outdated templates, unrealistic scenarios, and a compliance-first - [When Phishing Bypasses MFA: Lessons from Tycoon 2FA](https://popp3r.com/phishing-bypasses-mfa-tycoon-2fa-takedown/): On March 4, 2026, Microsoft, Europol, and a coalition of industry partners announced the disruption of Tycoon 2FA, one of the most prolific phishing-as-a-service platforms ever documented. The takedown is a meaningful win for defenders, but the story it tells about how phishing bypasses MFA should be required reading for anyone building a security awareness - [When the Boss Calls: AI Voice Scams Target Employees](https://popp3r.com/ai-voice-scam-employee-training/): AI voice scam employee training is no longer a future concern for Canadian organizations. On March 9, 2026, Canada's Competition Bureau issued a public alert warning that scammers are using artificial intelligence to impersonate government officials, politicians, and other trusted figures with a level of realism that makes these calls remarkably difficult to detect. The - [Retail Data Breach: Phishing Awareness Training Gap](https://popp3r.com/retail-data-breach-phishing-awareness-training/): Retail Data Breach: Phishing Awareness Training Gap By POPP3R Cybersecurity | March 20, 2026 Table of Contents What Happened at Loblaw Why Exposed PII Fuels Phishing Campaigns Retail Data Breach Phishing Awareness Training: The Missing Layer Key Steps for Canadian Retailers What Happened at Loblaw On March 10, 2026, Loblaw Companies Limited confirmed that a - [Cybersecurity firm POPP3R announces strategic partnerships for disruptive Gamified Awareness solutions at NCA Convene](https://popp3r.com/cybersecurity-firm-popp3r-announces-strategic-partnerships-for-disruptive-gamified-awareness-solutions-at-nca-convene/): Cybersecurity firm POPP3R announces strategic partnerships for disruptive Gamified Awareness solutions at NCA Convene - IssueWire ## Pages - [Home](https://popp3r.com/): We protect your reputation, assets and people. We are a Canadian consulting firm, specializing in SME, municipalities and non-profit organizations. - [Is Your Domain Secure?](https://popp3r.com/is-your-domain-secure/): Is your domain secure? Your Website Domain Your Email Address Must match the domain above — we only assess domains you can be reached at. Check My Domain has your account been breached? If “No”, congratulations! You are safe for now. It might be worth it to continue reading below and use some best - [securedbytes](https://popp3r.com/securedbytes/) - [Ransomware attacks in Canada](https://popp3r.com/ransomwareca/): Recent Ransomware Attacks in Canada Loading... - [IRAP SME Cybersecurity Program](https://popp3r.com/irapsme/): SME Cyber Security Support Program IRAP by Hernán Popper - [Videos](https://popp3r.com/videos/): Cybersecurity Videos Self Assessment Gap Analysis - [Tools](https://popp3r.com/tools/): Has your email been breached? https://p3.ar/breachedIncident Response Plan Generator: https://p3.ar/irpSecurity Awareness Training Program Generator: https://p3.ar/ASAPCybersecurity Posture Checklist: https://p3.ar/checklist BETAEmail Server Configuration Checker: Coming soon!Email Breach Monitor: Coming soon! - [Cybersecurity Assessment](https://popp3r.com/assessment/): Cybersecurity Posture Assessment 60% of small businesses and non-profits will fold within 6 months of an incident. Do you even know where you stand? We make it simple. We help you understand your current posture, your risks, what is urgent and what is important. And how to fix it, step by step. Included in your - [FAQ](https://popp3r.com/faq/): How can we help? Frequently Asked Questions What is Cybersecurity? Cybersecurity is the protection of data, information, computers, devices and networks from cyber threats and attacks.In plain English, it is all about protecting our data, devices, and networks so we can use them with no issues. It implies that only authorized users within the organization can - [Phishing Simulations](https://popp3r.com/phishing-simulations/): Phishing Simulations 95% of cyberattacks start with an email All that hackers need is a single “click” on the wrong link. Just one. How many of your employees will click?Evaluate your workforce readiness with customized phishing simulations and social engineering attacks. Managed phishing reveals risk by identifying vulnerable staff so you can improve training and policies. Phishing tests - [Consulting](https://popp3r.com/consulting/): Consulting Every need is different when a specific requirement or need arises, or simply when you don't know where to start, you need a trusted advisor. We are experts in providing a wide range of services to help organizations protect their sensitive information and systems from cyber threats. We can help you identify vulnerabilities in your - [Privacy Policy/Terms of Use](https://popp3r.com/privacy-policy/): Privacy Policy This privacy policy outlines what personal information we collect about you, how we use it, and who we share it with when you visit or purchase from https://www.popp3r.com. It also explains your rights regarding your personal information and who you can contact if you have any questions. Personal information we collect When you visit the Site, we automatically collect - [Cybersecure Canada Certification](https://popp3r.com/cybersecure-canada-certification/): Cybersecure Canada Certification About cybersecure canada CyberSecure Canada is the nation's cybersecurity certification program for small and medium-sized organizations. By taking steps to improve your organization’s cyber security posture you will: limit the impacts of cyber incidents enhance your competitive advantage and attract new business reassure your customers and investors that their information is protected - [Human Risk Management Innovation](https://popp3r.com/innovation/): Human Risk Management Innovation Traditional Security Awareness Training is not working. Yes, you phish your users. Yes, you might be compliant. But… Are behaviors changing?Save your staff from “Death from LMS”… Let them have fun!We are proud to introduce to the north American market two revolutionary concepts, based on the principles of gamification and experiential learning. - [Canadian Program for Cyber Security Certification (CPCSC)](https://popp3r.com/cpcsc/): Canadian Program for Cyber Security Certification (CPCSC) About the Canadian Program for Cyber Security Certification (CPCSC) Canadian defense suppliers can now prepare for the upcoming CPCSC certification requirements with our streamlined compliance solutions, ensuring your business meets all mandatory cyber security standards without disrupting operations. Starting your CPCSC compliance journey now secures your competitive advantage - [vCiso](https://popp3r.com/vciso/): Virtual CISO Services Protect your organization with the expertise of a Chief Information Security Officer (CISO) without having to hire a full-time resource Cyberthreats are growing and can pose a significant threat to your business. 65% of small and medium sized businesses and enterprises have experienced a cyberattack in the last year. Regulatory demands and cyber - [In The News](https://popp3r.com/about-us/in-the-news/): in the news https://www.isstories.com/2024/11/04/pioneering-partnership-combines-human-risk-management-with-mindful-security-to-transform-enterprise-cybersecurity/ https://www.channelinsider.com/news-and-trends/us/vciso-expands-channel-providers-enhances-enterprise-security/ Learning from the UofW cyberattack POPP3R Cybersecurity Wins Major Contract with TransLink for Security Awareness Training in Partnership with KnowBe4 Homegrown Cyber Awareness Partner Selected by National Public Broadcaster Police warn Manitobans about Interac e-transfer scam U of W cyberattack a lesson for province: experts ‘A problem for life’: Students - [Services](https://popp3r.com/services/): Services Human Risk ManagementSecurity awareness should be ongoing within every organization; hence a security plan is necessary. From simply fulfilling a compliance requirement to a comprehensive culture change program to manage your human risk, our team will design, implement and manage a solution that fits your needs. Learn more Compliance & CertificationsCompleting a certification process - [CDAP Cybersecurity Assessment](https://popp3r.com/cdap-assessment/): CDAP Cybersecurity Assessment You are an approved CDAP advisor, and an expert in your field. We are too. We help you enhance your Digital adoption plans with an ISED approved cybersecurity assessment and personalized plan for your client. As of January 17, 2024, ISED recommends including a Cybersecurity Assessment as part of any CDAP plan. - [About Us](https://popp3r.com/about-us/): About Us Popp3r cybersecurity POPP3R CYBERSECURITY is a Canadian boutique firm based in Winnipeg, Manitoba. We are located at University of Manitoba’s Innovation Hub.We specialize in cybersecurity for small-medium businesses, municipalities and non-profit organizations. We strategically partner with several of the most respected security technology firms in Canada and abroad, offering our clients access to a broad - [October Cybersecurity Awareness Month 2023](https://popp3r.com/october2023/) - [Contact Us](https://popp3r.com/contact-us/): Contact us Book a Meeting Every company is different, right? We get that. So we’ll take a look at what you need and make sure the cybersecurity program we set up for you fits your company just right. No one-size-fits-all approach here. Book Now Get in Touch Don’t wait, take the first step towards a - [Has your account been breached](https://popp3r.com/has-your-account-been-breached/): Check your email and find out if it has been breached Email Verify has your account been breached? If “No”, congratulations! You are safe for now. It might be worth it to continue reading below and use some best email practices.If your email is listed in any data breach, immediately change your password! A safer - [Education & Training](https://popp3r.com/training/): Training & Certifications Comprehensive Cybersecurity Training for Your Team Give your employees the must-have cyber skills to protect your organization and advance their careers with industry-recognized certifications. Invest in security talent tailored to your needs. The world is advancing faster than ever before. New technologies and the expansive internet are fundamentally reshaping how we live, learn, - [Human Risk Management](https://popp3r.com/human-risk-management/): Human Risk Management Security Awareness is much more than a once-a-year event or being compliant traditional Security Awareness approach is failing. An effective Security Awareness Training program educates the user about the cyber security risks like phishing, social engineering through games and practical simulation to know the cyber security risks in real world scenarios. It ## Elementor Header & Footer Builder - [Footer](https://popp3r.com/elementor-hf/footer/): 100 Innovation Dr #441Winnipeg, MB R3T 6G2Canada +1 204.202.3005 +1 844.5.POPP3R Quick Links Menu Home Services About Us Contact Us FAQ Privacy Policy/Terms of Use Services Menu Cybersecurity Posture Assessments Human Risk Management Phishing Simulations vCISO Services Consulting ## Categories - [News](https://popp3r.com/category/news/) ## Tags - [security awareness training](https://popp3r.com/tag/security-awareness-training/) - [phishing](https://popp3r.com/tag/phishing/) - [retail data breach](https://popp3r.com/tag/retail-data-breach/) - [human risk management](https://popp3r.com/tag/human-risk-management/) - [Canada cybersecurity](https://popp3r.com/tag/canada-cybersecurity/) - [vishing](https://popp3r.com/tag/vishing/) - [deepfake](https://popp3r.com/tag/deepfake/) - [AI voice scam](https://popp3r.com/tag/ai-voice-scam/) - [social engineering](https://popp3r.com/tag/social-engineering/) - [MFA bypass](https://popp3r.com/tag/mfa-bypass/) - [phishing simulation](https://popp3r.com/tag/phishing-simulation/) - [phishing simulations](https://popp3r.com/tag/phishing-simulations/) - [employee behavior](https://popp3r.com/tag/employee-behavior/) - [cybersecurity culture](https://popp3r.com/tag/cybersecurity-culture/) - [employee security training](https://popp3r.com/tag/employee-security-training/) - [Canadian cybersecurity](https://popp3r.com/tag/canadian-cybersecurity/) - [data breach](https://popp3r.com/tag/data-breach/) - [supply chain security](https://popp3r.com/tag/supply-chain-security/) - [credential theft](https://popp3r.com/tag/credential-theft/) - [email security](https://popp3r.com/tag/email-security/) - [human risk](https://popp3r.com/tag/human-risk/) - [voice phishing](https://popp3r.com/tag/voice-phishing/) - [cybersecurity training program](https://popp3r.com/tag/cybersecurity-training-program/) - [social engineering defense](https://popp3r.com/tag/social-engineering-defense/) - [spear phishing](https://popp3r.com/tag/spear-phishing/) - [DMARC](https://popp3r.com/tag/dmarc/) - [identity attacks](https://popp3r.com/tag/identity-attacks/) - [phishing awareness](https://popp3r.com/tag/phishing-awareness/) - [financial sector](https://popp3r.com/tag/financial-sector/) - [Canada](https://popp3r.com/tag/canada/) - [CIRO](https://popp3r.com/tag/ciro/) - [quishing](https://popp3r.com/tag/quishing/) - [QR code phishing](https://popp3r.com/tag/qr-code-phishing/) - [device code phishing](https://popp3r.com/tag/device-code-phishing/) - [Microsoft 365](https://popp3r.com/tag/microsoft-365/) - [OAuth](https://popp3r.com/tag/oauth/) - [MFA](https://popp3r.com/tag/mfa/) - [mobile security](https://popp3r.com/tag/mobile-security/) - [ClickFix](https://popp3r.com/tag/clickfix/) - [employee training](https://popp3r.com/tag/employee-training/) - [AI voice cloning](https://popp3r.com/tag/ai-voice-cloning/) - [CRA scam](https://popp3r.com/tag/cra-scam/) - [tax season phishing](https://popp3r.com/tag/tax-season-phishing/) - [contextual training](https://popp3r.com/tag/contextual-training/) - [phishing prevention](https://popp3r.com/tag/phishing-prevention/) - [behaviour change cybersecurity](https://popp3r.com/tag/behaviour-change-cybersecurity/) - [payroll fraud](https://popp3r.com/tag/payroll-fraud/) - [AiTM](https://popp3r.com/tag/aitm/) - [Storm-2755](https://popp3r.com/tag/storm-2755/) - [phishing as a service](https://popp3r.com/tag/phishing-as-a-service/) - [W3LL](https://popp3r.com/tag/w3ll/) - [behaviour change](https://popp3r.com/tag/behaviour-change/) - [social engineering defence](https://popp3r.com/tag/social-engineering-defence/) - [vendor risk](https://popp3r.com/tag/vendor-risk/) - [SharePoint](https://popp3r.com/tag/sharepoint/) - [Patch Tuesday](https://popp3r.com/tag/patch-tuesday/) - [zero-day vulnerability](https://popp3r.com/tag/zero-day-vulnerability/) - [Microsoft](https://popp3r.com/tag/microsoft/) - [security awareness program](https://popp3r.com/tag/security-awareness-program/) - [callback phishing](https://popp3r.com/tag/callback-phishing/) - [Silent Ransom Group](https://popp3r.com/tag/silent-ransom-group/) - [IT impersonation](https://popp3r.com/tag/it-impersonation/) - [law firm cybersecurity](https://popp3r.com/tag/law-firm-cybersecurity/) - [ransomware awareness training](https://popp3r.com/tag/ransomware-awareness-training/) - [ransomware](https://popp3r.com/tag/ransomware/) - [security awareness](https://popp3r.com/tag/security-awareness/) - [security awareness for Canadian organizations](https://popp3r.com/tag/security-awareness-for-canadian-organizations/) - [Microsoft 365 security](https://popp3r.com/tag/microsoft-365-security/) - [security awareness for nonprofits](https://popp3r.com/tag/security-awareness-for-nonprofits/) - [Canadian nonprofit cybersecurity](https://popp3r.com/tag/canadian-nonprofit-cybersecurity/) - [Interlock ransomware](https://popp3r.com/tag/interlock-ransomware/) - [ransomware awareness](https://popp3r.com/tag/ransomware-awareness/) - [vishing awareness](https://popp3r.com/tag/vishing-awareness/) - [business email compromise](https://popp3r.com/tag/business-email-compromise/) - [Microsoft 365 phishing](https://popp3r.com/tag/microsoft-365-phishing/) - [phishing-as-a-service](https://popp3r.com/tag/phishing-as-a-service-2/) - [security awareness metrics](https://popp3r.com/tag/security-awareness-metrics/) - [data breach costs Canada](https://popp3r.com/tag/data-breach-costs-canada/) - [IBM breach report 2026](https://popp3r.com/tag/ibm-breach-report-2026/) - [security awareness for schools](https://popp3r.com/tag/security-awareness-for-schools/) - [social engineering attack](https://popp3r.com/tag/social-engineering-attack/) - [education cybersecurity](https://popp3r.com/tag/education-cybersecurity/) - [DfE breach](https://popp3r.com/tag/dfe-breach/) - [Canadian school cybersecurity](https://popp3r.com/tag/canadian-school-cybersecurity/) - [Black Hat 2026](https://popp3r.com/tag/black-hat-2026/) - [AI phishing](https://popp3r.com/tag/ai-phishing/) - [Gunra ransomware](https://popp3r.com/tag/gunra-ransomware/) - [CISA advisory](https://popp3r.com/tag/cisa-advisory/) - [Canadian nonprofits](https://popp3r.com/tag/canadian-nonprofits/) - [credential phishing](https://popp3r.com/tag/credential-phishing/) - [employee security](https://popp3r.com/tag/employee-security/) - [recruitment phishing](https://popp3r.com/tag/recruitment-phishing/) - [browser in the browser](https://popp3r.com/tag/browser-in-the-browser/) - [marketing security](https://popp3r.com/tag/marketing-security/) - [cybersecurity Canada](https://popp3r.com/tag/cybersecurity-canada/) - [healthcare cybersecurity](https://popp3r.com/tag/healthcare-cybersecurity/) - [smishing prevention](https://popp3r.com/tag/smishing-prevention/) - [SaaS security](https://popp3r.com/tag/saas-security/) - [fake job interview attack](https://popp3r.com/tag/fake-job-interview-attack/) - [device-code phishing](https://popp3r.com/tag/device-code-phishing-2/) - [AI cybercrime](https://popp3r.com/tag/ai-cybercrime/)