Phishing & Social Engineering

Security awareness tips, industry news, and product updates.

Traveler checking a booking confirmation on a smartphone at an airport
Phishing & Social EngineeringSecurity Awareness Tips

Travel Phishing Up 122 Percent: BSI Issues Summer Alert

Germany's BSI warns travelers about fake booking confirmations as Check Point measures a 122 percent three-year surge in travel sector attacks. Vacation phishing hits personal devices that also carry corporate mail - making it a workplace problem.

Natalie Hoffmann·8/8/2026·6 min read
Close-up of a browser address bar on a laptop screen in an office
Phishing & Social EngineeringThreat Intelligence

Menlo Report: 1 in 5 Phishing Links Evade URL Filters

Menlo Security's 2026 Browser Threat Report finds one in five clicked phishing links goes completely undetected by URL filtering, and a third of evasive threats come from 'trusted' domains. The data-driven case for trained humans as the last line of defense.

David Kowalski·8/7/2026·5 min read
Employee seeing an instant training lesson after clicking a simulated phishing email
Phishing & Social EngineeringProduct Updates

Teachable Moments: Just-in-Time Phishing Training on Click

When an employee clicks a simulated phishing link, empowsec turns the mistake into an instant micro-lesson: a Teachable Moment page that explains the exact red flags they just missed, at the moment they are most receptive to learning.

Marcus Chen·8/7/2026·6 min read
Employee receiving an unexpected phone call at an office workstation
Phishing & Social EngineeringThreat Intelligence

Vishing Campaign Abuses Entra Passkey Enrollment Flow

A vishing crew is calling employees as fake Microsoft IT staff and walking them through a bogus Entra passkey enrollment - then registering the attacker's own passkey for persistent access. The weak point is the enrollment moment, not the passkey.

Marcus Chen·8/6/2026·6 min read
A laptop screen displaying code, representing an information-stealing malware attack
Phishing & Social EngineeringThreat Intelligence

Microsoft Warns of ACR Stealer Surge Using ClickFix Lures

Microsoft is warning of a surge in ACR Stealer infections across its enterprise customers, driven by the ClickFix lure that tricks employees into pasting a malicious command themselves. Here is how the attack works - and why the fix is as much about training as it is about tooling.

Marcus Chen·7/19/2026·6 min read
Reporting a phishing email from Outlook
Phishing & Social EngineeringProduct Updates

Report Phishing from Outlook: The empowsec Add-In Guide

empowsec's Outlook add-in gives employees a one-click 'Report phishing' button in their inbox - capturing email headers and content for review while instantly rewarding employees who correctly identify a simulation.

Marcus Chen·7/3/2026·8 min read
Employee searching for a software download on a laptop in an office
Phishing & Social EngineeringThreat Intelligence

Malvertising & SEO Poisoning: The Fake Download Trap

Attackers are buying ads and gaming search results so the top hit for popular software is a trojanized download. Here's how malvertising and SEO poisoning infect employees - and how to train against it.

David Kowalski·6/28/2026·7 min read
Office worker on a laptop video call reviewing a chat message in a collaboration app
Phishing & Social EngineeringThreat Intelligence

Teams & Slack Phishing: The Threat Beyond the Inbox

Phishing has moved out of the inbox and into Microsoft Teams, Slack, and calendar invites — platforms employees trust by default. Here is how the attacks work and how to extend your defenses to cover them.

Elena Vasquez·6/26/2026·7 min read
An employee reading an urgent text message on a smartphone at work
Phishing & Social Engineering

Gift Card Scams: The "Are You Available?" CEO Fraud

"Are you available? I need a quick favor." It's the opening line of a gift card scam impersonating your CEO - low-tech, high-volume, and aimed at new and junior staff. Here's the pattern and the one rule that stops it.

Thomas Eriksson·6/25/2026·7 min read