What social engineering penetration testing reveals about the untested assumptions behind your security, how it works, what it costs, and whether it’s legal in the UK.
social engineering
-
-
Attackers used a Custom GPT on OpenAI’s own domain to push a fake ChatGPT and a ClickFix lure. Here is how the chain worked and what to check.
-
Phishing simulation testing shows exactly who clicks and who reports, but NCSC and UK GDPR both set limits on how to run it fairly. Here is how the process works.
-
Business email compromise costs businesses billions a year without a single virus or hacked network. Here’s how BEC scams work, the main types, and the defences that actually stop them.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
Russian intelligence services exploited Signal’s linked device feature and fake support texts to access thousands of accounts. Here is the exact technique and what to change in your settings today.
-
Russian intelligence is stealing Signal backup recovery keys to read encrypted message histories, without breaking the encryption. Here’s what that means for how UK businesses use secure messaging.
-
Two members of Scattered Spider have pleaded guilty over the 2024 TfL breach. The techniques they used are low-tech and still active. Here is what organisations can do to make …
-
The digital landscape has become a battlefield where online scams evolve daily. Cybercriminals deploy sophisticated tactics that target businesses worldwide. Your organisation faces threats that traditional security measures cannot stop. …
-
Businesses should conduct regular network assessments to ensure that their IT processes are performing efficiently. From identifying obsolete hardware and software to improving security and devising disaster plans, a well-designed …