Cloned company sites stole B2B advance payments
A campaign cloned Russian corporate websites to steal B2B advance payments. Learn its tradecraft, warning signs and payment controls.
Phishing, scams, safer work and practical habits that help employees recognise pressure, verify requests and report threats quickly.
A campaign cloned Russian corporate websites to steal B2B advance payments. Learn its tradecraft, warning signs and payment controls.
Explore a free SOC analyst course with 32 modules, 316 lessons, quizzes, and worked analysis from triage and SIEM to OT, AI, and crisis response.
CERT Polska reports an intense UNC1151/Ghostwriter Gmail campaign. Fake security alerts steal passwords and real-time 2FA codes from Polish users.
OpenAI's local model detects and masks PII, but it does not guarantee anonymisation or GDPR compliance. Build a safer pipeline for European data.
FBI and CISA warn that Russian-linked actors are phishing Signal backup recovery keys. Learn how the attack works and how to respond safely.
Fake ads featuring well-known people are flooding social media. We explain how deepfake investment fraud works and how to recognise it.
Groups like Scattered Spider call the IT help desk to reset MFA and breach the company. How the 2026 attacks work and how to verify identity.
A QR code slips past email filters and leads to a fake page straight from your phone. We explain how quishing works and how to defend against it.
A SIM swap lets criminals take over your phone number — and with it your texts, codes and accounts. How it works, how to spot it and how to protect yourself.
Criminals impersonate KSeF, e-government and gov.pl domains to target company finance teams. What this phishing looks like and how to secure it.
A campaign impersonating mObywatel uses sender spoofing and a fake 200 PLN fine. We explain why it looks so convincing and how not to fall for it.
BEC is one of the most expensive scams for companies. We explain how invoice fraud and the 'urgent CEO transfer' work — and how to stop them.
An intensive campaign impersonates BLIK using SMS spoofing and fake login panels. We show how criminals take over online banking and how to break the chain.
A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
Phishing still accounts for most successful breaches. We explain why employee education alone isn't enough and what to add to your defences.
Fake shops, spoofed payments and intercepted cards. A practical guide to spotting a fraudulent store and paying safely online.
A fake parcel-fee text leads to card or banking phishing. Learn how to inspect the domain, authorisation prompt and incident response.
Your phone knows more about you than your computer. Twelve practical settings and habits that genuinely protect your data, accounts and privacy.
Remote work is here to stay — and with it company data on home networks and private hardware. A practical standard: devices, access, Wi-Fi.
Impersonations of OLX and Vinted are among the most reported scams in Poland. We explain the 'safe payment' mechanism that actually robs the seller.
Ads promise a VPN gives anonymity and total security. We explain what a VPN really does, what it doesn't protect against and when it's worth using.
Seniors are fraudsters' most common target: fake grandchild, police or bank staff. Learn the schemes and how to protect parents and grandparents.
A hacked friend's account asks for a BLIK code or a scan of your ID. We explain how account takeovers happen and why the chain of trust is the weakest link.
How to protect your child online without surveillance and bans? A practical guide to the risks, parental control settings and the conversation that works.
Without SPF, DKIM and DMARC anyone can send emails impersonating your domain. We explain these three mechanisms simply and show how to deploy them.
Microsoft documented internal-looking phishing enabled by complex mail routing and weak spoof protection. A technical analysis of headers, DMARC and connectors.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.