Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

Scam-Yourself Attacks: How Cybercriminals Turn Victims Into Their Own Hackers

Posted on December 5, 2024December 5, 2024 By Martin Hinton

We’ve reported that human error is often at the root of cybersecurity breaches. From weak passwords to careless clicks, people are the weakest link in cyber defense. And if behavioral psychology can boost sales in legitimate businesses, why not in crime? Like stores use your desire for a bargain to take you from your cash, cybercriminals have learned how to exploit the same psychology to access your devices.

We’ve all heard the saying, “Fool me once, shame on you. Fool me twice, shame on me.” But what if the person fooling you is yourself—and it’s happening repeatedly? Gen Digital Inc.’s Q3 Threat Report shows how cybercriminals use psychological manipulation to make people unknowingly compromise their own devices. These “Scam-Yourself Attacks” increased by an astounding 614% in just one quarter. The report lays bare a new era of cyber trickery that preys on human error.

Our takeaways are as follows; you can get the whole report here.

Scam-Yourself Attacks

“Scam-Yourself Attacks” involves attackers guiding users into becoming unwitting accomplices. The strategy relies on users’ own curiosity or frustration with tech issues. Then the “help” arrives. Providing what appears to be a helpful tutorial or urgent fix. These scams involve several techniques: fake tutorials, misleading technical solutions like “ClickFix” scams, fake CAPTCHA prompts, and fake software updates.

The idea is simple—cybercriminals exploit users’ desire to learn or solve problems. The malicious advice is often found on popular platforms like YouTube. A tutorial might guide someone to disable their antivirus to install software. What seems like an innocent action leads to malware gaining full control. In ClickFix scams, users are tricked into copying malicious code into their own command prompts. Fake CAPTCHA prompts have also evolved into a devious tool: what looks like a simple “I’m not a robot” test ends up inserting harmful scripts onto a user’s device.

The sophistication of these “Scam-Yourself Attacks” lies in their familiarity. People trust YouTube tutorials, CAPTCHAs, and update notifications because these elements are everywhere in our daily online interactions. Attackers are using these trusted interactions to gain access. Siggi Stefnisson, Gen’s Cyber Safety CTO, put it this way, “Scams continued to dominate the threat landscape this quarter, and what’s more concerning is how well they blend into people’s everyday experiences.”

The Rise in Data Theft

Don’t worry data theft is still around! According to Gen’s Q3 Threat Report, data-stealing malware activity increased by 39% this quarter. The malware Lumma Stealer prominent malware, expanded its presence by a staggering 1154%. It found its way onto victims’ devices through methods like fake YouTube tutorials and GitHub repositories. Then it targeted sensitive data such as account credentials and crypto wallets.

Ransomware also saw a significant uptick, with the number of attacks doubling compared to last quarter. The Magniber ransomware exploited outdated systems, particularly targeting Windows 7, which is still used by about 4% of global users. Attackers took advantage of vulnerabilities in unpatched systems. ,Yet another reminder of how important updating software and systems regularly is.

Mobile Threats and the Expanding Landscape of Attacks

The mobile threat landscape is evolving as well, with identity and financial theft becoming central focuses. Spyware activity grew by 166%, with new strains such as NGate targeting bank card NFC data, allowing attackers to withdraw cash from ATMs or make unauthorized payments. Banking malware also rose sharply, driven by malware like Rocinante, which targeted users in Europe.

A notable element of mobile scams is their delivery method. We’ve probably all gotten one from the “USPS,” the malicious SMS messages. This remains a favored way these types of scams get “delivered.” Avast, a Gen’s brands, continues to improve its defenses against mobile threats. The more people rely more on their phones, the more these devices are being targeted.

AI and Deepfake Technology Complicate the Threat Landscape

As technology advances, criminals are leveraging AI to create even more sophisticated scams. Deepfake technology and AI-generated phishing campaigns are becoming harder to detect. Attackers use realistic deepfakes to mislead victims, even creating scams linked to high-profile events. This quarter, a group called CryptoCore used deepfake videos featuring famous figures like Elon Musk to lure people into fake cryptocurrency investments, costing victims millions globally.

Conclusions from the Report: A Warning and a Call to Vigilance

The Gen Q3 Threat Report shows something many of you know but too many don’t. The cyber threat landscape is becoming more sophisticated by blending seamlessly into everyday online activities. The rise of “Scam-Yourself Attacks” reveals just how deeply attackers are exploiting human psychology. By making people unwitting participants in their own downfall, these scams underscore the need for greater awareness and vigilance.

The saying goes, “Fool me once, shame on you; fool me twice, shame on me.” In today’s digital age, however, it might be more apt to say, “Fool yourself, and you’re doing exactly what the scammers want.” We need to be more aware of the dangers lurking behind seemingly familiar interactions. Whether it’s a YouTube tutorial, a CAPTCHA prompt, or an unexpected software update, critical thinking is our best defense against cyber threats.

As cybercriminals grow more adept at using our own habits against us, cybersecurity products like those offered by Gen and its brands are crucial. Real-time threat detection, proactive protection, and increased digital literacy can help reduce the impact of these attacks. The key takeaway? You didn’t win lotto, and think, “Did I order a package?” before you click—it could save you from becoming your own worst enemy.

Other News: Remembering the Obvious: In Cybersecurity and Insurance, People Matter Most – Opinion(Opens in a new browser tab).

Other News: Ransomware hackers target NHS hospitals with new cyberattacks.

Martin Hinton

Martin Hinton is the Executive Editor and Publisher of Cyber Insurance News and Information. With over three decades of journalism experience across six continents, his work encompasses investigative reporting, documentaries, and coverage of cultural, political, and business news. To learn more about his career, click on his name to visit his LinkedIn page.

Cybersecurity, Cybersecurity Report Tags:AI, Artificial Intelligence, Artificial Intelligence Cyber Crime, cyber crime, cyber insurance, cyber liability insurance, Cybersecurity, Data Theft, deepfake, Gen, Gen Digital, Gen Digital Inc.'s Q3 Threat Report, human error, Scam-Yourself Attacks

Post navigation

Previous Post: Beazley Security Expands Leadership to Support Growth in US and Europe
Next Post: CyberCube Partners with HUB International to Offer Cyber Risk Analytics in North America

Related Posts

  • Five Eyes Nations Launch Unified Security Campaign for Startups Cybersecurity
  • GenAI Adoption Outpaces Security: 2025 Data Threat Report Exposes Gaps and Solutions AI & Cyber Insurance
  • New Report: ICS/OT Cybersecurity Budgets Lag as Attacks Surge, Leaving Critical Infrastructure at Risk Critical Infrastructure cyber insurance and security
  • Ransomware in Q4 2024 Spike Amid Shift to Scalable Attacks – Report Cyber Insurance
  • Cybersecurity Threats: Malicious AI – Cyber Insurance Reshaping Business Risk in 2024 – Chubb Cybersecurity
  • Cork Cyber Insurance Policy Analyzer Empowers MSPs to Simplify SMB Cybersecurity Cyber Insurance

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In this clip from our latest podcast episode, Dan Candee, CEO of Cork Protection, dives into a critical topic that hits close to home: Cybersecurity for Main Street businesses.

🛡️ With a background in enterprise-level cybersecurity on Wall Street and a personal connection to small business through his family, Dan shares why Cork focuses on protecting small and mid-sized businesses from rising cyber threats.

🚨 "The threat actors are getting better, and they're coming after Main Street more and more."

👉 Discover why Main Street is being underserved in today's digital threat landscape and how Cork is filling that gap with a unique value proposition.

🔗 Learn more about Cork: corkinc.com
🎧 Full Podcast Episode: www.youtube.com/@CyberInsuranceNews/podcasts

📣 Don't forget to LIKE, SUBSCRIBE, and hit the 🔔 notification bell so you never miss a powerful conversation.

#Cybersecurity #SmallBusiness #MainStreet #DanCandee #CorkProtection #TechForGood #SMBs #PodcastClip #CyberThreats #BusinessSecurity
Cybersecurity for Main Street: Dan Candee on Protecting Small Businesses | CEO of Cork Protection
SMB Cyber Threats - In this episode of the Cyber Insurance News Podcast, host Martin Hinton talks with Dan Candee, CEO of Cork Protection, about the rising tide of cyber threats targeting small and mid-sized businesses (SMBs). Dan shares his journey from Main Street entrepreneur to cybersecurity leader, offering real-world insight into the threat landscape, financial vulnerabilities, and how AI and managed service providers (MSPs) can help fortify business resilience.

We explore:
• Why Main Street is more vulnerable than Wall Street
• Common SMB cybersecurity blind spots (like ACH fraud)
• The evolving role of managed service providers
• How Cork Protection blends cybersecurity and cyber insurance
• Real-world attack case studies and practical advice for SMBs

Whether you’re a small business owner, MSP, or cyber pro, this episode unpacks how to prepare, prevent, and protect your organization in today’s digital world.

📌 Topics: cybersecurity, cyber insurance, social engineering, SMB protection, ransomware, AI in security, MSPs

🎙 Guest: Dan Candee, CEO of Cork Protection
📢 Host: Martin Hinton, Executive Editor, Cyber Insurance News

👉 Don’t forget to like, comment, and subscribe for more insights on cyber insurance and digital defense!

#CyberSecurity #CyberInsurance #SMB #AI #CyberPodcast #BusinessResilience #smallbusiness #sme
00:00 Introduction - Dan Candee and Cork Protection
02:27 The Importance of Cybersecurity for Small Businesses
05:29 Understanding Cyber Threats and Their Impact
08:26 The Role of Managed Service Providers in Cybersecurity
11:24 24Financial Protection and Cyber Insurance Solutions
14:01 Leveraging AI in Cybersecurity
16:53 Navigating Cyber Insurance Policies
19:56 Empowering Small Businesses with Knowledge
21:52 The Future of Cybersecurity and Community Resilience
26:05 MSP/ MSSP The Lingo decoded
29:05 Finals Thoughts and a bit of Hope!
SMBs Are Cyber Targets | Dan Candee on Cyber Resilience & AI | Cyber Insurance News Podcast EP#6
Cyberattack on Small Business is on the rise—and AI is making it worse. In this episode of the Cyber Insurance News Podcast, host Martin Hinton sits down with William Altman of CyberCube to unpack how AI is enabling threat actors to more efficiently target and exploit small businesses.

🔐 From credential stuffing to brute force attacks, William explains how cybercriminals use AI to bypass login portals and MFA solutions—putting millions of small business owners at risk.

🎙️ Timestamps:
0:00 - Introduction
6:26 - William Altman on AI and threat actors
6:50 - Credential stuffing, brute force & reused credentials
10:00 - What small businesses can do right now
14:20 - The future of AI in cybercrime

🎧 Don’t miss this crucial update on the cybersecurity landscape for small businesses. Subscribe and stay informed.

#cyberattack #smallbusiness #AI #cybersecurity #CyberCube
Cyberattack on Small Business: How AI Supercharges Cyber Threats | William Altman @CyberCube"
Load More... Subscribe

Categories

  • 8-K
  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI AI in Cybersecurity Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime CyberCube cyber insurace cyber insurance cyberinsurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyber liability insurance cyberliabilityinsurance Cyber Resilience Cyber Risk Cyber Risk Management cyber security Cybersecurity cybersecurity insurance Cyber threats Data Breach Data Breaches Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • NuHarbor’s SLED Cybersecurity Report Unveils Trends and Strategies Cyber Insurance for Government
    • CatX and CyberCube Partner to Enhance Cyber Risk Analytics Cyber Insurance Carriers & Brokers
    • Cyber Insurance: Does It Really Pay Out? Insights from Woodruff Sawyer Cyber Insurance
    • New York State Uses Cyber Regulations to Go After Allstate Company For Repeat Breaches Cyber Insurance
    • Coalition Launches Reinsurance Intermediary to Expand Cyber Reinsurance Offerings Reinsurance
    • CyberSmart Completes $15M B-Round; Provides Insurance/Security Platform for SMBs  Cyber Insurance Carriers & Brokers
    • How’s The Fortune 1000 Doing With Cyber Security? Check Out Data “Recaptured” From Cyber Crooks.  Cyber Insurance Best Practices
    • Ransomware Crisis Worsens in 2023: Calls for Urgent Action to Ban Payments – Report Ransomware Insurance

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme