Computer Security US Blog

Computer Security News and Insights

Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

In 2023, the FTC hit Fortnite maker Epic Games with a $520 million settlement — partly because of how poorly they handled children's data and privacy notifications. The breach itself was damaging. The response failures made it catastrophic. If you're reading this, you either just discovered a

Carl B. Johnson Nov 26, 2019 7 min read
Data Breach Examples

Data Breach Examples 2026: Lessons from This Year

2026 Has Already Been Brutal for Data Security We're barely halfway through the year, and the data breach examples from 2026 already paint a grim picture. Healthcare systems, school districts, financial platforms, and major retailers have all made headlines — not for innovation, but for failing to protect customer

Carl B. Johnson Nov 26, 2019 6 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 24 Billion Stolen Passwords Nobody Talks About In 2022, researchers at Digital Shadows found over 24 billion username-and-password pairs circulating on dark web marketplaces and criminal forums. That number has only grown. If you think your organization's credentials aren't in that pile, I'd

Carl B. Johnson Nov 26, 2019 7 min read
Strong Passwords

How to Create a Strong Password That Actually Stops Hackers

In 2023, a single reused password gave threat actors access to 23andMe's credential-stuffing attack, exposing the genetic data of nearly 7 million users. The attackers didn't exploit some exotic zero-day vulnerability. They just tried stolen username-password pairs from other breaches — and millions of them worked. If

Carl B. Johnson Nov 26, 2019 6 min read
Password Manager Benefits

Password Manager Benefits That Stop 80% of Breaches

In 2024, a single set of stolen Snowflake credentials led to the breach of over 165 organizations — including Ticketmaster and AT&T — exposing hundreds of millions of customer records. The root cause wasn't some exotic zero-day exploit. It was reused passwords without multi-factor authentication. Every one of

Carl B. Johnson Nov 02, 2019 7 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In 2023, MGM Resorts lost an estimated $100 million after a threat actor bypassed their security by social engineering the help desk into resetting an employee's credentials — credentials that lacked properly enforced multi-factor authentication at critical junctures. That single phone call cascaded into one of the most expensive

Carl B. Johnson Nov 02, 2019 8 min read
Multi-Factor Authentication

MFA vs Two-Factor Authentication: What Actually Matters

In September 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider bypassed the company's authentication controls using a simple social engineering phone call. The attackers didn't crack a password vault or exploit a zero-day. They convinced a help desk employee to

Carl B. Johnson Nov 02, 2019 6 min read