Computer Security US Blog

Computer Security News and Insights

Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read
Ransomware

How Ransomware Spreads: 6 Attack Vectors in 2026

A Single Email Cost One Hospital Chain $100 Million In 2024, Change Healthcare — a subsidiary of UnitedHealth Group — suffered a ransomware attack that disrupted pharmacy operations, insurance claims, and patient care across the United States. The company paid a $22 million ransom. Total damages exceeded $100 million. The initial entry

Carl B. Johnson Jul 25, 2026 5 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask business owners what phishing actually means, most give me a vague answer about "fake emails." That incomplete

Carl B. Johnson Jul 24, 2026 5 min read
Ransomware Examples 2026

Ransomware Examples 2026: Real Attacks Hitting Now

The Ransom Note Nobody Expected In January 2026, a mid-sized hospital network in the American Midwest discovered that every imaging workstation, patient scheduling system, and billing server had been encrypted overnight. The ransom demand: 200 Bitcoin. Staff resorted to paper charts and fax machines for eleven days. Surgeries were postponed.

Carl B. Johnson Jul 24, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

A Single Text Message Cost This Company $15 Million In 2022, Twilio disclosed that a coordinated smishing campaign tricked employees into entering credentials on a fake login page. Attackers used those credentials to access internal systems and compromise data for over 100 customers. The whole thing started with a text

Carl B. Johnson Jul 23, 2026 5 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Email Cost One Company $100 Million In 2024, MGM Resorts confirmed that a social engineering attack — which started with a single phone call and a phish-style credential theft scheme — contributed to losses exceeding $100 million. The threat actors behind the Scattered Spider group didn't need

Carl B. Johnson Jul 23, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

The FBI Told You About Medusa. Are You Listening? In March 2025, the FBI and CISA issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare systems, school districts, legal firms, manufacturers. The common thread? Almost every intrusion started

Carl B. Johnson Jul 22, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Summer2024!" In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade — and that number hasn't meaningfully dropped. I've personally investigated incidents where an entire corporate

Carl B. Johnson Jul 22, 2026 5 min read