Computer Security US Blog

Computer Security News and Insights

computer security

Computer Security in 2026: What Actually Works

In 2023, MGM Resorts lost roughly $100 million after a social engineering phone call — a single conversation — gave threat actors the foothold they needed to deploy ransomware across the entire enterprise. That incident didn't start with a zero-day exploit or some nation-state weapon. It started with a help

Carl B. Johnson Aug 15, 2026 5 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

A Single Email Cost This Company $100 Million In 2019, Toyota Boshoku Corporation lost $37 million to a single business email compromise attack. A threat actor impersonated a senior executive and convinced a finance employee to change wire transfer details. The money vanished. That's phishing — not some abstract

Carl B. Johnson Aug 15, 2026 5 min read
Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Single Click Cost One Hospital Chain $100 Million In 2020, Universal Health Services — a Fortune 500 hospital operator — got hit by the Ryuk ransomware strain. The result: 400 facilities knocked offline, staff reverting to pen and paper, and an estimated $67 million in direct costs plus ongoing damages that

Carl B. Johnson Aug 15, 2026 5 min read
Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, a finance employee at Clorox received what looked like a routine vendor email. One click later, threat actors had a foothold inside the network. The resulting cyberattack disrupted operations for months and cost the company an estimated $356 million in damages

Carl B. Johnson Aug 14, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Proved Most Plans Are Fiction When Uber disclosed in 2022 that it had concealed a 2016 breach affecting 57 million users — and that its former CSO had been convicted of federal obstruction charges for the cover-up — it exposed something uglier than the breach itself. The company had

Carl B. Johnson Aug 14, 2026 5 min read
Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, a small accounting firm in Ohio discovered that a browser toolbar one employee installed — what looked like a harmless coupon finder — had been silently logging keystrokes and exfiltrating client tax records for eleven months. The toolbar was adware on the surface. Underneath, it was spyware. And the firm

Carl B. Johnson Aug 13, 2026 6 min read
Data Breach Notification

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of roughly 100 million Americans. The fallout wasn't just technical — it was a regulatory nightmare. State attorneys general demanded answers. Congressional hearings followed. And organizations downstream from the breach scrambled to figure out

Carl B. Johnson Aug 12, 2026 6 min read
FBI Gmail

FBI Gmail Warning: What You Must Do Right Now

The FBI Just Told 1.8 Billion Gmail Users to Pay Attention When the FBI issues a public warning about a specific email platform, it's not a drill. Over the past year, the FBI has repeatedly flagged Gmail as a primary target for sophisticated phishing campaigns, AI-generated social

Carl B. Johnson Aug 12, 2026 6 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: What You Owe

23andMe Proved That Getting Breached Is Bad — But Notifying Wrong Is Worse In late 2023, 23andMe disclosed a breach affecting nearly 7 million users. The breach itself was devastating. But the company's notification missteps — delayed disclosures, shifting blame to users, and inconsistent communications across jurisdictions — turned a security

Carl B. Johnson Aug 11, 2026 6 min read