Computer Security US Blog

Computer Security News and Insights

PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Scam Steals Millions

The Phishing Email That Came From PayPal's Own Servers In late 2024, security researchers at Avanan documented a campaign where threat actors sent phishing invoices through PayPal's actual invoicing system — meaning the emails passed SPF, DKIM, and DMARC checks flawlessly. The same tactic has since merged

Carl B. Johnson Jun 24, 2026 5 min read
Third Party Risk

Third Party Vendor Cybersecurity Risk: A 2026 Guide

In early 2024, a breach at Change Healthcare — a subsidiary of UnitedHealth Group — crippled pharmacies and hospitals across the United States for weeks. The attack didn't start at a hospital. It started at a third party vendor. A single set of compromised credentials on a system without multi-factor

Carl B. Johnson Jun 24, 2026 5 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

A $4.88 Million Average — and a Framework Most Organizations Ignore IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88 million per incident. That's a record. Yet when I ask mid-size companies whether they've implemented any NIST standards,

Carl B. Johnson Jun 24, 2026 5 min read
Insider Threats

How to Prevent Insider Threats Before They Cost Millions

In 2022, a former employee at Cash App's parent company, Block, downloaded reports containing the personal information of 8.2 million customers — months after they'd left the company. Their access had never been revoked. That single oversight triggered SEC filings, lawsuits, and reputational damage that took

Carl B. Johnson Jun 23, 2026 5 min read
phishing simulation training

Phishing Simulation Training: Why Most Programs Fail

A 60% Click Rate That Should Have Been a Wake-Up Call I ran a phishing simulation training exercise for a mid-size logistics company last year. The first campaign used a fake Microsoft 365 password reset email — nothing fancy, no zero-day exploit, just a convincing lure. Sixty percent of employees clicked.

Carl B. Johnson Jun 22, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: What Actually Works in 2026

The Breach That Didn't Have to Cost $350 Million When Equifax disclosed its 2017 breach affecting 147 million people, the eventual settlement topped $700 million. But here's what most people forget: the vulnerability that attackers exploited had a patch available months before the breach. Equifax didn&

Carl B. Johnson Jun 22, 2026 5 min read
Phishing Attack Examples

Phishing Attack Examples: 7 Real Scams Still Working

The Email That Cost One Company $121 Million In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to stealing over $121 million from Google and Facebook using nothing more than fake invoices and spoofed email addresses. No zero-day exploits. No sophisticated malware. Just phishing emails that looked like they

Carl B. Johnson Jun 21, 2026 6 min read
Define Cyber

Define Cyber: What It Really Means in 2026

In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States for weeks. UnitedHealth Group eventually disclosed the breach may have affected up to 100 million individuals. If you still think the word "cyber" is just a vague buzzword tossed around

Carl B. Johnson Jun 21, 2026 5 min read