Computer Security US Blog

Computer Security News and Insights

Stolen Credentials Dark Web

Stolen Credentials Dark Web: Where Your Passwords End Up

In January 2024, researchers discovered a file called "Naz.API" circulating on dark web forums. It contained over 70 million unique email addresses and their associated passwords — harvested from credential-stealing malware installed on everyday computers. Most of the victims had no idea their login information was for sale.

Carl B. Johnson Sep 05, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts had a multi-billion dollar security stack — endpoint detection, firewalls, SIEM platforms, the works. A single social engineering phone call bypassed all of it. The attackers impersonated an employee, convinced the IT help desk to reset credentials, and caused an estimated $100 million in damages. If you

Carl B. Johnson Sep 04, 2026 5 min read
SaaS Security

SaaS Security Best Practices Your Team Is Ignoring

The Breach That Started With a Forgotten SaaS App In 2023, a Salesforce misconfiguration exposed sensitive data at multiple government agencies and financial institutions. The root cause wasn't sophisticated malware or a zero-day exploit. It was a permissions setting that nobody reviewed after initial deployment. That single oversight

Carl B. Johnson Sep 04, 2026 6 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

In March 2024, the FBI's IC3 reported that Americans lost over $45 million to smishing and vishing schemes in a single year — and those are just the cases people actually reported. I've personally investigated incidents where a single SMS message led to a six-figure wire transfer

Carl B. Johnson Sep 04, 2026 5 min read
Spear Phishing

What Is Spear Phishing? The Targeted Attack Behind Major Breaches

A Single Email Cost This Company $100 Million In 2015, Ubiquiti Networks disclosed that threat actors used carefully crafted emails impersonating company executives to trick finance employees into wiring $46.7 million to overseas accounts. The attackers didn't use malware. They didn't exploit a software vulnerability.

Carl B. Johnson Sep 03, 2026 6 min read
Spoofing

Spoofing Attacks: How Hackers Impersonate You

In 2023, the FBI's Internet Crime Complaint Center reported that business email compromise — a category heavily fueled by spoofing — accounted for over $2.9 billion in adjusted losses. That made it the single most financially devastating cybercrime category they tracked. Not ransomware. Not crypto scams. Spoofing-driven impersonation. If

Carl B. Johnson Sep 03, 2026 6 min read
Phishing

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. And those are just the ones people actually reported. I've spent years helping organizations recover from phishing attacks, and I

Carl B. Johnson Sep 02, 2026 5 min read
Cyber Security

Cyber Security in 2026: What Actually Stops Breaches

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number hasn't gone down. If you're responsible for cyber security at any level — whether you're a CISO, an

Carl B. Johnson Sep 02, 2026 5 min read