Computer Security US Blog

Computer Security News and Insights

Multi-Factor Authentication

What Is Multi-Factor Authentication? A Real-World Guide

In 2022, Uber's entire internal network was compromised because a single contractor approved a push notification on their phone. The threat actor had already stolen the contractor's password through social engineering — all they needed was that one tap. That breach exposed internal tools, source code, and

Carl B. Johnson Aug 25, 2026 5 min read
Phishing Attack

Phishing Attack Anatomy: How Breaches Actually Start

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past the help desk with a single phone call. But that attack started the way most do — with a phishing attack that gathered the intelligence needed to make that call convincing.

Carl B. Johnson Aug 24, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States. The root cause? Compromised credentials on a remote access system that lacked multi-factor authentication. One account. No MFA. Billions of dollars in damage. I&

Carl B. Johnson Aug 24, 2026 5 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read
FakeEmail

FakeEmail Scams: How Attackers Spoof Your Inbox

A Single FakeEmail Cost This Company $37 Million In 2024, the FBI's Internet Crime Complaint Center reported that business email compromise — attacks built on fakeemail messages that impersonate trusted senders — generated over $2.9 billion in adjusted losses. That made BEC the costliest cybercrime category for the fourth

Carl B. Johnson Aug 23, 2026 5 min read
Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts employee through a simple phone call to the IT help desk. That single conversation — not a sophisticated zero-day exploit, not a nation-state attack — led to a ransomware incident that shut

Carl B. Johnson Aug 23, 2026 5 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

A Phone Call That Sounds Exactly Like Google Support — But Isn't In late 2024, a Microsoft solutions consultant named Sam Mitrovic nearly lost his Google account to an AI-generated voice that sounded indistinguishable from a real Google support agent. The caller ID showed a legitimate Google number. The

Carl B. Johnson Aug 22, 2026 5 min read
Phishing

Phishing: Why It Still Works and How to Stop It

A Single Email Cost This Company Everything In 2023, MGM Resorts lost an estimated $100 million after a threat actor used a phone-based social engineering attack — a technique closely related to phishing — to gain access to their systems. The attackers didn't exploit a zero-day vulnerability or brute-force a

Carl B. Johnson Aug 22, 2026 5 min read