Tag

credential theft

Examines credential theft methods such as keylogging, brute force attacks, credential stuffing, and password spraying. Learn how attackers steal login information and what defensive measures organizations can deploy to safeguard user credentials.

posts

fake email

Fake Email: How to Spot It Before It Costs You

In 2023, a finance employee at a multinational firm in Hong Kong wired $25 million after receiving what appeared to be a legitimate video call from the company's CFO — a deepfake. But the attack started with something far simpler: a fake email. That initial message looked routine, requested

Carl B. Johnson Oct 02, 2026 5 min read
phishing attack

Phishing Attack Trends in 2026: What's Actually Working

The Phishing Attack That Cost One Hospital $65 Million In February 2024, Change Healthcare — one of the largest health payment processors in the U.S. — was hit by a ransomware attack that started with a single compromised credential. No multi-factor authentication on a remote access portal. One phishing attack opened

Carl B. Johnson Sep 11, 2026 5 min read
FBI Gmail

FBI Gmail Warning: What You Must Do Right Now

The FBI Just Told 1.8 Billion Gmail Users to Pay Attention When the FBI issues a public warning about a specific email platform, it's not a drill. Over the past year, the FBI has repeatedly flagged Gmail as a primary target for sophisticated phishing campaigns, AI-generated social

Carl B. Johnson Aug 12, 2026 6 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on email filters and endpoint detection, phishing still works. And it works devastatingly well. If you've ever

Carl B. Johnson Aug 02, 2026 5 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask business owners what phishing actually means, most give me a vague answer about "fake emails." That incomplete

Carl B. Johnson Jul 24, 2026 5 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Email Cost One Company $100 Million In 2024, MGM Resorts confirmed that a social engineering attack — which started with a single phone call and a phish-style credential theft scheme — contributed to losses exceeding $100 million. The threat actors behind the Scattered Spider group didn't need

Carl B. Johnson Jul 23, 2026 5 min read
computer security advice

Computer Security Advice That Actually Works in 2026

The Breach That Started With a Single Browser Extension In early 2024, a data breach at a mid-size healthcare firm started not with some sophisticated zero-day exploit, but with a Chrome extension an employee installed to manage their tabs. That extension harvested saved passwords, session cookies, and browser history. Within

Carl B. Johnson May 15, 2026 5 min read
group online svindel

Group Online Svindel: How Fraud Rings Target You

In 2023, the FBI's IC3 received over 880,000 cybercrime complaints with losses exceeding $12.5 billion — and a growing share of those losses trace back to organized fraud rings, not lone hackers. Group online svindel — the coordinated, scalable online fraud committed by organized threat actor groups — is

Carl B. Johnson May 06, 2026 5 min read
FBI Gmail

FBI Gmail Warning: What Every Organization Must Do Now

The FBI Gmail Alert That Changed the Threat Landscape In late 2024, the FBI issued a stark public service announcement: sophisticated phishing campaigns were actively targeting Gmail's 1.8 billion users, and the attacks were so convincing that even security-savvy professionals were falling for them. By 2025, the

Carl B. Johnson Apr 11, 2026 5 min read
phish

How One Phish Can Cost Your Company Millions

A Single Phish Email Took Down a $13 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish — shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The company paid a $4.4 million ransom within hours. That's the

Carl B. Johnson Jan 26, 2026 7 min read