Tag

credential theft

Examines credential theft methods such as keylogging, brute force attacks, credential stuffing, and password spraying. Learn how attackers steal login information and what defensive measures organizations can deploy to safeguard user credentials.

posts

phishing email

Phishing Email Attacks in 2025: What Actually Works

One Phishing Email Cost MGM Resorts $100 Million In September 2023, a single social engineering phone call — preceded by a carefully crafted phishing email reconnaissance campaign — led to the breach that shut down MGM Resorts' operations across Las Vegas. Slot machines went dark. Hotel room keys stopped working. The

Carl B. Johnson Dec 27, 2025 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In January 2024, a finance employee at a multinational firm in Hong Kong transferred $25.6 million to criminals after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. That's where phishing lives now — far beyond

Carl B. Johnson Sep 18, 2024 7 min read
FBI Gmail

FBI Gmail Warning: What You Need to Know in 2024

The FBI Gmail Alerts That Should Have Your Attention In early 2024, the FBI issued multiple warnings about sophisticated attacks targeting Gmail users — and the threat landscape has only intensified since. These aren't the clumsy Nigerian prince scams of a decade ago. Threat actors are now using AI-generated

Carl B. Johnson Jul 13, 2024 6 min read
pretexting attacks

Pretexting Attack Examples: Real Scams Costing Millions

In 2023, a finance employee at a multinational firm wired $25 million after a video call with someone they believed was their CFO. It wasn't. The entire call — every face, every voice — was a deepfake fabricated by threat actors who'd spent weeks building a detailed pretext.

Carl B. Johnson Apr 07, 2024 7 min read
phishing meaning

Phishing Meaning: What It Really Looks Like in 2022

In March 2022, threat actors used a simple phishing text message to breach Okta through a third-party contractor, Sitel. That single compromised credential gave attackers access to internal systems supporting thousands of Okta's customers. The attack didn't require sophisticated malware or a zero-day exploit. It required

Carl B. Johnson Oct 24, 2022 7 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Took Down a $4 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish or credential reuse — gave attackers access to Colonial Pipeline's network. The result: a ransomware attack that shut down 5,500 miles of fuel pipeline, triggered gas shortages

Carl B. Johnson Aug 31, 2021 8 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2021, Ireland's Health Service Executive got hit with a Conti ransomware attack that started with a single phishing email. One employee opened one malicious Excel attachment, and the entire national healthcare system went offline for weeks. That's the real-world weight behind the phishing meaning

Carl B. Johnson Aug 25, 2021 7 min read
phishing email

Phishing Email Attacks: What They Look Like in 2021

In May 2021, a single phishing email led to the shutdown of Colonial Pipeline — the largest fuel pipeline in the United States. The attackers used compromised credentials, likely harvested through a phishing campaign, to deploy ransomware that disrupted fuel supply across the entire East Coast. That one email triggered panic

Carl B. Johnson Aug 18, 2021 7 min read
phishing emails

How to Spot Phishing Emails Before They Cost You

In July 2021, a single phishing email led to a ransomware attack that shut down fuel deliveries across the entire U.S. East Coast. The Colonial Pipeline breach started — like most breaches do — with a compromised credential. If one employee had known how to spot phishing emails, $4.4 million

Carl B. Johnson Aug 18, 2021 7 min read