Tag

Credential Theft Prevention

Addresses the tactics attackers use to steal login credentials and the countermeasures organizations can deploy. Topics include multi-factor authentication, credential monitoring, dark web surveillance, secure authentication protocols, and employee awareness training.

posts

Gmail Phishing Attacks

Gmail Sophisticated Attacks: FBI Phishing Warnings for 2026

A Google Developer Nearly Lost Everything to a Fake Support Call In early 2025, a well-known Google developer publicly documented how he nearly fell for a sophisticated phishing attack targeting his Gmail account. The caller ID showed a legitimate Google phone number. The voice on the other end sounded professional,

Carl B. Johnson Aug 20, 2026 6 min read
Fake Email

Fake Email: How to Spot One Before It Costs You

In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook — using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from spoofed email addresses, and two of the most sophisticated tech companies on

Carl B. Johnson Aug 19, 2026 6 min read
Data Breach Examples 2026

Data Breach Examples 2026: Lessons from Real Attacks

We're barely halfway through 2026, and the breach disclosures are already stacking up at a pace that should alarm every executive, IT director, and business owner reading this. If you're searching for data breach examples 2026, you're probably trying to figure out what'

Carl B. Johnson Aug 16, 2026 5 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

A Single Email Cost This Company $100 Million In 2019, Toyota Boshoku Corporation lost $37 million to a single business email compromise attack. A threat actor impersonated a senior executive and convinced a finance employee to change wire transfer details. The money vanished. That's phishing — not some abstract

Carl B. Johnson Aug 15, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 10-Character Password That Cost a Hospital $3 Million In 2023, CommonSpirit Health disclosed a ransomware attack that disrupted operations across multiple states. Investigators traced the initial access back to compromised credentials — a password that met the organization's minimum requirements but crumbled under a credential stuffing attack. The

Carl B. Johnson Aug 10, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 11-Billion-Record Wake-Up Call In January 2024, researchers discovered a file called "RockYou2024" containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. That's not a typo. Billions of passwords — many still in active use — sitting in a downloadable text file. If you&

Carl B. Johnson Aug 08, 2026 5 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Email Phishing Red Flags

Email Phishing Red Flags: 9 Signs You're Being Targeted

The Email That Cost One Company $37 Million In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked

Carl B. Johnson Jul 31, 2026 5 min read