Tag

Credential Theft Prevention

Addresses the tactics attackers use to steal login credentials and the countermeasures organizations can deploy. Topics include multi-factor authentication, credential monitoring, dark web surveillance, secure authentication protocols, and employee awareness training.

posts

Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Cold

In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints related to phishing and its variants — including vishing — resulting in losses exceeding $18.7 billion across all reported cybercrime categories. Voice phishing, or vishing, is one of the fastest-growing attack vectors because it bypasses

Carl B. Johnson Jul 30, 2026 5 min read
Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read
Password Security

Password Security Best Practices That Stop Breaches

The 2024 Verizon Data Breach Investigations Report found that stolen credentials were involved in 77% of attacks against web applications. Let me restate that: more than three out of four web app breaches started with a compromised password. Despite billions spent on perimeter defenses, password security best practices remain the

Carl B. Johnson Jul 15, 2026 5 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

The Call That Almost Fooled a Google Engineer In 2024, a Google engineer received a phone call from someone claiming to be Google support. The caller ID showed a legitimate Google number. The voice was professional, calm, and eerily convincing. It was AI-generated. The FBI warns Gmail users of sophisticated

Carl B. Johnson Jul 15, 2026 5 min read
Strong Passwords

Strong Password Examples That Actually Stop Hackers

In 2023, a single reused password led to the MGM Resorts breach that cost the company over $100 million in damages. The threat actor didn't exploit a zero-day vulnerability or write custom malware. They called the help desk, social-engineered their way in, and leveraged weak credentials to move

Carl B. Johnson Jul 13, 2026 5 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 10-Billion-Password Wake-Up Call In July 2024, a file called "RockYou2024" appeared on a popular hacking forum containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. It was the largest credential compilation ever leaked. Within weeks, threat actors were running those passwords against corporate

Carl B. Johnson Jul 12, 2026 5 min read
Password Manager Benefits

Password Manager Benefits That Stop 80% of Breaches

One Reused Password Cost This Company $10 Million In 2024, the Snowflake customer breach wave compromised over 165 organizations — including Ticketmaster and AT&T — because attackers used stolen credentials harvested from infostealer malware. The common thread? Employees reusing passwords across personal and corporate accounts with no password manager in

Carl B. Johnson Jul 10, 2026 5 min read
Phishing Awareness Program

Phishing Awareness Program: Build One That Works

The Click That Cost One Company $47 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a single social engineering phone call that led to credential theft. The resulting breach caused an estimated $100 million in damages. And it started with

Carl B. Johnson Jul 01, 2026 5 min read
Phish Setlist

Phish Setlist for Security: Building Your Attack Plan

What a Phish Setlist Actually Means for Your Security Team When the band Phish takes the stage, they never play the same setlist twice. Every show is crafted for the audience. Your phishing simulation program should work the same way. A phish setlist — a curated, rotating collection of phishing attack

Carl B. Johnson Jun 28, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeter Defense Is Dead

The Breach That Proved "Trust But Verify" Was a Lie In 2020, a threat actor compromised SolarWinds' Orion software update mechanism and silently infiltrated over 18,000 organizations — including multiple U.S. federal agencies and Fortune 500 companies. The attackers didn't blast through firewalls. They

Carl B. Johnson Jun 25, 2026 6 min read