Tag

Credential Theft Prevention

Addresses the tactics attackers use to steal login credentials and the countermeasures organizations can deploy. Topics include multi-factor authentication, credential monitoring, dark web surveillance, secure authentication protocols, and employee awareness training.

posts

Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 11-Billion-Record Wake-Up Call In January 2024, researchers discovered a file called "RockYou2024" containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. That's not a typo. Billions of passwords — many still in active use — sitting in a downloadable text file. If you&

Carl B. Johnson Aug 08, 2026 5 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Email Phishing Red Flags

Email Phishing Red Flags: 9 Signs You're Being Targeted

The Email That Cost One Company $37 Million In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked

Carl B. Johnson Jul 31, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Cold

In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints related to phishing and its variants — including vishing — resulting in losses exceeding $18.7 billion across all reported cybercrime categories. Voice phishing, or vishing, is one of the fastest-growing attack vectors because it bypasses

Carl B. Johnson Jul 30, 2026 5 min read
Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read
Password Security

Password Security Best Practices That Stop Breaches

The 2024 Verizon Data Breach Investigations Report found that stolen credentials were involved in 77% of attacks against web applications. Let me restate that: more than three out of four web app breaches started with a compromised password. Despite billions spent on perimeter defenses, password security best practices remain the

Carl B. Johnson Jul 15, 2026 5 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

The Call That Almost Fooled a Google Engineer In 2024, a Google engineer received a phone call from someone claiming to be Google support. The caller ID showed a legitimate Google number. The voice was professional, calm, and eerily convincing. It was AI-generated. The FBI warns Gmail users of sophisticated

Carl B. Johnson Jul 15, 2026 5 min read
Strong Passwords

Strong Password Examples That Actually Stop Hackers

In 2023, a single reused password led to the MGM Resorts breach that cost the company over $100 million in damages. The threat actor didn't exploit a zero-day vulnerability or write custom malware. They called the help desk, social-engineered their way in, and leveraged weak credentials to move

Carl B. Johnson Jul 13, 2026 5 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 10-Billion-Password Wake-Up Call In July 2024, a file called "RockYou2024" appeared on a popular hacking forum containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. It was the largest credential compilation ever leaked. Within weeks, threat actors were running those passwords against corporate

Carl B. Johnson Jul 12, 2026 5 min read