Tag

Credential Theft Prevention

Addresses the tactics attackers use to steal login credentials and the countermeasures organizations can deploy. Topics include multi-factor authentication, credential monitoring, dark web surveillance, secure authentication protocols, and employee awareness training.

posts

Insider Threats

How to Prevent Insider Threats Before They Cost Millions

In 2022, a former employee at Cash App's parent company, Block, downloaded reports containing the personal information of 8.2 million customers — months after they'd left the company. Their access had never been revoked. That single oversight triggered SEC filings, lawsuits, and reputational damage that took

Carl B. Johnson Jun 23, 2026 5 min read
Business Email Compromise

Business Email Compromise: The $2.9B Threat in 2026

One Email Cost This Company $37 Million In 2024, Orion Engineering — a mid-size firm with 200 employees — wired $37 million to what they believed was a trusted overseas supplier. The invoice looked legitimate. The email thread was real. The bank details were the only thing that had changed. By the

Carl B. Johnson Jun 15, 2026 5 min read
Data Breach Examples 2026

Data Breach Examples 2026: Lessons from Real Attacks

In January 2026, a major U.S. healthcare network disclosed that threat actors had exfiltrated over 3 million patient records after compromising a single employee's credentials through a phishing email. It wasn't sophisticated malware. It wasn't a zero-day. It was a fake password-reset page.

Carl B. Johnson Jun 11, 2026 5 min read
Strong Passwords

Strong Password Examples That Actually Stop Hackers

The 6-Character Password That Cost a Company $4.88 Million IBM's 2024 Cost of a Data Breach Report pegged the global average breach cost at $4.88 million. In my experience analyzing post-breach forensics, weak or reused passwords remain the single most common entry point for threat actors.

Carl B. Johnson May 31, 2026 5 min read
Phishing Awareness

How to Recognize a Phishing Email Before You Click

The Email That Cost One Company $100 Million In 2019, Toyota Boshoku Corporation lost $37 million in a single business email compromise attack. A threat actor impersonated a senior executive, sent a convincing email, and an employee wired the funds. No malware. No zero-day exploit. Just one phishing email that

Carl B. Johnson May 22, 2026 6 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

In 2023, a single reused password gave threat actors access to 23andMe's credential stuffing attack, ultimately exposing the genetic data of 6.9 million users. The attackers didn't exploit a zero-day vulnerability. They didn't deploy sophisticated malware. They simply tried known username-password combinations from

Carl B. Johnson May 20, 2026 5 min read
Insider Threat Awareness

Insider Threat Awareness: What Most Companies Miss

The Threat Already Inside Your Network In 2023, Tesla disclosed that two former employees had leaked the personal data of more than 75,000 workers to a German news outlet. It wasn't a sophisticated hack. It wasn't a nation-state threat actor. It was people who already

Carl B. Johnson May 17, 2026 5 min read
Fake Email

Fake Email: How to Spot One Before It Costs You

In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from a lookalike domain, and two of the most technologically sophisticated companies on

Carl B. Johnson May 06, 2026 5 min read