Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

FakeEmail

FakeEmail Attacks: How Threat Actors Spoof Your Inbox

The FakeEmail That Cost One Company $37 Million In 2024, the FBI's IC3 reported that business email compromise — the art of sending a convincing fakeemail that impersonates a trusted sender — accounted for over $2.9 billion in adjusted losses. That's not a typo. One European company

Carl B. Johnson Oct 04, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

The Phone Call That Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That single vishing call — a voice phishing attack — triggered a ransomware event that shut down

Carl B. Johnson Oct 03, 2026 5 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask executives to give me a phishing definition, most of them still say something like "those fake emails from

Carl B. Johnson Oct 02, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The FBI Didn't Issue a Joint Advisory for Nothing In March 2025, CISA, the FBI, and MS-ISAC released a joint cybersecurity advisory (#StopRansomware) specifically about the Medusa ransomware variant. By that point, Medusa had already hit over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, technology,

Carl B. Johnson Oct 01, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks Your Team Ignores Daily

3389: The Port That Keeps Giving — to Attackers In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as the single most common initial access vector in ransomware incidents reported to law enforcement. Not phishing. Not USB drives. RDP. And yet, in 2026, I still

Carl B. Johnson Sep 30, 2026 6 min read
Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

A Marketing Team's Slack Alternative Cost Their Company $2.1 Million I once consulted for a mid-sized healthcare firm that suffered a data breach because three employees in the marketing department decided to use an unsanctioned project management tool. They uploaded patient-adjacent data to a platform with zero

Carl B. Johnson Sep 28, 2026 5 min read
Vishing

FBI Warning: Vishing and Smishing Attacks Surge in 2026

The Phone Call That Cost One Company $23 Million In early 2024, a finance employee at a multinational firm in Hong Kong joined a video call with what appeared to be the company's CFO and several colleagues. Every person on the screen was a deepfake. The employee transferred

Carl B. Johnson Sep 25, 2026 5 min read
Phishing Links

What Is a Phishing Link? How to Spot and Stop Them

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Behind nearly every one of those complaints was a single moment: someone clicked a link they shouldn't have. If you&

Carl B. Johnson Sep 24, 2026 6 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In 2024, Ivanti disclosed critical vulnerabilities in its VPN appliances — CVE-2024-21887 and CVE-2023-46805 — that were actively exploited by threat actors before patches were available. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. That's not a drill. That's your VPN

Carl B. Johnson Sep 24, 2026 5 min read
Dark Web

What Is the Dark Web? A Security Pro's Real Guide

Your Employees' Passwords Are Probably Already There In 2024, the FBI's Internet Crime Complaint Center reported over $16 billion in losses from cybercrime — and a staggering amount of that activity traces back to marketplaces most people never see. If you've ever wondered what is the

Carl B. Johnson Sep 23, 2026 5 min read