Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware.

Carl B. Johnson Aug 19, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That one vishing call triggered a ransomware attack that shut down slot machines, hotel key

Carl B. Johnson Aug 18, 2026 5 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Defenses

In 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider impersonated an employee on a help desk call — a textbook spear phishing technique that bypassed every technical control the company had. The attacker didn't blast out a million generic emails. They researched one

Carl B. Johnson Aug 17, 2026 5 min read
Stolen Credentials Dark Web

Stolen Credentials Dark Web: How Your Logins Get Sold

In 2024, the FBI's Internet Crime Complaint Center (IC3) reported that compromised credentials were a factor in a staggering number of the complaints they received, driving billions of dollars in losses. I've personally worked incident response cases where a single set of stolen credentials — purchased on

Carl B. Johnson Aug 17, 2026 5 min read
Fake Identity Website

Fake Identity Website Scams: How to Spot Them Fast

A Single Fake Identity Website Fueled a $10 Million Fraud Ring In 2023, the FBI dismantled an identity fraud operation that relied heavily on fake identity websites — convincing portals designed to harvest personal data from unsuspecting victims. The ring used stolen credentials to open bank accounts, file fraudulent tax returns,

Carl B. Johnson Aug 17, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The Ransomware Gang That Treats Phishing Like a Business In March 2025, CISA and the FBI issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare, education, legal, insurance, manufacturing. The attack vector in the vast majority of cases?

Carl B. Johnson Aug 11, 2026 5 min read
Ransomware

How Ransomware Spreads: 6 Attack Vectors in 2026

A Single Email Took Down a $5.8 Billion Pipeline In May 2021, a single compromised password shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The attack didn't start with some exotic zero-day exploit. It started with a stolen credential and an

Carl B. Johnson Aug 08, 2026 6 min read
AI Phishing Attacks

Gmail Users Warned About Sophisticated AI-Driven Phishing

The AI-Generated Email That Fooled a Security Engineer In early 2025, a Google Workspace consultant named Sam Mitrovic publicly documented how he nearly fell for an AI-driven phishing attack targeting his Gmail account. The attacker spoofed Google's support number, used a perfectly natural AI-generated voice, and referenced real

Carl B. Johnson Aug 08, 2026 6 min read