Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Phishing

What Is Phishing? The Attack Behind 90% of Breaches

In 2023, a single phishing email gave attackers access to MGM Resorts' entire IT infrastructure. The result: over $100 million in losses, days of operational chaos, and a security wake-up call that echoed across every industry. The attackers didn't exploit a zero-day vulnerability or deploy sophisticated malware.

Carl B. Johnson Sep 22, 2026 5 min read
Insider Threat Awareness

Insider Threat Awareness: What Most Companies Miss

The Threat Already Inside Your Building In 2022, a former Twitter employee was convicted of spying on behalf of Saudi Arabia, accessing the personal data of thousands of users — including dissidents — using nothing more than his legitimate employee credentials. No malware. No phishing email. Just a trusted insider with access

Carl B. Johnson Sep 21, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

In March 2025, CISA and the FBI issued a joint advisory warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, and manufacturing. The attack vector in the vast majority of cases? Phishing emails and credential theft. If you think your

Carl B. Johnson Sep 19, 2026 6 min read
Phishing Scams

Phishing Scams in 2026: What Actually Works to Stop Them

The Phishing Email That Cost One Company $37 Million In 2024, a finance employee at a multinational firm in Hong Kong joined a video call with people who looked and sounded exactly like the company's CFO and other executives. Every face on that call was a deepfake. The

Carl B. Johnson Sep 18, 2026 6 min read
Smishing Attacks

Smishing Attack Examples: Real Texts That Steal Data

The Text Message That Cost One Company $15 Million In 2022, Twilio disclosed that a sophisticated smishing campaign tricked several employees into handing over their credentials via text messages impersonating the company's IT department. The attackers then used those stolen credentials to access internal systems and customer data.

Carl B. Johnson Sep 18, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read
Data Breach

What Causes a Data Breach: 7 Root Causes in 2026

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number keeps climbing. And yet, the root causes behind most breaches haven't changed much in the past decade. The same mistakes keep

Carl B. Johnson Sep 17, 2026 5 min read
Phishing Prevention Tips

Phishing Prevention Tips That Actually Stop Attacks

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Yet most of the phishing prevention tips circulating online read like they were written in 2009. "Don't click suspicious

Carl B. Johnson Sep 16, 2026 5 min read
Data Breach Examples 2026

Data Breach Examples 2026: Real Incidents and Lessons

We're barely halfway through 2026 and the breach disclosures are already piling up. From healthcare systems crippled by ransomware to credential theft campaigns that bypassed legacy MFA, the data breach examples of 2026 reinforce a pattern I've tracked for over a decade: organizations keep making the

Carl B. Johnson Sep 15, 2026 5 min read