Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask executives to give me a phishing definition, most of them describe something from 2009: a Nigerian prince email with

Carl B. Johnson Sep 13, 2026 5 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In March 2024, a finance employee at a Hong Kong multinational wired $25 million to threat actors after a single phishing email led to a deepfake video call with what appeared to be the company's CFO. That's not a Hollywood plot — it's a police-confirmed

Carl B. Johnson Sep 10, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read
Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

The Phone Call That Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into transferring $25 million after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. The attackers never

Carl B. Johnson Sep 08, 2026 5 min read
Fake Identity Website

Fake Identity Website Scams: How to Spot and Stop Them

A Single Fake Identity Website Cost One Company $23 Million In early 2024, a finance employee at Arup, a British engineering firm, was tricked into transferring approximately $25 million after threat actors used a deepfake video call combined with a fake identity website that impersonated senior executives. The site looked

Carl B. Johnson Sep 07, 2026 5 min read