Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Spring2024!" In 2023, a Verizon Data Breach Investigations Report finding shook the industry: roughly 49% of breaches involved stolen credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. Reused, predictable, phishable passwords. I've responded to incidents where the root cause was

Carl B. Johnson Aug 06, 2026 5 min read
Password Manager

Why Use a Password Manager: The Case Is Closed

In January 2024, a massive credential stuffing attack compromised over 34,000 PayPal accounts — not because PayPal's systems failed, but because users reused passwords across multiple sites. The attackers didn't hack anything. They simply tried stolen credentials from other breaches and walked right in. If you&

Carl B. Johnson Aug 05, 2026 5 min read
Keylogger Attack

Keylogger Attack: How Hackers Steal Every Keystroke

In 2023, the FBI's IC3 received over 21,000 complaints related to malware infections that led directly to credential theft — and a significant number of those involved keyloggers silently recording every password, credit card number, and private message typed on a compromised machine. A keylogger attack doesn'

Carl B. Johnson Aug 04, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into wiring $25 million after a video call with what appeared to be the company's CFO — deepfake technology made the voice and face indistinguishable from the real

Carl B. Johnson Aug 04, 2026 6 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on cybersecurity tools, a single deceptive email still opens the door to catastrophic breaches. If you've ever

Carl B. Johnson Jul 30, 2026 5 min read
Phishing

What Is a Phishing Attack? A Security Pro Explains

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated dozens of breaches that started with a single deceptive email. So when someone asks me what is a

Carl B. Johnson Jul 29, 2026 6 min read
Phishing Scams

Phishing Scams: What Actually Works to Stop Them

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing scams — making it the most reported cybercrime category for the fifth consecutive year. The real number is almost certainly higher, because most incidents never get reported. I've spent years helping organizations

Carl B. Johnson Jul 29, 2026 5 min read
Strong Passwords

How to Create a Strong Password That Actually Works

In 2023, a single compromised password at MGM Resorts helped threat actors trigger a social engineering attack that cost the company over $100 million. The attackers didn't exploit some exotic zero-day vulnerability. They exploited people — and weak credential hygiene handed them the keys. If you've ever

Carl B. Johnson Jul 28, 2026 5 min read
Group Online Svindel

Group Online Svindel: How Organized Fraud Rings Work

A Single Fraud Ring Stole $75 Million — And Nobody Noticed for Months In 2023, the FBI dismantled a business email compromise (BEC) ring that operated across multiple countries, defrauding companies of tens of millions of dollars. The operation wasn't run by a lone wolf. It was a coordinated

Carl B. Johnson Jul 28, 2026 5 min read