Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Insider Threat Examples

Insider Threat Examples: Real Breaches That Cost Millions

In 2022, a former Amazon engineer named Paige Thompson was convicted for the Capital One breach that exposed over 100 million customer records. She wasn't an outside hacker who cracked through a firewall. She was an insider — someone with knowledge of the cloud infrastructure who exploited a misconfigured

Carl B. Johnson Sep 07, 2026 5 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Hijack Your Traffic

In April 2022, researchers at Tsinghua University and the University of California disclosed a new class of DNS cache poisoning vulnerabilities affecting major DNS software. The attack, dubbed "MaginotDNS," could redirect users from legitimate banking and email sites to pixel-perfect phishing pages — and the victims never saw a

Carl B. Johnson Sep 07, 2026 6 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does to Networks

In 2023, the FBI's Internet Crime Complaint Center reported over $12.5 billion in losses from cybercrime — and a staggering percentage of those incidents started with a single piece of software pretending to be something it wasn't. Trojan horse malware remains one of the most effective

Carl B. Johnson Sep 05, 2026 5 min read
Phishing Scams

What Is a Phishing Scam? A Security Pro's Real Guide

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated phishing incidents at organizations of every size, from ten-person startups to Fortune 500 companies. The pattern is always

Carl B. Johnson Sep 05, 2026 5 min read
Stolen Credentials Dark Web

Stolen Credentials Dark Web: Where Your Passwords End Up

In January 2024, researchers discovered a file called "Naz.API" circulating on dark web forums. It contained over 70 million unique email addresses and their associated passwords — harvested from credential-stealing malware installed on everyday computers. Most of the victims had no idea their login information was for sale.

Carl B. Johnson Sep 05, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

In March 2024, the FBI's IC3 reported that Americans lost over $45 million to smishing and vishing schemes in a single year — and those are just the cases people actually reported. I've personally investigated incidents where a single SMS message led to a six-figure wire transfer

Carl B. Johnson Sep 04, 2026 5 min read
Spear Phishing

What Is Spear Phishing? The Targeted Attack Behind Major Breaches

A Single Email Cost This Company $100 Million In 2015, Ubiquiti Networks disclosed that threat actors used carefully crafted emails impersonating company executives to trick finance employees into wiring $46.7 million to overseas accounts. The attackers didn't use malware. They didn't exploit a software vulnerability.

Carl B. Johnson Sep 03, 2026 6 min read
Phishing

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. And those are just the ones people actually reported. I've spent years helping organizations recover from phishing attacks, and I

Carl B. Johnson Sep 02, 2026 5 min read
Cyber Hygiene

What Is Cyber Hygiene? The Daily Habits That Stop Breaches

A Billion Records Exposed Because Someone Skipped the Basics In 2024, the National Public Data breach exposed an estimated 2.9 billion records — Social Security numbers, addresses, phone numbers — all because basic security controls failed. Not a sophisticated zero-day exploit. Not a nation-state attack. Just poor fundamentals. That's

Carl B. Johnson Aug 31, 2026 5 min read