Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Shoulder Surfing Attack

Shoulder Surfing Attack: The Low-Tech Threat You Ignore

A financial analyst at a Fortune 500 company typed her corporate credentials into a laptop at Chicago O'Hare. The man sitting two seats behind her wasn't reading the news on his phone — he was recording her screen. Within 48 hours, the attacker used those stolen credentials

Carl B. Johnson Aug 31, 2026 5 min read
Phishing Email

Phishing Email Attacks: What Actually Works in 2026

One Phishing Email Cost This Company $100 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a phishing email and a follow-up phone call. Threat actors from the Scattered Spider group used social engineering to trick an IT help desk employee,

Carl B. Johnson Aug 30, 2026 6 min read
Phishing

Define Phishing: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on security tools, phishing remains the number one way threat actors break into organizations. So let's actually

Carl B. Johnson Aug 29, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Credential Theft Problem Nobody Takes Seriously Enough In January 2024, a massive credential dump called "Naz.API" exposed over 70 million unique email addresses and passwords harvested from stealer malware and credential-stuffing operations. Most of those credentials worked because the victims reused passwords across multiple services. I&

Carl B. Johnson Aug 27, 2026 5 min read
Mobile Phishing Attacks

Mobile Phishing Attacks: Why Your Phone Is Now #1 Target

82% of Phishing Sites Now Target Mobile Devices In 2024, Zimperium's Global Mobile Threat Report found that 82% of phishing sites specifically targeted mobile devices. That number didn't surprise me. What surprised me was how many security teams I spoke with still treated mobile phishing attacks

Carl B. Johnson Aug 27, 2026 6 min read
Whaling Attack Cybersecurity

Whaling Attack Cybersecurity: How Execs Get Targeted

The CEO Who Wired $47 Million to a Stranger In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million) after a threat actor impersonated the company's CEO via email and instructed an employee to wire funds for a fake acquisition project. The CEO and

Carl B. Johnson Aug 26, 2026 6 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — more than any other cybercrime category. That number has only climbed since. I've investigated breaches at organizations of every size, and the entry point is almost always the same: one employee who

Carl B. Johnson Aug 25, 2026 6 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Redirect Your Traffic

Your Employees Typed the Right URL — And Still Got Hacked In April 2022, researchers at Avast documented a campaign where a threat actor compromised home routers and used DNS hijacking to redirect users from legitimate banking sites to pixel-perfect phishing clones. Victims typed the correct URL into their browser. Their

Carl B. Johnson Aug 25, 2026 6 min read
Multi-Factor Authentication

What Is Multi-Factor Authentication? A Real-World Guide

In 2022, Uber's entire internal network was compromised because a single contractor approved a push notification on their phone. The threat actor had already stolen the contractor's password through social engineering — all they needed was that one tap. That breach exposed internal tools, source code, and

Carl B. Johnson Aug 25, 2026 5 min read