Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Cyber Hygiene

What Is Cyber Hygiene? The Daily Habits That Stop Breaches

A Single Unpatched Laptop Cost One Hospital $3 Million In 2023, the U.S. Department of Health and Human Services settled with a healthcare provider after a ransomware attack that started on one employee's unpatched workstation. The machine hadn't been updated in over 90 days. That

Carl B. Johnson Apr 02, 2026 5 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does to You

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion — and a staggering number of those incidents started with a single file that looked perfectly legitimate. That file was trojan horse malware, disguised as an invoice, a software update,

Carl B. Johnson Apr 01, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The FBI Warned You About Medusa. Did You Listen? In March 2025, the FBI and CISA issued a joint advisory — #StopRansomware: Medusa Ransomware — warning that the Medusa ransomware gang had already hit over 300 organizations across critical infrastructure sectors. Healthcare, education, manufacturing, technology. The common thread? Nearly every intrusion started

Carl B. Johnson Jan 26, 2026 7 min read
Phishing

Phishing in 2026: What's Actually Working Against It

The Threat That Refuses to Die In January 2025, the FBI's Internet Crime Complaint Center (IC3) released its annual report showing that phishing and its variants remained the number one reported cybercrime by volume — for the fifth consecutive year. Over 298,000 complaints. That number only counts the

Carl B. Johnson Jan 18, 2026 7 min read
Smishing

FBI Warning on Smishing Texts: What You Must Do Now

In December 2025, the FBI issued a stark public warning: delete suspicious text messages immediately. The advisory specifically called out a wave of smishing texts — SMS-based phishing attacks — targeting Americans with fake toll road notices, package delivery scams, and fraudulent financial alerts. The bureau's Internet Crime Complaint Center

Carl B. Johnson Jan 18, 2026 7 min read
Phish Tour

Phish Tour: A Guided Walk Through Modern Attacks

Welcome to the Phish Tour Nobody Asked For In March 2025, a finance employee at a mid-size manufacturing firm received a Microsoft Teams message from someone impersonating the CFO. The message included a link to a SharePoint page that looked flawless. Within 90 seconds, the employee entered their credentials. Within

Carl B. Johnson Jan 18, 2026 7 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In May 2025, the FBI's Internet Crime Complaint Center reported that phishing was — for the ninth consecutive year — the most-reported cybercrime category, with over 300,000 complaints in a single year. That number only counts the people who bothered to report it. The real volume is staggering. Yet

Carl B. Johnson Jan 17, 2026 7 min read
Phishing

Definition of a Phishing Attack: What It Really Looks Like

The MGM Breach Started With a Single Phone Call In September 2023, a threat actor called the MGM Resorts help desk, pretended to be an employee, and talked their way into a credential reset. Within hours, the Scattered Spider group had deep access to MGM's systems. The result:

Carl B. Johnson Jan 17, 2026 7 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Your Defenses

In September 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider used a spear phishing voice call — a single, well-researched phone call to the company's IT help desk — to compromise the entire organization. The attacker already knew the target employee's name,

Carl B. Johnson Jan 17, 2026 8 min read