Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The Ransomware Gang That Treats Phishing Like a Business In March 2025, CISA and the FBI issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare, education, legal, insurance, manufacturing. The attack vector in the vast majority of cases?

Carl B. Johnson Aug 11, 2026 5 min read
Ransomware

How Ransomware Spreads: 6 Attack Vectors in 2026

A Single Email Took Down a $5.8 Billion Pipeline In May 2021, a single compromised password shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The attack didn't start with some exotic zero-day exploit. It started with a stolen credential and an

Carl B. Johnson Aug 08, 2026 6 min read
AI Phishing Attacks

Gmail Users Warned About Sophisticated AI-Driven Phishing

The AI-Generated Email That Fooled a Security Engineer In early 2025, a Google Workspace consultant named Sam Mitrovic publicly documented how he nearly fell for an AI-driven phishing attack targeting his Gmail account. The attacker spoofed Google's support number, used a perfectly natural AI-generated voice, and referenced real

Carl B. Johnson Aug 08, 2026 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Criminals Fake Their Way In

In 2023, the FBI's Internet Crime Complaint Center reported over 43,000 victims of spoofing-related fraud, with losses exceeding $300 million. That number has only climbed since. And here's the part that should keep you up at night: a spoofing caller doesn't need malware,

Carl B. Johnson Aug 07, 2026 6 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Spring2024!" In 2023, a Verizon Data Breach Investigations Report finding shook the industry: roughly 49% of breaches involved stolen credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. Reused, predictable, phishable passwords. I've responded to incidents where the root cause was

Carl B. Johnson Aug 06, 2026 5 min read
Password Manager

Why Use a Password Manager: The Case Is Closed

In January 2024, a massive credential stuffing attack compromised over 34,000 PayPal accounts — not because PayPal's systems failed, but because users reused passwords across multiple sites. The attackers didn't hack anything. They simply tried stolen credentials from other breaches and walked right in. If you&

Carl B. Johnson Aug 05, 2026 5 min read
Keylogger Attack

Keylogger Attack: How Hackers Steal Every Keystroke

In 2023, the FBI's IC3 received over 21,000 complaints related to malware infections that led directly to credential theft — and a significant number of those involved keyloggers silently recording every password, credit card number, and private message typed on a compromised machine. A keylogger attack doesn'

Carl B. Johnson Aug 04, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into wiring $25 million after a video call with what appeared to be the company's CFO — deepfake technology made the voice and face indistinguishable from the real

Carl B. Johnson Aug 04, 2026 6 min read