Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on cybersecurity tools, a single deceptive email still opens the door to catastrophic breaches. If you've ever

Carl B. Johnson Jul 30, 2026 5 min read
Phishing

What Is a Phishing Attack? A Security Pro Explains

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated dozens of breaches that started with a single deceptive email. So when someone asks me what is a

Carl B. Johnson Jul 29, 2026 6 min read
Phishing Scams

Phishing Scams: What Actually Works to Stop Them

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing scams — making it the most reported cybercrime category for the fifth consecutive year. The real number is almost certainly higher, because most incidents never get reported. I've spent years helping organizations

Carl B. Johnson Jul 29, 2026 5 min read
Strong Passwords

How to Create a Strong Password That Actually Works

In 2023, a single compromised password at MGM Resorts helped threat actors trigger a social engineering attack that cost the company over $100 million. The attackers didn't exploit some exotic zero-day vulnerability. They exploited people — and weak credential hygiene handed them the keys. If you've ever

Carl B. Johnson Jul 28, 2026 5 min read
Group Online Svindel

Group Online Svindel: How Organized Fraud Rings Work

A Single Fraud Ring Stole $75 Million — And Nobody Noticed for Months In 2023, the FBI dismantled a business email compromise (BEC) ring that operated across multiple countries, defrauding companies of tens of millions of dollars. The operation wasn't run by a lone wolf. It was a coordinated

Carl B. Johnson Jul 28, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read
Fake Email

Fake Email Attacks: How to Spot and Stop Them

In 2023, the FBI's Internet Crime Complaint Center reported that business email compromise — a category built almost entirely on the fake email — cost victims over $2.9 billion. That wasn't from sophisticated zero-day exploits. It was from emails that looked real but weren't. I&

Carl B. Johnson Jul 25, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

A Single Text Message Cost This Company $15 Million In 2022, Twilio disclosed that a coordinated smishing campaign tricked employees into entering credentials on a fake login page. Attackers used those credentials to access internal systems and compromise data for over 100 customers. The whole thing started with a text

Carl B. Johnson Jul 23, 2026 5 min read