Tag

Credential Theft

Posts exploring how attackers steal usernames, passwords, and authentication tokens through phishing, keylogging, brute force attacks, and credential stuffing. Includes actionable guidance on multi-factor authentication, password managers, and monitoring for compromised credentials.

posts

Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

The FBI Told You About Medusa. Are You Listening? In March 2025, the FBI and CISA issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare systems, school districts, legal firms, manufacturers. The common thread? Almost every intrusion started

Carl B. Johnson Jul 22, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Summer2024!" In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade — and that number hasn't meaningfully dropped. I've personally investigated incidents where an entire corporate

Carl B. Johnson Jul 22, 2026 5 min read
Phishing Meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Despite billions spent on security technology, a single deceptive email still remains the most reliable way for a threat actor to breach an

Carl B. Johnson Jul 21, 2026 5 min read
Work From Home Cybersecurity

Work From Home Cybersecurity: A Practical Guide

The $20 Million Breach That Started on a Home Wi-Fi Network In 2024, a healthcare company disclosed a breach that exposed 11 million patient records. The root cause? A remote employee connected to an unsecured home network, clicked a phishing link, and handed over VPN credentials to a threat actor.

Carl B. Johnson Jul 19, 2026 5 min read
Phishing Awareness

Phish Food: What Threat Actors Serve Your Employees

Your Employees Are Eating Phish Food Every Day In March 2024, MGM Resorts was still tallying the damage from a social engineering attack that started with a single phone call. The estimated cost exceeded $100 million. The threat actor didn't exploit a zero-day vulnerability or deploy some exotic

Carl B. Johnson Jul 19, 2026 6 min read
Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Email

In 2023, a finance employee at a multinational firm wired $25 million after receiving what appeared to be emails from the company's CFO. The messages were convincing, urgent, and completely fabricated. The attacker used a fake mailer — a tool designed to forge the "From" field in

Carl B. Johnson Jul 17, 2026 5 min read
Phishing Emails

How Phishing Emails Work: The Psychology Behind Them

A Fake Invoice Cost One Company $121 Million In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to orchestrating a phishing scheme that stole over $121 million from Google and Facebook. His weapon wasn't malware. It wasn't a zero-day exploit. It was email — and an

Carl B. Johnson Jul 14, 2026 5 min read
Phishing Scams

Phishing Scams: What They Cost and How to Stop Them

The FBI Says Phishing Scams Are the #1 Cybercrime — And It's Not Even Close In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints about phishing scams — more than any other cybercrime category. That number has topped the charts for five consecutive

Carl B. Johnson Jul 13, 2026 6 min read
DNS Spoofing

DNS Spoofing Attack: How Hackers Redirect Your Traffic

A Bank's Customers Were Logging In — Just Not to the Real Bank In 2017, attackers hijacked DNS records for a major Brazilian bank, redirecting all of its online customers to perfectly cloned phishing sites for roughly five hours. Every login, every transaction, every credential — harvested in real time.

Carl B. Johnson Jul 13, 2026 5 min read