Tag

Cybersecurity Awareness

Articles on cybersecurity awareness cover the foundational knowledge individuals and organizations need to recognize and respond to digital threats. Topics include safe browsing habits, password hygiene, social engineering tactics, and building a security-first culture across teams.

posts

Computer Security Software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts had a multi-billion dollar security stack — endpoint detection, firewalls, SIEM platforms, the works. A single social engineering phone call bypassed all of it. The attackers impersonated an employee, convinced the IT help desk to reset credentials, and caused an estimated $100 million in damages. If you

Carl B. Johnson Sep 04, 2026 5 min read
Spoofing

Spoofing Attacks: How Hackers Impersonate You

In 2023, the FBI's Internet Crime Complaint Center reported that business email compromise — a category heavily fueled by spoofing — accounted for over $2.9 billion in adjusted losses. That made it the single most financially devastating cybercrime category they tracked. Not ransomware. Not crypto scams. Spoofing-driven impersonation. If

Carl B. Johnson Sep 03, 2026 6 min read
Cyber Hygiene

What Is Cyber Hygiene? The Daily Habits That Stop Breaches

A Billion Records Exposed Because Someone Skipped the Basics In 2024, the National Public Data breach exposed an estimated 2.9 billion records — Social Security numbers, addresses, phone numbers — all because basic security controls failed. Not a sophisticated zero-day exploit. Not a nation-state attack. Just poor fundamentals. That's

Carl B. Johnson Aug 31, 2026 5 min read
Phishing Email

Phishing Email Attacks: What Actually Works in 2026

One Phishing Email Cost This Company $100 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a phishing email and a follow-up phone call. Threat actors from the Scattered Spider group used social engineering to trick an IT help desk employee,

Carl B. Johnson Aug 30, 2026 6 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In March 2024, a threat actor breached a major healthcare provider's network using a single compromised password — no second factor required. The organization had purchased MFA licenses two years prior but never enforced enrollment. That gap cost them months of remediation and exposed the records of over 100,

Carl B. Johnson Aug 30, 2026 5 min read
Cyber Incident Reporting

How to Report a Cyber Incident: A Step-by-Step Guide

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase in losses over the previous year. And those are just the incidents that were actually reported. In my experience, for every cyber incident that gets

Carl B. Johnson Aug 29, 2026 5 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Redirect Your Traffic

Your Employees Typed the Right URL — And Still Got Hacked In April 2022, researchers at Avast documented a campaign where a threat actor compromised home routers and used DNS hijacking to redirect users from legitimate banking sites to pixel-perfect phishing clones. Victims typed the correct URL into their browser. Their

Carl B. Johnson Aug 25, 2026 6 min read
Multi-Factor Authentication

What Is Multi-Factor Authentication? A Real-World Guide

In 2022, Uber's entire internal network was compromised because a single contractor approved a push notification on their phone. The threat actor had already stolen the contractor's password through social engineering — all they needed was that one tap. That breach exposed internal tools, source code, and

Carl B. Johnson Aug 25, 2026 5 min read
Phishing Attack

Phishing Attack Anatomy: How Breaches Actually Start

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past the help desk with a single phone call. But that attack started the way most do — with a phishing attack that gathered the intelligence needed to make that call convincing.

Carl B. Johnson Aug 24, 2026 5 min read
Phishing

Phishing: Why It Still Works and How to Stop It

A Single Email Cost This Company Everything In 2023, MGM Resorts lost an estimated $100 million after a threat actor used a phone-based social engineering attack — a technique closely related to phishing — to gain access to their systems. The attackers didn't exploit a zero-day vulnerability or brute-force a

Carl B. Johnson Aug 22, 2026 5 min read