Tag

data breach prevention

Strategies, technologies, and policies for preventing data breaches before they occur. This tag covers access controls, encryption, endpoint protection, incident response planning, vulnerability management, and the human factors that contribute to data exposure in organizations of all sizes.

posts

phishing meaning

Phishing Meaning: What It Really Looks Like in 2022

In March 2022, threat actors used a simple phishing text message to breach Okta through a third-party contractor, Sitel. That single compromised credential gave attackers access to internal systems supporting thousands of Okta's customers. The attack didn't require sophisticated malware or a zero-day exploit. It required

Carl B. Johnson Oct 24, 2022 7 min read
cyber security

Cyber Security in 2022: What's Actually Breaking

In March 2022, Okta confirmed that the Lapsus$ threat actor group had breached a third-party support contractor, potentially affecting hundreds of enterprise customers. A few weeks later, the same group hit Microsoft, Nvidia, and Samsung. These weren't obscure targets — they were companies with massive cyber security budgets, sophisticated

Carl B. Johnson Aug 11, 2022 7 min read
computer security

Computer Security in 2022: What Actually Works Now

In March 2022, Okta confirmed that the Lapsus$ threat actor group had accessed an internal support engineer's laptop, potentially affecting hundreds of downstream customers. A few weeks before that, the same group hit Nvidia, Samsung, and Microsoft. These weren't obscure targets. These were companies with massive

Carl B. Johnson Aug 11, 2022 6 min read
cybersecurity awareness training

Cybersecurity Awareness Training: What Works in 2022

In January 2022, the Red Cross disclosed that a cyberattack compromised the personal data of over 515,000 vulnerable people — victims of conflict, missing persons, detainees. The attack vector? A threat actor exploiting an unpatched vulnerability, combined with social engineering techniques that went undetected for weeks. It's a

Carl B. Johnson Mar 21, 2022 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2021, Ireland's Health Service Executive got hit with a Conti ransomware attack that started with a single phishing email. One employee opened one malicious Excel attachment, and the entire national healthcare system went offline for weeks. That's the real-world weight behind the phishing meaning

Carl B. Johnson Aug 25, 2021 7 min read
fake identity website

Fake Identity Website Threats: What You Must Know

A $900,000 FTC Settlement Started with a Fake Identity Website In 2020, the FTC took action against operators running deceptive websites that harvested personal information under the guise of offering government services. Consumers thought they were applying for benefits or retrieving official documents. Instead, their Social Security numbers, dates

Carl B. Johnson Jul 01, 2021 7 min read
cybersecurity

Cybersecurity in 2021: What Actually Works Right Now

The Colonial Pipeline Attack Changed Everything On May 7, 2021, a single compromised password shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom to the DarkSide threat actor group — and Americans along the East Coast panic-bought gasoline for days. That'

Carl B. Johnson Jul 01, 2021 7 min read
computer security

Computer Security in 2021: What Actually Works Now

The Colonial Pipeline Hack Changed the Conversation On May 7, 2021, a single compromised password shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom in Bitcoin to the DarkSide ransomware group. Gas stations across the Southeast ran dry. Panic buying erupted.

Carl B. Johnson Jun 03, 2021 7 min read
cyber security

Cyber Security Basics That Actually Stop Breaches

The Colonial Pipeline Hack Was a Wake-Up Call Nobody Should Have Needed On May 7, 2021, a single compromised password shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom to the DarkSide threat actor group, and fuel shortages rippled across the

Carl B. Johnson Jun 01, 2021 6 min read
insider threat indicators

Insider Threat Indicators: Spotting Danger Before Damage

In July 2020, a 17-year-old in Florida convinced a Twitter employee to hand over internal credentials. Within hours, the attacker hijacked accounts belonging to Barack Obama, Elon Musk, and Apple — tweeting a Bitcoin scam to millions. The breach didn't start with a sophisticated exploit or zero-day vulnerability. It

Carl B. Johnson Dec 12, 2020 7 min read