Tag

Identity Security

Content focused on protecting digital identities from compromise, including topics like credential theft prevention, identity governance, privileged access management, and strategies for reducing identity-based attack surfaces across organizations.

posts

Spoof

Spoof Attacks: How Threat Actors Trick Your Defenses

The CEO Email That Wasn't From the CEO In early 2025, a mid-sized logistics company wired $3.1 million to a bank account in Hong Kong. The CFO had received an email — apparently from the CEO — requesting an urgent wire transfer for a confidential acquisition. The email address

Carl B. Johnson Jan 17, 2026 7 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

The Breach That Started With a Single Stolen Password In January 2024, a threat actor used stolen credentials to access a Snowflake customer environment — no malware, no exploit, just a username and password harvested months earlier. The fallout hit Ticketmaster and AT&T, exposing hundreds of millions of records.

Carl B. Johnson Jun 15, 2025 8 min read
Multi-Factor Authentication

MFA vs Two-Factor Authentication: What Really Matters

In March 2024, a threat actor bypassed a major healthcare provider's two-factor authentication by intercepting SMS codes through a SIM-swapping attack — compromising over 2 million patient records. The organization thought they were protected. They had "MFA" checked off on their compliance audit. But they'd

Carl B. Johnson Jun 15, 2025 7 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In September 2023, MGM Resorts lost an estimated $100 million after a threat actor bypassed their security by socially engineering a helpdesk employee into resetting MFA credentials. Let that sink in. The company had multi-factor authentication. It still wasn't enough — because the multi-factor authentication setup and the processes

Carl B. Johnson Jan 20, 2024 7 min read
Multi-Factor Authentication

MFA vs Two-Factor Authentication: What Actually Matters

In July 2020, a teenager orchestrated one of the most high-profile breaches in social media history — the Twitter hack that compromised accounts belonging to Barack Obama, Elon Musk, and Apple. The attack vector? Social engineering and credential theft that bypassed weak authentication controls. It was a brutal reminder that passwords

Carl B. Johnson Jan 11, 2021 6 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In 2023, MGM Resorts lost an estimated $100 million after a threat actor bypassed their security by social engineering the help desk into resetting an employee's credentials — credentials that lacked properly enforced multi-factor authentication at critical junctures. That single phone call cascaded into one of the most expensive

Carl B. Johnson Nov 02, 2019 8 min read
Multi-Factor Authentication

MFA vs Two-Factor Authentication: What Actually Matters

In September 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider bypassed the company's authentication controls using a simple social engineering phone call. The attackers didn't crack a password vault or exploit a zero-day. They convinced a help desk employee to

Carl B. Johnson Nov 02, 2019 6 min read