Tag

Phish Tour

Guides readers through interactive walkthroughs and breakdowns of real-world phishing scenarios. The Phish Tour tag features step-by-step analyses of phishing emails, fraudulent websites, and social engineering tactics, helping readers build hands-on recognition skills.

posts

Phish Tour

Phish Tour: Mapping the Anatomy of a Phishing Attack

Welcome to the Phish Tour: How a Single Email Becomes a Full-Blown Breach In March 2023, the FBI's IC3 received over 298,000 complaints related to phishing schemes — more than any other cybercrime category by a wide margin. That number has only climbed since. Yet most people still

Carl B. Johnson May 24, 2026 5 min read
Phish Tour

Phish Tour: A Guided Tour Through Modern Phishing

Welcome to the Phish Tour Nobody Asked For In March 2024, MGM Resorts was still tallying the damage from a social engineering attack that started with a single phone call. The threat actor convinced a help desk employee to reset credentials. Total estimated cost: over $100 million. That attack didn&

Carl B. Johnson Apr 17, 2026 5 min read
Phish Tour

Phish Tour: A Guided Walk Through Modern Attacks

Welcome to the Phish Tour Nobody Asked For In March 2025, a finance employee at a mid-size manufacturing firm received a Microsoft Teams message from someone impersonating the CFO. The message included a link to a SharePoint page that looked flawless. Within 90 seconds, the employee entered their credentials. Within

Carl B. Johnson Jan 18, 2026 7 min read
Phish Tour

Phish Tour: Walk Through a Real Phishing Attack

A Single Email Cost This Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into transferring $25 million after a deepfake video call that started with one phishing email. That's not a hypothetical. That happened. And it began the same way nearly

Carl B. Johnson Oct 17, 2024 7 min read
Phish Tour

Phish Tour: Simulated Attacks That Train Your Team

One Clicked Link Cost This Company Everything In September 2022, a single employee at Uber clicked a link in a social engineering attack. The threat actor, reportedly affiliated with Lapsus$, used that foothold to access internal systems, Slack channels, and cloud infrastructure. The breach made global headlines — not because Uber&

Carl B. Johnson Nov 21, 2022 7 min read
Phish Tour

Phish Tour: Simulate Real Attacks Before Hackers Do

One Click Cost Colonial Pipeline $4.4 Million In May 2021, a single compromised credential shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom to a threat actor group called DarkSide. The entry point wasn't some exotic zero-day exploit.

Carl B. Johnson Aug 25, 2021 7 min read
Phish Tour

Phish Tour: How Attackers Map Your Organization

They Don't Just Send One Email — They Run a Phish Tour In 2023, the FBI's IC3 received over 298,000 phishing complaints, making it the most reported cybercrime category for the fifth consecutive year. But here's the part that doesn't make the

Carl B. Johnson Feb 27, 2020 6 min read
Phish Tour

Phish Tour: How Attackers Rotate Tactics to Hook You

In early 2024, researchers at Proofpoint documented a campaign where a single threat actor group rotated through at least six distinct phishing lure templates in under three weeks — targeting financial services, healthcare, and education sectors in sequence. Security teams that recognized the first lure missed the second. Those who caught

Carl B. Johnson Jun 23, 2019 6 min read