Tag

phishing awareness

Provides resources for building phishing awareness among individuals and teams. Articles cover how to recognize phishing emails, conduct simulated phishing exercises, develop security-conscious habits, and implement ongoing awareness training programs within organizations.

posts

phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2025, the FBI's Internet Crime Complaint Center reported that phishing was — for the ninth consecutive year — the most-reported cybercrime in the United States. Not ransomware. Not cryptojacking. Phishing. The simplest attack in the playbook continues to cause the most damage, and the phishing meaning most people

Carl B. Johnson Jan 17, 2026 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In January 2024, a finance employee at a multinational firm in Hong Kong transferred $25.6 million to criminals after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. That's where phishing lives now — far beyond

Carl B. Johnson Sep 18, 2024 7 min read
computer security advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached executive email accounts using a password spray attack against a legacy test account that lacked multi-factor authentication. Microsoft. One of the largest technology companies on Earth. Compromised

Carl B. Johnson May 13, 2024 7 min read
cyber security

Cyber Security in 2022: What's Actually Breaking

In March 2022, Okta confirmed that the Lapsus$ threat actor group had breached a third-party support contractor, potentially affecting hundreds of enterprise customers. A few weeks later, the same group hit Microsoft, Nvidia, and Samsung. These weren't obscure targets — they were companies with massive cyber security budgets, sophisticated

Carl B. Johnson Aug 11, 2022 7 min read
cybersecurity awareness training

Cybersecurity Awareness Training: What Works in 2022

In January 2022, the Red Cross disclosed that a cyberattack compromised the personal data of over 515,000 vulnerable people — victims of conflict, missing persons, detainees. The attack vector? A threat actor exploiting an unpatched vulnerability, combined with social engineering techniques that went undetected for weeks. It's a

Carl B. Johnson Mar 21, 2022 7 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Took Down a $4 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish or credential reuse — gave attackers access to Colonial Pipeline's network. The result: a ransomware attack that shut down 5,500 miles of fuel pipeline, triggered gas shortages

Carl B. Johnson Aug 31, 2021 8 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2021, Ireland's Health Service Executive got hit with a Conti ransomware attack that started with a single phishing email. One employee opened one malicious Excel attachment, and the entire national healthcare system went offline for weeks. That's the real-world weight behind the phishing meaning

Carl B. Johnson Aug 25, 2021 7 min read
phishing emails

How to Spot Phishing Emails Before They Cost You

In July 2021, a single phishing email led to a ransomware attack that shut down fuel deliveries across the entire U.S. East Coast. The Colonial Pipeline breach started — like most breaches do — with a compromised credential. If one employee had known how to spot phishing emails, $4.4 million

Carl B. Johnson Aug 18, 2021 7 min read
fake identity website

Fake Identity Website Threats: What You Must Know

A $900,000 FTC Settlement Started with a Fake Identity Website In 2020, the FTC took action against operators running deceptive websites that harvested personal information under the guise of offering government services. Consumers thought they were applying for benefits or retrieving official documents. Instead, their Social Security numbers, dates

Carl B. Johnson Jul 01, 2021 7 min read