Tag

Phishing Awareness

Phishing awareness articles teach readers to identify and avoid phishing attacks across email, SMS, voice calls, and social media. Content includes real-world phishing examples, red flags to watch for, reporting procedures, and tips for running phishing simulation campaigns.

posts

Phishing Awareness

Phish Food: What Threat Actors Serve Your Employees

Your Employees Are Eating Phish Food Every Day In March 2024, MGM Resorts was still tallying the damage from a social engineering attack that started with a single phone call. The estimated cost exceeded $100 million. The threat actor didn't exploit a zero-day vulnerability or deploy some exotic

Carl B. Johnson Jul 19, 2026 6 min read
Cybersecurity for Law Firms

Cybersecurity for Law Firms: Protecting Client Data

In November 2023, the international law firm Allen & Overy confirmed it was hit by a LockBit ransomware attack that disrupted internal systems and exposed sensitive data. They weren't alone. The American Bar Association disclosed a data breach that same year affecting 1.4 million members. If you

Carl B. Johnson Jul 18, 2026 5 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

The Call That Almost Fooled a Google Engineer In 2024, a Google engineer received a phone call from someone claiming to be Google support. The caller ID showed a legitimate Google number. The voice was professional, calm, and eerily convincing. It was AI-generated. The FBI warns Gmail users of sophisticated

Carl B. Johnson Jul 15, 2026 5 min read
Securing Employee Mobile Devices

Securing Employee Mobile Devices: A Practical Guide

The Breach That Started With a Single Phone In 2022, Uber suffered a devastating breach after a threat actor targeted an employee's mobile device with repeated multi-factor authentication push requests. The attacker combined social engineering with MFA fatigue, and one tap on a phone screen gave them access

Carl B. Johnson Jul 14, 2026 5 min read
Cybersecurity for Healthcare

Cybersecurity for Healthcare Organizations: A 2026 Guide

The Hospital That Lost 133 Days to Ransomware In 2024, Change Healthcare suffered a ransomware attack that disrupted claims processing for thousands of hospitals, pharmacies, and clinics across the United States. UnitedHealth Group, its parent company, disclosed costs exceeding $870 million in the first quarter alone. Patient care was delayed.

Carl B. Johnson Jul 12, 2026 5 min read
Cybersecurity Policy for Employees

Cybersecurity Policy for Employees: A Practical Guide

In 2023, MGM Resorts lost an estimated $100 million after a threat actor social-engineered a help desk employee with a ten-minute phone call. The attacker didn't exploit a zero-day vulnerability. They exploited a gap in employee policy — specifically, the identity verification process for password resets. A strong cybersecurity

Carl B. Johnson Jul 05, 2026 5 min read