Tag

phishing prevention

Targeted advice on identifying and stopping phishing attacks before they cause damage. Topics include recognizing social engineering tactics, deploying email filtering tools, conducting phishing simulations, and training employees to report suspicious messages promptly.

posts

pretexting attacks

Pretexting Attack Examples: Real Scams Costing Millions

In 2023, a finance employee at a multinational firm wired $25 million after a video call with someone they believed was their CFO. It wasn't. The entire call — every face, every voice — was a deepfake fabricated by threat actors who'd spent weeks building a detailed pretext.

Carl B. Johnson Apr 07, 2024 7 min read
computer security

Computer Security in 2022: What Actually Works Now

In March 2022, Okta confirmed that the Lapsus$ threat actor group had accessed an internal support engineer's laptop, potentially affecting hundreds of downstream customers. A few weeks before that, the same group hit Nvidia, Samsung, and Microsoft. These weren't obscure targets. These were companies with massive

Carl B. Johnson Aug 11, 2022 6 min read
CISA cybersecurity guidelines

CISA Cybersecurity Guidelines: What They Mean for You

The Federal Agency Most Hackers Wish You'd Ignore In May 2021, Colonial Pipeline paid $4.4 million in ransom after a single compromised password shut down fuel delivery across the Eastern Seaboard. Within days, CISA — the Cybersecurity and Infrastructure Security Agency — issued an advisory with specific defensive measures

Carl B. Johnson Jan 01, 2022 7 min read
computer security

Computer Security in 2021: What Actually Works Now

The Colonial Pipeline Hack Changed the Conversation On May 7, 2021, a single compromised password shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom in Bitcoin to the DarkSide ransomware group. Gas stations across the Southeast ran dry. Panic buying erupted.

Carl B. Johnson Jun 03, 2021 7 min read
cyber security

Cyber Security Basics That Actually Stop Breaches

The Colonial Pipeline Hack Was a Wake-Up Call Nobody Should Have Needed On May 7, 2021, a single compromised password shut down the largest fuel pipeline in the United States. Colonial Pipeline paid a $4.4 million ransom to the DarkSide threat actor group, and fuel shortages rippled across the

Carl B. Johnson Jun 01, 2021 6 min read
CISA cybersecurity guidelines

CISA Cybersecurity Guidelines: What Actually Matters

In January 2024, CISA itself disclosed that a threat actor had exploited vulnerabilities in Ivanti products to breach two of its own systems. Let that sink in. The federal agency responsible for setting cybersecurity standards for the entire nation got hit. If that doesn't convince you that simply

Carl B. Johnson Sep 14, 2019 7 min read
cyber security

Cyber Security in 2026: What Actually Works Now

In March 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. The root cause? Stolen credentials on a system without multi-factor authentication. One overlooked gap in cyber security brought a $32 billion company to its knees and

Carl B. Johnson Feb 25, 2019 6 min read
computer security

Computer Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Computer Security In early 2024, Change Healthcare — one of the largest health payment processors in the United States — got hit with a ransomware attack that disrupted pharmacy operations, delayed patient care, and exposed the protected health information of roughly 100 million individuals.

Carl B. Johnson Feb 25, 2019 7 min read