Tag

phishing training for employees

Articles and guides focused on phishing training programs designed for employees. This tag covers simulated phishing exercises, recognizing malicious emails, reporting suspicious messages, and building workforce resilience against social engineering attacks that target organizations.

posts

phishing training for employees

Phishing Training for Employees: What Actually Works

A Single Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee with a phone call. That single interaction — not a sophisticated zero-day exploit, not a nation-state supply chain attack — led to a ransomware incident that cost the

Carl B. Johnson Sep 25, 2025 7 min read
phishing training for employees

Phishing Training for Employees: What Actually Works

In 2023, MGM Resorts lost roughly $100 million after a threat actor called a help desk, impersonated an employee found on LinkedIn, and talked their way past security controls. No zero-day exploit. No nation-state malware. Just a phone call. That incident crystallized something I've been telling organizations for

Carl B. Johnson Feb 09, 2020 8 min read