Tag

Phishing

Explore in-depth articles about phishing attacks, including email phishing, spear phishing, smishing, and vishing. Learn how attackers craft deceptive messages, steal credentials, and compromise systems — and discover proven strategies to detect and block these threats.

posts

Phishing

Phishing in 2026: What's Actually Working Against It

The Threat That Refuses to Die In January 2025, the FBI's Internet Crime Complaint Center (IC3) released its annual report showing that phishing and its variants remained the number one reported cybercrime by volume — for the fifth consecutive year. Over 298,000 complaints. That number only counts the

Carl B. Johnson Jan 18, 2026 7 min read
Phishing

Definition of a Phishing Attack: What It Really Looks Like

The MGM Breach Started With a Single Phone Call In September 2023, a threat actor called the MGM Resorts help desk, pretended to be an employee, and talked their way into a credential reset. Within hours, the Scattered Spider group had deep access to MGM's systems. The result:

Carl B. Johnson Jan 17, 2026 7 min read
Spoof

Spoof Attacks: How Threat Actors Trick Your Defenses

The CEO Email That Wasn't From the CEO In early 2025, a mid-sized logistics company wired $3.1 million to a bank account in Hong Kong. The CFO had received an email — apparently from the CEO — requesting an urgent wire transfer for a confidential acquisition. The email address

Carl B. Johnson Jan 17, 2026 7 min read
Phishing

Phishing Attacks in 2025: What Actually Works to Stop Them

In January 2025, a finance employee at a multinational firm in Hong Kong wired $25 million to threat actors after a deepfake video call convinced him his CFO had authorized the transfer. The attack started the same way almost all of them do — with a phishing email. If you'

Carl B. Johnson Dec 27, 2025 7 min read
Spoofing

What Is Spoofing? The Attack Behind 90% of Breaches

In March 2025, the FBI's Internet Crime Complaint Center reported that spoofing-related fraud accounted for billions in losses across American businesses and individuals. Every major data breach investigation I've worked on in the past five years started the same way — someone trusted something that wasn'

Carl B. Johnson Dec 09, 2025 7 min read
Fake Identity Website

Fake Identity Website Threats: What You Need to Know

A Single Fake Identity Website Cost One Company $47 Million In early 2024, a finance employee at engineering firm Arup wired $25 million after joining a video call with what appeared to be the company's CFO and other colleagues. Every person on that call was a deepfake. The

Carl B. Johnson Nov 13, 2025 7 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

The Attack That Cost MGM Resorts $100 Million Started With a Phone Call In September 2023, a threat actor called the MGM Resorts IT help desk, impersonated an employee they found on LinkedIn, and talked their way into a password reset. Within hours, the attackers had deployed ransomware across MGM&

Carl B. Johnson Sep 22, 2025 7 min read
Smishing Attack Examples

Smishing Attack Examples: 7 Real Texts That Steal Data

In March 2025, the FBI's IC3 warned that Americans lost over $470 million to phishing and smishing schemes in the prior reporting year — and text-based attacks were growing faster than any other vector. I've personally triaged incidents where a single SMS message led to a six-figure

Carl B. Johnson Sep 21, 2025 8 min read
Social Engineering Examples

Social Engineering Examples: 7 Real Attacks in 2025

In September 2023, a threat actor called Scattered Spider called MGM Resorts' IT help desk, impersonated an employee they found on LinkedIn, and convinced a technician to reset credentials. The result: an estimated $100 million in losses, a ransomware lockout across casino floors and hotel systems, and weeks of

Carl B. Johnson Sep 21, 2025 7 min read