Tag

security awareness training

Resources and best practices for designing and delivering effective security awareness training programs. Covers phishing simulations, compliance requirements, behavior change techniques, measuring training effectiveness, and fostering a culture of vigilance across organizations.

posts

phishing email

Phishing Email Attacks in 2025: What Actually Works

One Phishing Email Cost MGM Resorts $100 Million In September 2023, a single social engineering phone call — preceded by a carefully crafted phishing email reconnaissance campaign — led to the breach that shut down MGM Resorts' operations across Las Vegas. Slot machines went dark. Hotel room keys stopped working. The

Carl B. Johnson Dec 27, 2025 7 min read
computer security

Computer Security in 2025: What Actually Works Now

In February 2025, the FBI's Internet Crime Complaint Center reported that cybercrime losses in 2024 exceeded $16 billion — a staggering jump from the $12.5 billion reported the year before. That number landed like a gut punch across the security community, but honestly, none of us were surprised.

Carl B. Johnson Nov 06, 2025 7 min read
phishing training for employees

Phishing Training for Employees: What Actually Works

A Single Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee with a phone call. That single interaction — not a sophisticated zero-day exploit, not a nation-state supply chain attack — led to a ransomware incident that cost the

Carl B. Johnson Sep 25, 2025 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In January 2024, a finance employee at a multinational firm in Hong Kong transferred $25.6 million to criminals after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. That's where phishing lives now — far beyond

Carl B. Johnson Sep 18, 2024 7 min read
computer security

Computer Security in 2024: What Actually Works Now

In February 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by a ransomware attack that disrupted pharmacy operations, delayed patient care, and potentially exposed the protected health information of tens of millions of Americans. The root cause? Compromised credentials on a remote

Carl B. Johnson Jul 10, 2024 7 min read
computer security advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached executive email accounts using a password spray attack against a legacy test account that lacked multi-factor authentication. Microsoft. One of the largest technology companies on Earth. Compromised

Carl B. Johnson May 13, 2024 7 min read
pretexting attacks

Pretexting Attack Examples: Real Scams Costing Millions

In 2023, a finance employee at a multinational firm wired $25 million after a video call with someone they believed was their CFO. It wasn't. The entire call — every face, every voice — was a deepfake fabricated by threat actors who'd spent weeks building a detailed pretext.

Carl B. Johnson Apr 07, 2024 7 min read
cyber security

Cyber Security in 2022: What's Actually Breaking

In March 2022, Okta confirmed that the Lapsus$ threat actor group had breached a third-party support contractor, potentially affecting hundreds of enterprise customers. A few weeks later, the same group hit Microsoft, Nvidia, and Samsung. These weren't obscure targets — they were companies with massive cyber security budgets, sophisticated

Carl B. Johnson Aug 11, 2022 7 min read