Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Whaling Attack Cybersecurity

Whaling Attack Cybersecurity: How Execs Get Targeted

The CEO Who Wired $47 Million to a Stranger In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million) after a threat actor impersonated the company's CEO via email and instructed an employee to wire funds for a fake acquisition project. The CEO and

Carl B. Johnson Aug 26, 2026 6 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — more than any other cybercrime category. That number has only climbed since. I've investigated breaches at organizations of every size, and the entry point is almost always the same: one employee who

Carl B. Johnson Aug 25, 2026 6 min read
Phishing Attack

Phishing Attack Anatomy: How Breaches Actually Start

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past the help desk with a single phone call. But that attack started the way most do — with a phishing attack that gathered the intelligence needed to make that call convincing.

Carl B. Johnson Aug 24, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States. The root cause? Compromised credentials on a remote access system that lacked multi-factor authentication. One account. No MFA. Billions of dollars in damage. I&

Carl B. Johnson Aug 24, 2026 5 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read
FakeEmail

FakeEmail Scams: How Attackers Spoof Your Inbox

A Single FakeEmail Cost This Company $37 Million In 2024, the FBI's Internet Crime Complaint Center reported that business email compromise — attacks built on fakeemail messages that impersonate trusted senders — generated over $2.9 billion in adjusted losses. That made BEC the costliest cybercrime category for the fourth

Carl B. Johnson Aug 23, 2026 5 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

A Phone Call That Sounds Exactly Like Google Support — But Isn't In late 2024, a Microsoft solutions consultant named Sam Mitrovic nearly lost his Google account to an AI-generated voice that sounded indistinguishable from a real Google support agent. The caller ID showed a legitimate Google number. The

Carl B. Johnson Aug 22, 2026 5 min read
Phishing

Phishing: Why It Still Works and How to Stop It

A Single Email Cost This Company Everything In 2023, MGM Resorts lost an estimated $100 million after a threat actor used a phone-based social engineering attack — a technique closely related to phishing — to gain access to their systems. The attackers didn't exploit a zero-day vulnerability or brute-force a

Carl B. Johnson Aug 22, 2026 5 min read