Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Cybersecurity for Nonprofits

Cybersecurity for Nonprofits: A Practical Defense Guide

The Breach That Nearly Killed a Children's Charity In 2023, Save the Children International confirmed a cyberattack by the BianLian ransomware group that reportedly compromised nearly 7 GB of sensitive data — including financial records, health data, and personal information. A global nonprofit with dedicated IT resources still got

Carl B. Johnson Sep 09, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read
Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

The Phone Call That Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into transferring $25 million after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. The attackers never

Carl B. Johnson Sep 08, 2026 5 min read
Fake Identity Website

Fake Identity Website Scams: How to Spot and Stop Them

A Single Fake Identity Website Cost One Company $23 Million In early 2024, a finance employee at Arup, a British engineering firm, was tricked into transferring approximately $25 million after threat actors used a deepfake video call combined with a fake identity website that impersonated senior executives. The site looked

Carl B. Johnson Sep 07, 2026 5 min read
Insider Threat Examples

Insider Threat Examples: Real Breaches That Cost Millions

In 2022, a former Amazon engineer named Paige Thompson was convicted for the Capital One breach that exposed over 100 million customer records. She wasn't an outside hacker who cracked through a firewall. She was an insider — someone with knowledge of the cloud infrastructure who exploited a misconfigured

Carl B. Johnson Sep 07, 2026 5 min read
Phishing Scams

What Is a Phishing Scam? A Security Pro's Real Guide

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated phishing incidents at organizations of every size, from ten-person startups to Fortune 500 companies. The pattern is always

Carl B. Johnson Sep 05, 2026 5 min read
Stolen Credentials Dark Web

Stolen Credentials Dark Web: Where Your Passwords End Up

In January 2024, researchers discovered a file called "Naz.API" circulating on dark web forums. It contained over 70 million unique email addresses and their associated passwords — harvested from credential-stealing malware installed on everyday computers. Most of the victims had no idea their login information was for sale.

Carl B. Johnson Sep 05, 2026 5 min read