Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Ransomware Examples 2026

Ransomware Examples 2026: Real Attacks Hitting Now

The Ransom Note Nobody Expected In January 2026, a mid-sized hospital network in the American Midwest discovered that every imaging workstation, patient scheduling system, and billing server had been encrypted overnight. The ransom demand: 200 Bitcoin. Staff resorted to paper charts and fax machines for eleven days. Surgeries were postponed.

Carl B. Johnson Jul 24, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

A Single Text Message Cost This Company $15 Million In 2022, Twilio disclosed that a coordinated smishing campaign tricked employees into entering credentials on a fake login page. Attackers used those credentials to access internal systems and compromise data for over 100 customers. The whole thing started with a text

Carl B. Johnson Jul 23, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

The FBI Told You About Medusa. Are You Listening? In March 2025, the FBI and CISA issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare systems, school districts, legal firms, manufacturers. The common thread? Almost every intrusion started

Carl B. Johnson Jul 22, 2026 5 min read
CEO Fraud Email Scam

CEO Fraud Email Scam: How Attackers Steal Millions

A Single Email Cost This Company $37 Million In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million at the time) after attackers impersonated the CEO and convinced a finance employee to wire funds to accounts controlled by threat actors. The employee believed they were following

Carl B. Johnson Jul 20, 2026 6 min read
Cybersecurity Culture

Cybersecurity Culture in the Workplace: Build It or Pay

One Click Cost MGM Resorts Over $100 Million In September 2023, a social engineering attack against MGM Resorts International shut down slot machines, hotel key cards, and reservation systems across Las Vegas. The threat actors didn't exploit a zero-day vulnerability. They called the help desk, impersonated an employee,

Carl B. Johnson Jul 20, 2026 6 min read
Work From Home Cybersecurity

Work From Home Cybersecurity: A Practical Guide

The $20 Million Breach That Started on a Home Wi-Fi Network In 2024, a healthcare company disclosed a breach that exposed 11 million patient records. The root cause? A remote employee connected to an unsecured home network, clicked a phishing link, and handed over VPN credentials to a threat actor.

Carl B. Johnson Jul 19, 2026 5 min read
Phishing Awareness

Phish Food: What Threat Actors Serve Your Employees

Your Employees Are Eating Phish Food Every Day In March 2024, MGM Resorts was still tallying the damage from a social engineering attack that started with a single phone call. The estimated cost exceeded $100 million. The threat actor didn't exploit a zero-day vulnerability or deploy some exotic

Carl B. Johnson Jul 19, 2026 6 min read
Tailgating Attack

Tailgating Attack Cybersecurity: The Threat at Your Door

In 2019, a former employee of Capital One walked into an AWS cloud environment — digitally, not physically — but the breach that exposed over 100 million records started with exploiting trust and access. That same principle of exploiting trust is exactly how a tailgating attack in cybersecurity works in the physical

Carl B. Johnson Jul 19, 2026 5 min read
Cybersecurity for Law Firms

Cybersecurity for Law Firms: Protecting Client Data

In November 2023, the international law firm Allen & Overy confirmed it was hit by a LockBit ransomware attack that disrupted internal systems and exposed sensitive data. They weren't alone. The American Bar Association disclosed a data breach that same year affecting 1.4 million members. If you

Carl B. Johnson Jul 18, 2026 5 min read