Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

In March 2024, the FBI's IC3 reported that Americans lost over $45 million to smishing and vishing schemes in a single year — and those are just the cases people actually reported. I've personally investigated incidents where a single SMS message led to a six-figure wire transfer

Carl B. Johnson Sep 04, 2026 5 min read
Spear Phishing

What Is Spear Phishing? The Targeted Attack Behind Major Breaches

A Single Email Cost This Company $100 Million In 2015, Ubiquiti Networks disclosed that threat actors used carefully crafted emails impersonating company executives to trick finance employees into wiring $46.7 million to overseas accounts. The attackers didn't use malware. They didn't exploit a software vulnerability.

Carl B. Johnson Sep 03, 2026 6 min read
Phishing

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. And those are just the ones people actually reported. I've spent years helping organizations recover from phishing attacks, and I

Carl B. Johnson Sep 02, 2026 5 min read
Cyber Security

Cyber Security in 2026: What Actually Stops Breaches

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number hasn't gone down. If you're responsible for cyber security at any level — whether you're a CISO, an

Carl B. Johnson Sep 02, 2026 5 min read
Shoulder Surfing Attack

Shoulder Surfing Attack: The Low-Tech Threat You Ignore

A financial analyst at a Fortune 500 company typed her corporate credentials into a laptop at Chicago O'Hare. The man sitting two seats behind her wasn't reading the news on his phone — he was recording her screen. Within 48 hours, the attacker used those stolen credentials

Carl B. Johnson Aug 31, 2026 5 min read
Phishing Email

Phishing Email Attacks: What Actually Works in 2026

One Phishing Email Cost This Company $100 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a phishing email and a follow-up phone call. Threat actors from the Scattered Spider group used social engineering to trick an IT help desk employee,

Carl B. Johnson Aug 30, 2026 6 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In March 2024, a threat actor breached a major healthcare provider's network using a single compromised password — no second factor required. The organization had purchased MFA licenses two years prior but never enforced enrollment. That gap cost them months of remediation and exposed the records of over 100,

Carl B. Johnson Aug 30, 2026 5 min read