Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Group Online Svindel

Group Online Svindel: How Organized Fraud Rings Work

A Single Fraud Ring Stole $75 Million — And Nobody Noticed for Months In 2023, the FBI dismantled a business email compromise (BEC) ring that operated across multiple countries, defrauding companies of tens of millions of dollars. The operation wasn't run by a lone wolf. It was a coordinated

Carl B. Johnson Jul 28, 2026 5 min read
Fake Email

Fake Email Attacks: How to Spot and Stop Them

In 2023, the FBI's Internet Crime Complaint Center reported that business email compromise — a category built almost entirely on the fake email — cost victims over $2.9 billion. That wasn't from sophisticated zero-day exploits. It was from emails that looked real but weren't. I&

Carl B. Johnson Jul 25, 2026 5 min read
Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read
Ransomware Examples 2026

Ransomware Examples 2026: Real Attacks Hitting Now

The Ransom Note Nobody Expected In January 2026, a mid-sized hospital network in the American Midwest discovered that every imaging workstation, patient scheduling system, and billing server had been encrypted overnight. The ransom demand: 200 Bitcoin. Staff resorted to paper charts and fax machines for eleven days. Surgeries were postponed.

Carl B. Johnson Jul 24, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

A Single Text Message Cost This Company $15 Million In 2022, Twilio disclosed that a coordinated smishing campaign tricked employees into entering credentials on a fake login page. Attackers used those credentials to access internal systems and compromise data for over 100 customers. The whole thing started with a text

Carl B. Johnson Jul 23, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

The FBI Told You About Medusa. Are You Listening? In March 2025, the FBI and CISA issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare systems, school districts, legal firms, manufacturers. The common thread? Almost every intrusion started

Carl B. Johnson Jul 22, 2026 5 min read
CEO Fraud Email Scam

CEO Fraud Email Scam: How Attackers Steal Millions

A Single Email Cost This Company $37 Million In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million at the time) after attackers impersonated the CEO and convinced a finance employee to wire funds to accounts controlled by threat actors. The employee believed they were following

Carl B. Johnson Jul 20, 2026 6 min read