Tag

Social Engineering

Learn how attackers use psychological manipulation to trick people into revealing sensitive information or performing unsafe actions. Topics include pretexting, baiting, tailgating, vishing, and real-world social engineering case studies that expose common human vulnerabilities.

posts

CEO Fraud

CEO Fraud Email Scam: How Attackers Steal Millions

A Single Email Cost This Company $47 Million In 2015, Ubiquiti Networks disclosed that threat actors impersonating company executives tricked employees into wiring $46.7 million to overseas accounts. The attackers never breached a firewall. They never deployed malware. They sent emails — and those emails were enough. That's

Carl B. Johnson Oct 04, 2026 6 min read
FakeEmail

FakeEmail Attacks: How Threat Actors Spoof Your Inbox

The FakeEmail That Cost One Company $37 Million In 2024, the FBI's IC3 reported that business email compromise — the art of sending a convincing fakeemail that impersonates a trusted sender — accounted for over $2.9 billion in adjusted losses. That's not a typo. One European company

Carl B. Johnson Oct 04, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

The Phone Call That Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That single vishing call — a voice phishing attack — triggered a ransomware event that shut down

Carl B. Johnson Oct 03, 2026 5 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask executives to give me a phishing definition, most of them still say something like "those fake emails from

Carl B. Johnson Oct 02, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The FBI Didn't Issue a Joint Advisory for Nothing In March 2025, CISA, the FBI, and MS-ISAC released a joint cybersecurity advisory (#StopRansomware) specifically about the Medusa ransomware variant. By that point, Medusa had already hit over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, technology,

Carl B. Johnson Oct 01, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

A $12.5 Billion Problem That Keeps Getting Worse The FBI's Internet Crime Complaint Center reported $12.5 billion in cybercrime losses for 2023 — a 22% jump from the prior year. And the trajectory hasn't slowed. If you're reading this in 2026 and still

Carl B. Johnson Sep 29, 2026 5 min read
CEO Fraud

CEO Fraud Email Scam: How Attackers Steal Millions

A Single Email Cost This Company $47 Million In 2015, Ubiquiti Networks disclosed that threat actors impersonating senior executives tricked finance employees into wiring $46.7 million to overseas accounts controlled by attackers. No malware. No zero-day exploit. Just a convincing email that looked like it came from the CEO.

Carl B. Johnson Sep 26, 2026 5 min read
Vishing

FBI Warning: Vishing and Smishing Attacks Surge in 2026

The Phone Call That Cost One Company $23 Million In early 2024, a finance employee at a multinational firm in Hong Kong joined a video call with what appeared to be the company's CFO and several colleagues. Every person on the screen was a deepfake. The employee transferred

Carl B. Johnson Sep 25, 2026 5 min read
Phishing Links

What Is a Phishing Link? How to Spot and Stop Them

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Behind nearly every one of those complaints was a single moment: someone clicked a link they shouldn't have. If you&

Carl B. Johnson Sep 24, 2026 6 min read