Tag

Social Engineering

Learn how attackers use psychological manipulation to trick people into revealing sensitive information or performing unsafe actions. Topics include pretexting, baiting, tailgating, vishing, and real-world social engineering case studies that expose common human vulnerabilities.

posts

Phish Tour

Phish Tour: How Attackers Map Your Organization

They Don't Just Send One Email — They Run a Phish Tour In 2023, the FBI's IC3 received over 298,000 phishing complaints, making it the most reported cybercrime category for the fifth consecutive year. But here's the part that doesn't make the

Carl B. Johnson Feb 27, 2020 6 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In March 2024, MGM Resorts was still tallying the damage from a social engineering attack that started with a single phone call to their help desk. The total cost exceeded $100 million. The attacker didn't exploit a zero-day vulnerability or crack military-grade encryption. They impersonated an employee found

Carl B. Johnson Feb 27, 2020 6 min read
Phishing

Definition of a Phishing Attack: What It Really Means

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing — making it the single most reported cybercrime for the fifth consecutive year. Yet when I ask executives what phishing actually is, most give me a vague answer about "fake emails." That&

Carl B. Johnson Feb 27, 2020 7 min read
Spoofing

Spoofing Attacks: How Hackers Impersonate You Online

In 2023, a finance employee at the multinational firm Arup wired $25 million to threat actors after a deepfake video call that spoofed the company's CFO and several colleagues. Every face on the screen was fake. Every voice was synthesized. The employee had no reason to doubt what

Carl B. Johnson Feb 27, 2020 7 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Your Defenses

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider used a spear phishing phone call to trick a help desk employee into resetting credentials. One call. One employee. One hundred million dollars. That's not a bulk spam campaign — that's

Carl B. Johnson Feb 23, 2020 7 min read
Spoof

Spoof Attacks: How Threat Actors Hijack Trust

A Single Spoofed Email Cost This Company $46.7 Million In 2016, FACC Operations GmbH, an Austrian aerospace parts manufacturer, lost €42 million (roughly $46.7 million USD) after attackers sent a spoofed email impersonating the company's CEO. The finance department wired the money to accounts controlled by

Carl B. Johnson Feb 23, 2020 7 min read
AI Phishing Attacks

FBI Warns Gmail Users of AI-Driven Phishing Attacks

When the FBI Tells You to Pay Attention, Pay Attention In late 2024, the FBI issued a stark public service announcement warning that threat actors are leveraging generative AI to craft highly convincing phishing campaigns — and Gmail's 1.8 billion users sit squarely in the crosshairs. The FBI

Carl B. Johnson Feb 23, 2020 7 min read
Phishing Email

Phishing Email Attacks: How to Spot and Stop Them

One Phishing Email Cost This Company $100 Million In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook using nothing more than fraudulent invoices and carefully crafted phishing emails. He impersonated a legitimate hardware vendor, sent fake invoices to accounts payable

Carl B. Johnson Feb 16, 2020 7 min read
Phishing

Phishing Attacks in 2026: How to Spot and Stop Them

In 2024, the FBI's Internet Crime Complaint Center (IC3) reported that phishing was the most frequently reported cybercrime — again. Over 193,000 complaints were filed for phishing alone, and the real number is far higher since most incidents go unreported. I've spent years watching organizations get

Carl B. Johnson Feb 16, 2020 6 min read