Tag

Social Engineering

Learn how attackers use psychological manipulation to trick people into revealing sensitive information or performing unsafe actions. Topics include pretexting, baiting, tailgating, vishing, and real-world social engineering case studies that expose common human vulnerabilities.

posts

Phishing

What Is Phishing? The Attack Behind 90% of Breaches

In 2023, a single phishing email gave attackers access to MGM Resorts' entire IT infrastructure. The result: over $100 million in losses, days of operational chaos, and a security wake-up call that echoed across every industry. The attackers didn't exploit a zero-day vulnerability or deploy sophisticated malware.

Carl B. Johnson Sep 22, 2026 5 min read
Insider Threat Awareness

Insider Threat Awareness: What Most Companies Miss

The Threat Already Inside Your Building In 2022, a former Twitter employee was convicted of spying on behalf of Saudi Arabia, accessing the personal data of thousands of users — including dissidents — using nothing more than his legitimate employee credentials. No malware. No phishing email. Just a trusted insider with access

Carl B. Johnson Sep 21, 2026 5 min read
Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, security researchers at Kaspersky identified over 100 million adware attacks in a single quarter. That same year, spyware variants like SpinOk embedded themselves inside legitimate apps on the Google Play Store, affecting over 421 million downloads. Both threats rode in through the front door — and most users never

Carl B. Johnson Sep 20, 2026 5 min read
Types of Malware

Types of Malware: What Every Organization Must Know

A Single Email Delivered 11 Different Types of Malware In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion. A significant chunk of those losses traced back to malware delivered through phishing emails and social engineering. I've

Carl B. Johnson Sep 20, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

In March 2025, CISA and the FBI issued a joint advisory warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, and manufacturing. The attack vector in the vast majority of cases? Phishing emails and credential theft. If you think your

Carl B. Johnson Sep 19, 2026 6 min read
Phishing Scams

Phishing Scams in 2026: What Actually Works to Stop Them

The Phishing Email That Cost One Company $37 Million In 2024, a finance employee at a multinational firm in Hong Kong joined a video call with people who looked and sounded exactly like the company's CFO and other executives. Every face on that call was a deepfake. The

Carl B. Johnson Sep 18, 2026 6 min read
Smishing Attacks

Smishing Attack Examples: Real Texts That Steal Data

The Text Message That Cost One Company $15 Million In 2022, Twilio disclosed that a sophisticated smishing campaign tricked several employees into handing over their credentials via text messages impersonating the company's IT department. The attackers then used those stolen credentials to access internal systems and customer data.

Carl B. Johnson Sep 18, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read