Tag

Social Engineering

Learn how attackers use psychological manipulation to trick people into revealing sensitive information or performing unsafe actions. Topics include pretexting, baiting, tailgating, vishing, and real-world social engineering case studies that expose common human vulnerabilities.

posts

PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read
Fake Identity Website

Fake Identity Website Scams: How to Spot and Stop Them

A Single Fake Identity Website Cost One Company $23 Million In early 2024, a finance employee at Arup, a British engineering firm, was tricked into transferring approximately $25 million after threat actors used a deepfake video call combined with a fake identity website that impersonated senior executives. The site looked

Carl B. Johnson Sep 07, 2026 5 min read
Insider Threat Examples

Insider Threat Examples: Real Breaches That Cost Millions

In 2022, a former Amazon engineer named Paige Thompson was convicted for the Capital One breach that exposed over 100 million customer records. She wasn't an outside hacker who cracked through a firewall. She was an insider — someone with knowledge of the cloud infrastructure who exploited a misconfigured

Carl B. Johnson Sep 07, 2026 5 min read
DNS Spoofing Attack

DNS Spoofing Attack: How Hackers Hijack Your Traffic

In April 2022, researchers at Tsinghua University and the University of California disclosed a new class of DNS cache poisoning vulnerabilities affecting major DNS software. The attack, dubbed "MaginotDNS," could redirect users from legitimate banking and email sites to pixel-perfect phishing pages — and the victims never saw a

Carl B. Johnson Sep 07, 2026 6 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does to Networks

In 2023, the FBI's Internet Crime Complaint Center reported over $12.5 billion in losses from cybercrime — and a staggering percentage of those incidents started with a single piece of software pretending to be something it wasn't. Trojan horse malware remains one of the most effective

Carl B. Johnson Sep 05, 2026 5 min read
Phishing Scams

What Is a Phishing Scam? A Security Pro's Real Guide

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated phishing incidents at organizations of every size, from ten-person startups to Fortune 500 companies. The pattern is always

Carl B. Johnson Sep 05, 2026 5 min read
Smishing Attack Examples

Smishing Attack Examples: Real Texts That Steal Data

In March 2024, the FBI's IC3 reported that Americans lost over $45 million to smishing and vishing schemes in a single year — and those are just the cases people actually reported. I've personally investigated incidents where a single SMS message led to a six-figure wire transfer

Carl B. Johnson Sep 04, 2026 5 min read
Spear Phishing

What Is Spear Phishing? The Targeted Attack Behind Major Breaches

A Single Email Cost This Company $100 Million In 2015, Ubiquiti Networks disclosed that threat actors used carefully crafted emails impersonating company executives to trick finance employees into wiring $46.7 million to overseas accounts. The attackers didn't use malware. They didn't exploit a software vulnerability.

Carl B. Johnson Sep 03, 2026 6 min read