Phishing
Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.
Term
description · examples · notesPhishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.
Description
The strength of phishing is not in the technique but in the psychology. The message creates pressure — your account is suspended, the parcel could not be delivered, the invoice is overdue — so a person reacts before they have time to think. Mass phishing goes to thousands of addresses at once, counting on at least a small share of people biting. That is enough, because the cost of sending is practically nothing.
The defense works on two levels. Technical: mail filtering, link checking, two-factor authentication that makes a stolen password unusable. Human: through training. The habit being built is to check the sender and the link address before clicking, and to treat a message that hurries you as the first sign for suspicion. No filter catches everything, so the person remains the last and most important line.
Examples
- A false notice that your account has been suspended, with a link to a login page that looks like the real one.
- An email with an attachment dressed up as an invoice or a purchase order, which actually carries malware.
- A message about an undelivered parcel leading to a page for some small additional charge, built only to collect card details.
Notes
- Mass phishing goes at everyone at once and is easy to recognize by its generic greeting; targeted phishing (spear phishing) is cut to fit the victim and is far more dangerous.
- Checking the sender's address and the link's destination before clicking is the basic measure; if the message hurries and threatens, that is one more reason to stop.
Mentioned in the news
- 23. JUL 2026. Ugašen Kratos, servis koji je gurao 15.000 fišing kampanja mesečno →
- 16. JUN 2026. SearchLeak: Sa legitimnim Microsoft linkom do krađe internih podataka →
- 19. MAJ 2026. Tycoon2FA preuzima Microsoft 365 naloge preko device-code phishinga →
- 8. MAJ 2026. Microsoft opisao phishing kampanju protiv 35.000 korisnika →
- 7. MAJ 2026. Google Ads zloupotrebljen za phishing GoDaddy ManageWP naloga →
- 6. MAJ 2026. Phishing kampanja koristi SimpleHelp i ScreenConnect za trajni udaljeni pristup →
- 5. MAJ 2026. Bluekit phishing kit uvodi AI asistenta i automatsku registraciju domena →
- 5. MAJ 2026. Google AppSheet zloupotrebljen u phishing kampanji za krađu Facebook naloga →
- 28. APR 2026. Propust u Robinhood registraciji korišćen za phishing poruke →
- 28. APR 2026. Phishing ponovo glavni način početnog upada, navodi Cisco →
- 20. APR 2026. Lažna obaveštenja o curenju podataka mogu biti nova zamka za korisnike →
- 15. APR 2026. SAD i Indonezija ugasile W3LL platformu za phishing i krađu pristupa →
- 15. APR 2026. Microsoft uvodi nova Windows upozorenja i zaštitu za rizične RDP fajlove →
- 4. APR 2026. Device code phishing napadi eksplodirali kako se šire novi phishing kitovi →
- 2. APR 2026. Phishing postaje opasniji, a firmama trebaju novi slojevi zaštite →
- 2. APR 2026. EvilTokens olakšava device code phishing napade na Microsoft naloge →
- 28. MAR 2026. Holandska policija prijavila bezbednosni incident posle phishing napada →
- 24. MAR 2026. Tycoon2FA se brzo oporavio posle policijskog gašenja infrastrukture →
- 21. MAR 2026. Azure Monitor upozorenja zloupotrebljena za callback phishing kampanju →
- 11. MAR 2026. Lažne ChatGPT i Gemini iOS aplikacije kradu Facebook naloge →
- 5. MAR 2026. Starkiller fišing kit koristi AiTM tehniku za krađu naloga →
- 24. FEB 2026. Poshmark prevare: kako bezbedno kupovati i prodavati →
- 17. FEB 2026. Hakeri ciljaju kupce zainteresovane za Zimske olimpijske igre →
- 15. FEB 2026. DocuSign fišing: kako prepoznati i zaustaviti napade →
- 14. FEB 2026. Spiderman fišing kit cilja Microsoft 365 naloge →
- 4. JUL 2026. Lažne saobraćajne kazne, navodno od Puteva Srbije, vode do krađe platnih kartica →
- 29. MAJ 2026. Ne baš vešti hakeri sa AI-jem pod miškom, vrebaju Ukrajinu →
- 5. MAJ 2026. Telegram Mini Apps zloupotrebljeni za crypto prevare i Android malware →
- 5. MAJ 2026. Skoro polovina firmi u UK pogođena sajber napadima ili curenjem podataka →
- 5. MAJ 2026. FBI upozorava na krađu tereta preko lažnih logističkih firmi →
- 28. APR 2026. Kineskojezične PhaaS platforme šire krađu kredencijala preko SMS poruka →
- 24. APR 2026. Poverenje postaje nova površina napada u imejl prevarama →
- 24. APR 2026. Rast smishing napada u Srbiji kroz lažnu eUprava kampanju →
- 22. APR 2026. Kako napadači danas najčešće ulaze u poslovne sisteme →
- 22. APR 2026. Identitetski napadi i dalje otvaraju vrata bez exploita →
- 15. APR 2026. VENOM phishing platform gađa Microsoft naloge direktora i višeg menadžmenta →
- 2. APR 2026. WhatsApp poruke korišćene za širenje VBS malwarea sa UAC bypass lancem →
- 2. APR 2026. Homoglyph napadi koriste slična slova za lažne sajtove →
- 20. MAR 2026. Perseus Android bankarski malver prati Notes aplikacije radi krađe osetljivih podataka →
- 19. MAR 2026. ThreatsDay bilten: FortiGate RaaS, Citrix eksploatacija, MCP zloupotrebe i LiveChat phishing →
- 14. MAR 2026. INTERPOL uklonio 45.000 zlonamernih IP adresa i uhapsio 94 osobe u globalnoj operaciji protiv sajber kriminala →
- 13. MAR 2026. Interpolova operacija Synergia III ugasila 45.000 IP adresa povezanih sa sajber kriminalom →
- 11. MAR 2026. Sednit koristi RoundPress napade na webmail servere →
- 11. MAR 2026. Microsoft uvodi phishing-otpornu prijavu na Windows kroz Entra passkeys →
- 4. MAR 2026. Iranski hakeri podižu nivo pretnje prema SAD i saveznicima →
- 2. MAR 2026. Android korisnici suočeni sa novim bezbednosnim izazovima u eri AI →
- 24. FEB 2026. DPRK hakerske grupe ciljaju kripto platforme →
- 18. FEB 2026. Najčešće prevare koje ciljaju mala preduzeća →
- 18. FEB 2026. Napadači koriste DKIM replay napade za zaobilaženje bezbednosnih filtera →
- 17. FEB 2026. Maliciozni Bing oglasi koriste se za distribuciju prevara i malvera →
Techniques
carried out with 4Techniques used to carry it out. Select one to open its page.
Defenses
countered by 8How it is defended against. Select one to open its page.