166 terms · 75/46/45
Threat № 026 · class: social eng.

Phishing

Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.

Term

description · examples · notes

Phishing is the most widespread form of social-engineering attack and, in a great many cases, the first link in any serious break-in. The attacker sends a message that appears to come from a known organization — a bank, a courier, a government service, a colleague — and leads the victim into doing one of three things: clicking a link, opening an attachment, or entering their credentials somewhere.

Description

The strength of phishing is not in the technique but in the psychology. The message creates pressure — your account is suspended, the parcel could not be delivered, the invoice is overdue — so a person reacts before they have time to think. Mass phishing goes to thousands of addresses at once, counting on at least a small share of people biting. That is enough, because the cost of sending is practically nothing.

The defense works on two levels. Technical: mail filtering, link checking, two-factor authentication that makes a stolen password unusable. Human: through training. The habit being built is to check the sender and the link address before clicking, and to treat a message that hurries you as the first sign for suspicion. No filter catches everything, so the person remains the last and most important line.

Examples

  • A false notice that your account has been suspended, with a link to a login page that looks like the real one.
  • An email with an attachment dressed up as an invoice or a purchase order, which actually carries malware.
  • A message about an undelivered parcel leading to a page for some small additional charge, built only to collect card details.

Notes

  • Mass phishing goes at everyone at once and is easy to recognize by its generic greeting; targeted phishing (spear phishing) is cut to fit the victim and is far more dangerous.
  • Checking the sender's address and the link's destination before clicking is the basic measure; if the message hurries and threatens, that is one more reason to stop.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 4

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 8