No history yet

Understanding Phishing

What is Phishing?

Phishing is a type of cyberattack where criminals trick you into giving them sensitive information, like passwords or credit card numbers. They do this by pretending to be a person or organization you trust, such as a bank, a social media site, or even a coworker.

The goal is simple: to fool you into clicking a malicious link, downloading a harmful attachment, or just handing over your private data. The name comes from "fishing," because the attackers are essentially casting a baited hook and waiting for someone to bite.

Lesson image

These attacks come in many forms, but they all share the same core strategy of deception. Understanding the different types can help you spot them before you get hooked.

Common Types of Phishing

While the classic phishing attack is an email, scammers use several channels to reach their victims.

Email Phishing This is the most common form. Attackers send a deceptive email to a wide audience, hoping that a small percentage will fall for the trick. These messages often look like they're from well-known companies and might ask you to "verify your account" or claim you've won a prize.

Spear Phishing Unlike the broad approach of regular email phishing, spear phishing is highly targeted. The attacker researches a specific person or organization to make the message as convincing as possible. They might find information on your social media profiles or your company's website to personalize the email.

Spear phishing targets individuals: instead of "Dear Customer" an email might address you by name, refer to a recent transaction you've made and/or draw on other information that you've shared online – often on social networks.

Because they feel personal and relevant, these attacks can be much harder to spot.

Vishing and Smishing Phishing isn't just limited to email. When it happens over the phone, it's called vishing (voice phishing). A scammer might call you pretending to be from your bank or a government agency. When the attack comes via text message, it's known as smishing (SMS phishing). A common smishing message might be a fake package delivery notification with a link to track it.

The Psychology of the Scam

Phishing works by exploiting human psychology. Attackers don't just rely on fake logos; they create situations designed to make you act without thinking. They want to bypass your logical brain and trigger an emotional reaction.

Most phishing attacks create a sense of immediacy and influence fear to extract information from end-users.

Creating a sense of urgency is a classic tactic. An email might claim that your account will be suspended in 24 hours unless you take immediate action. This pressure is designed to make you panic and click before you've had a chance to question the message's authenticity.

Fear is another powerful motivator. A message might warn you that your account has been compromised or that suspicious activity has been detected. The fear of losing your money or data can push you to follow the attacker's instructions quickly. Other tactics include appealing to greed with fake lottery winnings or curiosity with intriguing but vague messages.

By understanding these tricks, you can learn to pause, think critically, and recognize when you're being manipulated.

Quiz Questions 1/5

What is the primary goal of a phishing attack?

Quiz Questions 2/5

An attacker researches a specific company's CFO and sends them a personalized email that appears to be from the CEO, requesting an urgent wire transfer. What is this highly targeted attack called?