No history yet

Understanding Phishing

What Is Phishing?

Phishing is a type of cyberattack where criminals trick people into giving away sensitive information. Think of it like a digital con artist. They disguise themselves as a trustworthy person or company and send a message, usually an email, to lure you in.

The goal is to get you to reveal personal details like passwords, credit card numbers, or social security numbers. They might also try to trick you into installing malicious software, known as malware, on your computer.

Lesson image

When a phishing attack succeeds, the consequences for an organization can be severe. It can lead to unauthorized access to confidential data, significant financial losses, and damage to the company's reputation. A single click on a deceptive link can open the door to a much larger breach of the entire corporate network.

Common Phishing Methods

While email is the most common tool for phishing, attackers use several methods to reach their targets. The specific approach often depends on how much they know about their victim.

Email Phishing is the broadest form of attack. Scammers send out massive numbers of generic emails, hoping a small percentage of recipients will take the bait. These messages often mimic well-known banks, social media sites, or online retailers.

Spear Phishing is much more targeted. In this attack, the criminal researches their target beforehand—which could be a specific person, department, or company. The message will seem much more personal and legitimate because it includes details like the target's name, job title, or recent projects. This personalization makes it harder to detect.

Vishing stands for "voice phishing." It's the same scam, but it happens over the phone. An attacker might call and pretend to be from tech support, a government agency, or your bank to coax sensitive information out of you.

Smishing, or "SMS phishing," uses text messages to carry out the attack. These messages often contain urgent-sounding links, like a fake package delivery notification or a warning that an account has been compromised.

Attack TypeMediumTargeting
PhishingEmailBroad / Impersonal
Spear PhishingEmailSpecific / Personalized
VishingPhone CallBroad or Specific
SmishingSMS Text MessageBroad or Specific

Phishing in the Real World

Phishing isn't a new threat; it's been around for decades. One of the earliest documented cases dates back to the mid-1990s, when attackers targeted AOL users by creating fake accounts with names like "BillingAdmin" to trick people into revealing their passwords.

More recently, a high-profile spear-phishing attack in 2016 targeted the Democratic National Committee (DNC). Attackers sent carefully crafted emails that appeared to be security alerts from Google, prompting officials to click a link and enter their credentials. This single act of deception led to a massive data breach with significant political consequences.

These events show how a simple, deceptive message can have a powerful and lasting impact.