No history yet

Understanding Phishing

What is Phishing?

Imagine a fisherman casting a wide net, hoping to catch a few fish. A cybercriminal does something similar, but instead of a net, they use deceptive emails, text messages, or websites. They're not after fish—they're after your sensitive information. This is the essence of phishing.

phishing

noun

A type of social engineering attack where an attacker sends a fraudulent message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious software on the victim's infrastructure like ransomware.

The goal is to trick you into giving up things like passwords, credit card numbers, or company secrets. Attackers do this by impersonating a person or organization you trust, such as your bank, your boss, or a popular online service. They create a convincing fake message to lure you in.

Lesson image

Types of Phishing Attacks

Not all phishing attacks are the same. While some are like casting a wide net, others are more like using a spear to target a specific fish. Understanding the different types can help you spot them more easily.

TypeMethodTargetExample
Email PhishingMass emailsWide, non-specific audienceA generic email from a "bank" asking you to verify your account.
Spear PhishingHighly personalized emailsSpecific individuals or companiesAn email to a finance employee that seems to be from their CEO, asking for an urgent wire transfer.
SmishingSMS text messagesAnyone with a mobile phoneA text message with a link, claiming you have a package delivery issue.
VishingVoice calls or voicemailsAnyone with a phoneA phone call from someone pretending to be from tech support, asking for remote access to your computer.

Spear phishing is particularly dangerous because the attacker often does their homework. They might use details from your social media profiles or company website to make their message incredibly convincing. The more personal the message, the more likely someone is to fall for it.

The Psychology of the Scam

Phishing works by exploiting human psychology, not just technology. Attackers know which emotional buttons to push to make people act without thinking.

Most phishing attacks create a sense of immediacy and influence fear to extract information from end-users.

Here are some common tactics:

  • Urgency: Messages that scream "Act now!" or "Your account will be closed!" are designed to make you panic. When you're rushed, you're less likely to scrutinize the message for red flags.

  • Authority: People tend to comply with requests from figures of authority. Phishers will pose as your boss, the CEO, a government agency like the IRS, or law enforcement to intimidate you into action.

  • Greed: The promise of a prize, a lottery win, or an unexpected inheritance can cloud judgment. The lure of a reward makes people more willing to click a suspicious link or provide personal information.

  • Curiosity: Attackers might send a message that says "See who's been looking at your profile" or "Your recent order details." Natural curiosity can lead you to click without considering the source.

Lesson image

Recognizing these psychological triggers is the first step in defending against phishing. If an email or message makes you feel a strong emotion—fear, excitement, or pressure—it’s a signal to slow down and investigate before you click.

Quiz Questions 1/5

What is the primary goal of a phishing attack?

Quiz Questions 2/5

An email that appears to be from your direct manager, mentioning a specific project you're working on and asking you to click a link to review a new document, is a classic example of what?