Phishing Prevention Masterclass
Understanding Phishing
What is Phishing?
Phishing is a type of online scam where attackers impersonate legitimate organizations or people to trick you into revealing sensitive information. Think of it like a digital con artist. They aren't breaking down your digital door; they're trying to get you to hand over the keys yourself.
Phishing is the combination of social engineering and technical exploits designed to convince a victim to provide personal information, usually for the monetary gain of the attacker.
The goal is almost always to steal things like passwords, credit card numbers, bank account details, or other personal data. Attackers use this information to commit identity theft or financial fraud. They create a convincing lure, or "bait," and cast it out, waiting for someone to bite.
Common Phishing Methods
Phishing attacks come in many forms, but they all share the same goal of deception. The most common method uses a familiar tool: email.
Email Phishing
noun
The practice of sending fraudulent emails that appear to be from reputable sources to induce individuals to reveal personal information.
This is the classic phishing attack. An attacker sends an email that looks like it's from a well-known company, such as a bank, a social media site, or an online store. The email might claim there's a problem with your account or that you've won a prize.
These emails usually contain a link that directs you to a fake website. This website will look nearly identical to the real one. If you enter your login information or personal details on the fake site, the attacker captures it.
Targeted and Personal Attacks
While many phishing emails are sent to thousands of people at once, some attackers take a more focused approach.
Spear phishing is a highly personalized attack that targets a specific individual or organization.
Unlike broad phishing campaigns that use generic greetings like "Dear Customer," a spear phishing email will use your name, job title, or other specific details to gain your trust. The attacker often researches their target on social media or company websites to make the message more convincing.
For example, an attacker might pose as your company's IT department and send an email about a mandatory software update, referencing a project you're currently working on. The level of detail makes the scam much harder to spot.
Phishing Beyond Email
Scammers don't just use email. They also use text messages and phone calls to steal information.
| Term | Channel | Description |
|---|---|---|
| Smishing | SMS (Text Message) | Short for "SMS phishing." You receive a text message with a fraudulent link or a request for personal information. A common example is a fake package delivery notification. |
| Vishing | Voice (Phone Call) | Short for "voice phishing." An attacker calls you and pretends to be from a trusted institution, like your bank or the government, to trick you into revealing sensitive data. |
Another growing area for phishing is social media. This is known as angler phishing.
Angler phishing happens when attackers use fake social media accounts to impersonate the customer service accounts of real companies.
They monitor social media for users who post complaints or questions to a company. The attacker then swoops in with a reply from their fake account, offering to help. They'll try to move the conversation to a private channel and ask for your account details or other personal information to "resolve" your issue. Because the interaction starts with you reaching out for help, it can feel more legitimate, making it a particularly sneaky tactic.
What is the primary goal of a phishing attack?
An attacker researches a company's finance department, then sends a targeted email to a specific employee posing as the CFO and requesting an urgent wire transfer. What type of attack is this?