Overview
Direct Answer
Phishing is a targeted social engineering attack wherein adversaries send fraudulent communications—typically emails, SMS, or messaging platforms—impersonating trusted entities to deceive recipients into divulging sensitive credentials, financial information, or system access. The attack exploits human psychology and trust rather than technical vulnerabilities.
How It Works
An attacker crafts a message that mimics legitimate correspondence from a bank, employer, or service provider, often including authentic-looking branding, urgency cues, or threats to lower victim vigilance. Recipients are directed to malicious links or attachments that either harvest credentials through fake login forms or deploy malware. Success depends on psychological manipulation and the difficulty recipients face in distinguishing fraudulent from genuine communications.
Why It Matters
Phishing remains the initial attack vector for a significant proportion of enterprise data breaches and ransomware infections, making it a critical vector for risk management and compliance programmes. Organisations face operational disruption, regulatory penalties, and reputational damage; individuals risk identity theft and financial loss. Employee awareness and detection mechanisms are essential to reducing organisational exposure.
Common Applications
Phishing attacks target financial services (credential harvesting), healthcare systems (patient data theft), government agencies, and corporate environments (business email compromise). Variants include spear-phishing directed at specific individuals and whaling targeting senior executives. Attackers also exploit third-party supply chains to gain initial footholds.
Key Considerations
Sophisticated phishing campaigns increasingly use legitimate infrastructure, stolen certificates, and domain lookalikes that evade technical controls. User training and authentication mechanisms such as multi-factor authentication reduce but do not eliminate risk; successful defence requires layered detection and incident response capabilities.
Referenced By2 terms mention Phishing
Other entries in the wiki whose definition references Phishing — useful for understanding how this concept connects across Cybersecurity and adjacent domains.
More in Cybersecurity
Cyber Insurance
Security GovernanceInsurance coverage protecting organisations against financial losses from cyberattacks, data breaches, and related incidents.
Software Supply Chain Security
Security GovernancePractices and tools that protect the integrity of software components, dependencies, build pipelines, and distribution channels from compromise and tampering.
Phishing-Resistant Authentication
Identity & AccessAuthentication methods such as FIDO2 passkeys and hardware security keys that are immune to phishing attacks because credentials are cryptographically bound to the legitimate service.
MITRE ATT&CK
Offensive SecurityA globally accessible knowledge base of adversary tactics and techniques based on real-world cyber observations.
Multi-Factor Authentication
Identity & AccessAn authentication method requiring two or more verification factors to gain access to a resource.
Threat Modelling
Security GovernanceA structured approach for identifying, quantifying, and addressing security threats to a system or application.
Security Orchestration, Automation and Response
Defensive SecurityA technology stack that integrates security tools and automates incident response workflows, enabling faster triage, investigation, and remediation of security alerts.
AI-Powered Threat Detection
Offensive SecuritySecurity systems that leverage machine learning and behavioural analytics to identify sophisticated cyber threats, anomalous patterns, and zero-day attacks in real time.