Phishing
Phishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
Phishing is the most common form of social engineering. The attacker sends a message — typically email — that impersonates a trusted entity and persuades the recipient to click a link, open an attachment, or enter credentials on a fake website.
How it works
A typical phishing attack involves three components:
- A convincing pretext. The message appears to come from a bank, employer, SaaS vendor, delivery service, or government agency. It creates urgency ("Your account will be locked in 24 hours") or curiosity ("You have a pending invoice").
- A payload. This is usually a link to a credential-harvesting page that mirrors a legitimate login screen, or an attachment containing malware. Some phishing messages ask the recipient to reply with information directly.
- Infrastructure. Attackers register lookalike domains, set up HTTPS certificates, and host cloned login pages that are visually indistinguishable from the real thing.
Mass phishing casts a wide net — the same message goes to thousands of recipients. More targeted variants include spear phishing (aimed at specific individuals) and whaling (aimed at executives).
How to defend against it
No single control stops all phishing. A layered defense includes:
- Email security gateways that filter known-bad senders, domains, and attachment types. These catch the bulk of commodity phishing but miss novel campaigns.
- Multi-factor authentication (MFA) so that stolen credentials alone are not enough to access systems. Be aware that attackers increasingly use MFA fatigue and adversary-in-the-middle proxies to bypass MFA.
- Regular phishing simulations that test employees with realistic lures and deliver immediate coaching when someone clicks. See our guide on phishing simulation best practices.
- A one-click reporting button so employees can flag suspicious messages instantly, feeding real-time intelligence to the SOC.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo