Definition
Phishing is a cyber attack method where attackers send fraudulent communications, often via email, to trick recipients into revealing sensitive information or installing malware. These messages typically appear to come from reputable sources.How It Works
- 1The attacker crafts a convincing email or message that mimics a trusted source.
- 2The message prompts the target to click a link or download an attachment.
- 3The link directs to a fake website or initiates a malware download.
- 4The target enters credentials or personal information, which the attacker collects.
Key Characteristics
- Deceptive appearances: Emails or messages seem to be from trusted sources.
- Urgency or alarm: Messages often create a sense of urgency, like threats of account closure.
- Generic greetings: Use of non-specific salutations such as "Dear Customer."
Comparison
| Type | Medium | Target Specificity | Example |
|---|---|---|---|
| Phishing | General | Fake bank emails | |
| Spear Phishing | Specific individuals | CEO-targeted scams | |
| Whaling | High-level targets | Executive scams | |
| Clone Phishing | Cloned previous email | Replicated alerts | |
| Smishing | SMS | General | Fake lottery texts |
| Vishing | Voice | General or specific | Fake tech support |
Real-World Example
The 2016 Podesta email hack involved spear phishing where a fake Google login page was used to harvest credentials. Another example is the Google Docs phishing worm, which used a fake app to gain account access.Detection & Prevention
- Use email filtering tools like Barracuda and Proofpoint.
- Verify URLs before clicking links—hover over links to check authenticity.
- Implement multi-factor authentication to protect accounts.
- Educate users about identifying phishing attempts.
Common Misconceptions
- 1Phishing only targets individuals: Organizations are also frequent targets.
- 2Phishing is always obvious: Attacks can be sophisticated and hard to spot.
- 3Antivirus software alone can prevent phishing: It requires a combination of tools and awareness.