Skip to main content
Book 07 · SecurityPage 27 of 50

Phishing

Pronunciation
FISH-ing
Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/phishing

In short

Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.

What is phishing?

Phishing is a form of social engineering, meaning it targets people rather than software bugs. The attacker sends a message that appears to come from someone trustworthy, such as a bank, a delivery company, a colleague, or the IT department, and tries to get the victim to click a link, open an attachment, enter login details on a fake page, or send money. The name is a play on fishing: the attacker casts bait and waits for someone to bite.

Phishing comes in several forms. Mass phishing sends the same message to millions of people, spear phishing targets a specific person using details about their job or life, and business email compromise impersonates executives or suppliers to request urgent payments. The same tricks appear in text messages (smishing), phone calls (vishing), QR codes, and chat apps, and modern attacks may use AI-generated text or voices and fake sites that capture both a password and a one-time code in real time.

Common warning signs include urgency or threats, such as 'your account will be closed today', a sender address or link domain that is slightly off, requests for passwords or codes that a real service would never ask for, and unexpected attachments. Defenses work in layers: training people to pause and verify requests through a separate channel, email authentication standards (SPF, DKIM, and DMARC) that make sender spoofing harder, link and attachment filtering, and phishing-resistant multi-factor authentication such as passkeys or hardware security keys, which don't work on a fake site.

Phishing is often confused with spam and with malware. Spam is any unwanted bulk message, while phishing is specifically designed to deceive you into handing something over, and malware is harmful software that a phishing message may deliver. For developers, phishing matters because stolen credentials are one of the most common ways attackers break into systems, so MFA and least-privilege access limit the damage when someone is fooled.

Key takeaways

  • Phishing tricks people into revealing credentials, codes, or money by impersonating someone trusted.
  • It arrives by email, text message, phone call, QR code, and chat apps.
  • Spear phishing targets specific people with personalized messages.
  • Urgency, mismatched links, and requests for passwords are common warning signs.
  • Phishing-resistant MFA, such as passkeys or security keys, doesn't work on fake sites.

Example

Checking a domain's email authentication recordsbash
# SPF, DKIM, and DMARC records help mail servers reject spoofed senders

# SPF: which servers are allowed to send mail for the domain
dig +short TXT example.com
# "v=spf1 include:_spf.mail.example.net -all"

# DMARC: what receivers should do with mail that fails the checks
dig +short TXT _dmarc.example.com
# "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"

# DKIM: the public key used to verify message signatures (selector "s1")
dig +short TXT s1._domainkey.example.com

Readers ask

What should I do if I clicked a phishing link?

Close the page without entering anything else. If you typed a password, change it right away on the real site and anywhere else you reused it, turn on multi-factor authentication, and report the incident to your IT or security team.

What is the difference between phishing and spear phishing?

Regular phishing sends the same generic message to many people and hopes some of them fall for it. Spear phishing is aimed at a specific person or organization and uses personal details, such as colleagues' names or current projects, to make the message more convincing.

Does multi-factor authentication stop phishing?

It helps a lot, but not every method is equally strong. One-time codes from SMS or an authenticator app can still be captured by a real-time fake site, while passkeys and hardware security keys are tied to the real website's domain and won't work on an impostor.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings