Phishing
- Pronunciation
- FISH-ing
In short
Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
What is phishing?
Phishing is a form of social engineering, meaning it targets people rather than software bugs. The attacker sends a message that appears to come from someone trustworthy, such as a bank, a delivery company, a colleague, or the IT department, and tries to get the victim to click a link, open an attachment, enter login details on a fake page, or send money. The name is a play on fishing: the attacker casts bait and waits for someone to bite.
Phishing comes in several forms. Mass phishing sends the same message to millions of people, spear phishing targets a specific person using details about their job or life, and business email compromise impersonates executives or suppliers to request urgent payments. The same tricks appear in text messages (smishing), phone calls (vishing), QR codes, and chat apps, and modern attacks may use AI-generated text or voices and fake sites that capture both a password and a one-time code in real time.
Common warning signs include urgency or threats, such as 'your account will be closed today', a sender address or link domain that is slightly off, requests for passwords or codes that a real service would never ask for, and unexpected attachments. Defenses work in layers: training people to pause and verify requests through a separate channel, email authentication standards (SPF, DKIM, and DMARC) that make sender spoofing harder, link and attachment filtering, and phishing-resistant multi-factor authentication such as passkeys or hardware security keys, which don't work on a fake site.
Phishing is often confused with spam and with malware. Spam is any unwanted bulk message, while phishing is specifically designed to deceive you into handing something over, and malware is harmful software that a phishing message may deliver. For developers, phishing matters because stolen credentials are one of the most common ways attackers break into systems, so MFA and least-privilege access limit the damage when someone is fooled.
Key takeaways
- Phishing tricks people into revealing credentials, codes, or money by impersonating someone trusted.
- It arrives by email, text message, phone call, QR code, and chat apps.
- Spear phishing targets specific people with personalized messages.
- Urgency, mismatched links, and requests for passwords are common warning signs.
- Phishing-resistant MFA, such as passkeys or security keys, doesn't work on fake sites.
Example
# SPF, DKIM, and DMARC records help mail servers reject spoofed senders
# SPF: which servers are allowed to send mail for the domain
dig +short TXT example.com
# "v=spf1 include:_spf.mail.example.net -all"
# DMARC: what receivers should do with mail that fails the checks
dig +short TXT _dmarc.example.com
# "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"
# DKIM: the public key used to verify message signatures (selector "s1")
dig +short TXT s1._domainkey.example.comReaders ask
What should I do if I clicked a phishing link?
Close the page without entering anything else. If you typed a password, change it right away on the real site and anywhere else you reused it, turn on multi-factor authentication, and report the incident to your IT or security team.
What is the difference between phishing and spear phishing?
Regular phishing sends the same generic message to many people and hopes some of them fall for it. Spear phishing is aimed at a specific person or organization and uses personal details, such as colleagues' names or current projects, to make the message more convincing.
Does multi-factor authentication stop phishing?
It helps a lot, but not every method is equally strong. One-time codes from SMS or an authenticator app can still be captured by a real-time fake site, while passkeys and hardware security keys are tied to the real website's domain and won't work on an impostor.
See also
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- DNSDevOps & Cloud, p. 16DNS is the internet's naming system that translates human-readable domain names like example.com into the numeric IP addresses computers use to connect.
- Social EngineeringSecurity, p. 39Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
- MalwareSecurity, p. 20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
Spotted a mistake or something missing on this page?Suggest an edit