Phishing
A B C D E F G H I K L M N O P Q R S T U V W Z

What Is Phishing?

Phishing is a cyberattack method in which criminals impersonate trusted entities through fraudulent communications, most commonly email, to deceive recipients into disclosing sensitive information such as login credentials, financial data, or personal details, or into taking actions that compromise security such as clicking malicious links or downloading weaponized attachments. Phishing is consistently the most common initial access vector in cyberattacks and the leading cause of data breaches globally.
Despite significant investment in technical security controls, phishing persists because it targets human judgment rather than technical vulnerabilities. Even sophisticated security practitioners can be deceived by well-crafted phishing messages that accurately mimic legitimate communication in context, format, and timing.

Types of Phishing Attacks

Mass Phishing

Broad-scale campaigns that send identical or near-identical fraudulent messages to large recipient lists without specific targeting. Mass phishing relies on volume: even a very low success rate across millions of emails produces a significant number of compromised accounts or delivered malware infections.

Spear Phishing

Targeted attacks directed at specific individuals or organizations, personalized with researched details that make the message appear credible and relevant to the recipient. Spear phishing requires more preparation but achieves dramatically higher success rates than mass campaigns.

Whaling

Spear phishing specifically targeting senior executives and high-value individuals such as CFOs, CEOs, and board members, whose authority and access make their compromise particularly valuable to attackers.

Vishing and Smishing

Phishing conducted by voice call (vishing) or SMS text message (smishing) rather than email. These channels are increasingly exploited because users often apply less scrutiny to phone and text interactions than to email.

Technical and Human Defenses Against Phishing

Technical controls form the first line of defense: email authentication protocols (SPF, DKIM, DMARC) reduce spoofing; anti-phishing filters scan links and attachments; multi-factor authentication limits the impact of compromised credentials even when phishing succeeds.
Human defenses are equally critical. Regular security awareness training simulated phishing exercises that build recognition skills without the consequences of a real incident, and a reporting culture where employees feel comfortable flagging suspicious messages without fear of blame close the gaps that technical controls cannot fully address.

The Business Impact of Successful Phishing Attacks

Phishing is the entry point for some of the costliest cybersecurity incidents: ransomware deployments, business email compromise fraud, data breaches, and account takeovers. The financial impact extends beyond direct losses to regulatory fines, legal costs, operational disruption, reputational damage, and the significant cost of incident response and system recovery.

Key Takeaways

Scroll to Top