Typical signs include an unusual sender address, spelling mistakes, generic greetings, and artificial urgency. Check links by hovering over them before clicking, and never open unexpected attachments.
Phishing: Definition & explanation
In a nutshell
Phishing is a fraud technique where attackers use fake emails, texts, or websites to steal sensitive data like passwords or credit card details. Messages impersonate trusted senders such as banks or online services.
How does Phishing work?
Phishing works on a simple principle: attackers send messages that appear to come from a trusted source – a bank, a delivery service, or a known online shop. The message usually includes an urgent call to action, such as confirming account details or clicking a link due to alleged suspicious activity. The link leads to a fake website that closely mimics the original. If the victim enters credentials there, they go straight to the attackers. Alternatively, phishing emails carry malicious attachments that install malware when opened. Modern variants also use SMS (smishing), calls (vishing), or social media messages. Spear phishing is particularly dangerous: attackers research a specific target to make the message more personal and convincing. Warning signs include spelling errors, unusual sender addresses, generic greetings, or artificial time pressure. Protective measures include two-factor authentication, passkeys instead of passwords, and general skepticism toward unexpected links and attachments. A VPN doesn't directly prevent phishing but stops data interception on unsecured networks.
Advantages of Phishing
- Recognizable through typical warning signs
- Awareness training significantly reduces success rate
- 2FA prevents account takeover despite stolen data
- Passkeys make classic phishing ineffective
- Spam filters block many attempts automatically
Disadvantages of Phishing
- Can lead to identity theft
- Financial losses from stolen credentials
- Increasingly sophisticated, AI-generated forgeries
- Even experienced users can be fooled
- Companies suffer reputational and data damage
Frequently asked questions
Change the affected password immediately and enable two-factor authentication if you haven't already. Also inform the relevant bank or service and monitor your account for suspicious activity.
A VPN encrypts your internet connection but doesn't stop you from clicking a fake link or entering data into a fraudulent form. It only protects against data interception on unsecured networks, not the deception itself.
Guides with Phishing
No linked guides for this term yet.