What is Phishing?
Also known as: phishing attack, phishing email
Phishing is fraud in which an attacker impersonates a trusted organisation or person in an email, message or link to get the victim to hand over a password or card details, or to open a malicious file. It is the most common starting point of cyberattacks on organisations.
Phishing exploits trust, fear and urgency rather than technology, which is why antivirus and mail filters never stop all of it: the email that gets past the filter has to be caught by a person. According to Verizon's 2024 Data Breach Investigations Report (DBIR), 68% of breaches involved a human element.
How to spot it
- Urgency or threats: "your account will be locked in 24 hours"
- A sender address that is almost, but not quite, the real one
- A link that goes to a different domain than the text says
- An unexpected attachment, or a request for a password or code
What to do
- Don't click: open the site yourself by typing the address
- Report the suspicious email to IT or the security team
- If you already entered a password, change it now and tell IT
Related courses
- Identifying phishingThe phishing foundation course: how to spot a fake email, sender and link, and what to do when something looks off.
- Email threatsPhishing, dangerous attachments and financial fraud by email, with practical examples and an exercise.
- Link safetyHow to read a link before clicking, spot a spoofed domain and avoid landing on a phishing page.
- Fake login page detectorSimulation: practise telling real and fake login pages apart.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.