What is Phishing?

Also known as: phishing attack, phishing email

Phishing is fraud in which an attacker impersonates a trusted organisation or person in an email, message or link to get the victim to hand over a password or card details, or to open a malicious file. It is the most common starting point of cyberattacks on organisations.

Phishing exploits trust, fear and urgency rather than technology, which is why antivirus and mail filters never stop all of it: the email that gets past the filter has to be caught by a person. According to Verizon's 2024 Data Breach Investigations Report (DBIR), 68% of breaches involved a human element.

How to spot it

  • Urgency or threats: "your account will be locked in 24 hours"
  • A sender address that is almost, but not quite, the real one
  • A link that goes to a different domain than the text says
  • An unexpected attachment, or a request for a password or code

What to do

  • Don't click: open the site yourself by typing the address
  • Report the suspicious email to IT or the security team
  • If you already entered a password, change it now and tell IT

Related courses

Terms on this topic

More topics

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.