What is phishing?
Phishing is a scam that impersonates someone you trust to get passwords, money or access. The main kinds, and why it keeps working.
Phishing is a scam in which a criminal pretends to be a person or organisation you trust, so that you will hand over something of value. That might be a password, bank or card details, a payment, or access to an account.
Email is the best-known route. The same trick is played by text message, phone call, social media and messaging apps.
The main kinds
- Bulk phishing goes to millions of inboxes at once, with no particular victim in mind.
- Spear phishing is aimed at one business or one person. The attacker uses real details about your staff or company to make the message more convincing.
- Text message phishing uses SMS, often posing as a bank, a delivery or utility company, or a government service.
- Voice phishing, or vishing, is done by phone. Callers can fake the caller ID and may use voice cloning to sound like someone you know.
- QR code phishing, or quishing, hides the harmful link in a QR code, where you cannot read it before you scan.
- Business email compromise goes after a payment. A supplier’s real mailbox is broken into and the bank details on a genuine invoice are changed, or someone poses as a senior person and asks for an invoice to be paid.
Why it works
A phishing message goes around your security by asking a person to open the door. The Australian Signals Directorate (ASD) points to a few reasons that people do.
- It looks real. Messages carry official logos and wording. In business email compromise they can come from a genuine account that has been taken over.
- It creates urgency. Pressure to act now leaves no time to check.
- It borrows trust. The sender claims to be your bank, your manager or a supplier you already deal with.
- It can be hard to verify. Caller IDs and voices can be faked, and a familiar voice makes people more likely to believe the caller.
What it leads to
A stolen password lets the attacker sign in as you, read your email and send scams to your contacts from your address. A link or attachment can install malware, ransomware included. A changed bank detail sends a real payment to the criminal’s account.
Do not rely on staff alone
The UK’s National Cyber Security Centre warns that defences often lean too heavily on people spotting fake emails. Training helps, and it should be one layer among several.
- Turn on multi-factor authentication, so that a stolen password is not enough to sign in.
- Set up email authentication, so that other people cannot send email that appears to come from your domain. SPF, DKIM and DMARC, explained without the jargon covers how.
- Agree one way to verify any payment or change of bank details, such as calling a number you already hold.
- Make reporting easy, and thank the person who reports a click.
The warning signs in a single message are in How to spot a phishing email. To see whether your own domain can be impersonated, run the free email domain check.
Sources
- Phishing (Australian Signals Directorate) cyber.gov.au
- Protecting against business email compromise (Australian Signals Directorate) cyber.gov.au
- Phishing attacks: defending your organisation (UK National Cyber Security Centre) ncsc.gov.uk
- Phishing: glossary definition (NIST Computer Security Resource Center) csrc.nist.gov