Phishing is a form of social engineering and fraudulent deception designed to trick individuals into handing over sensitive information, such as login credentials and financial details, or downloading malicious software. Attackers commonly use phishing to steal user credentials, hijack user sessions, deliver malware, or execute unauthorized commands. It remains a widely used method for cybercriminals to gain initial unauthorized access to digital systems.
Phishing attacks are executed through several channels and methodologies:
- Email Phishing: Deceptive messages delivered via email, ranging from broad scam distribution to highly targeted campaigns such as spear phishing or whaling.
- Voice Phishing (Vishing): Attacks carried out over phone calls, frequently utilizing Voice over IP (VoIP) features like caller ID spoofing and interactive voice response systems to impersonate trusted organizations.
- SMS Phishing (Smishing): Phishing attempts delivered via text messaging.
- Adversary-in-the-Middle and QR Code Attacks: Technical variations that transparently relay authentication to legitimate websites or leverage scannable codes to intercept user data.
Personalized phishing efforts can be augmented using compromised personal details obtained through third-party data breaches, as well as modern tools like large language models. Defensive measures against phishing include technical security controls, public awareness campaigns, regulatory legislation, and organizational user education, including simulated phishing tests to evaluate and improve user responses.