Phishing
Also known as: Phishing attack
Phishing refers to fraudulent messages that impersonate a trusted sender to trick someone into revealing credentials or installing malware.
Phishing refers to messages, usually email, that impersonate a trusted source – a bank, a colleague, a supplier – to get the recipient to hand over login credentials, click a malicious link, or open an attachment. The goal is almost always account access or getting malware onto a device.
In practice this ranges from mass-sent messages, often recognizable by poor language or a mismatched sender address, to targeted attacks tailored to a specific person that draw on real details from their work environment – such as a fake invoice that appears to come from a known supplier. These targeted messages are called spear phishing.
A common misconception is that phishing is always recognizable by obvious mistakes. Well-crafted, targeted messages contain no spelling errors and no obviously wrong address, and often can't be told apart from a genuine message by content alone – what usually gives it away is the unusual request itself, such as an urgent payment.
What it means in practice
For a business, phishing is the most common starting point for stolen credentials and malware infections, because it targets people rather than technology. A sign that a business is vulnerable is staff routinely opening attachments and links without checking the sender or context. NDVDL combines technical filtering with security awareness training, because technology alone doesn't reliably stop phishing.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.