Glossary
What is phishing?
Phishing is a social engineering attack in which someone sends a fraudulent message, usually by email but also by SMS, chat or phone, pretending to be a trusted person or organisation.
- Also known as
- Email phishing, phishing scam
- Channel
- Mostly email; also SMS, chat apps and voice
- Typical goal
- Credentials, malware installation or payment
- Related term
- Spear-phishing
How it works
A familiar face,
a small request.
- 01
Impersonate
The attacker copies a sender people trust: a bank, a supplier, IT, HR or a delivery service.
- 02
Deliver
The message lands in an inbox or phone with a plausible reason to act: a locked account, an invoice, a parcel.
- 03
Pressure
A deadline, penalty or reward pushes the reader to act before checking.
- 04
Collect
A link leads to a fake login page, an attachment carries malware, or a reply sends money or data to the attacker.
Simulated examples
Two everyday
phishing lures.
Tax refund desk <refunds@gst-return.example>
GST refund approved
Your refund is ready. Confirm your business bank details to receive it today.
Confirm details- Unexpected good news
- Asks for bank details
- Sender domain doesn’t match any official portal
Questions buyers ask
Frequently asked questions.
What is the main goal of phishing?
Most phishing aims to steal login credentials, install malware or trick someone into sending money or data. The message is just the delivery method.
What should I do if I clicked a phishing link?
Tell your security team straight away through your organisation’s reporting process. If you entered a password, change it from a trusted device and follow your team’s guidance.
How do I report a phishing email?
Use your organisation’s report button or reporting process, or forward it to your security team. Don’t reply to the sender or click anything in the message.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo