Glossary

What is phishing?

Phishing is a social engineering attack in which someone sends a fraudulent message, usually by email but also by SMS, chat or phone, pretending to be a trusted person or organisation.

Also known as
Email phishing, phishing scam
Channel
Mostly email; also SMS, chat apps and voice
Typical goal
Credentials, malware installation or payment
Related term
Spear-phishing

How it works

A familiar face,
a small request.

  1. 01

    Impersonate

    The attacker copies a sender people trust: a bank, a supplier, IT, HR or a delivery service.

  2. 02

    Deliver

    The message lands in an inbox or phone with a plausible reason to act: a locked account, an invoice, a parcel.

  3. 03

    Pressure

    A deadline, penalty or reward pushes the reader to act before checking.

  4. 04

    Collect

    A link leads to a fake login page, an attachment carries malware, or a reply sends money or data to the attacker.

Simulated examples

Two everyday
phishing lures.

Questions buyers ask

Frequently asked questions.

What is the main goal of phishing?

Most phishing aims to steal login credentials, install malware or trick someone into sending money or data. The message is just the delivery method.

What should I do if I clicked a phishing link?

Tell your security team straight away through your organisation’s reporting process. If you entered a password, change it from a trusted device and follow your team’s guidance.

How do I report a phishing email?

Use your organisation’s report button or reporting process, or forward it to your security team. Don’t reply to the sender or click anything in the message.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo