Security Term

Phishing

A social engineering attack that uses deceptive emails, messages, or websites to trick users into revealing credentials or installing malware.

What is Phishing?

Phishing is the most common initial access vector in data breaches. Attackers impersonate trusted entities — banks, IT departments, or cloud providers. Variants include spear phishing (targeted), vishing (voice), and smishing (SMS). Employee awareness training and email filtering are primary defenses.

Understanding this concept is crucial for maintaining a robust security posture. In the context of modern cyber threats, phishing represents a significant area of focus for security professionals and organizations alike.