Phishing
Phishing is an online scam in which attackers send fraudulent emails, text messages, or web pages that appear to come from a trusted source in order to trick people into revealing sensitive information. This information can include passwords, account numbers, credit card numbers, or Social Security numbers. The goal is typically to steal money or a person's identity.
Phishing is a social-engineering technique that attempts to acquire sensitive data, such as usernames, passwords, bank account numbers, or payment card numbers, through fraudulent solicitation delivered via email, text message, or a spoofed web site that impersonates a well-known or trusted entity. In a payment context, phishing may target authentication credentials and cardholder data, though the specific data sought depends on the attacker's objective. Phishing is one vector among several used to enable downstream fraud such as account takeover or identity theft; it exploits human trust rather than a technical vulnerability alone, and no single control fully eliminates it.
Why it matters
Phishing matters because it targets people rather than technology, exploiting human trust to acquire credentials and sensitive data that attackers can then use to commit fraud. In a payment context, a successful phishing attack may yield authentication credentials, account numbers, or cardholder data, which can feed downstream activity such as account takeover or identity theft. Because the attack exploits human decision-making rather than a specific technical vulnerability, controls that harden systems do not, on their own, eliminate the risk.
Phishing is one vector among several, and it is often an early step in a longer chain of fraud rather than the fraud itself. The data an attacker seeks depends on their objective: some campaigns pursue login credentials for accounts, while others target payment card numbers or personal identifiers. This variability means that defenders should treat phishing as an enabling technique that can precede multiple distinct fraud outcomes, and should assess exposure across the specific data types their environment handles.
No single control fully eliminates phishing, and detection approaches carry trade-offs between false positives, which can block legitimate messages, and false negatives, which let fraudulent messages through. Effective mitigation typically combines user awareness, technical filtering, and authentication measures, while recognizing that determined attackers adapt their lures over time.
Who it's relevant to
Inside Phishing
Common questions
Answers to the questions practitioners most commonly ask about Phishing.