What is Phishing?
Phishing is an email or Internet message that tries to trick recipients into giving up personal information. Cybercriminals use it to gain account numbers, passwords and credit card details. They then use this info to steal money from their victims’ checking accounts or run up bills on their credit cards in their victim’s names.
The origin of the term is not clear, but phishing’s name may be derived from its use of bait to lure unsuspecting victims into a trap. Often, phishing messages look authentic. They might include a real company logo and a padlock icon that appears to denote a secure site. They might even include an email address that closely resembles a colleague’s or a phone number from a known organization.
Typically, phishing messages ask users to click on links, call or open attachments that contain malware or other malicious software. In some cases, the malware will infect a user’s computer or a company network.
Cybercriminals can also use phishing to gain access to confidential information that companies keep on their computers or servers. For example, they might impersonate a manager or CEO and demand a fraudulent transfer of funds to a fake bank account.
Employees can help reduce the risk of phishing attacks by being aware of common phishing tricks. For example, emails claiming to offer too-good-to-be-true prizes like cash or luxury items are red flags, as are messages with false senses of urgency (like “Your account will expire if you don’t act now”). Companies can also set policies that prevent employees from sending monetary transfers over email and make sure they always verify requests for sensitive info over the phone or in person.