What is Phishing and How Does it Affect Your Organization?
Phishing is a cyberattack that occurs when attackers masquerade as trustworthy entities in email, SMS (text message) and phone calls or on websites, urging recipients to click links or provide credentials. This enables the bad actors to harvest sensitive information and conduct a number of malicious activities, including identity theft and data breaches.
A successful phishing attack may result in stolen money, fraudulent charges on credit cards or loss of access to photos, videos and files. The impact to an organization can be more severe, as attacks often target employees who have a role in critical business functions like sales, finance and IT.
Using social engineering tactics to infiltrate targets, threat actors rely on their victims’ emotions to lower their guard and take an unsafe action such as clicking on a link or entering login credentials. Attackers use a variety of tactics, such as an unfamiliar greeting or lack of grammar and spelling errors, a sense of urgency and suspicious attachments to lure unsuspecting victims into their trap.
To increase their chances of success, attackers target brands that have high visibility or are recognizable by their victims, such as well-known banks, online retailers and makers of popular apps. This is known as brand phishing. Some phishers even go so far as to create fake text messages claiming to be from their wireless provider or the US Postal Service, targeting their targets’ phones to gain valuable personal information.
Other types of phishing include credential phishing, where bad actors trick their victims by posing as legitimate entities through emails and fake login pages to steal login credentials. Spear phishing, on the other hand, involves an attacker infiltrating the internal network of an organization by compromising low-level employees’ email accounts to gain access to critical information.