Phishing – How to Recognize and Report Phishing
Cybercriminals phish to steal passwords, personal information or money. Learn what to recognize and how to report phishing to protect your organization from costly attacks.
Phishing occurs when a malicious actor poses as a trusted source in an email, text or phone message in an attempt to gather sensitive information from their targets. Typically, attackers will lure victims into revealing their usernames or passwords, credit card data or downloading malware by pretending to be legitimate organizations that they trust. Attackers can deliver phishing attacks via any number of delivery mechanisms including email, text messages (also known as smishing), voice calls (also known as vishing) or even social media sites in the form of malicious ads.
Advanced Sophistication
Thanks to years of cyber breaches, criminals have a vast amount of stolen information that they feed into artificial intelligence systems that can craft highly personalized and hard-to-identify phishing scams. These automated attacks also make use of domain spoofing, which further conceals the origin of fraudulent emails.
Recognize Urgency & Pressure Tactics
Sophisticated attackers use the language of trust to gain your attention and persuade you to act quickly, often with fake messages that threaten account closure or legal action within unrealistic timeframes. They may also include urgent requests to click on links that take you to phony websites designed to capture your login credentials or other sensitive information and, in some cases, install malware on your device. Attackers also often rely on emotional appeals to tug at your heartstrings, with messages claiming to be your loved ones in need of help.