Phishing
Phishing is a message built to look like it came from someone you trust, so that you hand over a password, a code or a payment.
Also known as email scam fake email credential theft
Definition
Phishing is a message built to look like it came from someone you trust, such as a bank, a supplier, a colleague or a delivery company. It asks for one small thing, and that is exactly why it works. Sign in here, approve this, confirm the code we just sent, pay this invoice today, and each request feels too small to argue with. The message is the whole attack, so nothing on your computer is broken and there is nothing to repair.
That is why antivirus and firewalls rarely stop it, because phishing aims at the person, not the software. The convincing ones copy a real logo, a real sender name and a real reason to hurry. The worst arrive as a reply inside a thread you were already in, because the attacker read it first from a mailbox they had taken. So everything above the last few lines is genuine, and that is the part people miss.
The expensive attack is rarely a stolen password but an invoice, and it works because everything about the email fits. A supplier writes that their bank details have changed, so please pay the new account from now on. The logo is right, the amount is one you expected, the tone is theirs, and the money goes out on Thursday. Nobody notices for a month, banks recover very little by then, and that is why Linkysoft asks to see how a company approves payments first.
The defence that works is boring, and few companies bother with it. Never check a request using the contact details inside it, because a fake email carries a fake number as easily as a fake logo. Call the supplier on the number you had before the message arrived, and treat any change of bank details as something two people approve, not one. A password manager helps quietly, because it reads the page's real address and will not type your password into a lookalike domain while your eyes are on the logo.
Software can also take the decision out of the inbox. When a payment change must be approved on a screen in the company's own web application, or with a tap in the staff mobile app, the email has nowhere to land. Training still matters, but people are tired at four in the afternoon, so a defence that needs everyone alert will fail. That is why the cybersecurity work Linkysoft does usually starts by finding the three places where one person, alone, can move money or hand out access.
Questions about Phishing
How can I tell if an email is phishing?
I clicked and typed my password. What should I do now?
Does two-step login stop phishing?
Is phishing only an email problem?
How do I protect a small team without a big budget?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.