Phishing

Phishing is a message built to look like it came from someone you trust, so that you hand over a password, a code or a payment.

Also known as email scam fake email credential theft

Definition

Phishing is a message built to look like it came from someone you trust, such as a bank, a supplier, a colleague or a delivery company. It asks for one small thing, and that is exactly why it works. Sign in here, approve this, confirm the code we just sent, pay this invoice today, and each request feels too small to argue with. The message is the whole attack, so nothing on your computer is broken and there is nothing to repair.

That is why antivirus and firewalls rarely stop it, because phishing aims at the person, not the software. The convincing ones copy a real logo, a real sender name and a real reason to hurry. The worst arrive as a reply inside a thread you were already in, because the attacker read it first from a mailbox they had taken. So everything above the last few lines is genuine, and that is the part people miss.

The expensive attack is rarely a stolen password but an invoice, and it works because everything about the email fits. A supplier writes that their bank details have changed, so please pay the new account from now on. The logo is right, the amount is one you expected, the tone is theirs, and the money goes out on Thursday. Nobody notices for a month, banks recover very little by then, and that is why Linkysoft asks to see how a company approves payments first.

The defence that works is boring, and few companies bother with it. Never check a request using the contact details inside it, because a fake email carries a fake number as easily as a fake logo. Call the supplier on the number you had before the message arrived, and treat any change of bank details as something two people approve, not one. A password manager helps quietly, because it reads the page's real address and will not type your password into a lookalike domain while your eyes are on the logo.

Software can also take the decision out of the inbox. When a payment change must be approved on a screen in the company's own web application, or with a tap in the staff mobile app, the email has nowhere to land. Training still matters, but people are tired at four in the afternoon, so a defence that needs everyone alert will fail. That is why the cybersecurity work Linkysoft does usually starts by finding the three places where one person, alone, can move money or hand out access.

Questions about Phishing

How can I tell if an email is phishing?
Look at what it wants you to do, not at how it looks. If it pushes you to hurry, asks for a code or a password, or changes payment details, stop and call the sender on a number you already had.
I clicked and typed my password. What should I do now?
Change that password straight away, and change it anywhere else you used the same one. Then tell your bank or your IT contact, and check that no new rule is quietly forwarding your email somewhere else.
Does two-step login stop phishing?
It helps a great deal, but it is not a wall. Some attacks ask for the code as well and use it within seconds. A code you did not request is itself a warning that someone already has your password.
Is phishing only an email problem?
No. The same trick arrives by text message, on WhatsApp, in a phone call, or as a fake advert in search results. The channel changes; the request for a code, a password or a payment does not.
How do I protect a small team without a big budget?
Write one rule and repeat it: no bank details change without a phone call to a number you already knew. Turn on two-step login for email, and make it safe for staff to report a mistake without being blamed.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.