Phishing
- Phishing is a type of cyber attack where attackers impersonate legitimate institutions, such as banks, government agencies, or well-known companies, in an attempt to trick users into revealing sensitive information like passwords, credit card numbers, or other personal data.
- Phishing attacks usually utilize legitimate-looking information to trick the victims into sending their sensitive information to the attacker.
Methodology
- Impersonation: The attacker creates a fake email, website, or message that closely resembles one from a trusted source, such as a bank or an online store.
- Urgency or Fear: The phishing message often includes a sense of urgency, such as threatening that your account will be locked, or asking you to verify your information immediately to prevent issues with your account.
- Tricking the Victim: Victims are asked to click on a link or open an attachment, leading them to a fake website designed to collect login credentials, financial details, or other sensitive information.
- Stealing Information: Once the victim enters their details into the fake site, the attacker collects the information and can use it for fraudulent activity, like unauthorized transactions, identity theft, or selling the data on the dark web.
Types of Phishing
- Email Phishing: The most common form, where attackers send fraudulent emails that appear to be from trusted entities.
- Spear Phishing: A more targeted form of phishing, where attackers tailor the message to a specific individual or organization, often using personal information to make it more convincing.
- Smishing
- Vishing