Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is Phishing?

DefinitionPhishing is a scam in which the attacker impersonates a trusted person or organization, by email, message, phone call or fake website, to trick the victim into handing over credentials, data or payments, or into running a malicious file.

Common types

  • Mass phishing: generic messages, such as fake account suspension notices, sent to thousands of people.
  • Spear phishing: a message aimed at a specific person or team, built with public information about the target.
  • Whaling and BEC: scams targeting executives, or impersonating executives and suppliers, to divert payments.
  • Smishing and vishing: variants via SMS or messaging apps and via phone calls.
  • Quishing: QR codes that lead to fake pages and evade some email filters.

Why it still works

Phishing attacks a person's decision, not a technical flaw. With generative AI, messages arrive free of language errors and with convincing context. What still gives the scam away is the request: urgency, an exception to the process and secrecy. Almost every successful phishing attack ends in a credential, a session token or an MFA approval, which opens the way to fraud, data leaks or ransomware.

How to protect yourself

  • Phishing-resistant MFA, such as passkeys and FIDO2 security keys, on the most critical accounts.
  • Recurring training with realistic simulations and a simple channel to report suspicious messages.
  • Confirmation through a second channel for payments and changes to bank details.
  • Monitoring for signs of account compromise, such as unusual logins, repeated MFA approvals and forwarding rules created in the mailbox.

Network Secure operates a 24×7 SOC certified to ISO/IEC 27001:2022.

Frequently asked questions

What is the difference between phishing and social engineering?

Social engineering is the set of manipulation techniques used to get someone to act against their own security. Phishing is one of those techniques, carried out through messages, websites or calls that imitate a trusted source.

What should I do if I clicked a phishing link?

Report it to the security team immediately. If you entered your password, change it, revoke active sessions and review the account's MFA; the sooner you act, the smaller the attacker's window.

Go deeper