Back to Glossary

Attack technique

Phishing

Impersonating a trusted person, organisation or service to induce disclosure of information or an unsafe action.

Related domain: CybersecurityConcept ID: concept-phishing

Definition

Phishing is a Social Engineering technique in which an attacker impersonates a trusted person, organisation or service to induce a victim to disclose sensitive information or perform a particular action.

Human Explanation

An attacker sends a message or creates a false website intended to persuade a user to provide information, approve a request or open a harmful link or attachment.

Why it Matters

Phishing remains a common route to unauthorised access because it targets both human decisions and the credentials or actions that systems trust.

Conceptual Boundary

Phishing is not limited to email. It may use text messages, instant messaging, social media, websites or telephone calls; Spear Phishing is its deliberately targeted form.

Practical Perspective

Effective protection combines technical filtering and strong Authentication with users who verify unusual requests through a trusted channel.

Related Concepts