EN - FR - DE - ES - IT - PT -

LexiconDream

🎣 Phishing

A fraudulent attempt to obtain sensitive data by posing as a trusted entity.

Phishing

Phishing tricks people into handing over credentials, money, or access. The attacker poses as a trusted entity: a bank, a colleague, a software vendor, a government agency. The message creates urgency. Your account will be closed. A payment is overdue. A package could not be delivered. Click the link, enter your password, and the attacker has what they need.

Phishing is the most common initial access vector in breaches. It works because it targets people, not systems. Technical controls help. Email filters catch known phishing domains. DMARC and SPF make spoofing harder. Link scanners check URLs before users click. But filters miss things. A well-crafted phishing email from a compromised legitimate account passes every check. Training helps too, though it is not a cure. People click when they are busy, distracted, or scared. The best defense combines filtering, training, and MFA. If a password is stolen, MFA stops the login. If MFA is bypassed through a proxy, behavioral detection catches the anomaly. No single layer is enough.

Common phishing lures

Report phishing emails instead of deleting them. The security team needs to know what is getting through.

Comments

No comments yet. Be the first to share a thought.

Leave a comment