← Reference · Home · Print this page

Cybersecurity · Awareness

Phishing

Reference entry · last updated 20261006

Phishing uses deceptive messages to persuade a person to reveal sensitive information, open a harmful link, download malicious software, or send money. Messages often impersonate a trusted source.[1][2]

First principles and definitions

NIST describes requests to log in, download files, transfer funds, and submit sensitive information as reasons to pause and verify.[1]

A familiar logo can appear in a fraudulent message. FTC guidance shows an example that copies company branding to support a false billing story.[3]

Channels and targeting

NIST describes these channel and targeting distinctions.[4] Its small-business guidance also includes social-media messages.[1]

Targeted messages can use publicly available company or employee details to appear convincing.[2]

Illustrative message

Illustrative example: a message claims that a bank account will be suspended today unless the recipient signs in through an attached link. It copies the bank's name and adds an urgent deadline. This is a hypothetical example, not a report of a specific campaign.

The proposed safe response is to open the bank's known app or contact its established support channel. The message's link and phone number are excluded from that verification.

Verify requests independently

NIST recommends verifying urgent requests through known contact details or a public company website, rather than details supplied in the message. FTC guidance gives the same independent-contact advice.[1][3]

Illustrative review sequence:

  1. Pause the requested action. Note what information, payment, or download is being requested.
  2. Open a known app or a saved official address. For a colleague, use an established contact method.
  3. Confirm the specific request through that channel, including any changed payment details.
  4. Report an unresolved suspicious request through the organisation's reporting process.

No training can teach everyone to spot every phishing attempt. NCSC guidance recommends layered technical, process, and people controls and prompt reporting without punishment for mistakes.[2]

After a click or disclosure

Illustrative incident record: keep the message, time, requested action, and what was clicked or shared for the responder. Avoid forwarding suspicious attachments to uninvolved colleagues.

Layered protection

Email filtering, maintained security software, and multi-factor authentication (MFA) support phishing defence.[1] MFA requires more than one authentication factor.[3] Phishing-resistant methods bind authentication to the legitimate service; NIST describes FIDO authenticators and security keys as examples.[4]

Phishing-resistant authentication addresses stolen authentication secrets. It does not prevent every phishing outcome, such as malware installation or disclosure of other personal information.[4]

The FTC recommends reporting a suspected phishing message before deleting it.[3]

See also

References

  1. NIST, Phishing, Small Business Cybersecurity Corner, updated 20250819.
  2. National Cyber Security Centre, Phishing attacks: defending your organisation, targeting, layered mitigation, and reporting guidance.
  3. Federal Trade Commission, How To Recognize and Avoid Phishing Scams, recognition, independent contact, response, and reporting sections.
  4. Andrew Regenscheid and Ryan Galluzzo, NIST, Phishing Resistance: Protecting the Keys to Your Kingdom, 20230201.