← Reference · Home · Print this page
Cybersecurity · Awareness
Phishing
Reference entry · last updated 20261006
Phishing uses deceptive messages to persuade a person to reveal sensitive information, open a harmful link, download malicious software, or send money. Messages often impersonate a trusted source.[1][2]
First principles and definitions
NIST describes requests to log in, download files, transfer funds, and submit sensitive information as reasons to pause and verify.[1]
A familiar logo can appear in a fraudulent message. FTC guidance shows an example that copies company branding to support a false billing story.[3]
Channels and targeting
- Email phishing sends the request by email.
- Smishing uses text messages.
- Vishing uses voice calls.
- Spear phishing targets a specific person; whaling targets a senior leader.
NIST describes these channel and targeting distinctions.[4] Its small-business guidance also includes social-media messages.[1]
Targeted messages can use publicly available company or employee details to appear convincing.[2]
Illustrative message
Illustrative example: a message claims that a bank account will be suspended today unless the recipient signs in through an attached link. It copies the bank's name and adds an urgent deadline. This is a hypothetical example, not a report of a specific campaign.
The proposed safe response is to open the bank's known app or contact its established support channel. The message's link and phone number are excluded from that verification.
Verify requests independently
NIST recommends verifying urgent requests through known contact details or a public company website, rather than details supplied in the message. FTC guidance gives the same independent-contact advice.[1][3]
Illustrative review sequence:
- Pause the requested action. Note what information, payment, or download is being requested.
- Open a known app or a saved official address. For a colleague, use an established contact method.
- Confirm the specific request through that channel, including any changed payment details.
- Report an unresolved suspicious request through the organisation's reporting process.
No training can teach everyone to spot every phishing attempt. NCSC guidance recommends layered technical, process, and people controls and prompt reporting without punishment for mistakes.[2]
After a click or disclosure
- Report the suspected incident promptly to the responsible IT or security contact and follow the incident plan.[1]
- If credentials were shared, change affected passwords through the genuine service. Change reused passwords on other accounts.[1]
- If a financial account was affected, contact the bank promptly through a known channel and monitor transactions.[1]
- If a link or attachment may have installed malware, FTC guidance recommends updating security software and running a scan.[3]
Illustrative incident record: keep the message, time, requested action, and what was clicked or shared for the responder. Avoid forwarding suspicious attachments to uninvolved colleagues.
Layered protection
Email filtering, maintained security software, and multi-factor authentication (MFA) support phishing defence.[1] MFA requires more than one authentication factor.[3] Phishing-resistant methods bind authentication to the legitimate service; NIST describes FIDO authenticators and security keys as examples.[4]
Phishing-resistant authentication addresses stolen authentication secrets. It does not prevent every phishing outcome, such as malware installation or disclosure of other personal information.[4]
The FTC recommends reporting a suspected phishing message before deleting it.[3]
See also
References
- NIST, Phishing, Small Business Cybersecurity Corner, updated 20250819.
- National Cyber Security Centre, Phishing attacks: defending your organisation, targeting, layered mitigation, and reporting guidance.
- Federal Trade Commission, How To Recognize and Avoid Phishing Scams, recognition, independent contact, response, and reporting sections.
- Andrew Regenscheid and Ryan Galluzzo, NIST, Phishing Resistance: Protecting the Keys to Your Kingdom, 20230201.