Phishing Basics
Phishing is a social engineering technique where an attacker tries to trick someone into doing something useful for the attacker.
That might include:
- clicking a malicious link
- opening an attachment
- entering a password into a fake login page
- sending money or sensitive data
- approving a login prompt
Why phishing works
Phishing often works because it abuses normal human behavior:
- urgency
- fear
- trust
- habit
- curiosity
- routine workplace processes
Simple example
An employee receives an email that looks like it came from Microsoft 365. It says their password will expire today and asks them to sign in.
The login page is fake. If the employee enters their password, the attacker may capture it.
Defensive habits
Useful habits include:
- slow down when a message creates urgency
- check the sender and link destination
- use MFA
- report suspicious messages
- avoid reusing passwords