File:Example_bank_phishing_email.svg · Wikimedia Commons · See Wikimedia Commons
phishing
Sign in to saveAlso known as phishing attack
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim navigates the site, and traverses any additional security boundaries with the victim. As of 2020, it is the most common type of cybercrime, with the Federal Bureau of Investigation's Internet Crime Complaint Center reporting more incident
Phishing is a scam where attackers trick people into revealing sensitive information or downloading harmful software by creating fake websites or messages that look legitimate. It matters because phishing has become the most common type of cybercrime, putting millions of people at risk of identity theft, financial loss, and malware infections.
AI-generated from the Wikipedia summary — may contain errors.
Wikidata facts
Show 1 more fact
- Commons category
- Phishing
via Wikidata · CC0
~31 min read
Article
32 sectionsContents
- Types
- Email phishing
- <span class="anchor" id="spearphishing"></span> Spear phishing
- Voice phishing (Vishing)
- SMS phishing (smishing)
- Page hijacking
- QR code phishing (quishing)
- Man-in-the-Middle phishing
- Techniques
- Link manipulation
- Social engineering
- History
- Early history
- 2000s
- 2010s
- 2020s
- Anti-phishing
- User training
- Technical approaches
- Filtering out phishing mail
- Browsers alerting users to fraudulent websites
- Augmenting password logins
- Monitoring and takedown
- Multi-factor authentication
- Legal responses
- Notable incidents
- Sector-specific impact
- Healthcare
- See also
- Notes
- References
- External links
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim navigates the site, and traverses any additional security boundaries with the victim. As of 2020, it is the most common type of cybercrime, with the Federal Bureau of Investigation's Internet Crime Complaint Center reporting more incidents of phishing than any other type of cybercrime.
Modern phishing campaigns increasingly target multi-factor authentication (MFA) systems, not just passwords. Attackers use spoofed login pages and real-time relay tools to capture both credentials and one-time passcodes. In some cases, phishing kits are designed to bypass two-factor authentication by immediately forwarding stolen credentials to the attacker's server, enabling instant access. A 2024 blog post by Microsoft Entra highlighted the rise of adversary-in-the-middle (AiTM) phishing attacks, which intercept session tokens and allow attackers to authenticate as the victim.
Gallery (15)
Available in 79 languages
- Español
- Français
- Deutsch
- 中文
- 日本語
- Русский
- Português
- Italiano
- العربية
- हिन्दी
- Albanian
- Armenian
- Azerbaijani
- Bahasa Indonesia
- Bangla
- Basque
- be_x_old
- Belarusian
Show 60 more
- Bosnian
- Bulgarian
- Burmese
- Catalan
- Croatian
- Czech
- Danish
- Esperanto
- Estonian
- Finnish
- Galician
- Georgian
- Greek
- Gujarati
- Haitian Creole
- Hebrew
- Hungarian
- Ido
- Interlingua
- Irish
- Kazakh
- Kyrgyz
- Latin
- Latvian
- Lithuanian
- Lombard
- Luxembourgish
- Macedonian
- Malay
- Malayalam
- Marathi
- Mongolian
- Nederlands
- Norwegian
- Norwegian Nynorsk
- Polski
- Punjabi
- Romanian
- Serbian
- Serbian (Latin)
- simple
- Slovak
- Slovenian
- Svenska
- Tamil
- Tiếng Việt
- Türkçe
- Ukrainian
- Urdu
- Uzbek
- Walloon
- Welsh
- Western Panjabi
- Wu Chinese
- zh_min_nan
- zh_yue
- Zulu
- فارسی
- ไทย
- 한국어
via Wikidata sitelinks · CC0