Email Phishing
Commonly used in Security, Cybersecurity
Email phishing is a type of cyber-attack that involves sending deceptive emails designed to appear legitimate. The attacker’s aim is to manipulate the recipient into taking an action that compromises security, such as clicking on a malicious link or downloading an infected attachment.
How It Works
Phishing emails are crafted to mimic the appearance and tone of trusted entities like banks, companies, or colleagues. They often include urgent language or alarming messages to prompt quick action. The email may contain links that direct the recipient to fake websites that resemble legitimate ones, where sensitive information such as login credentials or financial data is collected. Alternatively, attachments may contain malware that infects the recipient’s device when opened.
The success of phishing relies heavily on social engineering techniques, exploiting human psychology to bypass technical security measures. Attackers often gather information about their targets beforehand to make their messages more convincing and personalized.
Common Use Cases
- Sending fake bank notifications to steal login credentials from account holders.
- Distributing malware via email attachments disguised as invoices or delivery notices.
- Impersonating company executives to request sensitive internal information.
- Launching spear-phishing campaigns targeting specific individuals within an organisation.
- Harvesting employee credentials to gain access to corporate networks.
Why It Matters
For IT professionals and security practitioners, understanding email phishing is crucial because it remains one of the most common and effective cyber-attack methods. Recognising phishing attempts helps prevent data breaches, financial loss, and damage to reputation. Many cybersecurity certifications include modules on identifying and mitigating phishing threats, making it a fundamental skill for safeguarding organisational assets. As attackers continuously evolve their tactics, ongoing awareness and training are vital to maintaining security resilience against these deceptive attacks.