Phishing — IT Glossary | ITU Online IT Training
+1 855.488.5327 customerservice@ituonline.com Mon – Fri: 9:00am – 5:00pm ET

Phishing

Commonly used in Cybersecurity

Ready to start learning?Individual Plans →Team Plans →

Phishing is a cyberattack in which attackers try to deceive individuals into revealing sensitive information, such as passwords, credit card numbers, or personal identification details. These attacks often involve fraudulent communications that appear to come from trusted sources.

How It Works

In a typical phishing attack, the attacker sends emails, messages, or creates fake websites that mimic legitimate organisations or services. The goal is to lure the recipient into providing confidential information by convincing them that the request is legitimate. These messages often create a sense of urgency or fear to prompt quick action, such as clicking a malicious link or opening an infected attachment. Once the victim responds or inputs their details, the attacker gains access to their private data, which can be used for identity theft, financial fraud, or further cyberattacks.

Phishing campaigns can be highly sophisticated, using techniques such as email spoofing, social engineering, and website cloning to increase their chances of success. Cybercriminals often gather intelligence beforehand to personalise messages, making them more convincing and harder to detect. Training and awareness are critical in recognising and avoiding these deceptive tactics.

Common Use Cases

  • Sending fake login pages that mimic popular banking websites to steal credentials.
  • Distributing emails that claim to be from company executives requesting confidential information.
  • Launching spear-phishing campaigns targeting specific individuals within an organisation.
  • Using malicious links in messages to install malware or ransomware on a victim’s device.
  • Creating fake social media profiles to gather personal data and build trust for future scams.

Why It Matters

Phishing remains one of the most common and effective methods used by cybercriminals to breach security and access sensitive data. For IT professionals and security practitioners, understanding phishing techniques is essential for implementing preventative measures, such as email filtering, user training, and multi-factor authentication. Certification candidates often encounter phishing as a key topic in cybersecurity exams, reflecting its significance in protecting organisational and personal information. Recognising and mitigating phishing threats is critical for maintaining the integrity, confidentiality, and availability of digital assets in any organisation.

Ready to start learning?Individual Plans →Team Plans →
Discover More, Learn More
Understanding the Security Operations Center: A Deep Dive Discover how a Security Operations Center enhances your cybersecurity defenses, improves incident… What Is a Security Operations Center (SOC)? Discover what a security operations center is and how it enhances organizational… Step-by-Step Guide to Implementing a Security Operations Center in Your Organization Discover how to effectively implement a security operations center in your organization… Building a Security Operations Center: A Complete SOC Setup Blueprint Discover how to build a comprehensive Security Operations Center to enhance cybersecurity… Understanding SOC Functions: The Complete Guide to Security Operations Center Operations Discover how SOC functions support security monitoring, threat detection, and incident response… Counterintelligence and Operational Security in Cybersecurity: A Guide for CompTIA SecurityX Certification Discover essential strategies to enhance your cybersecurity skills by understanding counterintelligence and…