Phishing is a social engineering technique that tricks victims into revealing sensitive information or taking harmful actions through email or other messaging systems. It remains one of the most common entry points for cyberattacks across all industries.
Phishing
A huge part of social engineering attacks, or really any kind of cyber security attack, starts out with phishing. So let's jump into what phishing is.
Essentially, phishing is attempting to trick a victim into disclosing sensitive data through email. Two key things when it comes to phishing: number one, we're doing it through email, and also we're trying to get information.
We've started using this term a little more broadly than just that. For instance, maybe I'm trying to get them to open up an attachment or install something. Maybe I'm not seeking information specifically -- maybe it's some other type of action. So really phishing has broadened in terms of what it's trying to do. It's not just information, but it could be any kind of malicious behavior, any kind of social engineering.
Not only that, but some definitions use a broader term of phishing in the sense of how it's being delivered. It could be through phishing, but it also could be through smishing, or instant messaging, or perhaps even phishing any kind of message-based system. So maybe a better term would be attempting to trick victims into disclosing sensitive information, or doing something that compromises security, through a messaging system.
Not only that, but we often train users to use a phishing button. A phishing button shows up on the email client so they can identify phishing emails, and then we, as IT security professionals, can identify those phishing emails company-wide and do something about them.
So that's one thing we do, and often we tell them to go ahead and click on it for the spam messages as well, so we just take care of it all and get all of it out there. So in some cases we could extend this definition even to those spam emails.
To keep this simple, though, we're just going to say that phishing, in the traditional sense of the word, is attempting to trick victims into disclosing sensitive information through email or other messages. We'll just keep it straightforward like that, because that's the generally accepted term for what phishing is.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →