TechKnowSurge
VideoSecurityFree

Phishing

Phishing is a social engineering technique that tricks victims into revealing sensitive information or taking harmful actions through email or other messaging systems. It remains one of the most common entry points for cyberattacks across all industries.

Complete this video to capture a CTF flag worth 1 point.

About this video

Phishing is a foundational social engineering attack method in which a threat actor sends deceptive messages designed to manipulate recipients into revealing sensitive information or taking actions that undermine security. Originally defined as email-based credential theft, the term has evolved to encompass a wider range of malicious objectives, including prompting victims to open malicious attachments, install malware, or perform other harmful actions without necessarily surrendering data directly. Delivery methods have also expanded beyond email to include SMS-based attacks, known as smishing, as well as instant messaging platforms and other message-based systems. From a defensive standpoint, organizations train end users to identify and report suspicious messages using phishing report buttons built into email clients, enabling security teams to detect and respond to phishing campaigns across the entire organization. Spam reporting is often incorporated into the same workflow, streamlining the process of removing unwanted and potentially dangerous messages. At its core, phishing remains defined by the intent to deceive through messaging, and understanding this technique is essential groundwork for anyone working in IT security or studying cyberattack methodologies.

What you'll learn

What's covered

Phishing

Key terms

Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.

Topics

Phishing Social Engineering Cybersecurity Email Security Threat Awareness Cyber Attacks

Transcript

What Phishing Is

A huge part of social engineering attacks, or really any kind of cyber security attack, starts out with phishing. So let's jump into what phishing is.

Essentially, phishing is attempting to trick a victim into disclosing sensitive data through email. Two key things when it comes to phishing: number one, we're doing it through email, and also we're trying to get information.

How the Term Has Broadened

We've started using this term a little more broadly than just that. For instance, maybe I'm trying to get them to open up an attachment or install something. Maybe I'm not seeking information specifically -- maybe it's some other type of action. So really phishing has broadened in terms of what it's trying to do. It's not just information, but it could be any kind of malicious behavior, any kind of social engineering.

Not only that, but some definitions use a broader term of phishing in the sense of how it's being delivered. It could be through phishing, but it also could be through smishing, or instant messaging, or perhaps even phishing any kind of message-based system. So maybe a better term would be attempting to trick victims into disclosing sensitive information, or doing something that compromises security, through a messaging system.

The Phishing Button

Not only that, but we often train users to use a phishing button. A phishing button shows up on the email client so they can identify phishing emails, and then we, as IT security professionals, can identify those phishing emails company-wide and do something about them.

So that's one thing we do, and often we tell them to go ahead and click on it for the spam messages as well, so we just take care of it all and get all of it out there. So in some cases we could extend this definition even to those spam emails.

To keep this simple, though, we're just going to say that phishing, in the traditional sense of the word, is attempting to trick victims into disclosing sensitive information through email or other messages. We'll just keep it straightforward like that, because that's the generally accepted term for what phishing is.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →