# What is Phishing?

> Phishing is a social-engineering attack that uses a deceptive digital message or interaction to make someone reveal information, authorize an action, open malicious content, or visit an attacker-controlled service.

- Canonical URL: https://yellowcube.eu/glossary/phishing/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Email is common; phishing lures also appear in text messages, social media, search advertisements, QR codes, and collaboration platforms, while voice-based phishing is commonly called vishing.

Some campaigns imitate a familiar organization at scale; spear phishing is tailored to a particular person or group. Modern attacks may steal credentials through a convincing sign-in page, obtain MFA approval, deliver malware, redirect a payment, or persuade support staff to reset an account.

### Key points

- **Common signals:** Unexpected urgency, unusual requests, changed payment details, misleading addresses, suspicious destinations, or pressure to bypass procedure.
- **Technical controls:** Filtering, attachment isolation, domain authentication, safe browsing, phishing-resistant MFA, conditional access, and endpoint monitoring.
- **Process controls:** Independent verification, payment approval, secure recovery, easy reporting, and fast investigation of reported messages.
- **Important limitation:** Awareness training helps, but it cannot make every person identify every deception; systems and workflows must tolerate human error.

### Related terms

[Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/>) · [Email spoofing](<https://yellowcube.eu/glossary/email-spoofing/>) · [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/>) · [Social engineering](<https://yellowcube.eu/glossary/social-engineering/>) · [Spear phishing](<https://yellowcube.eu/glossary/spear-phishing/>) · [Adversary-in-the-middle (AiTM) phishing](<https://yellowcube.eu/glossary/adversary-in-the-middle-phishing/>) · [Typosquatting](<https://yellowcube.eu/glossary/typosquatting/>) · [Spam filtering](<https://yellowcube.eu/glossary/spam-filtering/>)

### Sources

[NIST glossary: Phishing](https://csrc.nist.gov/glossary/term/phishing) · [CISA: Recognize and Report Phishing](https://www.cisa.gov/secure-our-world/recognize-and-report-phishing)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

