Attack technique using fraudulent emails or messages to steal credentials or install malware, and the leading initial-access vector in cyber losses.
Phishing is an attack technique based on deception: the attacker sends a fraudulent message that mimics legitimate communication to induce the victim to reveal credentials, click on a malicious link or execute an infected attachment. It is the most frequently identified initial-access vector in post-loss cyber analyses, far ahead of direct exploitation of technical vulnerabilities. Several variants are distinguished by their degree of targeting. Mass phishing sends millions of generic messages, relying on volume to catch a few victims. Spear-phishing is personalized for a specific individual or organization, drawing on public information such as LinkedIn or company websites to increase plausibility. Whaling targets high-access executives specifically, whose compromise is particularly valuable to an attacker. Smishing and vishing exploit SMS and telephone calls respectively rather than emails. For the cyber insurer, the prevalence of phishing as an entry point means that employee awareness training and email filtering are fundamental underwriting controls, alongside multi-factor authentication which limits the damage when credentials are stolen.
A spear-phishing campaign targeting the finance team of an industrial SME sends an email mimicking an urgent request from senior management to validate a wire transfer. An employee clicks the link, enters their Active Directory credentials, and the attacker uses the account to deploy ransomware 72 hours later.
phishing, hameçonnage, spear-phishing, whaling, smishing, vishing