• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Phishing Email

Also known as: Credential Phishing, Spear Phishing, Whaling

DELIVERY

Fraudulent emails crafted to impersonate trusted entities (banks, employers, government agencies, delivery services) to trick recipients into clicking malicious links, opening weaponized attachments, or surrendering credentials and personal information. Attackers leverage urgency, authority, and fea…

Common attack flows

How it fits in a scam

This technique shows up duringDELIVERY

Before

  • Data Breach HarvestingTARGETING
  • Social Media ReconnaissanceTARGETING
  • Data BrokersTARGETING

After

  • Remote Access ToolPERSISTENCE
  • MalwareCOMPROMISE
  • Business Email CompromiseDELIVERY
  • Cookie HijackingCOMPROMISE

Defense

How to defend against this

How to spot it

  • Sender email domain does not match the organization being impersonated (e.g. @amaz0n-security.net instead of @amazon.com)
  • Generic greeting such as 'Dear Customer' instead of your actual name
  • Urgent or threatening language demanding immediate action or claiming dire consequences
  • Hovering over links reveals a URL that does not match the displayed text or expected domain
  • Unsolicited requests for personal information, credentials or financial details
  • Unexpected attachments especially .zip, .exe .html or .scr files
  • Message claims to be from an organization you have no relationship with
  • Email arrived unsolicited and asks you to click a link to 'verify' or 'update' account information

Tools you can use

  • Multi-Factor AuthenticationCost low · Effect high
  • Password ManagerCost low · Effect high
  • Email AliasesCost medium · Effect medium
  • Scam ScannerCost low · Effect medium
  • Browser Security ExtensionCost low · Effect medium
  • Mobile Security AppCost low · Effect high

Steps you can take

  • Direct Source VerificationCost low · Effect high
  • Official Channel VerificationCost low · Effect high
  • Verify HTTPS ConnectionsCost low · Effect medium

Seen in the wild

Where we’ve seen it

Campaigns

  • Business Email CompromisePrevalence high · Avg loss $125,000

Commonly targets

  • Small Business Owner
  • Developer
  • Corporate Worker
  • Gamer

Further reading

  • CISA

    US Cybersecurity and Infrastructure Security Agency guide on recognizing and reporting phishing attacks

  • OCC

    Office of the Comptroller of the Currency consumer guidance on phishing attack prevention

  • Sublime Security

    Comprehensive taxonomy of 17 phishing attack types with definitions and detection indicators

  • Security.org

    Consumer phishing protection guide covering detection signs and mitigation measures

Related techniques

Variants

  • Smishing
  • Vishing
  • Quishing

Same stage

  • Deepfake Voice Call
  • SEO Poisoning
  • Fake E-commerce Site
  • Pop-up Scareware
  • Package Delivery Scam
  • +13 more

Similar defense

  • Data Breach Harvesting
  • Remote Access Tool
  • Clipboard Hijacking
  • Malicious App Installation
  • Social Media Reconnaissance
  • +24 more