Technique
Phishing Email
Also known as: Credential Phishing, Spear Phishing, Whaling
Fraudulent emails crafted to impersonate trusted entities (banks, employers, government agencies, delivery services) to trick recipients into clicking malicious links, opening weaponized attachments, or surrendering credentials and personal information. Attackers leverage urgency, authority, and fea…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Sender email domain does not match the organization being impersonated (e.g. @amaz0n-security.net instead of @amazon.com)
- Generic greeting such as 'Dear Customer' instead of your actual name
- Urgent or threatening language demanding immediate action or claiming dire consequences
- Hovering over links reveals a URL that does not match the displayed text or expected domain
- Unsolicited requests for personal information, credentials or financial details
- Unexpected attachments especially .zip, .exe .html or .scr files
- Message claims to be from an organization you have no relationship with
- Email arrived unsolicited and asks you to click a link to 'verify' or 'update' account information
Tools you can use
Steps you can take
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading
CISA
US Cybersecurity and Infrastructure Security Agency guide on recognizing and reporting phishing attacks
OCC
Office of the Comptroller of the Currency consumer guidance on phishing attack prevention
Sublime Security
Comprehensive taxonomy of 17 phishing attack types with definitions and detection indicators
Security.org
Consumer phishing protection guide covering detection signs and mitigation measures