Meaning of PHISHING

What Does PHISHING Mean?

PHISHING is a technique used by criminals to gain personal information (e.g., usernames, passwords, bank-card details) by masquerading as a reputable entity or person in electronic correspondence (usually email).

A PHISHING email will typically include an attachment that installs malware onto the user's device or a link that directs the user to a malicious website where personal or financial information will be requested.

Although some PHISHING emails are poorly written and obviously fake, they are increasingly difficult to spot as cybercriminals are becoming adept at mimicking the look of the spoofed company (e.g., they will use logos from the spoofed company's site and copy the company's fonts and writing style). They also employ proven marketing techniques to improve the "open" or "click through" rates of their emails. Another common technique is to reference something that seems personal (e.g., a recent watch purchase). Such emails can be extremely effective against people for whom they are relevant (e.g., those who have recently bought a watch).

Of note, cybercriminals will also buy domain names that look similar to the spoofed company's site so the links in their emails look genuine. For example:

Real SiteFake Site
(This is called "typosquatting".)

Cybercriminals will also use JavaScript to show legitimate URLs instead of the malicious URL.

The different types of PHISHING include:

SPEAR PHISHING. SPEAR PHISHING is the term for a PHISHING attack aimed at a specific individual or company. The target of a SPEAR PHISHING attack will often be well researched to attain personal information to improve the relevance of the email.

WHALING. WHALING is the term for a PHISHING attack aimed at a senior executive.

CLONE PHISHING: CLONE PHISHING is the term for a PHISHING attack that closely mimics a legitimate company's email, typically by using a genuine email and changing the links.

VISHING. VISHING (short for VOICE PHISHING) is the term for a PHISHING attack that uses voice technology (e.g., landline phone, mobile phone, Skype).
Summary of Key Points

Definition for PHISHING

PHISHING means "an online scam to attain personal information for fraud". This is the most common definition for PHISHING on Snapchat, WhatsApp, Facebook, and Twitter. Here is some more information about PHISHING:

Examples of PHISHING in Sentences

Here is an example of PHISHING being used in a conversation:
  • Person A: Do you think this is a genuine email?
  • Person B: No, I think they're PHISHING. The punctuation looks dodgy, and it didn't give your name at the start.

An Academic Look at PHISHING

PHISHING is a homophone of fishing.

What Did We Used To Say?

Before the digital era, we might have said something like "a confidence fraud" instead of PHISHING.

A Text with PHISHING

