Phishing
Pronunciation: FISH-ing
Definition
Phishing is a social-engineering attack that impersonates a trusted person, brand, service, or workflow to induce disclosure of information, malware execution, funds transfer, or authorization of a harmful action. It is defined by deceptive persuasion rather than by email alone and can occur through websites, messaging apps, calls, search ads, QR codes, or wallet interfaces. Defenses combine authenticated communication, resistant authentication, transaction verification, domain monitoring, user reporting, safe link handling, and rapid credential or session revocation.
Overview
Phishing is a social-engineering attack that impersonates a trusted person, brand, service, or workflow to induce disclosure of information, malware execution, funds transfer, or authorization of a harmful action. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It is defined by deceptive persuasion rather than by email alone and can occur through websites, messaging apps, calls, search ads, QR codes, or wallet interfaces. It should be interpreted alongside Approval Phishing because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, defenses combine authenticated communication, resistant authentication, transaction verification, domain monitoring, user reporting, safe link handling, and rapid credential or session revocation.
It should connect the term to CEO Fraud where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.
Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.
The relationship with Authentication Failures should be documented where it affects residual risk or control ownership.
Key Takeaway
Defenses combine authenticated communication, resistant authentication, transaction verification, domain monitoring, user reporting, safe link handling, and rapid credential or session revocation.
Sources
- Recognize and Report Phishing — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Digital Identity Guidelines: Authentication and Authenticator Management, SP 800-63B-4 — NIST (2026-08-03)
- Business Email Compromise — FBI Internet Crime Complaint Center (2026-08-03)