Phishing
Phishing uses a deceptive message to influence a target into taking an action that benefits the attacker. The action may expose credentials, money, information, systems, or access, or may establish a foothold for later activity.
Email remains a common delivery channel, although phishing also appears through collaboration tools, messaging platforms, social media, file-sharing services, ticketing systems, and other business applications. The claimed source may be a trusted person, internal function, supplier, service provider, government body, or technology platform.
Phishing gains credibility by placing a request inside a familiar communication pattern or routine workflow. Branding, known names, expected notifications, and business context can reduce scrutiny before the sender, destination, or requested action is independently verified, and a professionally written message may carry few obvious anomalies to interrupt that.
How it appears
Section titled “How it appears”Phishing adapts to the communication channel and process being targeted. Account alerts, invoices, shared documents, delivery notifications, payment requests, security notices, meeting invitations, and internal business messages can all carry the same underlying structure.
A phishing message normally establishes a claimed source, supplies a reason for contact, and directs the target towards an action. Tailoring adds real organisational context: an existing thread, a ticket reference, a supplier name, or familiar branding lifted from legitimate correspondence. The surface wording changes from one campaign to the next, but this underlying arrangement of source, reason, and requested action holds across variants, particularly where the action touches credentials, money, access, or sensitive information.
Phishing often combines the following elements:
| Element | What it means | Examples |
|---|---|---|
| Claimed source | The person, function, organisation, or service the message appears to represent. | Supplier, executive, IT support, cloud service, courier, HR, finance, customer, service provider. |
| Reason for contact | The context given for the message and requested action. | Account issue, invoice, shared file, delivery update, security alert, payment change, document review. |
| Requested action | The action the message seeks from the target. | Open a link, open an attachment, approve a request, enter credentials, make a payment, disclose data. |
| Delivery mechanism | The mechanism through which the action is presented or reached. | Email link, attachment, QR code, shared document, login page, calendar invitation, chat message, file transfer. |
| Legitimacy detail | The copied, spoofed, or genuine context that makes the message appear credible. | Logos, signatures, real names, supplier details, previous thread text, ticket numbers, familiar branding. |
| Pressure or influence | The condition used to increase compliance or reduce scrutiny. | Urgency, authority, fear, curiosity, routine, convenience, financial pressure, account lockout warning. |
Indicators
Section titled “Indicators”Phishing indicators often appear as inconsistencies between the message, sender, process, or destination. Authentic branding and polished language do not remove the significance of an anomalous request or contact path.
| Indicator | What to look for |
|---|---|
| Unexpected message | The message arrives without an established context or requests action unrelated to current activity. |
| Sender mismatch | Display name, email address, domain, reply-to address, or sending service differs from the claimed source. |
| Link mismatch | Visible link text, destination preview, shortened URL, QR destination, or login page does not align with the claimed organisation or service. |
| Unexpected attachment | An unanticipated file, invoice, document, archive, macro-enabled file, or file-sharing notification accompanies the request. |
| Credential request | Passwords, MFA codes, recovery codes, tokens, account approvals, device approvals, or login through an unfamiliar page are requested. |
| Payment or supplier change | Payment, bank detail, invoice, purchase order, payroll, gift card, or supplier record changes are introduced through the message. |
| Urgency or fear | Account closure, missed deadlines, failed payments, security incidents, delivery problems, legal action, or business disruption are used to accelerate action. |
| Process bypass | Approval, procurement, finance, IT, helpdesk, document release, or supplier validation processes are expected to be bypassed. |
| Unusual tone or timing | Wording, timing, formality, urgency, or request style differs from the claimed sender or established process. |
| Verification resistance | Callback, escalation, ticketing, manager confirmation, or another approved verification path is discouraged. |