What is phishing? Here’s everything you need to know

Here's how to dodge the digital hooks of modern phishing attacks

What is phishing? Like actual fishing, it’s no fun to be on the end of the hook. But that’s where every modern web user will likely find themselves at some point in their time online. Whether it’s through a phony email promising millions, a phone caller claiming to be from your bank, or a faked website login form, phishing is everywhere. The scary thing? It’s more profitable than ever.

Unlike many modern threats to our digital selves, though, Phishing scams have existed for centuries in more classic form and decades in their most recent. There are new methods and attack vectors at play today, but all they do is take advantage of new communication mediums to perform the same age-old scams that have been fooling unwary people forever.

Social engineering

Cybersecurity Pay-and-Pray

The main component of any phishing scam is social engineering. That’s the practice of tricking the user into believing that the person, email, or, web page they are dealing with is legitimate. It’s psychological manipulation to commit fraud. A digital form of classic confidence tricks to encourage the divulging of personal information.

The most classic use of social engineering in phishing is with email. The Nigerian Prince scam is a well known one, but it also has its more modern forms on social media. Other variations on the theme include, phone calls, emails or social networking messages purporting to be from your bank that want you to click on a link, or an email that seems to come from a colleague who desperately needs you to open an attachment. In some cases that leads to malicious sites that continue the phishing attack, but they may also download malicious software which loops in malware for a combined attack.

In all cases, phishing attacks that lean on social engineering encourage the user to partake in an action which is not advisable. They may use language to suggest time is of the essence, appeal to good natures, or suggest familiarity to further apply pressure to the potential victim.

A good rule of thumb to avoid such scams is to consider the old adage of, “it’s too good to be true,” and to never click on links within emails. When it comes to attachments, asking colleagues to distribute them over file sharing platforms is safer and less susceptible to manipulation than emails which can easily be spoofed to look like they come from somewhere legitimate.

Phony forms

A more hands-off form of phishing involves faking more than just an email. In some cases entire websites — or at least their login pages — are spoofed to give further feeling of legitimacy. They might use similar-seeming web addresses, copied artwork and design choices, and even security certificates, depending on the complexity of the forgery.

As with the email scams, phishing websites are designed to encourage the victim to part with their personal information. A fake banking site or social network might steal your login credentials. A fake Bitcoin exchange might try to steal your cryptocurrency.

Although less common, the most sophisticated form of website spoofing involves using a security hole in a legitimate website to hijack it. When victims attempt to login, they are in fact putting their information into a phony login form, or are granting the attackers the ability to login to that site at the same time as them.

The best way to avoid such attacks is to always make sure you’re actually on the right website — not one with a similar URL — and to be suspicious of any surprise login prompts. If in doubt, type the web address you know to be safe in your web browser rather than using links.

Targeted phishing

Phishing is generally quite generic with attackers looking to cast their net wide to try and snare as many potential victims as possible. This is especially important now that most modern web browser employ anti-phishing security measures. However, some of the most effective phishing attacks have been successful because they were targeted. The practice of using specific information about individuals, perhaps garnered from a previous social engineering or malware attack, is known as spear phishing.

Spear phishing can take the guise of emails, phone calls, or instant messages in much the same way as more general attacks. They will employ disarming tactics like first name usage, or preferred personal information that could seem to only come from a legitimate source. This can be for the purpose of monetary gain, but there have also been instances of it being employed for the purpose of industrial espionage and political manipulation.

According to a 2017 Keepnet study, the average successful spear phishing attack on businesses nets the attackers $1.6 million, making it far more profitable than other types of digital attacks.

Another more niche form of phishing known as “whaling” can be even more lucrative. It specifically targets high-net worth individuals and businesses with the purpose of scamming them out of money or gaining high-level digital access to an organization.

Spear phishing attacks are, by their very nature, much harder to spot and avoid in turn. However, it’s important to remember that they rely on the same manipulative techniques as other phishing scams. They want your information. If you are very careful about the information you give out and the context you offer it in, you should be relatively safe from all forms of phishing.

You can further mitigate the problems associated with phishing attack fall out by using unique passwords on all your services and storing them in a strong password manager.


Don’t be fooled! Study exposes most popular phishing email subject lines

Phishing emails are on the rise and a new study out by the cybersecurity company Barracuda has exposed some of the most common phishing email subject lines used to exploit businesses. 

Confused about RSS? Don't be. Here's what it is and how to use it

What is an RSS feed, anyway? This traditional method of following online news is still plenty useful. Let's take a look at what RSS means, and what advantages it has in today's busy world.

Rooting your Android device is risky. Do it right with our handy guide

Wondering whether to root your Android smartphone or stick with stock Android? Perhaps you’ve decided to do it and you just need to know how? Here, you'll find an explanation and a quick guide on how to root Android devices.

Dodge the cryptojackers with the best torrent clients available today

Looking for the best torrent clients to help you share all of that wonderful legal content you own? Here's a list of our favorite torrent clients, all packed with great features while dodging malware and adverts.

Get ready to say goodbye to some IFTTT support in Gmail by March 31

If This Then That, the popular automation service, will drop some of its support for Gmail by March 31. The decision comes as a response to security concerns and is aimed to protect user data.

Get the new Dell XPS 13 for $750 with this limited-time deal

Dell is currently running a limited time deal lasting through Thursday, March 28, where you can bring home a version of this year's new XPS 13 for around $750 with the use of a special coupon code. 

Nvidia faces attacks from AMD, Intel, and even Google. Should it be worried?

Nvidia announced an expanded array of RTX server solutions designed to leverage the power of ray-tracing at GTC 2019. The effort will help Nvidia take on Google's Stadia in game streaming with GeForce Now, and the company's investments in…

This is the easiest way to save your iPhone data to your computer

Living in fear of losing your contacts, photos, messages, and notes on your iPhone? Fear no more -- in this guide, we'll break down exactly how to back up your iPhone to your computer using Apple's iTunes or to the cloud with iCloud.

Here are the best iPad Pro keyboard cases to pick up with your new tablet

The iPad Pro range can double as laptops, but they do need proper keyboards to fill in effectively. Thankfully, there are loads to choose from and we rounded up the best iPad Pro keyboard cases right here.

Microsoft’s Clippy came back from the dead, but didn’t last very long

Before Cortana, Alexa, and Siri even existed, Microsoft Clippy dominated the screens of computers in the 1990s to help assist Microsoft Office users when writing letters. He recently made a bit of a comeback only to die off again.

How 5G networks will make low-latency game streaming a reality

Faster speeds and more bandwidth are some of the many promises that 5G can deliver, but for gamers, the most important thing is low latency. To achieve low latency, carriers like AT&T and Verizon are exploring hybrid models for game…

Time to do taxes? Save up to 50 percent on H&R Block tax software this weekend

Tax season is stressful, and with new tax laws in effect this year, it's not a bad idea to get some help. H&R Block has you covered: For two days only, you can save 50 percent on its great software so you can file your taxes online and save…

Stop dragging windows on your Mac. Here's how to use Split View to multitask

The latest iterations of MacOS offer a native Split View feature that can automatically divide screen space between two applications. Here's how to use Split View on a Mac, adjust it as needed, and how it can help out.

Breeze through security with these checkpoint-friendly laptop bags

Getting through airport security is a drag, but your laptop bag shouldn’t be. Thankfully, these checkpoint-friendly laptop bags will get you and your gear to your destination with ease.