A social-engineering attack that tricks users into revealing credentials, clicking malicious links, or executing payloads — typically via spoofed email but increasingly via SMS (smishing), voice (vishing), and other channels.
Phishing remains the #1 initial-access vector for breaches. Generic phishing casts a wide net; spear phishing targets specific individuals with researched context (using LinkedIn data, recent press, even AI-generated voice clones). Defenses: phishing-resistant MFA (passkeys, hardware keys), email authentication (SPF/DKIM/DMARC), user training (which has limited effectiveness alone), and security tools that detonate links in sandboxes before delivery.
An employee receives an email apparently from the CEO requesting urgent wire transfer to a new vendor — classic Business Email Compromise (BEC) variant of spear phishing.
Phishing is the lowest-cost, highest-ROI attack — every successful phishing email saves the attacker weeks of technical exploitation work.
Need help implementing this in your business?
Get Started