Back to the glossary
    Social engineering & phishingCybersecurity glossary

    Phishing

    An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.

    Full definition

    Phishing is a social engineering attack where the attacker impersonates a trusted sender, such as a bank, a vendor or a colleague, so the victim hands over credentials, shares sensitive data, transfers money or installs malware. According to CISA, more than 90 percent of successful cyberattacks start with a phishing email.

    The term covers a family of variants defined by channel and target: spear phishing (aimed at a specific person), whaling (aimed at executives), smishing (via SMS), vishing (via voice) and quishing (via QR code). Corporate email remains the dominant channel because it is cheap, massive and impossible to filter perfectly.

    Defense combines two layers: technical filters that reduce the volume that gets through, and behavior training that prepares people for the email that inevitably does. Personalized phishing simulations, report rate and retesting are what make that second layer measurable.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.