Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Full definition
Phishing is a social engineering attack where the attacker impersonates a trusted sender, such as a bank, a vendor or a colleague, so the victim hands over credentials, shares sensitive data, transfers money or installs malware. According to CISA, more than 90 percent of successful cyberattacks start with a phishing email.
The term covers a family of variants defined by channel and target: spear phishing (aimed at a specific person), whaling (aimed at executives), smishing (via SMS), vishing (via voice) and quishing (via QR code). Corporate email remains the dominant channel because it is cheap, massive and impossible to filter perfectly.
Defense combines two layers: technical filters that reduce the volume that gets through, and behavior training that prepares people for the email that inevitably does. Personalized phishing simulations, report rate and retesting are what make that second layer measurable.
Related terms
Spear phishing
Phishing aimed at a specific person, built with real data about their role, company and tools. Far more effective than mass campaigns.
Smishing
Phishing via SMS or mobile messaging. It exploits trust in the phone and the absence of filters: the message arrives direct, short and with a link.
Vishing
Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.
Quishing
Phishing via QR code. The malicious link travels as an image, slips past email filters and opens on the phone, outside corporate defenses.
Phishing simulation
A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.