# What is Phishing?
Phishing is a social engineering attack where cybercriminals impersonate trusted entities (banks, colleagues, IT departments) to trick victims into sharing credentials, downloading malware, or making unauthorized wire transfers.
# Common Types of Phishing
Bulk Phishing (spray-and-pray emails), Spear Phishing (customized attacks targeting specific employees), Whaling (targeting C-suite executives), and Smishing/Vishing (SMS/Voice).
# Anatomy of a Malicious Email
Key indicators include spoofed sender addresses, urgent psychological language ('Immediate Account Suspension!'), mismatched link domains, and unsolicited attachments.
# Technical Controls (SPF, DKIM, DMARC)
Email authentication protocols prevent attackers from forging your organization's domain name.
# Security Awareness & Training
Regular simulated phishing drills and password manager adoption dramatically reduce successful credential harvesting.