← Back to All Articles
Homeβ€ΊArticlesβ€ΊSocial Engineering

What is Phishing? Types, Attack Vectors & Defenses

Explore social engineering techniques, spear phishing, credential harvesting, and technical email authentication controls (SPF, DKIM, DMARC).

β€’β€’β€’

# What is Phishing?

Phishing is a social engineering attack where cybercriminals impersonate trusted entities (banks, colleagues, IT departments) to trick victims into sharing credentials, downloading malware, or making unauthorized wire transfers.

# Common Types of Phishing

Bulk Phishing (spray-and-pray emails), Spear Phishing (customized attacks targeting specific employees), Whaling (targeting C-suite executives), and Smishing/Vishing (SMS/Voice).

# Anatomy of a Malicious Email

Key indicators include spoofed sender addresses, urgent psychological language ('Immediate Account Suspension!'), mismatched link domains, and unsolicited attachments.

# Technical Controls (SPF, DKIM, DMARC)

Email authentication protocols prevent attackers from forging your organization's domain name.

# Security Awareness & Training

Regular simulated phishing drills and password manager adoption dramatically reduce successful credential harvesting.