Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryIT Security

Phishing

Phishing is social engineering by message: attackers pose as a trusted sender to steal credentials or trigger actions. How it works, the variants, and what stops it.

Updated This page as Markdown

In short

Phishing is an attack in which a message that appears to come from a trusted sender (email, SMS, call, QR code) tricks a person into entering credentials, approving a login or opening a file. It is the most common initial access path in security incidents. Awareness helps, but only phishing-resistant authentication such as FIDO2 passkeys, together with detection of what happens after a click, makes a real difference.

What is phishing?

Phishing is a social engineering attack in which the attacker impersonates a trusted sender to make a person hand over credentials, approve an authentication request, transfer money or open a malicious file. The BSI describes it as the starting point of a wide range of crimes, from account takeover to attacks on critical infrastructure. NIST defines it as deceiving individuals into disclosing sensitive personal information through fraudulent communication that appears to be legitimate.

The medium varies, the pattern does not: a plausible pretext, time pressure and a link or attachment. Variants are named after the channel: spear phishing is targeted at one person or role, smishing uses SMS, vishing uses phone calls, often with cloned voices, and quishing hides the link in a QR code so that mail filters cannot read it.

Where is it defined?

There is no legal definition of phishing. German criminal law covers it through general provisions, in particular fraud (§ 263 StGB) and data espionage (§ 202a StGB). Regulation addresses it from the defender’s side: NIS2 lists basic cyber hygiene practices and cybersecurity training (Article 21(2)(g)) and multi-factor authentication (Article 21(2)(j)) among the mandatory measures for essential and important entities. NIST SP 800-63B defines what makes an authenticator phishing resistant: the authenticator cryptographically binds the login to the verifier’s real domain, which is what FIDO2 and passkeys do and what one-time codes cannot.

What it means in practice

Phishing is the most frequent way into a company that we see in incident analyses, and the realistic opening move in a red team engagement. Three observations from that work:

  • The click is not the failure, the architecture is. People will click. The question is what a stolen password or an approved push prompt gives the attacker. With single sign-on and legacy protocols that still accept passwords alone, it is often the whole company.
  • One-time codes are no longer a barrier. Adversary-in-the-middle kits sit between user and real login page and forward the code within seconds. The defence that holds is FIDO2 hardware keys or passkeys for every account that matters, starting with administrators, developers and finance.
  • Detection after the click decides the outcome. A login from a new country, a mailbox rule that forwards everything, an OAuth app that suddenly has mail access: these are the signals a SOC should alert on within minutes. Zyberdome, our managed SOC, is built around exactly this kind of identity telemetry.

For manufacturers of connected products the exposed accounts are different: code signing, update servers, cloud consoles and device management. Treat them as production infrastructure, not as office IT.

Common misunderstandings

Awareness training reduces click rates but does not get them to zero, and a programme that shames individuals teaches people to hide incidents instead of reporting them. Spam filters catch the bulk, not the targeted message that was written for one person. And phishing is not a problem of large companies: small firms are hit as often, with fewer people to notice.

FAQ

Frequently asked questions

Does multi-factor authentication stop phishing?

It stops the simple kind. Modern phishing kits proxy the real login page, relay the one-time code in real time and steal the session cookie, and push-based MFA is defeated by sending prompts until the user approves one. Only phishing-resistant methods, FIDO2 security keys and passkeys, bind the login to the real domain and survive this.

Is a phishing simulation part of a penetration test?

Not by default. A penetration test targets systems; phishing targets people and belongs in a red team engagement with explicit written authorisation, agreed rules on who may be targeted and how results are reported without naming individuals. We do not run phishing campaigns without that framework.

Is phishing relevant for a device manufacturer?

Yes, more than for most. The accounts that sign firmware, operate the update server or administer the device cloud are high-value targets. One phished developer account can turn into a malicious update for a whole fleet. Protect those accounts with hardware keys and separate them from everyday mailboxes.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab