Phishing
Phishing is social engineering by message: attackers pose as a trusted sender to steal credentials or trigger actions. How it works, the variants, and what stops it.
Updated This page as Markdown
In short
Phishing is an attack in which a message that appears to come from a trusted sender (email, SMS, call, QR code) tricks a person into entering credentials, approving a login or opening a file. It is the most common initial access path in security incidents. Awareness helps, but only phishing-resistant authentication such as FIDO2 passkeys, together with detection of what happens after a click, makes a real difference.
What is phishing?
Phishing is a social engineering attack in which the attacker impersonates a trusted sender to make a person hand over credentials, approve an authentication request, transfer money or open a malicious file. The BSI describes it as the starting point of a wide range of crimes, from account takeover to attacks on critical infrastructure. NIST defines it as deceiving individuals into disclosing sensitive personal information through fraudulent communication that appears to be legitimate.
The medium varies, the pattern does not: a plausible pretext, time pressure and a link or attachment. Variants are named after the channel: spear phishing is targeted at one person or role, smishing uses SMS, vishing uses phone calls, often with cloned voices, and quishing hides the link in a QR code so that mail filters cannot read it.
Where is it defined?
There is no legal definition of phishing. German criminal law covers it through general provisions, in particular fraud (§ 263 StGB) and data espionage (§ 202a StGB). Regulation addresses it from the defender’s side: NIS2 lists basic cyber hygiene practices and cybersecurity training (Article 21(2)(g)) and multi-factor authentication (Article 21(2)(j)) among the mandatory measures for essential and important entities. NIST SP 800-63B defines what makes an authenticator phishing resistant: the authenticator cryptographically binds the login to the verifier’s real domain, which is what FIDO2 and passkeys do and what one-time codes cannot.
What it means in practice
Phishing is the most frequent way into a company that we see in incident analyses, and the realistic opening move in a red team engagement. Three observations from that work:
- The click is not the failure, the architecture is. People will click. The question is what a stolen password or an approved push prompt gives the attacker. With single sign-on and legacy protocols that still accept passwords alone, it is often the whole company.
- One-time codes are no longer a barrier. Adversary-in-the-middle kits sit between user and real login page and forward the code within seconds. The defence that holds is FIDO2 hardware keys or passkeys for every account that matters, starting with administrators, developers and finance.
- Detection after the click decides the outcome. A login from a new country, a mailbox rule that forwards everything, an OAuth app that suddenly has mail access: these are the signals a SOC should alert on within minutes. Zyberdome, our managed SOC, is built around exactly this kind of identity telemetry.
For manufacturers of connected products the exposed accounts are different: code signing, update servers, cloud consoles and device management. Treat them as production infrastructure, not as office IT.
Common misunderstandings
Awareness training reduces click rates but does not get them to zero, and a programme that shames individuals teaches people to hide incidents instead of reporting them. Spam filters catch the bulk, not the targeted message that was written for one person. And phishing is not a problem of large companies: small firms are hit as often, with fewer people to notice.
FAQ
Frequently asked questions
Does multi-factor authentication stop phishing?
It stops the simple kind. Modern phishing kits proxy the real login page, relay the one-time code in real time and steal the session cookie, and push-based MFA is defeated by sending prompts until the user approves one. Only phishing-resistant methods, FIDO2 security keys and passkeys, bind the login to the real domain and survive this.
Is a phishing simulation part of a penetration test?
Not by default. A penetration test targets systems; phishing targets people and belongs in a red team engagement with explicit written authorisation, agreed rules on who may be targeted and how results are reported without naming individuals. We do not run phishing campaigns without that framework.
Is phishing relevant for a device manufacturer?
Yes, more than for most. The accounts that sign firmware, operate the update server or administer the device cloud are high-value targets. One phished developer account can turn into a malicious update for a whole fleet. Protect those accounts with hardware keys and separate them from everyday mailboxes.
Sources
Related pages
- GlossarySOC (Security Operations Center)A SOC monitors systems around the clock, detects attacks and coordinates the response. What it consists of, what NIS2 expects, and when a managed SOC is better.
- GlossaryIncident ResponseIncident response is the organised handling of a security incident from detection to recovery. The NIST phases, the NIS2 and CRA deadlines, and what to prepare up front.
- GlossaryRed teamingRed teaming is a goal-based, covert attack simulation that tests detection and response, not just vulnerabilities. Definition, frameworks, difference to a pentest.
- GlossaryNIS2NIS2 (Directive (EU) 2022/2555) sets cybersecurity duties for essential and important entities in 18 sectors. Scope, ten measures, reporting deadlines, German law.
- ServicesEnterprise-grade protection. SMB-friendly price.24/7 managed security for SMBs: SentinelOne endpoint protection, SOC analysts, incident response and reports at a fixed monthly price per device.
- ServicesA resilient IT foundation for your business.IT security for businesses: infrastructure, web application and cloud penetration testing, managed SOC and incident readiness, including healthcare.
