Phishing
Phishing is a social engineering attack in which an attacker sends fraudulent messages, usually email, designed to trick recipients into revealing credentials, transferring money, or running malicious content. Phishing is the most common initial-access technique in real-world breaches, and defending against it combines technical controls with security awareness training.
Phishing is a form of social engineering in which an attacker sends deceptive messages that appear to come from a trusted source, in order to manipulate the recipient into doing something harmful: entering their password on a fake login page, opening a malicious attachment, clicking a link that installs malware, or authorising a fraudulent payment. It remains the single most common way attackers gain their initial foothold, precisely because it targets people rather than technology.
The technique comes in several forms of increasing precision. Bulk phishing casts a wide net with generic messages sent to many recipients. Spear phishing targets specific individuals with tailored messages that reference real details to seem convincing. Whaling targets senior executives, whose access and authority make them especially valuable. Related techniques extend beyond email: smishing uses text messages, vishing uses voice calls, and quishing uses malicious QR codes. All share the same core: deception aimed at a human.
Phishing works because it exploits human psychology rather than technical flaws. Attackers create a sense of urgency, so the recipient acts before thinking; impersonate authority, such as a manager or a bank; and exploit trust in familiar brands and colleagues. A well-crafted phishing email can fool even careful people, and attackers increasingly use information gathered from social media and data breaches to make their messages highly plausible. Generative AI has made producing convincing, well-written lures easier still.
The consequences are serious because phishing is so often the first step in a larger attack. Stolen credentials give an attacker legitimate access to log in and begin lateral movement. A malicious attachment can establish the foothold from which an intrusion unfolds. Business email compromise, a costly form of phishing, tricks organisations into transferring funds to attacker-controlled accounts. Because phishing initiates so many breaches, stopping it prevents a large share of intrusions before they begin.
Defence requires both technology and people. Technical controls include email filtering, authentication standards that make spoofing harder, multi-factor authentication so that a stolen password alone is not enough, and browser and endpoint protections. But because no filter catches everything, the human layer is essential: regular, realistic security awareness training and simulated phishing exercises help people recognise and report suspicious messages, turning employees from the most-targeted weakness into an active line of defence.
Generative AI has raised the stakes by making convincing lures cheaper and easier to produce at scale, removing the spelling and grammar errors that once betrayed many phishing attempts. This makes the combination of technical controls and a well-trained, alert workforce more important than ever: filtering and multi-factor authentication stop much of the volume, while people who can recognise and report a suspicious message catch what slips through.
Through its social engineering service, Precursor runs realistic phishing simulations that test how an organisation’s people respond to convincing lures, and uses the results to focus awareness training where it is genuinely needed.