What it means
Phishing exploits a person's trust or sense of urgency to steer an action. The message may arrive through email, a text, a collaboration tool, or a phone conversation. It can seek credentials, a sign-in approval, a malicious download, or a payment to a different account. Polished language and familiar branding are not reliable indicators of legitimacy. Effective protection combines technical controls with clear workflows for verification and fast reporting. The person who notices a mistake can provide valuable early warning when reporting is easy and blame is avoided.
AN ILLUSTRATIVE SCENARIO
A supplier requests new bank details
A construction company receives a convincing email asking it to change a supplier's payment account before today's deadline. The accounts clerk uses the established supplier-verification process: a separate call to a previously recorded contact, not the number in the message. The supplier denies the request. Security preserves the message and checks whether similar emails reached other staff. The process works even if the message came from a genuinely compromised supplier mailbox, so sender appearance alone would not have been enough.
Put it to work
- Make sensitive actions follow a known verification route, especially payment changes, account recovery, and privileged access. Give employees a simple way to reach the legitimate team independently of the incoming message.
- Use appropriate email protections and phishing-resistant authentication where supported. Explain that authentication controls do not prevent every form of fraud, particularly an authorized person being persuaded to approve the wrong transaction.
- Provide a low-friction reporting button or contact and a practiced response for clicked links, disclosed passwords, or unexpected approvals. Gather useful details promptly without blaming the reporter.
How to check your work
Exercise a harmless simulated payment-change request and a reported sign-in mistake. Confirm staff can verify independently, the report reaches a responder, and that responder can locate relevant messages and revoke affected access when necessary.
Connect the ideas
- MFA
Authentication that requires more than one factor, such as something you know plus something you have.
- Authentication
The act of verifying a claimed identity with authenticators such as passwords, passkeys, or certificates.
- Incident
An event or set of events that actually or potentially causes a security loss requiring coordinated handling.