Knowledge / identity concepts acsc-glossary

Phishing

A bulk lure: fake message, urgency, a credential or a hostile file. Training helps. Phishing-resistant MFA and mail authentication help more.

PHISHING / identity abuse, not a malware class01Lure02Landing03Capture04ReuseControls: phishing-resistant MFA, reporting, mail auth, drills.

Phishing is social engineering at industrial scale. Unsolicited messages — usually email — ask for secrets, push a hostile attachment, or send you to a lookalike site. Related species: spear phishing (named target), whaling (executives), smishing (SMS), vishing (voice).

Defences that work: phishing-resistant MFA, a report button that goes somewhere, SPF/DKIM/DMARC, attachment and URL controls, and drills that do not humiliate people.

Lures that ask a user to paste a command are still phishing. The wrapper changed. The control set did not.

Fact source: ASD's ACSC glossary. Wording is Cyberstack's.