Phishing
Quick answer
Phishing is deception that persuades a person to hand over credentials, money or access, usually by imitating an organisation the person already trusts. Because the attack targets the person rather than the device, security software can block some of the delivery and almost none of the decision.
A phishing message asks its recipient to do something ordinary in an unusual context: sign in, confirm a payment, update details, open an attached invoice, approve a login prompt. The technical content may be entirely benign. What makes it an attack is that the organisation it claims to come from did not send it, and the destination it points to is controlled by someone else.
This matters for a library about antivirus software because phishing is where the two subjects separate. A scanner examines files and processes. A message that contains no file, links to a page that contains no malicious code, and relies entirely on the recipient typing a password, presents a scanner with nothing to examine.
The recognisable forms
- Bulk phishing
- Identical messages sent to very large numbers of addresses, imitating banks, delivery companies, government services or widely used platforms. Individually unconvincing, effective at volume.
- Spear phishing
- A message written for one recipient using details about them — their employer, a recent purchase, a colleague's name. The research is often drawn from public sources and from previous breaches.
- Business email compromise
- An attacker obtains access to a real mailbox, usually a supplier's, and sends a genuine-looking request to change bank details on an invoice. There is no forged sender and no malicious link; the message is authentic and the instruction is not.
- Smishing and vishing
- The same deception delivered by text message or voice call. Phone delivery removes most of the technical signals a reader might otherwise check.
- Multi-factor fatigue
- Repeated authentication prompts sent to a person who holds a valid second factor, in the hope that one is approved to make them stop. The attacker already has the password at this point.
What the software layer can and cannot do
Products described as offering phishing protection generally combine a handful of measures, each with a defined reach.
- Mail filtering removes a large share of bulk messages before delivery, using sender reputation, authentication records and content analysis. It is applied by the mail provider more often than by software on the device.
- Link checking compares the destination of a link against lists of known fraudulent sites. The list is reactive in the same way the catalogue described in signature detection is reactive, and fraudulent sites are frequently live for only a few hours.
- Browser warnings interrupt navigation to a flagged address. They depend on the same lists.
- Attachment scanning addresses the subset of phishing that carries a payload, which is the subset where a scanner contributes most.
None of these reach a message from a genuinely compromised supplier mailbox containing changed bank details. That form of loss is a business process problem, and the control that works is verification through a channel the attacker does not hold.
The structural point
Phishing succeeds when a real decision is made by a real person for reasons that seem sound at the time. Any description of it that treats the target as careless misunderstands the attack, and tends to make people less likely to report an incident quickly, which is the one response that limits the damage.
Why the familiar warning signs have weakened
Advice to look for spelling errors, awkward grammar and generic greetings described the bulk phishing of an earlier period accurately. It describes current messages much less well. Text generation has removed the language errors; brand assets are copied directly from the real site; and the padlock in the address bar indicates only that the connection is encrypted, which is true of fraudulent sites as readily as of genuine ones.
Address inspection has also become less dependable on its own. Domains that differ by one character, subdomains arranged to put a familiar name at the front, and legitimate hosting and link-shortening services used as intermediaries all produce addresses that survive a glance. The checks below are set out because they do not depend on the imitation being imperfect.
Checks that still hold up
- Initiate the contact independently. Do not use the link, number or address in the message. Open the organisation's site from a bookmark or a previously known address, or call a number taken from a statement or the back of a card.
- Treat urgency as a signal about the message, not about the situation. Pressure to act before verifying is a feature of the attack rather than a feature of real institutional process.
- Verify changes to payment details by voice, using a number already on file. This single step addresses the most expensive category.
- Never approve an authentication prompt that was not expected. An unexpected prompt means someone else has the password.
- Use a different password for every service, which limits the blast radius when one is given away. See password managers.
Reporting in Australia
Reporting matters, both because it can occasionally stop a transfer and because the aggregate data shapes enforcement. The relevant bodies and what each one is for:
| Situation | Where to report |
|---|---|
| Money sent, or bank details given | The bank or card issuer first and immediately, then Scamwatch |
| A scam received but not acted on | Scamwatch, run by the National Anti-Scam Centre |
| Cybercrime affecting a device or account | ReportCyber, via the Australian Cyber Security Centre |
| Personal information exposed in a breach | The organisation involved, and the OAIC if the response is inadequate |
| Online abuse or image-based abuse | The eSafety Commissioner |
| Misleading conduct by a business | The ACCC |
Identity documents compromised in a scam are a separate problem from the money. IDCARE, the national identity and cyber support service, is the body that assists with replacing and protecting compromised identity credentials, and is referred to by the agencies listed above.
Key terms on this page
- Credential
- Anything used to prove identity to a service: password, one-time code, passkey, recovery answer.
- Business email compromise
- Fraud conducted from a genuine mailbox the attacker controls.
- Multi-factor authentication
- A second proof of identity in addition to a password.
- Spoofing
- Making a message appear to originate from an address or number other than the real one.