True Aspect

Phishing

Quick answer

Phishing is deception that persuades a person to hand over credentials, money or access, usually by imitating an organisation the person already trusts. Because the attack targets the person rather than the device, security software can block some of the delivery and almost none of the decision.

A phishing message asks its recipient to do something ordinary in an unusual context: sign in, confirm a payment, update details, open an attached invoice, approve a login prompt. The technical content may be entirely benign. What makes it an attack is that the organisation it claims to come from did not send it, and the destination it points to is controlled by someone else.

This matters for a library about antivirus software because phishing is where the two subjects separate. A scanner examines files and processes. A message that contains no file, links to a page that contains no malicious code, and relies entirely on the recipient typing a password, presents a scanner with nothing to examine.

The recognisable forms

Bulk phishing
Identical messages sent to very large numbers of addresses, imitating banks, delivery companies, government services or widely used platforms. Individually unconvincing, effective at volume.
Spear phishing
A message written for one recipient using details about them — their employer, a recent purchase, a colleague's name. The research is often drawn from public sources and from previous breaches.
Business email compromise
An attacker obtains access to a real mailbox, usually a supplier's, and sends a genuine-looking request to change bank details on an invoice. There is no forged sender and no malicious link; the message is authentic and the instruction is not.
Smishing and vishing
The same deception delivered by text message or voice call. Phone delivery removes most of the technical signals a reader might otherwise check.
Multi-factor fatigue
Repeated authentication prompts sent to a person who holds a valid second factor, in the hope that one is approved to make them stop. The attacker already has the password at this point.

What the software layer can and cannot do

Products described as offering phishing protection generally combine a handful of measures, each with a defined reach.

None of these reach a message from a genuinely compromised supplier mailbox containing changed bank details. That form of loss is a business process problem, and the control that works is verification through a channel the attacker does not hold.

The structural point

Phishing succeeds when a real decision is made by a real person for reasons that seem sound at the time. Any description of it that treats the target as careless misunderstands the attack, and tends to make people less likely to report an incident quickly, which is the one response that limits the damage.

Why the familiar warning signs have weakened

Advice to look for spelling errors, awkward grammar and generic greetings described the bulk phishing of an earlier period accurately. It describes current messages much less well. Text generation has removed the language errors; brand assets are copied directly from the real site; and the padlock in the address bar indicates only that the connection is encrypted, which is true of fraudulent sites as readily as of genuine ones.

Address inspection has also become less dependable on its own. Domains that differ by one character, subdomains arranged to put a familiar name at the front, and legitimate hosting and link-shortening services used as intermediaries all produce addresses that survive a glance. The checks below are set out because they do not depend on the imitation being imperfect.

Checks that still hold up

  1. Initiate the contact independently. Do not use the link, number or address in the message. Open the organisation's site from a bookmark or a previously known address, or call a number taken from a statement or the back of a card.
  2. Treat urgency as a signal about the message, not about the situation. Pressure to act before verifying is a feature of the attack rather than a feature of real institutional process.
  3. Verify changes to payment details by voice, using a number already on file. This single step addresses the most expensive category.
  4. Never approve an authentication prompt that was not expected. An unexpected prompt means someone else has the password.
  5. Use a different password for every service, which limits the blast radius when one is given away. See password managers.

Reporting in Australia

Reporting matters, both because it can occasionally stop a transfer and because the aggregate data shapes enforcement. The relevant bodies and what each one is for:

Where to report, by what happened.
SituationWhere to report
Money sent, or bank details givenThe bank or card issuer first and immediately, then Scamwatch
A scam received but not acted onScamwatch, run by the National Anti-Scam Centre
Cybercrime affecting a device or accountReportCyber, via the Australian Cyber Security Centre
Personal information exposed in a breachThe organisation involved, and the OAIC if the response is inadequate
Online abuse or image-based abuseThe eSafety Commissioner
Misleading conduct by a businessThe ACCC

Identity documents compromised in a scam are a separate problem from the money. IDCARE, the national identity and cyber support service, is the body that assists with replacing and protecting compromised identity credentials, and is referred to by the agencies listed above.

Key terms on this page

Credential
Anything used to prove identity to a service: password, one-time code, passkey, recovery answer.
Business email compromise
Fraud conducted from a genuine mailbox the attacker controls.
Multi-factor authentication
A second proof of identity in addition to a password.
Spoofing
Making a message appear to originate from an address or number other than the real one.