Phishing Wiki
The phishing encyclopedia for security and IT teams
Clear, practical explainers on phishing tactics, attack techniques, and the controls that defend against them - written by offensive-security practitioners.
Phishing glossary
Phishing glossary
A
- Adversary-in-the-Middle (AiTM) phishing
- AiTM phishing places the attacker between the victim and the genuine login page. The victim authenticates against the real service, multi-factor authentication succeeds, and the attacker walks away with the resulting session cookie. It is the technique that turned "we have MFA" from an answer into a starting point.
B
- Business email compromise (BEC)
- Business email compromise is a targeted fraud in which an attacker impersonates an executive, a colleague or a supplier to redirect a payment or extract sensitive data. It typically contains no link, no attachment and no malicious code at all - which is exactly why it gets delivered.
C
- Can phishing bypass MFA?
- Yes, and routinely. Most deployed multi-factor authentication produces a code or an approval that a person hands over, and anything a person can hand over can be relayed by an attacker sitting in the middle. Only credentials cryptographically bound to the real website resist it.
D
- DMARC
- DMARC is the email-authentication standard that sits on top of SPF and DKIM. It adds the two things neither of them provides on its own: a requirement that the authenticated domain match the domain a human actually sees, and an instruction telling receiving mail servers what to do when a message fails.
H
- How to prevent phishing
- No control stops every phishing message reaching an inbox. The realistic goal is to make a delivered message harder to act on, make a successful one harder to convert into access, and make a mistake cheap to recover from. Those three aims map onto three layers.
- How to recognize phishing
- Three checks catch most phishing: who really sent it, where the link really goes, and what the message is actually asking you to do. The advice to look for bad spelling is obsolete - modern phishing is well written, and grammar is no longer a signal.
I
- I clicked a phishing link - what now?
- Take a breath first. Opening a phishing page is not the same as being compromised, and in most cases nothing has happened yet. What matters is not whether you clicked, but whether you typed something afterwards. This page walks through each case in order.
M
- MFA fatigue
- MFA fatigue, also called push bombing, is an attack in which someone who already has a valid password triggers login attempt after login attempt until the victim approves one of the resulting prompts. Nothing is technically broken. The person is simply worn down.
S
- Sextortion email with my password
- An email arrives claiming someone has recorded you through your webcam, and to prove it they quote a password you recognise. It is a bluff, sent unchanged to millions of addresses. There is almost certainly no recording, and you should not pay.
- Spear phishing
- Spear phishing is a phishing message written for one specific person or role, using real information about them. It abandons volume for credibility, and because it references things that are genuinely true, the usual advice about spotting suspicious messages largely stops applying.
- SPF record
- An SPF record is a DNS TXT record listing which mail servers are permitted to send messages using your domain in the envelope sender. Receiving servers check it on every inbound message. It is the oldest of the three email-authentication standards and the easiest one to get subtly wrong.
T
- The SPF 10 DNS lookup limit
- RFC 7208 caps SPF evaluation at ten DNS-querying mechanisms. Exceed it and the receiver returns PermError, which is treated as though the domain published no SPF record at all. Three or four cloud services are usually enough to hit it without anyone noticing.
- Types of phishing
- Phishing is a tactic, not a single channel, and the names multiply because each delivery route earned its own label. They divide cleanly along two axes: how the message reaches you, and how narrowly it was aimed at you.
W
- What is phishing?
- Phishing is a fraudulent message that impersonates a person or organisation you trust, in order to make you hand over credentials, money, or access to a system. It targets the person rather than the software, which is why patched, modern systems fall to it routinely.
Next step
Ready to measure your phishing and training program?
Book a demo and see how PhishGun can support your simulation and training program, reporting needs, and compliance evidence.