ArticleslgStudy

engineering

Phishing

Phishing is a engineering topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Phishing rather than just read about it. In short: Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim navigates the site, and traverses any additional security…

Phishing — main illustration
Phishing — illustration

Key takeaways

  • Phishing belongs to engineering; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Phishing to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Phishing from memory before moving on to harder problems.

Reference excerpt

Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim navigates the site, and traverses any additional security boundaries. Phishing remains the most prevalent type of cybercrime globally. While the Federal Bureau of Investigation's Internet Crime Complaint Center historically ranked it at the top, the threat has intensified significantly due to the integration of generative AI, which enables attackers to launch highly convincing, automated, and hyper-targeted phishing campaigns at an unprecedented scale. The term "phishing" was first recorded in 1995 in the cracking toolkit AOHell, but may have been used earlier in the hacker magazine 2600. It is a variation of fishing and refers to the use of lures to "fish" for sensitive information. Measures to prevent or reduce the impact of phishing attacks include legislation, user education, public awareness, and technical security measures. The importance of phishing awareness has increased in both personal and professional settings, with phishing attacks among businesses rising from 72% in 2017 to 86% in 2020, and reaching 94% in 2023. Phishing techniques and vectors include email spam, vishing (voice phishing), targeted phishing (spear phishing, whaling), smishing (SMS), quishing (QR code), cross-site scripting, and MiTM 2FA attacks.

Types

Email phishing Phishing attacks, often delivered via email, attempt to trick individuals into giving away sensitive information or login credentials. Most attacks are "bulk attacks" that are not targeted and are instead sent in bulk to a wide audience. The goal of the attacker can vary, with common targets including financial institutions, email and cloud productivity providers, and streaming services. The stolen information or access may be used to steal money, install malware, or spear phish others within the target organization. Compromised streaming service accounts may also be sold on darknet markets. This type of social engineering attack can involve sending fraudulent emails or messages that appear to be from a trusted source, such as a bank or government agency. These messages typically redirect to a fake login page where users are prompted to enter their credentials. In many cases, these messages are designed to create urgency or trust by imitating legitimate communications, encouraging victims to disclose sensitive information such as login credentials or financial details.

Spear phishing Spear phishing attacks are often more effective than general phishing attempts because they are tailored to specific individuals and leverage personal or organizational information to increase credibility and success rates. These attacks often target executives or those in financial departments with access to sensitive financial data and services. Spear phishing often employs multiple communication methods at the same time including email, SMS, and calls to create a false sense of urgency. Accountancy and audit firms are particularly vulnerable to spear phishing due to the value of the information their employees have access to. The Russian government-run Threat Group-4127 (Fancy Bear; GRU Unit 26165) targeted Hillary Clinton's 2016 presidential campaign with spear phishing attacks on over 1,800 Google accounts, using the accounts-google.com domain to threaten targeted users. A study on spear phishing susceptibility among different age groups found that 43% of youth aged 18–25 years and 58% of older users clicked on simulated phishing links in daily e‑mails over 21 days. Older women had the highest susceptibility, which declined among young users during the study but remained stable among older individuals.

Voice phishing (Vishing)

Voice over IP (VoIP) is used in vishing or voice phishing attacks, where attackers make automated phone calls to large numbers of people, often using text-to-speech synthesizers, claiming fraudulent activity on their accounts. The attackers spoof the calling phone number to appear as if it is coming from a legitimate bank or institution. The victim is then prompted to enter sensitive information or connected to a live person who uses social engineering tactics to obtain information. Vishing takes advantage of the public's lower awareness and trust in voice telephony compared to email phishing.

SMS phishing (smishing)

SMS phishing or smishing is a phishing attack using mobile text messages to deliver bait messages. The victim is usually asked to click a link, call a phone number, or contact an email address provided by the attacker. They may be asked to provide private information, such as login credentials. Attackers may pretend to be government officers, customer support, shippers, colleague, boss, or a wrong number. The range of possibilities requires permanent vigilance and critical thinking to detect attacks. Smishing messages may be identified when they come from unusual phone numbers. The difficulty in identifying illegitimate links can be compounded on mobile devices due to the limited display of URLs in mobile browsers. These kinds of scams apply various forms of social engineering including scammers that pretend to be financial institutions or customer service.

Page hijacking

Page hijacking involves redirecting users to malicious websites or exploit kits by compromising legitimate web pages, often using cross site scripting. Hackers may insert exploit kits such as MPack into compromised websites to exploit legitimate users visiting the server. Page hijacking can also involve insertion of malicious inline frames, allowing exploit kits to load. This tactic is often used together with watering hole attacks on corporate targets.

QR code phishing (quishing)

… excerpt ends here. Continue reading the full article.

Illustrations

Phishing illustration
Phishing: A typical style of SMS phishing message
A typical style of SMS phishing message
Phishing: A fake virus notification
A fake virus notification
Phishing: Frame of an animation by the U.S. Federal Trade Commission intended to educate citizens about phishing tactics
Frame of an animation by the U.S. Federal Trade Commission intended to educate citizens about phishing tactics
Phishing: Screenshot of Firefox 2.0.0.1 Phishing suspicious site warning
Screenshot of Firefox 2.0.0.1 Phishing suspicious site warning

Worked examples

Example 1 — a first encounter with Phishing

Start with the simplest possible case. Write down what Phishing claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In engineering, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Phishing before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Phishing ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Phishing

In research
Phishing appears in engineering research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Phishing in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Phishing is common in secondary-school and first-year university syllabi. It links to neighbouring topics Confidence tricks, Cybercrime, Deception, so understanding it makes those chapters shorter.
In everyday life
Look for Phishing outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Phishing in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Phishing means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Phishing out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Phishing in simple terms?

Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted…

Why does Phishing matter?

Because it connects several engineering ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Phishing?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Phishing.

Tags

  • Confidence tricks
  • Cybercrime
  • Deception
  • Fraud
  • Identity theft
  • Internet terminology
  • Organized crime activity
  • Social engineering (security)
  • Spamming
  • Types of cyberattacks

Keep exploring