What is Phishing?

social-engineering OpenTrojan Team Updated 2026-08-20

Phishing is a social engineering attack that tricks people into revealing credentials or installing malware. Learn to recognize and avoid it.

AI Answer

Phishing is a social engineering attack where attackers impersonate trusted parties to steal credentials, money, or install malware. Avoid it by verifying sender identity, checking URLs, and never clicking unsolicited links.

Definition

Phishing is a type of social engineering attack that uses fraudulent messages — often email — to trick victims into revealing sensitive information or installing malware.

Overview

Phishing is one of the most common and effective attack vectors. Attackers impersonate banks, employers, or platforms to trick users into acting.

Common signs

  • Urgency or fear (“your account will be suspended”).
  • Mismatched or suspicious URLs.
  • Unexpected attachments or links.
  • Requests for credentials or one-time codes.
  • Poor grammar and generic greetings.

How to verify

  1. Hover over links to inspect the real destination.
  2. Contact the sender through a known-good channel.
  3. Check the sender domain carefully for typosquats.
  4. Never provide one-time codes unless you initiated the request.

Defense

Use multi-factor authentication, unique passwords per account, and report suspicious messages to your security team or provider.

References