IT Glossary
What is Phishing?
Digital angling: messages impersonating trusted senders — banks, colleagues, suppliers — to steal your passwords, data or money.
The most successful cyberattack in history breaks no software at all — it persuades you to open the door yourself. Phishing is the bait message impersonating a trusted sender — your bank, the tax authority, a courier, a colleague, Microsoft — nudging you toward one action: clicking through to a cloned login page (the password typed there goes straight to the attacker), opening an infected attachment, or paying a subtly altered invoice. The forms keep evolving as defenses improve: the clumsy email full of typos has been joined by spear phishing (targeted, well-researched, flawlessly written with AI), smishing (text messages about a waiting parcel), vishing (voice calls, including cloned voices) and QR-code lures that slip past email filters. For companies, the prized targets are employee mailboxes — a compromised account becomes a launchpad, since the attacker reads real correspondence, learns the relationships, then strikes clients and suppliers in your name inside genuine conversations — and payment workflows. Mature defense has three floors, ranked by return on effort: two-factor authentication on every account that matters (hardware keys and passkeys are practically phishing-proof); trained reflexes — not bravado, but habits: sender address checked, links opened from bookmarks rather than messages, money and data requests confirmed on a second channel, periodic simulations keeping the guard up; and technical hygiene — modern mail filtering plus SPF, DKIM and DMARC on your own domain, so you are not the one easily imitated. The sentence that summarizes the field: phishing succeeds not where people are stupid but where they are rushed — real defense makes verification easier than haste.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
Accounts survive stolen passwords
2FA — ideally hardware keys or passkeys — means the phished password is no longer enough: the door also demands the key the attacker lacks.
Trained reflexes, not just warnings
Periodic simulations with feedback turn "beware of phishing" from slogan into measurable reflex — click rates fall sharply and stay down.
Payments procedurally immunized
Confirming any account change or unusual payment on a separate channel cuts off exactly the fraud that hurts most — the irreversible transfer.
Frequently asked questions
How do I recognize a well-crafted phishing email?
AI-written ones no longer betray themselves through typos — check the anchors that are hard to fake instead: the sender's real address (not the display name), the domain behind the link (hover before clicking), and above all the nature of the request: urgency plus a sensitive action (login, payment, data) means verification on another channel, however authentic it looks. Golden rule: no password ever typed on a page opened from a received link.
An employee clicked and entered their password — what are the first actions?
In order, within minutes: change that account's password (and anywhere it was reused), invalidate active sessions, check the mailbox's forwarding rules (attackers install silent redirects), verify 2FA, then bring in IT to investigate what was accessed and what messages went out. No witch hunts — the employee who reports within five minutes is the hero of the story; the one who stays silent out of fear turns an incident into a disaster.
How do I stop criminals from sending email in my company's name?
Configure the SPF, DKIM and DMARC trio on your domain, with an enforcement policy — DNS records telling the world which servers may send mail as you; without them, anyone can dispatch messages "from" your office address. It is a few hours of technical work, verifiable with free tools — and increasingly a precondition for your own legitimate email reaching inboxes instead of spam.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247