What is phishing?¶
Phishing is an attempt to persuade someone to take an action that benefits the offender, usually by impersonating a trusted person, organisation or service.
Avoid the dangerous assumption¶
The dangerous assumption is that phishing is only a badly written email asking for a password.
It can arrive by email, text message, social platform, collaboration tool, telephone call or another communication service. It may ask the recipient to click a link, open a file, enter credentials, approve a login, transfer money, reveal information or install software.
The communication is only one part of the method.
A phishing incident may involve:
- an impersonated sender
- a compromised legitimate account
- a malicious domain or website
- a fake login page
- a malicious attachment
- a telephone follow-up
- a request to approve authentication
- a payment or account-change instruction.
Investigators should identify the action the sender was trying to cause.
Was the objective credential theft, malware delivery, payment diversion, account takeover, information gathering or something else?
Preserve the original message or communication, not just a screenshot. Record the delivery platform, sender identifier, recipient, timestamp, links, attachments and any associated account or device activity.
Do not assume the apparent sender created the message. Email addresses, display names, telephone numbers and social accounts can be spoofed, compromised or impersonated.
Also distinguish delivery from success. A phishing message may have arrived without being opened. A link may have been clicked without credentials being entered. Credentials may have been entered without later misuse.
The phishing material can help show method, preparation and intent. It will not necessarily establish the identity of the person who created or sent it.
Operational takeaway¶
Identify what action the phishing communication was designed to cause, preserve the original material and separate delivery, interaction and successful compromise.