What is phishing?¶
Phishing is deceptive communication designed to make somebody do something that benefits the offender.
That may mean clicking a link, opening a file, entering credentials, approving a login, making a payment or giving away information.
The useful investigative question is not simply “was this phishing?”
It is:
what action was the communication trying to cause, and what actually happened afterwards?
Phishing can arrive through several channels¶
It may come through:
- email;
- text message;
- social media;
- collaboration platform;
- messaging service;
- telephone call;
- fake website reached from another source.
The delivery method changes, but the basic idea is the same: somebody is being manipulated into an action.
Think of the chain, not just the message¶
This makes the investigation much clearer.
Preserve the original delivery evidence¶
Where available, keep:
- native email/message;
- sender and recipient identifiers;
- exact time;
- full header or platform metadata;
- links;
- attachments;
- displayed content;
- thread/context.
A screenshot may still be useful, but the original communication usually preserves much more.
Delivery and success are separate¶
A phishing email can be delivered without being opened.
It can be opened without the link being clicked.
A link can be clicked without credentials being entered.
Credentials can be entered without later account access.
Each stage has its own evidence.
What can a phishing email actually prove? takes the email-specific question further.
Sender identity also needs care¶
The displayed sender may be spoofed.
A genuine account may have been compromised.
Infrastructure may be rented or shared.
So use the message to establish what was presented and how it was delivered, then follow account, device and provider records for attribution.
The practical point is: phishing is a chain of persuasion and response. Preserve the original communication, identify the action it sought, and prove what the recipient and systems actually did next.