Phishing

Phishing is a social engineering attack that uses deceptive emails, messages, or websites to trick people into handing over sensitive information or taking a harmful action. The attacker poses as someone trusted, a bank, an employer, a familiar service, and pressures the target into entering credentials, approving a payment, or opening a malicious attachment. It works because it targets human judgment rather than a software flaw.

The family has several variants worth recognizing. Spear phishing is aimed at a specific person using personal detail, whaling goes after executives, vishing uses phone calls, and smishing arrives by text message. What makes phishing so stubborn is that even strong technical filtering cannot catch everything, and a single convincing message to one busy employee can hand an attacker their first foothold. That is why it remains one of the most common ways breaches begin.

Why does phishing matter for the CISSP exam?

Phishing is studied under social engineering threats in Domain 1: Security and Risk Management, the largest exam domain at 16 percent. Know the variants, the technical controls that reduce it, and why awareness training is the essential complement.

CISA offers guidance through Secure Our World.