La page se tourne.
Le prochain chapitre arrive…
Psst… appropriez-vous votre lecture.
Polices et thèmes se trouvent dans Apparence. Vos yeux ont aussi leur mot à dire.
Le prochain chapitre arrive…
A personal code shown in legitimate exchange emails so fakes are easier to spot.
Vérification de la lecture vocale du navigateur…
Cette lecture est actuellement disponible en anglais. L’interface utilise la langue choisie.
Lire l’original anglais →Phishing is a form of social engineering and a scam in which attackers deceive people into revealing sensitive information or installing malware. Phishing can be used for credential theft, session hijacking, malware delivery, or command execution. Some attacks transparently relay authentication to a legitimate site, allowing the attacker to capture credentials and authenticated sessions. Phishing is a common initial-access method, and Large language models can automate personalized phishing at low cost.
Common forms include general email phishing, targeted spear phishing and whaling, voice phishing (vishing), and SMS phishing (smishing). Other forms use QR codes or relay authentication through an adversary-in-the-middle.
Measures to prevent or reduce the impact of phishing attacks include legislation, user education, public awareness, and technical security measures.
Phishing attacks, often delivered via email, attempt to trick individuals into giving away sensitive information or login credentials. General phishing is sent broadly, whereas spear phishing targets a particular person or group. The goal of the attacker can vary, with common targets including financial institutions, email and cloud productivity providers, and streaming services. The stolen information or access may be used to steal money, install malware, or spear phish others within the target organization. Compromised streaming service accounts may also be sold on darknet markets.
Such attacks can involve messages that appear to be from a trusted source, such as a bank or government agency. The messages may redirect to a counterfeit login page that collects credentials.
Spear phishing attacks can be more effective than general phishing attempts because they are tailored to specific individuals and use personal or organizational information to increase credibility. Whaling is a form of targeted phishing directed at senior decision-makers with access to valuable information. Automation can make personalized messages inexpensive enough to use at scale.
A field experiment sent simulated phishing emails to 100 younger and 58 older adults over 21 days. In this sample, 43% of participants clicked at least one simulated phishing link, and older women recorded the highest click rate among the four age-and-gender groups studied. Susceptibility declined among younger participants during the study but remained stable among older participants.
The Russian government-run Threat Group-4127 (Fancy Bear; GRU Unit 26165) used spear phishing against targets associated with Hillary Clinton's 2016 presidential campaign and the Democratic National Committee. SecureWorks linked the group to a separate 2015 campaign that targeted more than 1,800 Google accounts and used the spoofed domain accoounts-google.com.
Vishing, or voice phishing, uses telephone or Voice over IP calls to deliver the lure. Attackers may make automated calls, use text-to-speech, and claim that fraudulent activity has occurred on the recipient's account. They may spoof the caller number so that it appears to come from a bank or other institution. The victim is then prompted to enter sensitive information or connected to a person who uses social-engineering tactics to obtain it. A 2008 study found that voice phishing could exploit greater trust in voice telephony than in email.
Smishing is phishing delivered through SMS or MMS, often through an impersonating message, a malicious link, or a malware lure. The victim may be asked to click a link, call a phone number, or provide private information such as login credentials. The limited display of URLs on mobile devices can make illegitimate links harder to identify.
Sélectionné et remis en forme à partir de Phishing, par ses contributeurs, sous CC BY-SA 4.0. Révision 1376047697. Les sections et la mise en forme ont été abrégées ; la révision liée fournit le contexte complet et l’historique des contributions. Ce texte de référence conserve sa licence. Les liens de citation supplémentaires proviennent de cette révision et n’ont pas été vérifiés indépendamment ici.