Threats

What is Phishing?

Definition

A social engineering attack that uses email, text or messaging to trick people into clicking a malicious link, opening an attachment or handing over credentials.

How it works

Phishing remains one of the most common ways attackers get in. Messages imitate trusted brands, colleagues or suppliers, and increasingly use convincing login pages that can capture multi-factor codes.

Defence is layered: email filtering, phishing-resistant authentication, staff who know how to spot and report suspicious messages, and a team that investigates reports quickly.

Key points

  • The most common initial access route
  • Increasingly targets credentials and MFA codes
  • Reported emails are a valuable early warning
  • Simulations and training reduce click rates

Common questions

Does phishing training work?

Regular, realistic simulations combined with short, targeted training reduce risk, especially when reporting is quick and easy.

What happens to reported emails?

With Decoy, every reported email is investigated by an analyst and the reporter gets a verdict.

Talk to someone who does this every day

Questions about Phishing? Our team will give you a straight answer.

Contact us