What is phishing, really?
Phishing is a scam in which someone poses as a party you trust — your bank, a supplier, a parcel service, your employer or even a colleague — to get you to do something you normally wouldn't: enter a password, transfer money, open an attachment or click a link.
The word comes from 'fishing': the scammer casts out some bait and hopes someone bites. There's no break-in through complicated technical tricks — the attacker simply asks you, wrapped in a believable story. You're not the target because you're a computer, but because you're a human being.
Why it's such a big problem
Phishing has for years been the number one way organisations get hacked and individuals lose money. The reason is simple: it's cheap, it scales endlessly (one email can go to a million people), and it targets the weakest link that no antivirus program can patch — the human behind the screen.
For a business, only one employee needs to click to put an entire network at risk: stolen login details, ransomware, or a fake invoice that gets paid. For an individual, one moment of inattention can mean a cleaned-out bank account or a hijacked account.
The good news: because phishing targets people and not technology, you can also arm yourself against it as a person. That's exactly what you'll learn in this course.
- Think back to a suspicious message you once received yourself (a 'parcel could not be delivered', an 'account blocked', a strange request from a 'colleague').
- Write down in one sentence what the message wanted you to do.
- Keep this. By the end of the course you'll recognise exactly why it was suspicious.
- What is at the heart of phishing: a technical break-in or the deception of a human?
- Why is a single clicking employee a risk to an entire company?
- Why is shame after a slip-up dangerous?