The Short Version
Phishing (pronounced like “fishing”) is when a scammer sends a fake email, text, or message that looks like it’s from a trusted company (like your bank, Amazon, or Netflix). Their goal is to “hook” you into clicking a link and giving them your password or credit card number.
The Everyday Analogy
Imagine someone knocking on your front door wearing a fake UPS uniform, holding a clipboard. They tell you there is a package waiting for you, but you need to pay a $2 delivery fee and provide your credit card right there on the porch.
Phishing is exactly the same thing, just done digitally through your inbox.
How to Spot a Phishing Attempt
- The “Urgency” Trick: The message almost always claims something is wrong and you must act immediately (“Your account will be suspended in 24 hours!”).
- The Fake Link: If you hover your mouse over the link (without clicking it), the website address shown at the bottom of your screen looks wrong (e.g.,
amazon-support-help-123.cominstead ofamazon.com). - Generic Greetings: Instead of using your name, it says “Dear Customer” or “Dear Member.”
The Golden Rule
If you ever receive an email telling you to log in to resolve an issue, do not click the link in the email. Instead, open your web browser, type in the website address yourself (like paypal.com), and log in there to see if the alert is real.
Other Dictionary Terms
Access Control List (ACL)
A list of rules that specifies which users or systems are granted or denied access to a particular object or system resource.
Dictionary TermAdvanced Persistent Threat (APT)
A stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.
Dictionary TermARP Spoofing
A type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network.