High severity Attack Technique

Phishing

Fraudulent messages push victims to a fake login page or a malicious attachment.

Overview

Phishing substitutes human trust for technical exploitation. The message creates urgency, borrows a known brand, and routes the victim to a look-alike domain that captures credentials in real time.\nBulk phishing is a numbers game; the same infrastructure powers targeted follow-up once a credential is captured.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Look-alike domains registered days before a campaign
  • Login pages posting credentials to a foreign origin
  • Unexpected MFA prompts after clicking a mail link

Controls that stop it

  • Enforce Multi-Factor Authentication

    Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used