Overview
Phishing substitutes human trust for technical exploitation. The message creates urgency, borrows a known brand, and routes the victim to a look-alike domain that captures credentials in real time.\nBulk phishing is a numbers game; the same infrastructure powers targeted follow-up once a credential is captured.
Indicators of Compromise
Signals that suggest this is present on a system.
- Look-alike domains registered days before a campaign
- Login pages posting credentials to a foreign origin
- Unexpected MFA prompts after clicking a mail link
Controls that stop it
-
Enforce Multi-Factor Authentication
Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.