Phishing
Features of one example phishing email
| ||||||||||||||||
Phishing is a form of social engineering and a scam in which attackers deceive people into revealing sensitive information or installing malware. Phishing can be used for credential theft, session hijacking, malware delivery, or command execution. Some attacks transparently relay authentication to a legitimate site, allowing the attacker to capture credentials and authenticated sessions. Phishing is a common initial-access method, and Large language models can automate personalized phishing at low cost.
Common forms include general email phishing, targeted spear phishing and whaling, voice phishing (vishing), and SMS phishing (smishing). Other forms use QR codes or relay authentication through an adversary-in-the-middle.
Measures to prevent or reduce the impact of phishing attacks include legislation, user education, public awareness, and technical security measures.
Types
[edit]Email phishing
[edit]Phishing attacks, often delivered via email, attempt to trick individuals into giving away sensitive information or login credentials.[1] General phishing is sent broadly, whereas spear phishing targets a particular person or group.[2] The goal of the attacker can vary, with common targets including financial institutions, email and cloud productivity providers, and streaming services.[3] The stolen information or access may be used to steal money, install malware, or spear phish others within the target organization.[4] Compromised streaming service accounts may also be sold on darknet markets.[5] Such attacks can involve messages that appear to be from a trusted source, such as a bank or government agency. The messages may redirect to a counterfeit login page that collects credentials.[2]
Spear phishing
[edit]
Spear phishing attacks can be more effective than general phishing attempts because they are tailored to specific individuals and use personal or organizational information to increase credibility.[6] Whaling is a form of targeted phishing directed at senior decision-makers with access to valuable information.[2] Automation can make personalized messages inexpensive enough to use at scale.[7]
A field experiment sent simulated phishing emails to 100 younger and 58 older adults over 21 days. In this sample, 43% of participants clicked at least one simulated phishing link, and older women recorded the highest click rate among the four age-and-gender groups studied. Susceptibility declined among younger participants during the study but remained stable among older participants.[8]
The Russian government-run Threat Group-4127 (Fancy Bear; GRU Unit 26165) used spear phishing against targets associated with Hillary Clinton's 2016 presidential campaign and the Democratic National Committee.[9] SecureWorks linked the group to a separate 2015 campaign that targeted more than 1,800 Google accounts and used the spoofed domain accoounts-google.com.[10]
Voice phishing (vishing)
[edit]
Vishing, or voice phishing, uses telephone or Voice over IP calls to deliver the lure.[2][11] Attackers may make automated calls, use text-to-speech, and claim that fraudulent activity has occurred on the recipient's account. They may spoof the caller number so that it appears to come from a bank or other institution. The victim is then prompted to enter sensitive information or connected to a person who uses social-engineering tactics to obtain it.[11] A 2008 study found that voice phishing could exploit greater trust in voice telephony than in email.[12]
SMS phishing (smishing)
[edit]

Smishing is phishing delivered through SMS or MMS, often through an impersonating message, a malicious link, or a malware lure.[2] The victim may be asked to click a link, call a phone number, or provide private information such as login credentials.[13] The limited display of URLs on mobile devices can make illegitimate links harder to identify.[14]
QR code phishing (quishing)
[edit]In "quishing" (QR code phishing), a code directs the person who scans it to a malicious website. Because QR codes conceal their destination in a form people cannot read directly, users may struggle to distinguish malicious codes from legitimate ones. Across three experiments with 1,876 participants, almost no participants identified QR-based phishing.[15] Bogus codes may be sent by email or social media or printed on stickers placed over legitimate QR codes, such as those on car park notices.[16] QR phishing can also be combined with a browser-in-the-browser lure to induce the victim to approve the attacker's two-factor access.[17] The UK's National Cyber Security Centre assesses QR-code phishing as less common than other types of cyber fraud.[18]
Adversary-in-the-middle phishing
[edit]In adversary-in-the-middle (AiTM) phishing, a victim interacts with an impostor site that relays the authentication exchange to the legitimate service in real time. Authentication methods that require a person to enter a one-time code are not phishing-resistant because the impostor can relay that code to the real verifier.[19] Toolkits such as Evilginx automate this pattern by relaying credentials and a two-factor code while the victim is interacting with the phishing site.[20] An authenticated web session is commonly maintained with a session cookie; possession of such a bearer secret can permit use of the session until it expires or is invalidated.[19] Services that use short-lived session cookies restrict how long the captured session can be reused.[20]
Techniques
[edit]Drive-by compromise and phishing
[edit]MITRE ATT&CK classifies drive-by compromise and phishing as separate initial-access techniques.[21][22] In a drive-by compromise, attackers place malicious code on a website that a victim visits, for example by compromising a legitimate site or injecting scripts or inline frames. If the site is selected because it is frequented by a particular community or organization, the operation is commonly called a watering-hole attack.[21] A phishing message can nevertheless link to a website used for drive-by compromise, so the two techniques can occur in the same campaign.[21][22]
Link manipulation
[edit]Phishing links may use misspelled registered domains or deceptive subdomains to conceal their destination.[23] In the example http://www.yourbank.example.com/, the registered domain is example.com, while yourbank is only a subdomain. Another tactic is to make the link's displayed text appear trustworthy while the link itself leads to the phisher's site.
Internationalized domain names (IDNs) can be exploited via IDN spoofing[24] or homograph attacks[25] to allow attackers to create fake websites with visually identical addresses to legitimate ones. Separately, phishers have used open URL redirectors on trusted websites to disguise malicious destinations.[26][27][28] In http://www.exаmple.com/, for example, the third character is not the Latin letter 'a' but the Cyrillic character 'а'. A person who follows that link visits the malicious site http://www.xn--exmple-4nf.com/.
Social engineering
[edit]
Phishing often uses social engineering techniques to trick users into performing actions such as clicking a link, opening an attachment, or revealing sensitive information. It often involves impersonating a trusted entity and creating a sense of urgency,[29] like threatening to close or seize a victim's bank or insurance account.[30] Phishing attacks may rely on spoofing an organization's website to trick victims into entering credentials.[31]

Generative AI can make phishing and other social-engineering content more convincing by producing realistic text and images. It can also reduce the effort needed to personalize and automate attacks.[32][7]
In a 2026 experiment with 7,700 participants, LLM-personalized emails produced almost three times the click rate of generic phishing emails, at an estimated cost of about US$0.03 per message.[7]
History
[edit]Early history
[edit]Phishing was documented on AOL in 1995, and the term appeared in print by March 1997. Its spelling is generally linked to the earlier term "phreaking".[2] AOHell, released in 1994, allowed users to impersonate AOL staff and send instant messages asking victims to reveal their passwords.[33][34]
2000s
[edit]In the 2000s, phishing attacks became more organized and targeted. The first known direct attempt against a payment system, E-gold, occurred in June 2001, and shortly after the September 11 attacks, a "post-9/11 id check" phishing attack followed.[35] The first known phishing attack against a retail bank was reported in September 2003.[36] Between May 2004 and May 2005, approximately 1.2 million computer users in the United States suffered losses caused by phishing, totaling approximately US$929 million.[37] Phishing was recognized as a fully organized part of the black market, and specializations emerged on a global scale that provided phishing software for payment, which was assembled and used in phishing campaigns by organized gangs.[38][39] The United Kingdom banking sector suffered from phishing attacks, with losses from web banking fraud almost doubling in 2005 compared to 2004.[40][41] In 2006, almost half of phishing thefts were committed by groups operating through the Russian Business Network based in St. Petersburg.[42] Email scams posing as the Internal Revenue Service were also used to steal sensitive data from U.S. taxpayers.[43] A phishing campaign targeted Myspace users in 2006.[44] In 2007, 3.6 million adults lost US$3.2 billion due to phishing attacks.[45] The Anti-Phishing Working Group reported receiving 115,370 phishing email reports from consumers, with the US and China each hosting more than 25% of the phishing pages in the third quarter of 2009.[46]
2010s
[edit]In 2011, information related to RSA SecurID security tokens was stolen through a phishing attack.[47][48] Chinese phishing campaigns also targeted high-ranking officials in the US and South Korean governments and military, as well as Chinese political activists.[49][50]
In August 2013, Outbrain suffered a spear-phishing attack,[51] and in November 2013, 110 million customer and credit card records were stolen from Target customers through a phished subcontractor account.[52] Subsequently, the CEO and IT security staff were dismissed.[53]
In August 2014, iCloud leaks of celebrity photos were based on phishing e-mails that were sent to victims and looked like they came from Apple or Google.[54] In November 2014, phishing attacks on ICANN gave attackers administrative access to the Centralized Zone Data System, as well as data about users in the system and access to ICANN's public Governmental Advisory Committee wiki, blog, and whois information portal.[55]
Fancy Bear was linked to spear-phishing attacks against the Pentagon email system in August 2015,[56][57] and the group used a zero-day exploit in Java in a spear-phishing attack on the White House and NATO.[58][59] Fancy Bear carried out spear phishing attacks on email addresses associated with the Democratic National Committee in the first quarter of 2016.[60][61]
In August 2016, members of the Bundestag and political parties such as Linken-faction leader Sahra Wagenknecht, Junge Union, and the CDU of Saarland were targeted by spear-phishing attacks suspected to be carried out by Fancy Bear. In August 2016, the World Anti-Doping Agency reported receiving phishing emails that were sent to users of its database and claimed to be official WADA communications, but were consistent with the Russian hacking group Fancy Bear.[62][63][64]
Qatar recorded 93,570 phishing attacks in the first quarter of 2017.[65] In August 2017, customers of Amazon faced the Amazon Prime Day phishing attack, when hackers sent out seemingly legitimate deals to customers of Amazon. When Amazon's customers attempted to make purchases using the "deals", the transaction would not be completed, prompting the retailer's customers to input data that could be compromised and stolen.[66] In 2018, the company block.one, which developed the EOS.IO blockchain, was attacked by a phishing group who sent all customers phishing emails aimed at intercepting users' cryptocurrency wallet keys, and a later attack targeted airdrop tokens.[67]
2020s
[edit]The July 15, 2020, Twitter breach combined a counterfeit internal-service login page with telephone social engineering. A 17-year-old hacker and accomplices set up a fake website resembling Twitter's internal VPN provider used by remote working employees. Posing as helpdesk staff, they called multiple Twitter employees, directing them to submit their credentials to the fake VPN website.[68] Using the details supplied by the unsuspecting employees, they were able to seize control of several high-profile user accounts, including those of Barack Obama, Elon Musk, Joe Biden, and Apple Inc.'s company account. The hackers then sent messages to Twitter followers soliciting Bitcoin, promising to double the transaction value in return. The hackers collected 12.86 BTC (about $117,000 at the time).[69]
An analysis of 4,875 reported incidents affecting the European threat landscape from July 2024 through June 2025 found that phishing accounted for about 60% of observed initial-access cases.[70] Phishing-as-a-service platforms automate branded phishing kits by cloning login pages and distributing links through templated infrastructure, lowering the skill needed to run a campaign. ENISA reported that the Darcula platform had impersonated more than 200 organizations and targeted users in more than 100 countries.[70]
Anti-phishing
[edit]Anti-phishing programs combine measures at the training, mail, browser, network, authentication, and incident-response layers.[71]
User training
[edit]
Organizations commonly use simulated-phishing exercises that show training material after a recipient interacts with a test message.[72] One 2024 field study of a partner company's employees found that, in that setting, the measured benefit of embedded training came mainly from the periodic reminder created by the exercise rather than from material shown after a click; employees often did not consume that material, and mandatory completion did not improve secure behavior.[72]
Technical approaches
[edit]Modern technical defenses use overlapping controls rather than relying on a single filter or authentication step.
Mail filtering and sender authentication
[edit]Mail systems use content and reputation filtering alongside standards that authenticate sending domains.[3] Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) provide domain-level authentication, while DMARC checks whether a passing SPF or DKIM identifier aligns with the author domain shown in the message's From field and lets a domain owner publish handling and reporting policies.[73] DMARC addresses only some forms of exact-domain spoofing: it does not validate display names, visually similar domains, or message content, and a DMARC pass does not establish that a message is safe.[73] In a 2021 experiment covering 30 popular mail services and 23 email clients, every tested service or client was vulnerable to at least one newly identified sender-spoofing technique that exploited inconsistencies in the authentication chain.[74]
Browser and network blocking
[edit]Major desktop and mobile browsers display warnings for destinations on anti-phishing blocklists, sometimes supplemented by heuristic classifiers. These systems are reactive, so there can be a gap between a site's deployment and its addition to a list, and evasive sites may avoid prompt classification.[75] At the network level, protective DNS can refuse to resolve domains identified by phishing threat feeds and can log matching queries, adding an enforcement layer that does not depend on features in each client.[76]
Phishing-resistant authentication and session protection
[edit]Multi-factor authentication can limit the value of a stolen password, but not every second factor resists phishing. NIST does not classify manually entered one-time passwords or out-of-band codes as phishing-resistant because an impostor verifier can relay the value to the real service.[19] WebAuthn instead binds a cryptographic response to the authenticated relying-party domain; when correctly implemented, syncable WebAuthn authenticators, commonly called passkeys, can provide phishing resistance.[77]
An adversary-in-the-middle proxy can relay a password and a manually entered one-time code during a live login.[19] Authentication may then create a browser session maintained by a cookie used as a bearer secret; possession of that secret, rather than repeated entry of the user's authenticators, maintains the session.[19] Phishing-resistant sign-in should therefore be paired with controls for the session and its tokens. NIST recommends short, defined lifetimes for identity and access tokens, revocation and audience restrictions, session monitoring, and sender-constrained or proof-of-possession tokens where feasible.[78]
Detection, reporting and takedown
[edit]Reports from users and automated detection systems can feed newly discovered URLs to anti-phishing blocklists. Operators may also ask a hosting provider or domain registrar to disable the infrastructure, but takedown depends on cooperation and may take hours or days; blocklisting can act sooner, although it has its own coverage and latency gaps.[75] A response can therefore combine rapid reporting and blocking with token revocation after a compromise and, where possible, infrastructure takedown.[75][78]
Legal responses
[edit]Phishing is usually addressed through laws covering the conduct involved rather than through a single offense. In the United States, the Computer Fraud and Abuse Act applies to specified forms of unauthorized computer access, while other federal provisions may apply to wire fraud, access-device fraud, and aggravated identity theft, depending on the facts.[79]
In the European Union, Directive (EU) 2019/713 requires member states to criminalize specified conduct involving non-cash payment instruments; its recitals identify phishing and redirection to imitation websites as ways of obtaining payment instruments for fraud.[80] In England and Wales, prosecution guidance treats phishing as a form of cyber-enabled fraud and points prosecutors to the Fraud Act 2006, the Computer Misuse Act 1990, and related legislation, with the charge determined by the conduct.[81]
Because phishing campaigns, infrastructure, victims, and evidence can be spread across several countries, enforcement also relies on international cooperation. The Budapest Convention combines common offense categories with powers for obtaining electronic evidence and mechanisms for cooperation among its parties.[82] As of 20 September 2026[update], the United Nations Convention against Cybercrime had 82 signatories and three parties but was not yet in force; under Article 65, it will enter into force 90 days after the fortieth ratification, acceptance, approval, or accession.[83]
See also
[edit]- 2016–2021 literary phishing thefts – Ongoing international crime incident
- Anti-phishing software – Software to protect against scams
- Brandjacking – Assuming the online identity of another entity
- Clickjacking – Malicious technique of tricking a Web user
- In-session phishing – Type of phishing attack
- Internet fraud – Fraud or deception using the Internet
- Trojan horse (computing) – Type of malware
- Typosquatting – Form of cybersquatting which relies on mistakes when inputting a website address
References
[edit]- ↑ Jansson, K.; von Solms, R. (November 9, 2011). "Phishing for phishing awareness". Behaviour & Information Technology. 32 (6): 584–593. doi:10.1080/0144929X.2011.632650. ISSN 0144-929X. S2CID 5472217.
- 1 2 3 4 5 6 Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9.
- 1 2 Furnell, Steven; Millet, Kieran; Papadaki, Maria (July 2019). "Fifteen years of phishing: can technology save us?". Computer Fraud & Security. 2019 (7): 11–16. doi:10.1016/S1361-3723(19)30074-0. S2CID 199578115.
- ↑ "Spoofing and Phishing". Federal Bureau of Investigation. Retrieved May 30, 2026.
- ↑ Waddell, Kaveh (February 11, 2016). "The Black Market for Netflix Accounts". The Atlantic. Retrieved March 21, 2021.
- ↑ Alsharnouby, Mohamed; Alaca, Furkan; Chiasson, Sonia (2015). "Why phishing still works: User strategies for combating phishing attacks". International Journal of Human-Computer Studies. 82: 69–82. doi:10.1016/j.ijhcs.2015.05.005. Retrieved May 6, 2026.
- 1 2 3 Czybik, Stefan; Kouam, Anne Josiane; Heubl, Peter; Nold, Jan Magnus; Rieck, Konrad (2026). "A Large-Scale Study of Personalized Phishing using Large Language Models". 35th USENIX Security Symposium. USENIX Association. pp. 1687–1706. ISBN 978-1-939133-58-8. Retrieved September 20, 2026.
- ↑ Lin, Tian; Capecci, Daniel E.; Ellis, Donovan M.; Rocha, Harold A.; Dommaraju, Sandeep; Oliveira, Daniela S.; Ebner, Natalie C. (September 2019). "Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content". ACM Transactions on Computer-Human Interaction. 26 (5): 32. doi:10.1145/3336141. ISSN 1073-0516. PMC 7274040. PMID 32508486.
- ↑ Nakashima, Ellen; Harris, Shane (July 13, 2018). "How the Russians hacked the DNC and passed its e‑mails to WikiLeaks". The Washington Post. Archived from the original on March 21, 2021. Retrieved February 22, 2019.
- ↑ "Threat Group-4127 targets Google accounts". Secureworks. June 26, 2016. Archived from the original on August 11, 2019. Retrieved October 12, 2017.
- 1 2 Griffin, Slade E.; Rackley, Casey C. (September 26, 2008). "Vishing". Proceedings of the 5th Annual Conference on Information Security Curriculum Development. InfoSecCD '08. New York: Association for Computing Machinery. pp. 33–35. doi:10.1145/1456625.1456635. ISBN 978-1-60558-333-4.
- ↑ Wang, Xinyuan; Zhang, Ruishan; Yang, Xiaohui; Jiang, Xuxian; Wijesekera, Duminda (September 22, 2008). "Voice pharming attack and the trust of VoIP". Proceedings of the 4th International Conference on Security and Privacy in Communication Networks. SecureComm '08. ACM. pp. 1–11. doi:10.1145/1460877.1460908. ISBN 978-1-60558-241-2.
- ↑ "Scam Glossary". Federal Communications Commission. Retrieved April 29, 2026.
- ↑ Mishra, Sandhya; Soni, Devpriya (August 2019). "SMS Phishing and Mitigation Approaches". 2019 Twelfth International Conference on Contemporary Computing (IC3). IEEE. pp. 1–5. doi:10.1109/IC3.2019.8844920. ISBN 978-1-7281-3591-5. S2CID 202700726.
- ↑ Kowalewski, Marvin; Lassak, Leona; Dürmuth, Markus; Schnitzler, Theodor (2025). "Scanned and Scammed: Insecurity by ObsQRity? Measuring User Susceptibility and Awareness of QR Code-Based Attacks". 34th USENIX Security Symposium. USENIX Association. pp. 1415–1434. Retrieved September 20, 2026.
- ↑ Morris, Joanna (November 18, 2023). "Thornaby: Woman targeted in £13k railway station QR code scam". BBC News. Retrieved November 5, 2024.
- ↑ Akram, Muhammad Wahid; Sood, Keshav; Ul Hassan, Muneeb; Subba, Basant (December 2025). "Exemplifying Emerging Phishing: QR-Based Browser-in-the-Browser (BiTB) Attack". IEEE Networking Letters. 7 (4): 274–278. arXiv:2505.18944. Bibcode:2025INetL...7..274A. doi:10.1109/LNET.2025.3605640. ISSN 2576-3156.
- ↑ C, David (March 11, 2024). "QR Codes—what's the real risk?". National Cyber Security Centre. Retrieved November 5, 2024.
- 1 2 3 4 5 Temoshok, David; Fenton, James L.; Choong, Yee-Yin; et al. (July 2025). Digital Identity Guidelines: Authentication and Authenticator Management (Report). NIST Special Publication. National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-63B-4.
- 1 2 Lin, Xu; Ilia, Panagiotis; Solanki, Saumya; Polakis, Jason (2022). "Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser Fingerprinting". 31st USENIX Security Symposium. USENIX Association. pp. 1651–1668. Retrieved September 20, 2026.
- 1 2 3 "Drive-by Compromise (T1189)". MITRE ATT&CK. The MITRE Corporation. October 24, 2025. Retrieved September 20, 2026.
- 1 2 "Phishing (T1566)". MITRE ATT&CK. The MITRE Corporation. May 12, 2026. Retrieved September 21, 2026.
- ↑ Lain, Daniele; Nakatsuka, Yoshimichi; Kostiainen, Kari; Tsudik, Gene; Capkun, Srdjan (2025). "URL Inspection Tasks: Helping Users Detect Phishing Links in Emails". 34th USENIX Security Symposium. USENIX Association. pp. 1435–1454. Retrieved September 20, 2026.
- ↑ Johanson, Eric. "The State of Homograph Attacks Rev1.1". The Shmoo Group. Archived from the original on August 23, 2005. Retrieved August 11, 2005.
- ↑ Evgeniy Gabrilovich & Alex Gontmakher (February 2002). "The Homograph Attack" (PDF). Communications of the ACM. 45 (2): 128. doi:10.1145/503124.503156. S2CID 73840. Archived from the original (PDF) on November 4, 2019. Retrieved September 15, 2019.
- ↑ Leyden, John (August 15, 2006). "Barclays scripting SNAFU exploited by phishers". The Register. Archived from the original on June 13, 2019. Retrieved August 10, 2017.
- ↑ Levine, Jason. "Goin' phishing with eBay". Q Daily News. Archived from the original on March 26, 2019. Retrieved December 14, 2006.
- ↑ Leyden, John (December 12, 2007). "Cybercrooks lurk in shadows of big-name websites". The Register. Archived from the original on June 23, 2019. Retrieved August 10, 2017.
- ↑ Cui, Xinyue; Ge, Yan; Qu, Weina; Zhang, Kan (2020). "Effects of Recipient Information and Urgency Cues on Phishing Detection". HCI International 2020 - Posters. Communications in Computer and Information Science. Vol. 1226. pp. 520–525. doi:10.1007/978-3-030-50732-9_67. ISBN 978-3-030-50731-2. S2CID 220523895.
- ↑ Williams, Emma J; Joinson, Adam N (January 1, 2020). "Developing a measure of information seeking about phishing". Journal of Cybersecurity. 6 (1) tyaa001. doi:10.1093/cybsec/tyaa001. hdl:1983/7ba801b9-f6b8-4fc1-8393-de5238e76b2f. ISSN 2057-2085.
- ↑ "Spoofing and Phishing". Federal Bureau of Investigation. Archived from the original on September 10, 2026. Retrieved September 16, 2026.
- ↑ Schmitt, Marc; Flechais, Ivan (October 12, 2024). "Digital deception: generative artificial intelligence in social engineering and phishing". Artificial Intelligence Review. 57 (12) 324. doi:10.1007/s10462-024-10973-2. ISSN 1573-7462.
- ↑ Langberg, Mike (September 8, 1995). "AOL Acts to Thwart Hackers". San Jose Mercury News. Archived from the original on April 29, 2016. Retrieved March 14, 2012.
- ↑ Rekouche, Koceilah (2011). "Early Phishing". arXiv:1106.4692 [cs.CR].
- ↑ "GP4.3 – Growth and Fraud — Case #3 – Phishing". Financial Cryptography. December 30, 2005. Archived from the original on January 22, 2019. Retrieved February 23, 2007.
- ↑ Sangani, Kris (September 2003). "The Battle Against Identity Theft". The Banker. 70 (9): 53–54.
- ↑ Kerstein, Paul (July 19, 2005). "How Can We Stop Phishing and Pharming Scams?". CSO. Archived from the original on March 24, 2008.
- ↑ "In 2005, Organized Crime Will Back Phishers". IT Management. December 23, 2004. Archived from the original on December 31, 2010.
- ↑ Abad, Christopher (September 2005). "The economy of phishing: A survey of the operations of the phishing market". First Monday. Archived from the original on November 21, 2011. Retrieved October 8, 2010.
- ↑ "UK phishing fraud losses double". Finextra. March 7, 2006. Archived from the original on January 19, 2009. Retrieved May 20, 2006.
- ↑ Richardson, Tim (May 3, 2005). "Brits fall prey to phishing". The Register. Archived from the original on June 10, 2019. Retrieved August 10, 2017.
- ↑ Krebs, Brian (October 13, 2007). "Shadowy Russian Firm Seen as Conduit for Cybercrime". The Washington Post. Archived from the original on June 11, 2019. Retrieved September 8, 2017.
- ↑ "Suspicious e-Mails and Identity Theft". Internal Revenue Service. Archived from the original on February 21, 2011. Retrieved July 5, 2006.
- ↑ Kirk, Jeremy (June 2, 2006). "Phishing Scam Takes Aim at MySpace.com". IDG Network. Archived from the original on June 16, 2006.
- ↑ McCall, Tom (December 17, 2007). "Gartner Survey Shows Phishing Attacks Escalated in 2007; More than $3 Billion Lost to These Attacks". Gartner. Archived from the original on November 18, 2012. Retrieved December 20, 2007.
- ↑ APWG. "Phishing Activity Trends Report" (PDF). Archived from the original (PDF) on October 3, 2012. Retrieved November 4, 2013.
- ↑ "Anatomy of an RSA attack". RSA.com. RSA FraudAction Research Labs. Archived from the original on October 6, 2014. Retrieved September 15, 2014.
- ↑ Drew, Christopher; Markoff, John (May 27, 2011). "Data Breach at Security Firm Linked to Attack on Lockheed". The New York Times. Archived from the original on July 9, 2019. Retrieved September 15, 2014.
- ↑ Keizer, Greg (August 13, 2011). "Suspected Chinese spear-phishing attacks continue to hit Gmail users". Computerworld. Archived from the original on March 21, 2021. Retrieved December 4, 2011.
- ↑ Ewing, Philip (August 22, 2011). "Report: Chinese TV doc reveals cyber-mischief". Dod Buzz. Archived from the original on January 26, 2017. Retrieved December 4, 2011.
- ↑ Bump, Philip (August 15, 2013). "Syrian Hackers Use Outbrain to Target The Washington Post, Time, and CNN". The Atlantic Wire. Archived from the original on October 19, 2013. Retrieved August 15, 2013.
- ↑ O'Connell, Liz. "Report: Email phishing scam led to Target breach". Bring Me the News. Archived from the original on September 15, 2014. Retrieved September 15, 2014.
- ↑ Ausick, Paul (May 5, 2014). "Target CEO Sack". Archived from the original on September 15, 2014. Retrieved September 15, 2014.
- ↑ "Prosecutors find that 'Fappening' celebrity nudes leak was not Apple's fault". TechCrunch. March 15, 2016. Archived from the original on August 18, 2017.
- ↑ "ICANN Targeted in Spear Phishing Attack | Enhanced Security Measures Implemented". icann.org. Archived from the original on August 7, 2019. Retrieved December 18, 2014.
- ↑ Kube, Courtney (August 7, 2015). "Russia hacks Pentagon computers: NBC, citing sources". Archived from the original on August 8, 2019. Retrieved August 7, 2015.
- ↑ Starr, Barbara (August 7, 2015). "Official: Russia suspected in Joint Chiefs email server intrusion". Archived from the original on August 8, 2019. Retrieved August 7, 2015.
- ↑ Doctorow, Cory (August 28, 2015). "Spear phishers with suspected ties to Russian government spoof fake EFF domain, attack White House". Boing Boing. Archived from the original on March 22, 2019. Retrieved November 29, 2016.
- ↑ Quintin, Cooper (August 27, 2015). "New Spear Phishing Campaign Pretends to be EFF". EFF. Archived from the original on August 7, 2019. Retrieved November 29, 2016.
- ↑ Sanger, David E.; Corasaniti, Nick (June 14, 2016). "D.N.C. Says Russian Hackers Penetrated Its Files, Including Dossier on Donald Trump". The New York Times. Archived from the original on July 25, 2019. Retrieved October 26, 2016.
- ↑ Economist, Staff of (September 24, 2016). "Bear on bear". The Economist. Archived from the original on May 20, 2017. Retrieved October 25, 2016.
- ↑ Hyacinth Mascarenhas (August 23, 2016). "Russian hackers 'Fancy Bear' likely breached Olympic drug-testing agency and DNC, experts say". International Business Times. Retrieved September 13, 2016.
- ↑ "What we know about Fancy Bears hack team". BBC News. September 15, 2016. Archived from the original on March 22, 2019. Retrieved September 17, 2016.
- ↑ Gallagher, Sean (October 6, 2016). "Researchers find fake data in Olympic anti-doping, Guccifer 2.0 Clinton dumps". Ars Technica. Archived from the original on July 14, 2017. Retrieved October 26, 2016.
- ↑ "Qatar faced 93,570 phishing attacks in first quarter of 2017". Gulf Times. May 12, 2017. Archived from the original on August 4, 2018. Retrieved January 28, 2018.
- ↑ "Amazon Prime Day phishing scam spreading now!". The Kim Komando Show. Archived from the original on May 27, 2019. Retrieved January 28, 2018.
- ↑ "Cryptocurrency Hackers Are Stealing from EOS's $4 Billion ICO Using This Sneaky Scam". Jen Wieczner. Archived from the original on March 21, 2021. Retrieved May 31, 2018.
- ↑ "Twitter Investigation Report". New York State Department of Financial Services. October 14, 2020. Retrieved September 20, 2026.
- ↑ "Three Individuals Charged For Alleged Roles In Twitter Hack". justice.gov. Retrieved March 23, 2022.
- 1 2 European Union Agency for Cybersecurity (October 2025). ENISA Threat Landscape 2025 (PDF) (Report). European Union Agency for Cybersecurity. doi:10.2824/1946374. ISBN 978-92-9204-723-8. Retrieved September 20, 2026.
- ↑ Jøsang, Audun; et al. (2007). "Security Usability Principles for Vulnerability Analysis and Risk Assessment". Proceedings of the Annual Computer Security Applications Conference 2007 (ACSAC'07). Archived from the original on March 21, 2021. Retrieved November 11, 2020.
- 1 2 Lain, Daniele; Jost, Tarek; Matetić, Siniša; Kostiainen, Kari; Čapkun, Srdjan (October 2024). "Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training". Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery. pp. 4182–4196. doi:10.1145/3658644.3690348.
- 1 2 Herr, Todd M.; Levine, John (May 2026). Domain-Based Message Authentication, Reporting, and Conformance (DMARC) (Technical report). Internet Engineering Task Force. doi:10.17487/RFC9989. RFC 9989.
- ↑ Shen, Kaiwen; Wang, Chuhan; Guo, Minglei; et al. (August 2021). "Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks". 30th USENIX Security Symposium. USENIX Association. pp. 3201–3217.
- 1 2 3 Oest, Adam; Safaei, Yeganeh; Zhang, Penghui; et al. (August 2020). "PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists". 29th USENIX Security Symposium. USENIX Association. pp. 379–396.
- ↑ Rose, Scott; Liu, Cricket; Gibson, Ross (March 2026). Secure Domain Name System (DNS) Deployment Guide (Report). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-81r3.
- ↑ Galluzzo, Ryan (April 22, 2024). "Giving NIST Digital Identity Guidelines a Boost: Supplement for Incorporating Syncable Authenticators". Cybersecurity Insights. National Institute of Standards and Technology. Retrieved September 20, 2026.
- 1 2 Galluzzo, Ryan; Regenscheid, Andrew; Nelson, Stephanie; Lazcano, Christine (September 2026). Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (Report). National Institute of Standards and Technology. doi:10.6028/NIST.IR.8587.
- ↑ Berris, Peter G. (May 16, 2023). Cybercrime and the Law: Primer on the Computer Fraud and Abuse Act and Related Statutes (PDF) (Report). Congressional Research Service. pp. 36–39. R47557. Retrieved September 20, 2026.
- ↑ "Directive (EU) 2019/713 of the European Parliament and of the Council on combating fraud and counterfeiting of non-cash means of payment". EUR-Lex. European Union. April 17, 2019. recital 13 and arts. 1–6. Retrieved September 20, 2026.
- ↑ "Cybercrime—prosecution guidance". Crown Prosecution Service. June 29, 2026. sections "Fraud" and "Relevant Offences and Legislation". Retrieved September 20, 2026.
- ↑ "Benefits of the Convention on Cybercrime (Budapest Convention)". Cybercrime. Council of Europe. Retrieved September 20, 2026.
- ↑ "United Nations Convention against Cybercrime; Strengthening International Cooperation for Combating Certain Crimes Committed by Means of Information and Communications Technology Systems and for the Sharing of Evidence in Electronic Form of Serious Crimes". United Nations Treaty Collection. United Nations. December 24, 2024. status as at September 20, 2026; art. 65(1). Retrieved September 20, 2026.
