Ransomware entry
Often the first click.
Phishing is a social-engineering technique that pushes a victim to reveal secrets (passwords, MFA, cards) or take a dangerous action (malware, wire transfer) by impersonating a trusted entity—bank, coworker, cloud provider. Channels include email, SMS (smishing), voice (vishing), and work chat. It remains one of the top enterprise intrusion vectors.
In one sentence
Phishing tricks humans into stealing access or triggering harmful actions.
Key points
Term at a glance
The metaphor is a hook: bait (urgency, invoice, security alert) and hook (link or attachment).
Modern kits clone Microsoft 365 / bank pages in minutes.
For bilingual Quebec SMEs, local FR/EN lures (Revenu Québec, Desjardins, etc.) are common.
DMARC/DKIM/SPF, filtering, block dangerous attachments.
Phishing-resistant MFA when possible (FIDO keys).
Simulations + blameless reporting procedures.
Revoke sessions, reset secrets, mail forensics.
An employee gets a fake urgent “SharePoint share.” They type their password on a fake page. The attacker creates mailbox rules and sends fraudulent invoices. MFA plus unusual-sign-in alerts cut access within an hour.
Often the first click.
Redirected wires.
M365, Google Workspace.
Awareness required by insurers and frameworks.
| Phishing | Untargeted spam | |
|---|---|---|
| Intent | Steal access / trigger action | Often ads / volume |
| Targeting | Can be personalized | Broad and generic |
| Danger | High (intrusion, fraud) | Variable, often nuisance |
| Defense | Tech + process + humans | Anti-spam filters |
One click can cost more than a year of controls. Cyber insurers increasingly require MFA and awareness—and fraudsters speak Quebec French.
No, but it strongly reduces risk; prefer phishing-resistant methods.
No—encourage fast reporting.
Yes: smishing and social lures are common.
Don't panic: report, rotate secrets, revoke sessions.
Want to harden email, MFA, and anti-phishing awareness? We can scope a pragmatic plan.
Talk about phishing