Skip to content

What is phishing? Trust abuse as an attack

Phishing is a social-engineering technique that pushes a victim to reveal secrets (passwords, MFA, cards) or take a dangerous action (malware, wire transfer) by impersonating a trusted entity—bank, coworker, cloud provider. Channels include email, SMS (smishing), voice (vishing), and work chat. It remains one of the top enterprise intrusion vectors.

In one sentence

Phishing tricks humans into stealing access or triggering harmful actions.

Key points

  • Visual and narrative impersonation.
  • Spear phishing = personalized, more convincing.
  • MFA and a verify-first culture cut success rates.
  • Anti-phishing tools help but do not replace judgment.

Term at a glance

Phishing
Hameçonnage · Spear phishing · Social engineering email
English term
Phishing
Domain
Cybersecurity
Category
Threats
Level
Beginner to intermediate

What does “phishing” mean exactly?

The metaphor is a hook: bait (urgency, invoice, security alert) and hook (link or attachment).

Modern kits clone Microsoft 365 / bank pages in minutes.

For bilingual Quebec SMEs, local FR/EN lures (Revenu Québec, Desjardins, etc.) are common.

How do you defend against phishing?

  1. 01

    Shrink the surface

    DMARC/DKIM/SPF, filtering, block dangerous attachments.

  2. 02

    Strengthen auth

    Phishing-resistant MFA when possible (FIDO keys).

  3. 03

    Train and test

    Simulations + blameless reporting procedures.

  4. 04

    Respond fast

    Revoke sessions, reset secrets, mail forensics.

Concrete phishing example

An employee gets a fake urgent “SharePoint share.” They type their password on a fake page. The attacker creates mailbox rules and sends fraudulent invoices. MFA plus unusual-sign-in alerts cut access within an hour.

Why cover phishing?

Ransomware entry

Often the first click.

BEC / CEO fraud

Redirected wires.

Cloud account theft

M365, Google Workspace.

Compliance

Awareness required by insurers and frameworks.

Reality of phishing risk

  • Mature technical controls (DMARC, MFA)
  • Measurable training
  • Fast reporting limits damage
  • Clear CISA/OWASP guidance
  • Humans remain targetable
  • Deepfakes / credible urgency
  • Poor simulations cause fatigue
  • MFA bypass via adversary-in-the-middle

Phishing vs spam?

PhishingUntargeted spam
IntentSteal access / trigger actionOften ads / volume
TargetingCan be personalizedBroad and generic
DangerHigh (intrusion, fraud)Variable, often nuisance
DefenseTech + process + humansAnti-spam filters

Why phishing matters for a Quebec SME

One click can cost more than a year of controls. Cyber insurers increasingly require MFA and awareness—and fraudsters speak Quebec French.

FAQ

Does MFA stop all phishing?

No, but it strongly reduces risk; prefer phishing-resistant methods.

Punish employees who click?

No—encourage fast reporting.

SMS and LinkedIn too?

Yes: smishing and social lures are common.

After a click?

Don't panic: report, rotate secrets, revoke sessions.

Related terms

Sources and references

Want to harden email, MFA, and anti-phishing awareness? We can scope a pragmatic plan.

Talk about phishing
Glossary