Phishing Flashcards
Phishing
The process of attempting to acquire sensitive Information such as usernames, passwords, and credit card details.
Phishing is the major tool used by the bad guys to get users to click on something and lead them to confidential Information.
Spear Phishing
A small, focused, targeted phishing attack on a specific person or organization.
Phishing attack surface
The quantity of emails exposed on the internet. The more email addresses exposed, the bigger the attack footprint is and the higher the risk for phishing attacks.
Phish-Prone Percentage %
A term coined by KnowBe4 that indicates the percentage % of employees that are prone to click on phishing links.
Customer starts with a baseline for comparison. Before and after training usually every 12 months.
Social engineering
The act of manipulating people into performing actions or divulging confidential Information.
CEO fraud
A spear phishing attacks that targets high-risk users - people in Accounting, HR, or executive assistants in which the hackers claims to be the CEO and urges an employee to do something that would not be authorized by the legitimate sender.
Vishing (voice phishing)
A phishing attack conducted by telephone
Smishing
Phishing conducted via Short Message Service - (SMS), a telephone-based text messaging service.
Email spoofing
Spoofing (tricking or deceiving) computer systems or other computer users. Sending messages from bogus email address or faking the email address of another user.
Spoofing is a common tactic in CEO Fraud attacks.