What Is Phishing?

Phishing is a social engineering attack that tricks victims into revealing sensitive information — passwords, credit card numbers, or personal data — by impersonating a trusted entity. It remains the most common and effective cyberattack vector, responsible for over 80% of reported security incidents.

Phishing attacks come in many forms: deceptive emails that mimic banks or services, fake login pages that capture credentials, text messages (smishing), phone calls (vishing), and even QR codes that lead to malicious sites.

The sophistication of modern phishing has evolved dramatically. AI-generated phishing emails are grammatically perfect and personally targeted, making them nearly indistinguishable from legitimate communications.

Recognizing Phishing Attempts

Red Flags in Emails: • Urgency or threats ("Your account will be closed in 24 hours") • Generic greetings ("Dear Customer" instead of your name) • Suspicious sender email (support@g00gle.com instead of google.com) • Links that don't match the claimed destination (hover before clicking) • Unexpected attachments, especially .zip, .exe, or Office documents with macros • Requests for sensitive information (legitimate services never ask for passwords via email)

Red Flags in Websites: • URL doesn't match the expected domain (paypa1.com instead of paypal.com) • No HTTPS padlock • Poor visual quality — misaligned logos, pixelated images, broken formatting • Unusual form fields — a "bank" asking for your Social Security Number on a login page

Red Flags in Messages/Calls: • Unsolicited contact claiming to be from a service you use • Pressure to act immediately • Requests to bypass normal procedures

Prevention Strategies

Technical Defenses: • Use a password manager — it won't auto-fill on phishing sites • Enable MFA — even if credentials are stolen, the second factor protects you • Keep email client updated — modern clients block known phishing patterns • Use DNS-based protection (Cloudflare Gateway, Pi-hole with threat lists)

Behavioral Defenses: • Never click links in unexpected emails — navigate to the site directly • Verify urgent requests through a separate channel (call the company directly) • Don't download unexpected attachments • Check sender email addresses carefully, character by character

For Dead Man's Switch Users: Phishing attempts may try to trick you into "confirming" a fake heartbeat or resetting your vault. Always verify you're on the real ZeroLatch domain before clicking any heartbeat confirmation links. The URL should match exactly — bookmark the legitimate site for reference.