home/glossary/Phishing

Phishing

nounverified·updated May 9, 2026

A digital form of social engineering that uses authentic-looking—but bogus—emails to request information from users or direct them to a fake Web site that requests information.

polysemousNISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Senses

SANS Glossary of Security Terms

The use of e-mails that appear to originate from a trusted source to trick a user into entering valid credentials at a fake website. Typically the e-mail and the web site looks like they are part of a bank the user is doing business with.

National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon

A digital form of social engineering to deceive individuals into providing sensitive information.

ISACA Cybersecurity Glossary

This is a type of electronic mail (e-mail) attack that attempts to convince a user that the originator is genuine, but with the intention of obtaining information for use in social engineering Scope Note: Phishing attacks may take the form of masquerading as a lottery organization advising the recipient or the user's bank of a large win; in either case, the intent is to obtain account and personal identification number (PIN) details. Alternative attacks may seek to obtain apparently innocuous business information, which may be used in another form of active attack.

Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

A digital form of social engineering that uses authentic-looking—but bogus—e-mail to request information from users or direct them to fake websites that request information.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Deceiving individuals into disclosing sensitive personal information through deceptive computer-based means.

NIST SP 800-83

Tricking individuals into disclosing sensitive personal information through deceptive computer-based means.

Classifications

Entity Type

Threat90%rule-basedr:entity.threat.attack.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
Phishings
possessive
Phishing's
pluralpossessive
Phishings'