What is phishing?
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware.
What are common types of malware mentioned in the source?
Viruses, worms, adware, and ransomware.
What is the origin of the term 'phishing'?
It was first recorded in 1995 in the cracking toolkit AOHell, and is a variation of fishing, referring to lures to 'fish' for sensitive information.
What is spear phishing?
Spear phishing is a targeted phishing attack tailored to specific individuals, using personal or organizational information to increase credibility and success.
What is vishing?
Vishing (voice phishing) uses VoIP to make automated phone calls, often spoofing numbers, to trick victims into revealing sensitive information.
What is smishing?
Smishing (SMS phishing) uses mobile text messages to deliver bait, asking victims to click links, call numbers, or provide private information.
What is quishing?
Quishing is phishing using QR codes to trick users into visiting malicious sites or downloading malware.
What is page hijacking?
Page hijacking involves redirecting users to malicious websites by compromising legitimate web pages, often using cross-site scripting.
What is a watering hole attack?
A watering hole attack compromises a website frequented by a target group to exploit visitors, often used with page hijacking.
Why are strong passwords important?
Strong passwords help protect accounts from unauthorized access, reducing the risk of identity theft and data breaches.
What is social engineering?
Social engineering is manipulating people into divulging confidential information or performing actions, often by exploiting trust or urgency.
What is ransomware?
Ransomware is malware that encrypts a victim's files and demands payment for decryption.
What is a virus?
A virus is malware that attaches to legitimate files and spreads when the infected file is executed.
What is a worm?
A worm is self-replicating malware that spreads without human action, often over networks.
Why are software updates important for security?
Updates patch vulnerabilities that attackers could exploit, helping to protect against malware and other threats.
What is a common sign of a phishing email?
Urgency or threats, requests for personal information, and links to fake login pages.
What should you do if you receive a suspicious email?
Do not click links or download attachments; report it and delete it.
What is two-factor authentication (2FA)?
2FA adds an extra layer of security by requiring a second form of verification beyond a password.
What is a MiTM 2FA attack?
A man-in-the-middle attack that intercepts 2FA credentials to bypass security.
What is the role of user education in preventing phishing?
Educating users helps them recognize and avoid phishing attempts, reducing the success of attacks.
What is the trend in phishing attacks among businesses?
Phishing attacks among businesses rose from 72% in 2017 to 86% in 2020, reaching 94% in 2023.
What is the goal of bulk phishing attacks?
Bulk attacks are not targeted and are sent to a wide audience to trick anyone into giving away sensitive information or credentials.
What is the impact of generative AI on phishing?
Generative AI enables highly convincing, automated, and hyper-targeted phishing campaigns at an unprecedented scale.