Phishing
A social engineering attack where attackers pose as legitimate entities (via email, SMS, or fake websites) to trick users into revealing credentials or installing malware.
Phishing is the most common form of social engineering attack. Attackers send messages (email, SMS, social media) that appear to come from trusted sources (banks, employers, service providers) and direct victims to fake login pages or malicious downloads.
Phishing attacks have become increasingly sophisticated, using cloned websites, legitimate-looking domains, and personalized content. Spear phishing targets specific individuals, while whaling targets executives.
Defenses include email filtering, security awareness training, URL inspection, and (critically) password manager autofill. Because a password manager matches credentials to exact domains, it won’t autofill on a phishing domain, even if it looks identical to the real site. This makes password managers one of the most effective anti-phishing tools available.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide