AiVibe

Cybersecurity & Compliance

Phishing

A social engineering attack in which fraudulent emails, messages or websites impersonate trusted parties to trick people into revealing credentials, making payments or running malicious software.

Phishing exploits trust and urgency rather than technical flaws. Bulk campaigns send generic lures, spear phishing targets specific individuals using researched details, and whaling targets senior executives. Variants include smishing by text message, vishing by voice call, QR-code phishing and business email compromise, in which attackers impersonate executives or suppliers to redirect payments. Adversary-in-the-middle phishing kits proxy genuine login pages to capture session cookies and bypass some forms of multi-factor authentication.

Phishing is one of the most common initial access methods in data breaches and ransomware attacks, and it targets any organisation that uses email and cloud services. Attackers increasingly use generative AI to write convincing messages in many languages and to clone voices, which makes traditional warning signs such as poor grammar less reliable.

Layered defences include email authentication with SPF, DKIM and DMARC, filtering of links and attachments, phishing-resistant MFA such as FIDO2 security keys and passkeys, and verification procedures for payment changes. Security awareness training and simulated phishing exercises help staff recognise and report attempts, and a simple reporting button turns employees into an early-warning system. Reporting rates and time to report are more useful measures than click rates alone.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain Phishing for your plant, product or security programme, and draw how it fits.