Phishing
ELI5 — The Vibe Check
Phishing is when hackers pretend to be someone you trust — your bank, your boss, Google — to trick you into giving up your password or clicking a bad link. The name comes from 'fishing' because they cast bait and wait for someone to bite. The best defense is slowing down and double-checking sender addresses.
Real Talk
Phishing is a social engineering attack using fraudulent communications (emails, SMS, websites) that impersonate trusted entities to steal credentials, financial data, or install malware. Spear phishing targets specific individuals; whaling targets executives. Defenses: MFA, email filtering, security training.
When You'll Hear This
"The employee clicked a phishing link and gave up their credentials." / "Enable DMARC to prevent email spoofing used in phishing."
Related Terms
MFA (MFA)
MFA stands for Multi-Factor Authentication. It's the umbrella term for requiring multiple proofs of identity. 2FA is MFA with exactly two factors.
Password Manager
A password manager remembers all your passwords so you don't have to reuse the same one everywhere.
Social Engineering
Social engineering is hacking people, not computers.
Two-Factor Authentication (2FA)
2FA means you need two things to log in: something you know (password) and something you have (your phone).