Attack Techniques · 2.1
🎣 Phishing & Spear Phishing
The most common attack — a fake message asking you to act⏱ ~3 min
Phishing
Attackers send deceptive emails, messages, or links to websites that appear legitimate, aiming to trick recipients into clicking and revealing sensitive information such as passwords, credit card numbers, or personal data. Phishing is sent in bulk — the same message to thousands of people, betting that some percentage will fall for it.
Spear Phishing
Spear phishing is the targeted version. Instead of a generic blast, the attacker customizes the message using specific information about the target — their name, job title, recent projects, even a colleague's name — making it far more convincing.
Phishing
- •Mass-sent to thousands or millions
- •Generic content ('Dear Customer')
- •Lower success rate per message
- •Cast a wide net for any victim
Spear Phishing
- •Targeted at a specific person or small group
- •Personalized with real details (name, role, project)
- •Much higher success rate
- •Used for high-value targets: executives, finance, IT admins
Whaling — Spear Phishing the C-Suite
★ FactWhen the target is a senior executive (CEO, CFO), it's called 'whaling.' These attacks often impersonate a board member, auditor, or legal counsel, and request large wire transfers or sensitive financial data. Whaling attacks have cost individual companies tens of millions of dollars in a single incident.
How to Spot a Phishing Email
- •Mismatched sender address — display name says 'PayPal Support' but the email is from a random domain
- •Generic or slightly-off greeting — 'Dear Valued Customer' instead of your actual name
- •Urgency or threats — 'Act now or your account will be closed'
- •Suspicious links — hover over the link (don't click) to see the real destination URL before trusting it
- •Unexpected attachments — especially .zip, .exe, .scr, or macro-enabled Office files (.docm, .xlsm)
- •Poor grammar or formatting — though AI-generated phishing has made this less reliable as a signal
- •Requests for credentials or payment — legitimate companies rarely ask you to 'verify your password' by email
💡 TipHover over any link before clicking to preview the actual URL in your browser or email client's status bar. A link displaying 'paypal.com' might actually point to 'paypal-secure-verify.ru'. Always check the actual destination, not just the link text.
🧠Quick Checkfirst try = +5 XP
What makes spear phishing more dangerous than regular phishing?
🎮 Practice what you learned
⭐ 0 XP🔥 0 days