← Back to glossary

Social engineering to obtain credentials or actions.

Definition

Phishing is a social engineering technique that uses deceptive communications (email, SMS, calls) to induce victims to disclose credentials, install malware, or authorize transactions.

In plain English Social engineering to obtain credentials or actions.

Why this matters

Why it matters: It remains a top initial access vector for account takeover and malware delivery.

Example

Example: Spoofed domain email leading to a credential-harvesting site.