Phishing

Phishing

Identity

MITRE ATT&CK techniques: MITRE ATT&CK techniques: T1566 · T1078 · T1204

Entry vectors: Social engineering, email delivery

01 / 10

Deceptive emails that trick users into giving up credentials or downloading malware. The most reported cybercrime in 2025 with 191,561 FBI complaints.

191,561 complaints to the FBI in 2025, the most reported cybercrime. Losses hit $215.8M, nearly triple the $70M reported in 2024.

Source: FBI Internet Crime Complaint Center (IC3) 2025 Annual Report

Phishing uses deceptive emails, messages, or links to trick recipients into revealing credentials, downloading malware, or transferring funds. Spear phishing targets specific individuals; business email compromise (BEC) targets finance or executive personas. The domain looks clean, the email looks real, and most gateways let it through.

DWELL TIME

Days to weeks. Phishing is typically detected when downstream credential misuse is noticed, not the moment the credentials are compromised.

DETECTION GAP

Phishing is hardest to catch before the click. The email bypasses the gateway because the domain is clean at delivery time. Post-click signals are often buried in log volume. Most organizations detect phishing-initiated breaches only when downstream effects surface—credential misuse, unusual logins, data loss—and that can be days to weeks after the click.

  1. 1
    Reconnaissance

    The attacker scrapes LinkedIn, company websites, and job postings to build a believable pretext. No cost, no noise—all of this happens entirely outside your organization’s perimeter.

  2. 2
    Email delivery

    A phishing email is sent from a lookalike domain registered days earlier, complete with a valid TLS certificate. It impersonates IT, a vendor, or an executive. Urgency framing suppresses the recipient’s scepticism.

  3. 3
    Click: Credential harvest or dropper

    The user clicks the link and lands on a pixel-perfect login clone. Credentials are silently captured as the user types them in. Or, an attachment may open and a dropper executes on the endpoint.

  4. 4
    Post-compromise activity

    The attacker logs into the corporate email or VPN from a new IP. Email forwarding rules are created. Internal resources are enumerated. This is often the first detectable moment.

  5. 5
    Lateral movement and escalation

    Using harvested credentials, the attacker moves to connected systems—cloud apps, VPNs, file servers. The blast radius grows by the hour.

DETECTION SIGNALS

  • Email logs: Sender domain registered less than 30 days ago; lookalike hostname
  • DNS: Query to a newly registered or low-reputation domain
  • Sysmon EID 1: Unusual parent-child process—browser spawning powershell.exe
  • EID 4624: Successful login from a new IP or geolocation
  • O365/IMAP audit logs: Mailbox rules created by the account post-compromise

REAL-WORLD EXAMPLES

Twitter/X Bitcoin Scam (2020)

Attackers social-engineered Twitter employees by phone to gain access to internal admin tools, then hijacked accounts belonging to Obama, Biden, Musk, and Gates to run a Bitcoin scam. $120,000 stolen along with significant reputational damage.

FACC AG (2016)

An Austrian aerospace parts manufacturer lost €50M in a CEO fraud attack. An attacker impersonating the CEO instructed a finance employee to wire funds to an external account. Initial transfer: €50M. Approximately €10.9M was later recovered.

MGM Resorts (2023)

Initial access achieved via vishing—an attacker called the IT help desk impersonating an employee. This single call led to $100M+ in operational losses and days of disrupted casino operations.

Learn how cyberattacks transpire in
real world environments