Phishing refers to a variety of attacks that are intended to convince you to forfeit sensitive data to an imposter. These attacks can take a number of different forms; from spear-phishing (which targets a specific individual within an organization), to whaling (which goes one step further and targets senior executives or leaders). Furthermore, phishing attacks take place over multiple channels or even across channels; from the more traditional email-based attacks to those using voice – vishing – to those coming via text message – smishing. Regardless of the type or channel, the intent of the attack is the same – to exploit human nature to gain control of sensitive information (citation 1). These attacks typically make use of several techniques including impersonated websites, attacker-in-the-middle, and relay or replay to achieve their desired outcome.


More

ZDNet France: What if we replaced the “security by obscurity”, dependent on passwords, with “security by community”?

Security by obscurity is an outdated approach, not suited to today’s cyberattacks, nor to today’s…

Read More →

Infosecurity Magazine: November’s M&A News Roundup

On November 3, 1Password announced the acquisition of passwordless authentication company Passage. The move will…

Read More →

Silicon: Cybersecurity: automation, to the delight of attackers?

Automation stands out as one of the major trends in the predictions that cybersecurity market…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.