Threats & Attacks

What Is Phishing

Phishing is type of social engineering attack where attackers potray as trusted entities either banks, cloud services, working mate, etc to trick victim so they reveal their sensitive information like password, credit card number or other credentials.

What Is Phishing?

Phishing is type of social engineering attack where attackers potray as trusted entities either banks, cloud services, working mate, etc to trick victim so they reveal their sensitive information like password, credit card number or other credentials. Phishing can occur in various medium like email, SMS, phone call, or fake website

Why Phishing Matters in Cybersecurity

Phising becoming the most dangerous attack methods. Often become jumping stone for larger damage, malware infection, ransomeware, etc. Even organization with strong security system can be defeated by phising since it exploit human trust instead of technical vulnerabilities.

Common Types of Phishing

  • Email Phishing : fake email act like legitimate messages
  • Spear Phishing : Very targeted phishing with goal to specifics individual with high profile in organization
  • Smishing : Phishing attacks delivered through SMS or messaging apps
  • Vishing : Phishing attack through phone calls
  • Clone Phishing : Attackers copies a original email and modified links or attachment with malicious one

Signs of a Phishing Attack

  • Suspicious sender address
  • Demanding quick action (”reset your password now”)
  • Very slighty Misspelled domain
  • Ask for sensitive informations (passwords, banking details, credit card, etc)
  • Suspicious attachments or links

Example

A victim receives an email mention that from their bank, asking victim to “verify account”.

The email include link to fake a website login that pretend to identical the real one. Once victim enter their credentials to the fake website, the attackers steal them and gain access to their real bank account

How to Defend Against Phishing

  • Enable MFA (Multi-Factor Authentication) to protect account even if credential are stolen
  • Train employees about phishing awareness
  • Use email security gateways and spam filter to avoid suspicious emails
  • Check suspicious links or attachments before clicking them
  • Implement least privileges to limit damage of compromised account
  • Spear Phishing
  • Malware
  • Social Engineering
  • MFA
  • Ransomware
Ready to validate what matters?

Ready to validate what matters?

Plexicus is Proof-Driven AppSec: validated findings, contextual understanding, and reviewed remediation — anchored in evidence, scoped with you.

Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

Teams with fewer than 50 developers: start a 14-day Trial instead of booking a demo. Start a 14-day Trial →

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorised target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)