[ PH-02 · Phishing ]
How phishing reaches busy people, and how to catch it in time
Phishing works because it arrives at the wrong moment. The fake invoice lands at 4:55 on a Friday. The “missed delivery” text shows up while you’re waiting on a real parcel. The FBI’s Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in 2024, more than any other category it tracks.
Here we break lures down by what they’re after. Some want a password, so they send you to a copied login page. Some want money, so they impersonate a vendor or a boss. Some want you to install something, like the fake “verify you’re human” prompts that trick people into pasting commands into their own computer. For each, we explain the tell, the safe check, and what to do if you already clicked.
We cover email, text messages, voice calls and QR codes, because the channel doesn’t matter much. The pressure to act before thinking does.
Coming up: a beginner’s guide to phishing red flags, and what to do in the first ten minutes after a bad click.
Briefings in Phishing
No briefings filed in this section yet. The wire below is tracking the topic until our first one lands.
Reporting from The Hacker News
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerThe Hacker News
- Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects CallsThe Hacker News
- Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to IgnoreThe Hacker News
- 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360The Hacker News
- OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public FilesThe Hacker News
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default PasswordsThe Hacker News