# Phishing Explained In 6 Minutes | What Is A Phishing Attack? | Phishing Attack | Simplilearn

https://www.youtube.com/watch?v=XBkzBrXlle0

[00:00] Jane is relaxing at home when she receives an email from a bank that asks her to update her credit card PIN in the next 24 hours as a security measure.
[00:09] Judging the severity of the message, Jane follows the link provided in the email.
[00:14] On delivering her current credit card PIN and the supposedly updated one, the website became unresponsive, which prompted her to try sometime later.
[00:23] However, after a couple of hours, she noticed a significant purchase from a random website on that same credit card, which she never authorized.
[00:32] Frantically contacting the bank, Jane realized the original email was a counterfeit or a fake message with a malicious link that entailed credit card fraud.
[00:41] This is a classic example of a phishing attack.
[00:45] Phishing attacks are a type of social engineering where a fraudulent message is sent to a target on the premise of arriving from a trusted source.
[00:52] Its basic purpose is to trick the victim into revealing sensitive information like passwords and payment information.
[01:00] It's based on the word phishing, which
[01:02] Works on the concept of baits.
[01:04] If a supposed victim catches the bait, the attack can go ahead, which in our case makes Jane the fish and the phishing emails the bait.
[01:13] If Jane never opened the malicious link or was cautious about the email authenticity, an attack of this nature would have been relatively ineffective.
[01:23] But how does the hacker gain access to these credentials?
[01:26] A phishing attack starts with a fraudulent message, which can be transmitted via email or chat applications.
[01:31] Even using SMS conversations to impersonate legitimate sources is known as smishing, which is a specific category of phishing attacks.
[01:42] Irrespective of the manner of transmission, the message targets the victim in a way that coaxes them to open a malicious link and provide critical information on the requisite website.
[01:53] More often than not, the websites are designed to look as authentic as possible.
[01:58] Once the victim submit information using the link, be it a password or credit card details, the data is sent to the.
[02:04] Hacker who designed the email and the fake website.
[02:06] Giving him complete control over the account whose password was just provided.
[02:12] Often carried out in campaigns where an identical phishing mail sent to thousands of users, the rate of success is relatively low, but never zero.
[02:22] Between 2013 and 2015, corporate giants like Facebook and Google were tricked off of $100 million due to an extensive phishing campaign.
[02:32] Where a known common associate was impersonated by the hackers.
[02:36] Apart from credit access, some of these campaigns target the victim device and install malware when clicked on the malicious links.
[02:43] Which can later function as a botnet or a target for ransomware attacks.
[02:48] There is no single formula, where there are multiple categories of phishing attacks.
[02:52] The issue with Jane, where the hacker stole her bank credentials, falls under the umbrella of deceptive phishing.
[02:59] A general email sent out to thousands of users in this category, hoping some of them fall prey to the scam.
[03:05] Spear phishing on the other hand, is a bit customized version.
[03:09] The targets are researched before being sent an email.
[03:11] For example, if you never had a Netflix subscription, sending you an email that seems like the Netflix team sends it, becomes pointless.
[03:20] This is a potential drawback of deceptive phishing techniques.
[03:24] On the other hand, a simple screenshot of a Spotify playlist being shared on social media indicates a probable point of entry.
[03:31] The hacker can send counterfeit messages to the target user while implying the source of such messages being Spotify, tricking them into sharing private information.
[03:40] Since the hacker already knows the target uses Spotify, the chances of victims taking the bait increase substantially.
[03:48] For more important targets like CEOs and people with a fortune on their back, The research done is tenfold, which can be called a case of whaling.
[03:57] The hackers prepare and wait for the right moment to launch their phishing attack, often to steal industry secrets for rival companies or sell them off at a higher price.
[04:05] Apart from just emails, farming focuses on fake websites that resemble their original counterparts as much as possible.
[04:13] A prevalent method is to use domain names like Facebook with a single O or YouTube with no E.
[04:19] These are mistakes that people make when typing the full URL in the browser, leading them straight to a counterfeit webpage, which can fool them into submitting private data.
[04:28] A few more complex methods exist to drive people onto fake websites, like ARP spoofing and DNS cache poisoning, but they are rarely carried out due to time and resource constraints.
[04:40] Now that we know how phishing attacks work, let's look at ways to prevent ourselves from becoming victims.
[04:46] While the implications of a phishing attack can be extreme, protecting yourself against these is relatively straightforward.
[04:53] Jane could have saved herself from credit card fraud had she checked the link in the email for authenticity and that it redirected to a secure website that runs on the HTTPS protocol.
[05:04] Even suspicious messages shouldn't be.
[05:06] Entertained.
[05:07] One must also refrain from entering private information on random websites or pop-up windows, irrespective of how legitimate they seem.
[05:15] It is also recommended to use secure anti-phishing browser extensions like Cloud Fish to sniff out malicious emails from legitimate ones.
[05:21] The best way to prevent phishing is browsing the internet with care and being on alert for malicious attempts at all times.
[05:30] So, here is a question for you.
[05:30] If both me and my friends receive the same email that instructs us to change our Spotify password before the end of the day, even though one of us never use Spotify, what bracket does this phishing attack fall under?
[05:44] One, whaling.
[05:46] Two, spear fishing.
[05:46] Three, deceptive fishing.
[05:50] Four, farming.
[05:53] Think about it and leave your answers below in the comments section and three lucky winners will receive Amazon gift vouchers.
[05:59] Cyber attacks are becoming more prevalent due to the pandemic where work from home is the norm and people spend possibly more than half their day with a.
[06:07] Laptop.
[06:08] But we cannot stop every attack at the root.
[06:10] We must be informed and vigilant to fishing attacks among others to safeguard our data.
[06:16] We hope you enjoyed this video.
[06:17] If you did, a thumbs up would be really appreciated.
[06:20] Here's your reminder to subscribe to our channel and click on the bell icon for more on the latest technologies and trends.
[06:26] Thank you for watching and stay tuned for more from Simply Learn.
