Threats & Social EngineeringBeginnerThreat7 validated evidence records

Phishing

30 sec

A social-engineering attack that uses a deceptive message or interaction to persuade someone to reveal information, open malicious content, send money, or take another unsafe action.

Know

What is Phishing?

Phishing impersonates a trusted person, company, service, or situation. It may arrive through email, text, social media, collaboration tools, search results, QR codes, phone calls, or other channels. The attacker’s goal is usually to obtain credentials, money, sensitive information, malware execution, or access to a trusted environment.

Why it matters

Phishing targets human decision-making and can bypass technical controls by convincing a legitimate user to perform the attacker’s action for them.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationOperational validation

Fake IT-support contacts use Teams to obtain user-approved remote access

2026-09-02Microsoft Threat Intelligence

Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.

Why this is evidence

This is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.

See the source — Microsoft Threat Intelligence: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Technical ValidationOperational validation

TerminalFix uses a fake verification prompt to establish a reverse tunnel

2026-08-28Microsoft Threat Intelligence

Microsoft's TerminalFix analysis describes a fake CAPTCHA prompt that persuades a user to execute a command, followed by a multistage intrusion and a reverse tunnel.

Why this is evidence

The case connects a human verification pretext with malware execution and network access. Microsoft distinguishes observed activity from possible downstream actions; it did not observe the suggested ransomware or data-theft outcomes in this analyzed chain.

See the source — Microsoft Threat Intelligence: TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Technical ValidationResearch / emerging practice

Invisible Unicode characters appear in phishing keyword evasion

2026-09-03Microsoft Security Research

Microsoft describes invisible Unicode characters inserted into phishing text to obstruct keyword parsing. Signature activity increased from February 9 and remained elevated on weekdays for roughly three months. Layered protections flagged most of the messages.

Why this is evidence

This illustrates the difference between visible text and machine-processed content. It is newly published analysis of older activity, not evidence that all email protections are defeated or that every invisible character is malicious.

See the source — Microsoft Security Research: ASCII smuggling crosses over from AI prompt injection to phishing evasion
Technical ValidationOperational validation

Counterfeit vendor pages deliver changing malicious installers

2026-09-01Microsoft Threat Intelligence

Microsoft describes look-alike software download pages distributing malicious installers whose contents change between downloads. Observed affected devices were predominantly associated with China-based operations and Chinese-speaking users across several industries.

Why this is evidence

The campaign illustrates brand impersonation leading to malware delivery. Impersonating a vendor's download page does not establish compromise of its official distribution. The observed geography is not a measured global scope.

See the source — Microsoft Threat Intelligence: Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Government / AuthoritativeMeasured outcome

Phishing and spoofing remained among the most frequently reported internet crimes

2025FBI Internet Crime Complaint CenterCross-sector

The FBI's 2025 Internet Crime Report recorded more than one million complaints overall and identified phishing/spoofing among the most frequently reported complaint categories.

Why this is evidence

This is large-scale victim reporting evidence that phishing is not a theoretical training scenario; it remains a common real-world attack and fraud mechanism.

See the source — FBI: 2025 Internet Crime Report
Government / AuthoritativeMeasured outcome

Businesses reported hundreds of millions of dollars in BEC losses

2025FBI Internet Crime Complaint CenterCross-sector

The FBI's 2025 IC3 report lists reported Business Email Compromise losses above $568 million and separately documents AI-assisted BEC tactics including official-sounding executive impersonation and voice cloning.

Why this is evidence

BEC can produce major financial loss without exploiting a software vulnerability; the attacker exploits trust, business process, and identity verification.

See the source — FBI: 2025 Internet Crime Report
Government / AuthoritativeGovernment advisory

Scattered Spider targeted enterprise help desks and identity controls

2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors

A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.

Why this is evidence

The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.

See the source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A

Understand the mechanics

How it works

  1. 1

    The attacker selects a target or broad audience.

  2. 2

    A believable pretext is created, often using urgency, authority, fear, curiosity, or opportunity.

  3. 3

    The target is directed to click, scan, reply, call, open a file, authenticate, pay, or disclose information.

  4. 4

    If successful, the attacker uses the resulting access or information for fraud, compromise, persistence, or further attacks.

Practice

What to watch for

  • Unexpected request for credentials or money
  • Urgency or secrecy
  • Sender/domain mismatch
  • Unexpected login page
  • Link destination does not match its label
  • Unusual attachment or QR code

Perform

What to do

  1. 1

    Do not use the message’s link, attachment, number, or QR code.

  2. 2

    Verify through a known independent channel.

  3. 3

    Report the message using the approved security process.

  4. 4

    If credentials were entered, change them from a trusted device and report immediately.

How to reduce the risk

  • Phishing-resistant MFA
  • Email authentication and filtering
  • User reporting workflows
  • Role-based simulations
  • Browser and DNS protections
  • Clear payment and identity-verification procedures

Business impact

  • Account takeover
  • Fraud
  • Malware or ransomware
  • Data loss
  • Business email compromise
  • Downstream partner or customer compromise

What different roles should do

Employee

  • Pause when a request creates urgency
  • Verify using a known channel
  • Report suspicious messages

Security

  • Triage the message
  • Identify recipients and clicks
  • Contain compromised identities or endpoints

Framework & standards context

  • MITRE ATT&CK T1566 — Phishing

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02