# Phishing

> Tricking people into handing over credentials or clicking the payload — the front door of most breaches, because it attacks the part that cannot be patched.

Most breaches do not start with a clever exploit; they start with an email that looks like a colleague, an invoice or a courier. The attack surface is human attention under time pressure — 'urgent', 'final notice', 'the boss needs this today' — which no firewall filters.

Defence is layered: DMARC/SPF so your domain cannot be forged, link protection and MFA so a stolen password is not enough, and a culture where 'I clicked, what now' is reported in minutes instead of hidden. The technical floor matters; so does making reporting safe.

## Related terms

- https://dfieldsolutions.com/en/glossary/mfa.md
- https://dfieldsolutions.com/en/glossary/ransomware.md
- https://dfieldsolutions.com/en/glossary/incident-response.md

---

Source: https://dfieldsolutions.com/en/glossary/phishing
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
