Phishing is a social engineering attack where malicious actors impersonate legitimate individuals, organizations, or brand entities via email to trick recipients into revealing sensitive information (such as passwords, financial credentials, or private keys), downloading malware, or executing fraudulent wire transfers.
Because email protocols were not originally designed with identity verification built-in, phishing remains one of the primary vectors for initial access in cybersecurity breaches.
| Attack Vector | Target Audience | Description & Method |
|---|---|---|
| Standard Phishing | Mass Recipients | Generic, automated emails masquerading as major services (e.g., banks, cloud providers) to harvest credentials. |
| Spear Phishing | Targeted Individuals | Highly customized emails leveraging gathered OSINT (Open Source Intelligence) about a specific target or department. |
| Whaling | High-Level Executives | Targeted attacks aimed at CEOs, CFOs, or administrators to authorize large financial transactions or grant elevated privileges. |
| Business Email Compromise (BEC) | Finance / HR Departments | Impersonation of trusted executives, vendors, or business partners to divert invoice payments or intercept sensitive employee data. |
| Clone Phishing | Service Users | Intercepting or copying a legitimate, previously sent email and replacing links/attachments with malicious payloads. |
Phishing attacks rely on technical deception to bypass human scrutiny and automated security filters:
Attacker sends an email with a fake `From:` header displaying a trusted brand (e.g., `support@bank.com`), while the email originates from an unauthorized mail server.
Attackers register domains that visually resemble legitimate brand domains (e.g., using `teleneqar.ir` or `telenegar-security.ir` instead of `telenegar.ir`).
Using internationalized domain names (IDN) with lookalike Cyrillic or Greek characters that mimic Latin characters in web browsers and mail clients.
Emails contain links directing users to rogue landing pages designed to look identical to legitimate login portals. Links often use open redirects or URL shorteners to mask the final destination.
Preventing phishing requires a layered defense combining DNS-based email authentication protocols and inbound filtering security.
Implementing strict email authentication ensures unauthorized servers cannot spoof your domain in phishing campaigns:
<note warning> Without a strict DMARC policy (`p=quarantine` or `p=reject`), attackers can freely forge your domain name in outbound phishing messages sent to your customers or partners. </note>
Deploying BIMI displays your official trademarked logo directly in recipient inboxes, helping users quickly distinguish legitimate communications from phishing attempts.
Train security teams and automated filters to inspect Email Headers:
Audit your domain's anti-phishing defense posture using Telenegar Tools: