DON'T BE PHISHBAIT. PHISHING IS THE FRAUDULENT ATTEMPT TO OBTAIN SENSITIVE INFORMATION OR DATA, SUCH AS USERNAMES, PASSWORDS AND CREDIT CARD DETAILS, BY DISGUISING ONESELF AS A TRUSTWORTHY ENTITY IN AN ELECTRONIC COMMUNICATION.TYPICALLY CARRIED OUT BY EMAIL SPOOFING, INSTANT MESSAGING,AND TEXT MESSAGING, PHISHING OFTEN DIRECTS USERS TO ENTER PERSONAL INFORMATION AT A FAKE WEBSITE WHICH MATCHES THE LOOK AND FEEL OF THE LEGITIMATE SITE.AN EXAMPLE OF A PHISHING EMAIL, DISGUISED AS AN OFFICIAL EMAIL FROM A (FICTIONAL) BANK. THE SENDER IS ATTEMPTING TO TRICK THE RECIPIENT INTO REVEALING CONFIDENTIAL INFORMATION BY "CONFIRMING" IT AT THE PHISHER'S WEBSITE. NOTE THE MISSPELLING OF THE WORDS RECEIVED AND DISCREPANCY AS RECIEVED AND DISCREPENCY, RESPECTIVELY. ALTHOUGH THE URL OF THE BANK'S WEBPAGE APPEARS TO BE LEGITIMATE, THE HYPERLINK POINTS AT THE PHISHER'S WEBPAGE.
PHISHING IS AN EXAMPLE OF SOCIAL ENGINEERING TECHNIQUES USED TO DECEIVE USERS. USERS ARE LURED BY COMMUNICATIONS PURPORTING TO BE FROM TRUSTED PARTIES SUCH AS SOCIAL WEB SITES, AUCTION SITES, BANKS, COLLEAGUES/EXECUTIVES, ONLINE PAYMENT PROCESSORS OR IT ADMINISTRATORS. ATTEMPTS TO DEAL WITH PHISHING INCIDENTS INCLUDE LEGISLATION, USER TRAINING, PUBLIC AWARENESS, AND TECHNICAL SECURITY MEASURES (THE LATTER BEING DUE TO PHISHING ATTACKS FREQUENTLY EXPLOITING WEAKNESSES IN CURRENT WEB SECURITY.