
THREAT‑WATCH
Glossary
Phishing
Fraudulent messages, usually email, designed to trick recipients into revealing credentials or installing malware.
Phishing remains the most common way attackers gain initial access to an organization. ENISA's 2025 Threat Landscape report attributes 60% of successful intrusions to it. Modern phishing includes targeted variants like spear-phishing (aimed at a specific person) and business email compromise (impersonating a trusted contact to request a fraudulent payment or action).