Phishing
Was ist Phishing?
Dieser Eintrag liegt derzeit nur auf Englisch vor.
Phishing is a social-engineering attack where a malicious message pretends to be from a trusted brand or institution to trick the recipient into revealing credentials, payment details, or personal data, or into installing malware. It arrives over SMS (smishing), voice calls (vishing), or email, using stolen sender identities or long familiar numbers, and at an industry level it undermines trust in the branded communications legitimate businesses depend on.
More detail
Phishing campaigns are cheap to attempt but costly for the brands they impersonate: a convincing fake bank-alert text or delivery-failure SMS drives replies, credential theft, and downstream fraud, then teaches recipients to distrust every message from that sender — including the real ones. Smishing and vishing reuse the same playbook across channels, and caller-ID spoofing and compromised SMS routes are two of the technical enablers.
Defenses layer sender authentication with recipient filtering. On messaging, controlled channels like verified alphanumeric sender IDs, A2P 10DLC registration, and RCS verified senders make impersonation harder; on voice, STIR/SHAKEN attestation marks how strongly the caller's number is verified. On the recipient side, SMS firewalls and spam filters inspect content and patterns to flag or block suspected phishing before delivery.
Legitimate senders reduce phishing risk by keeping their own traffic unmistakable: consistent sender identity, registered brands and campaigns, DMARC enforcement on email, and avoiding look-alike URLs in message bodies. When a phishing wave impersonates your brand, the response is abuse-desk reporting, blocklisting the impersonating identifiers, and customer comms — not stopping legitimate sends.
Häufige Fragen
- What is phishing?
- Phishing is an attack where a fraudulent message impersonates a trusted brand or institution to trick the recipient into sharing credentials, payment details, or personal data, or into installing malware. It arrives over SMS (smishing), voice (vishing), or email, using stolen sender identities or look-alike numbers and links.
- What is the difference between phishing, smishing, and vishing?
- They are the same attack on different channels: phishing is the general term (often email), smishing is phishing over SMS text messages, and vishing is phishing over voice calls where the attacker impersonates a bank, carrier, or support agent live on the phone.
- How do businesses protect customers from phishing that impersonates their brand?
- Register and verify your sender identities (A2P 10DLC brands and campaigns, alphanumeric sender IDs, RCS verified senders, DMARC on email), keep your URLs consistent and recognisable, monitor for look-alike domains and spoofed sender IDs, and report impersonation to carrier abuse desks — while SMS firewalls and spam filters block flagged messages in transit.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.