{"id":1012,"date":"2025-12-22T08:48:35","date_gmt":"2025-12-22T07:48:35","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=1012"},"modified":"2026-05-29T23:10:03","modified_gmt":"2026-05-29T21:10:03","slug":"what-is-phishing-what-to-pay-attention-to","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-phishing-what-to-pay-attention-to\/","title":{"rendered":"What is phishing? What to pay attention to?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">When scaling enterprise web applications, securing corporate cloud directories, or safeguarding online business checkouts, maintaining a hardened cybersecurity perimeter is an absolute operational requirement. While network firewalls, cryptographic access tokens, and server blocks protect your hardware infrastructure from raw software exploits, malicious actors frequently target a different vulnerability: the human operational layer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The primary attack methodology used to exploit this vulnerability is <strong>Phishing<\/strong>.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-1888678532\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Phishing is a highly deceptive social engineering attack vector where cybercriminals masquerade as a trusted entity\u2014such as a bank, a cloud hosting provider, a utility corporation, or a senior executive\u2014to trick individuals into revealing sensitive credentials, financial data, or proprietary security access paths.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-phishing-what-to-pay-attention-to\/#1_Common_Phishing_Methodologies_and_Attack_Vectors\" >1. Common Phishing Methodologies and Attack Vectors<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/what-is-phishing-what-to-pay-attention-to\/#2_Critical_Warning_Signs_to_Watch_For\" >2. Critical Warning Signs to Watch For<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Common_Phishing_Methodologies_and_Attack_Vectors\"><\/span>1. Common Phishing Methodologies and Attack Vectors<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing operations have evolved far beyond basic mass-distribution spam, splitting into highly targeted execution strategies:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mass Campaign Phishing:<\/strong> Spray-and-pray operations where attackers send out thousands of identical, generic messages to unverified email lists. These commonly mimic urgent banking notifications, package tracking updates, or invoice demands, hoping a small percentage of recipients will click the embedded links.<\/li>\n\n\n\n<li><strong>Spear Phishing:<\/strong> A highly focused, customized attack targeting a specific individual, developer, or administrative worker within an organization. Attackers research their target using open-source intelligence (OSINT) and professional networks to craft highly convincing, personalized emails that reference active business projects or specific internal roles.<\/li>\n\n\n\n<li><strong>Whaling:<\/strong> A specialized branch of spear phishing directed exclusively at high-level corporate executives, such as CEOs, CFOs, or lead infrastructure directors. These attacks often take the form of fake legal subpoenas, high-priority corporate audits, or urgent wire transfer requests that demand immediate action.<\/li>\n\n\n\n<li><strong>Smishing and Vishing:<\/strong> Phishing variants executed outside traditional mail environments. Smishing utilizes SMS cell phone text strands containing malicious verification links, while vishing relies on voice phone calls where attackers use social engineering or AI voice synthesis to extract authentication codes over the phone.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Critical_Warning_Signs_to_Watch_For\"><\/span>2. Critical Warning Signs to Watch For<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To insulate your company operations from credential leaks, train your administrative and development teams to inspect all incoming communications for these behavioral and technical red flags:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>A. Artificial Urgency and Coercive Ultimatums<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing attacks depend on emotional manipulation to bypass logical verification. Messages often claim that your primary email mailbox will be locked, an active cloud domain will expire, a legal fine will be imposed, or a corporate payment has failed unless you click a link and re-verify your identity immediately.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>B. Mismatched and Deceptive Domain Names<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Always inspect the raw sender address line rather than relying on the visible display name. Attackers utilize subtle domain modifications\u2014known as <strong>typosquatting<\/strong> or lookalike domains\u2014to deceive targets. For instance, an email displaying the name of a verified host platform might actually originate from an address like <code>support@dhostlng-pl.com<\/code> (using an &#8220;l&#8221; instead of an &#8220;i&#8221;) or a generic, unaligned public account.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>C. Masked Hyperlinks and Fake Verification Portals<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Hovering your cursor over an embedded text link or button reveals its actual destination path. If an email claims to route you to your internal hosting management panel, but the hidden landing URL points to an unverified third-party IP address or an external scripting site, abort the connection immediately. These malicious portals mirror official login screens to capture typed passwords and multi-factor authentication tokens in real time.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>D. Generic Salutations and Missing Structural Verifications<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Automated mass campaigns frequently utilize generic greetings like &#8220;Dear Customer&#8221; or &#8220;Valued User&#8221; because they lack your exact account data records. Furthermore, legitimate business platforms rarely demand that you text back a raw password or transmit clear security tokens directly through an unauthenticated email thread.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42,10],"manual_kb_tag":[744,810,811,812,813,814,815,816,817,247],"class_list":["post-1012","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous","manualknowledgebasecat-safety","manual_kb_tag-phishing","manual_kb_tag-phishing-attacks","manual_kb_tag-phishing-prevention","manual_kb_tag-phishing-scams","manual_kb_tag-spear-phishing","manual_kb_tag-smishing","manual_kb_tag-pharming","manual_kb_tag-clone-phishing","manual_kb_tag-whaling","manual_kb_tag-phishing-protection"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/1012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":5,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/1012\/revisions"}],"predecessor-version":[{"id":5829,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/1012\/revisions\/5829"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=1012"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=1012"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=1012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}