What is Phishing? Anatomy of Attacks & Real-World Business Cases
1 / 15
Text15 min

What is Phishing? Anatomy of Attacks & Real-World Business Cases

Breakdown of Spear-Phishing, Business Email Compromise (BEC), and Fake Invoice wire fraud.

1. What is Phishing and why do attackers target SMEs?

Phishing is a social engineering technique where cybercriminals impersonate trusted entities (banks, suppliers, clients, logistics couriers, or tax authorities) to manipulate employees into revealing credentials, opening malicious attachments, or authorizing fraudulent wire transfers.

Cyber security threat monitoring
Figure 1.1: Cyber threat telemetry detecting unauthorized deception vectors.

Alarming Metric:

Over 85% of successful data breaches in small businesses originate from a single unvetted phishing email opened by an untrained employee.

2. Real-World Attack Breakdowns:

Fake Vendor Invoice (BEC)

Spoofed lookalike domains (e.g. supplier-invoices.com vs supplier.com) demanding immediate remittance to an offshore account.

Executive Impersonation (CEO Fraud)

High-pressure urgent notes mimicking senior leadership requesting immediate electronic funds transfers.

Code inspection and payload analysis
Figure 1.2: Dissecting weaponized attachments with double extensions (.pdf.exe).

3. Step-by-Step Defenses:

  1. Mandatory Out-of-Band Callback Policy: Never modify wire transfer bank details without verbal telephone confirmation via a pre-established phone number.
  2. Header & Exact Domain Inspection: Verify the true sender domain string following the @ symbol.
  3. Deploy SPF, DKIM & DMARC: DNS records that block domain spoofing at the mail server boundary.