About this module
This first lesson explains phishing without jargon and makes one point clear: your inbox is part of the security perimeter. Attackers impersonate banks, managers, executives, and familiar services because people are used to trusting those names. The lesson compares mass phishing, spear phishing, and whaling, then looks at the pressure tactics that make phishing work: fear, urgency, and false authority. Since 91% of successful cyberattacks start with a phishing email, learners leave with four practical checks: verify the sender, hover links, avoid logging in from email links, and report anything suspicious.
Key takeaways
Every day, billions of emails flood inboxes around the world. Hiding among them are carefully crafted traps designed to steal your credentials, money, and data.
This is phishing.
Phishing emails look like messages from banks, managers, or well-known services. Attackers craft them to blend in with legitimate communications and trick you into taking dangerous action.
Phishing is when a cybercriminal pretends to be someone you trust — your bank, your manager, or a familiar service — using email to trick you into revealing passwords, financial data, or personal information.
Mass phishing — sometimes called spray-and-pray — blasts identical fraudulent emails to millions of people at once. Even a tiny success rate yields thousands of victims for attackers who invest almost no effort.
Spear phishing is far more dangerous. Attackers research their target — studying social media, company websites, and public records — then craft a convincing, personalized email that is very hard to detect.
Whaling attacks go after the biggest targets — C.E.O.s, C.F.O.s, and board members. Because executives have authority over finances and data, a single successful whaling attack can cost a company millions of dollars.
Here is a number that should stop you in your tracks: ninety-one percent of all successful cyberattacks start with a phishing email.
That makes your inbox the single most important security perimeter in your organization.
Phishing exploits human psychology. Attackers create a sense of fear — your account will be locked — urgency — act now before midnight — or false authority — your C.E.O. needs this immediately.
These emotional triggers cause people to act without thinking.
Four checks can stop most phishing attacks cold. Verify the real sender address behind the display name. Hover every link to preview the true destination U.R.L.
Never log into any site reached through an email. And always report suspicious emails to I.T.
When someone clicks a phishing link or opens a malicious attachment, malware can install in seconds — silently logging keystrokes, stealing saved passwords, or encrypting your files for ransom.
One click can compromise an entire organization's network.
If you receive a suspicious email, follow three simple steps. First, stop — do not click, reply, or forward it.
Second, document it with a screenshot. Third, report it to your I.T. security team so they can act quickly and protect everyone else.
Reporting a suspicious email is never an overreaction. Your I.T. security team wants to hear about every concern, no matter how minor it seems.
One report from a vigilant employee has prevented countless costly breaches across organizations worldwide.
You are now equipped to recognize the signs of phishing, resist the psychological pressure attackers create, and report every suspicious message to your I.T. team.
These three habits make you a critical line of defense for your entire organization.



