Cybercriminals exploit human psychology through phishing emails, fake login pages and impersonation techniques. These attacks bypass technical defenses by manipulating users into revealing sensitive information, clicking malicious links or downloading infected files.
Typical signals
- Lookalike domains, OAuth consent phishing, MFA-prompt bombing
- Adversary-in-the-Middle (AitM) proxy flows (token/session theft)
- Smishing/QR-phishing + "CAPTCHA" lures to credential harvesters
Current-state check
- Shift from attachments to URLs and "malwareless" credential theft
- Protect collaboration tooling (Teams/SharePoint) and IdP portals
- Controls: phishing-resistant MFA, URL isolation, DMARC enforcement