A fraud technique that tricks victims into handing over credentials via a fake site or similar.
A social-engineering attack that uses a fake email or site disguised as a legitimate service to trick victims into giving up credentials or other information. Defenses typically combine training people to spot subtle differences from a legitimate domain (typosquatting) with sender authentication (SPF/DKIM/DMARC) that blocks spoofed email.
© 2026 ITBGM