Phishing is a form of internet fraud that deceives users into disclosing their sensitive and personal information by entering it on a fake website created by fraudsters.
During phishing, the user receives a message via email, social network, or other means, and the sender is often indicated as a financial institution or another organization familiar to the user. Sometimes, the sender's name is an imitation of the legitimate organization's name. Fraudsters attempt to trick the user into clicking on a link provided in the message, which leads to a fake website, and/or downloading an attached malicious file presented as a legitimate document. In this way, the user's information (any data entered by the user on the website, as well as information obtained by the downloaded malicious file) ends up in the hands of fraudsters, enabling them to use this information for their criminal purposes.
It is noteworthy that the fake website created by fraudsters is, in most cases, visually as similar as possible to the real, official website of a financial institution (e.g., an internet banking website, various payment websites). On a counterfeit website resembling internet banking, by entering the username, password, and other security credentials, fraudsters gain access to the user's bank accounts, which means they can take out loans in the victim's name, breach deposit agreements and appropriate funds, transfer money, etc. On a payment website, by disclosing the card number, expiration date, and three-digit security code, fraudsters may be able to make unauthorized transactions online using the user's card.