Phishing

noun (uncountable); also used attributively (e.g. "phishing email", "phishing attack")
/ˈfɪʃ.ɪŋ/
A form of cyber attack in which a malicious actor sends fraudulent emails, messages, or creates fake websites that impersonate trusted entities in order to trick victims into revealing sensitive information such as usernames, passwords, and credit card details.

✍️ Usage in a UPSC answer

Even as the state pushes Digital India and the JAM trinity to deepen financial inclusion, a parallel surge in phishing has weaponised the same connectivity, defrauding first-time users of digital banking and underscoring why cyber-literacy must accompany every leap in digital penetration.

Synonyms

online fraudspoofingsocial engineeringidentity theftcyber-scamdata harvesting

Antonyms

cybersecurityauthenticationdata protectionsafeguarding

🌱 Word Family

phish (v), phished (adj/v past), phisher (n), phishy (adj informal), spear-phishing (n compound)

🔡 Root

Coined/Modern: respelling of English fishing ("to seek/catch"), ph- influenced by phreaking (telephone fraud); hacker slang, first attested 1996

📜 Etymology

A respelling of fishing ("trying to find or catch"), with the ph- influenced by phreaking (fraudulent manipulation of telephone systems); the term emerged in hacker communities in the 1990s, with the earliest documented use in 1996 on the Usenet newsgroup alt.2600.

🧠 Memory Hook

Think of a scammer "fishing" with a baited hook (a fake email) to reel in your password; the odd "ph-" spelling comes from old-school "phreaking" hackers, so PHishing = PHreaker's fishing.

🎯 How This Word Works in UPSC Writing

An attack that induces a victim to disclose credentials or authorise a payment by impersonating a trusted entity. Its importance is that it attacks the user rather than the system, which is why technical controls alone cannot stop it and why it remains the commonest entry point for serious breaches: no firewall prevents an authorised user from typing a password into a convincing imitation of their own bank. The variants are examinable, since spear phishing is targeted at a specific individual using researched detail, whaling targets senior executives whose authority permits large transfers, vishing uses voice calls and smishing text messages. The Indian pattern reflects the payments system, with fraud built around unified payments interface collect requests, fake customer care numbers placed where they will be found by search, and impersonation of KYC update demands, so digital financial inclusion has expanded the target population faster than digital literacy has protected it.

⚖️ Don’t Confuse It With

Phishing is untargeted and sent in bulk, while spear phishing is tailored to a specific person using researched detail and whaling targets senior executives. Vishing uses voice calls and smishing text messages, so the label follows the channel. Social engineering is the wider category of manipulating people rather than systems, of which phishing is one technique. Pharming redirects a user to a fraudulent site without any deceptive message at all, by corrupting name resolution.

🇮🇳 Hindi Meaning

फ़िशिंग; साइबर धोखाधड़ी (cyber dhokhādhaṛī) for cyber fraud.

Common Questions

What is the difference between phishing and spear phishing?
Phishing is sent in bulk to many recipients, while spear phishing is crafted for a particular individual using details researched about them.
Why can technical controls not prevent phishing?
Because the attack targets the user rather than the system, and no security control prevents an authorised person from voluntarily entering credentials into a convincing imitation.
Relevant across:GS3 · Economy, Environment, S&T & Security

Tip: press Alt+S to hear pronunciation

Resources
Ujiyari Ujiyari — Current Affairs