Phishing is the attempt to induce a victim to reveal credentials, download malware, or perform a harmful action (such as a bank transfer) through social engineering — typically via email, but also SMS (smishing), calls (vishing) or QR codes (quishing). It is the most common entry point for corporate cybersecurity incidents — consistent studies show phishing as the initial vector in 70%+ of breaches.
Modern phishing is sophisticated. It goes far beyond the poorly translated emails from a Nigerian prince. Spear phishing targets a specific individual (an executive, a finance officer) with a plausible pretext; Business Email Compromise (BEC) imitates internal emails to authorise transfers; whaling specifically targets CEOs and CFOs. Generative AI has drastically lowered the cost of creating credible phishing in any language, including European Portuguese.
INFOS implements defence in layers: email security that filters known threats, correct DMARC/SPF/DKIM (to prevent spoofing of the customer's domain), mandatory MFA (even with a compromised credential, the attacker still needs the second factor), and continuous training with real phishing simulations. The human component is the most decisive — technical tools block 95%, but the 5% that get through fall to the employee's literacy.