Skip to content
Infrastructure & Security

Phishing

A social-engineering attack that induces the victim to reveal credentials or perform harmful actions.

Full definition

Phishing is the attempt to induce a victim to reveal credentials, download malware, or perform a harmful action (such as a bank transfer) through social engineering — typically via email, but also SMS (smishing), calls (vishing) or QR codes (quishing). It is the most common entry point for corporate cybersecurity incidents — consistent studies show phishing as the initial vector in 70%+ of breaches.

Modern phishing is sophisticated. It goes far beyond the poorly translated emails from a Nigerian prince. Spear phishing targets a specific individual (an executive, a finance officer) with a plausible pretext; Business Email Compromise (BEC) imitates internal emails to authorise transfers; whaling specifically targets CEOs and CFOs. Generative AI has drastically lowered the cost of creating credible phishing in any language, including European Portuguese.

INFOS implements defence in layers: email security that filters known threats, correct DMARC/SPF/DKIM (to prevent spoofing of the customer's domain), mandatory MFA (even with a compromised credential, the attacker still needs the second factor), and continuous training with real phishing simulations. The human component is the most decisive — technical tools block 95%, but the 5% that get through fall to the employee's literacy.

Talk to a specialist

Let's talk.
We'll come back within 24h with next steps.

No complicated forms. One email or call, a team that knows your sector, and a concrete path forward — whether MULTI, MAXIRETAIL, KORA, PPLPORTAL or infrastructure.

Talk to a specialist

Book a demo

Leave your details and we'll get back to you within one business day with next steps.