Phishing
Phishing is a social engineering attack that attempts to trick users into revealing sensitive information or performing harmful actions by pretending to be a trusted source.
“An attempt to acquire personal or sensitive information by masquerading as a trustworthy entity in an electronic communication.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Phishing?
Phishing attacks commonly use fraudulent emails, websites, messages, or phone calls to steal passwords, financial information, or install malware.
Social engineering: Exploits human trust rather than technical vulnerabilities.
Impersonation: Attackers pretend to be legitimate organizations or individuals.
Defense: User awareness and email security reduce phishing risks.
Real World Example
A regulated product team is preparing a release where Phishing appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats Phishing as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Phishing and similar ideas.
The page becomes useful in practice because Phishing is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which statement BEST describes Phishing in the context of ISTQB terminology?
Question 2
A tester needs to explain Phishing to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Phishing. Test your understanding with topic-specific questions in our Mock Exams.