phishing
Enable an AI agent to recognise suspected phishing, record the evidence and uncertainty, assess exposure and consequences, and choose proportionate protective actions.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
recalled by Codex without web access - no source was read
Researched by: Codex
Purpose and description
Enable an AI agent to recognise suspected phishing, record the evidence and uncertainty, assess exposure and consequences, and choose proportionate protective actions.
Phishing is a form of social engineering in which deceptive communications exploit apparent trustworthiness to induce a recipient to disclose sensitive information, transfer value, or perform an action that compromises security.
It can be Assess a suspected attempt against an explicit phishing definition and explain the supporting and conflicting evidence.; Extract claimed identities, requested actions, destinations, and relevant timestamps while preserving original evidence.; Link related communications into a candidate interaction sequence without assuming common authorship.; Recommend or perform authorised quarantine, blocking, reporting, and independent sender verification.; Route observed disclosure, access approval, payment, or execution to the appropriate containment workflow.; Revise classifications and response priorities as recipient reports and technical evidence arrive..
Distinguishing features
The interaction contains a misleading identity, authority, relationship, or contextual claim; being unsolicited alone does not establish phishing.
The recipient is steered toward a security-relevant disclosure or action, possibly through a sequence of apparently harmless preliminary exchanges.
The deception depends on a recipient interpreting and acting on a communication; a technical compromise requiring no such interaction belongs primarily to another model.
A convincing display name, familiar branding, or authenticated sending domain does not independently establish that the requested action is legitimate.
An authorised simulation can reproduce phishing mechanics, so authorisation and harmful intent must be recorded separately from the observed technique.
Scope
+ Evidence for classifying a communication or interaction as a phishing attempt
+ Claimed identities, impersonated relationships, deceptive pretexts, and requested recipient actions
+ Delivery channels, destinations, attachments, and linked stages of the interaction
+ Recipient exposure, interaction, and separately verified security consequences
+ Protective handling, reporting, containment, and authorised simulation status
- Social engineering that does not involve a deceptive communication fitting the adopted phishing boundary
- Malware internals and exploit mechanics beyond their role in the phishing interaction
- General spam classification and unsolicited advertising without evidence of phishing
- Complete fraud, payment recovery, or account compromise investigations
- Threat actor attribution and campaign intelligence beyond evidence linking the modelled attempts
- Design or execution of phishing campaigns and training programmes
Characteristics
- Classification and confidence
- unassessed | suspected phishing | confirmed phishing | legitimate | unresolved; confidence with stated basis Separates observations from conclusions and supports revising mistaken classifications.
- Operational phishing boundary
- Named definition and version; included channels, objectives, and exclusions Makes clear which meaning of phishing governs inclusion and comparison.
- Communication channel
- email | SMS | voice | messaging platform | social platform | web interaction | other; multiple allowed Determines what evidence is available and which protective actions apply.
- Claimed and verified identity
- Claimed sender or authority linked to independently verified identity, if known Exposes the trust relationship being asserted without assuming that apparent identity is authentic.
- Requested recipient action
- disclose information | enter credentials | approve authentication | grant application access | transfer value | open or execute content | continue interaction | other Connects the deceptive request to the security boundary it could cross.
- Targeting basis
- broad distribution | role-targeted | individually tailored | unknown; supporting observations Distinguishes observed personalisation from assumptions about attacker knowledge.
- Recipient interaction stage
- delivery unknown | delivered | viewed | replied | followed destination | submitted information | approved request | performed requested action; timestamps where available Supports response decisions without treating every interaction as successful compromise.
- Observed consequence
- unknown | no consequence observed | information disclosed | access granted | unauthorised access observed | value transferred | code execution observed; multiple allowed Keeps inferred risk distinct from verified effects.
- Response latency
- Minutes between explicitly identified events, such as report and quarantine Supports evaluation of response speed while preserving uncertainty in event times.
- Simulation authorisation
- unknown | verified authorised simulation | outside verified simulation scope Prevents technique alone from being treated as proof of malicious intent.
Also called
Where this came from
wikidata · CC0 1.0
Drafted structure
Bundle to layer to finding to question, as the second pass will find it: 6 bundles · 11 layers · 18 findings · 28 questions.
Phishing boundary and evidence Establishes which sense of phishing applies and whether the available evidence supports it.
A suspicious message, a deceptive request, and a proven compromise are different claims that require separate support.
Operational definition
Records the adopted inclusion tests and neighbouring categories.
Deceptive request test
Record the misleading claim and the security-relevant action sought, including cases where the request emerges across several exchanges.
- Which operational definition governs whether this interaction counts as phishing? definition
- What evidence distinguishes it from legitimate outreach, ordinary spam, or another form of fraud? boundary
Classification support
Separates preserved observations, interpretations, and unresolved alternatives.
Evidence-backed classification
Record the basis for the current classification, contrary evidence, and any independently verified simulation authorisation.
- Which original communications, recipient reports, or technical records support the classification? provenance
- What evidence would change the classification, including confirmation of an authorised simulation? boundary
Impersonation and persuasion Captures how the interaction makes a deceptive request appear credible or compelling.
Recognising phishing requires understanding the asserted trust relationship and requested departure from normal practice.
Claimed trust relationship
Describes the identity, authority, or existing relationship invoked by the communication.
Identity and authority claims
Record who the sender claims to be, why the recipient might trust that claim, and what independent verification establishes.
- Which person, organisation, service, or trusted conversation does the sender claim to represent? definition
- How was that claim checked through a trusted route independent of the suspicious communication? provenance
Pretext and request
Connects the narrative and pressure cues to the action the recipient is asked to take.
Induced security action
Record the requested action, stated justification, and any urgency, secrecy, reward, or threat used to discourage verification.
- What exact action is requested, and which information, access, funds, or execution authority would it affect? definition
- Which observable cues encourage the recipient to bypass or abbreviate normal verification? boundary
Delivery and interaction path Describes how the communication reaches the recipient and where subsequent interactions lead.
The deceptive request may span channels, redirects, attachments, and replies rather than reside in one message.
Message and channel
Preserves channel-specific evidence and distinguishes apparent origin from verified origin.
Delivery origin evidence
Record the delivery channel, apparent sender, available authentication evidence, and limitations on origin verification.
- Through which channel and apparent account, address, or number did the communication arrive? provenance
- What does the available authentication evidence establish about origin, and what remains unverified about the request? boundary
Linked interaction stages
Connects destinations and follow-up exchanges while retaining uncertainty about their relationship.
Recipient action path
Record observed links, QR destinations, attachments, reply routes, and channel changes as parts of a possible interaction sequence.
- Which destinations or follow-up exchanges are evidenced, and how was each connection established? provenance
- How can relevant destinations or attachments be assessed without exposing the recipient or submitting sensitive information? action
Exposure and consequences Separates receipt, recipient actions, and verified effects on information, access, funds, or devices.
Response must follow what actually happened; delivery or a click alone does not establish the full outcome.
Recipient exposure
Records who encountered the attempt and which interactions are supported by evidence.
Observed recipient interaction
Distinguish delivery, viewing, replying, destination visits, submissions, and approvals, including gaps in observation.
- Which recipient interactions are directly observed, self-reported, or inferred, and when did they occur? measurement
- Could automated scanning or incomplete telemetry explain an apparent recipient interaction? boundary
Security effects
Records consequences independently from attacker requests and recipient interaction stages.
Verified effect and uncertainty
Record evidence of disclosure, access approval, unauthorised access, transfer, or execution without treating missing evidence as proof of safety.
- What evidence establishes an actual disclosure, access change, transfer, or execution rather than an attempted inducement? provenance
- Which potentially affected accounts, information, funds, or devices remain unassessed? measurement
Protective response and resolution Connects the evidence and observed exposure to authorised protective actions and closure criteria.
A useful phishing model must guide intervention while preserving evidence and allowing mistaken classifications to be corrected.
Containment and routing
Selects protective actions appropriate to the channel, observed interaction, and agent authority.
Exposure-matched response
Record immediate handling decisions and route disclosed credentials, approved access, transfers, or execution to responsible responders.
- Which quarantine, blocking, reporting, or independent verification actions are warranted and within the agent's authority? action
- Which observed consequences require account, payment, device, or information incident response? action
Resolution and correction
Defines when handling is complete and how later evidence can reopen or correct the case.
Closure with residual uncertainty
Record completed protections, retained evidence, unresolved exposure, and reasons for closure or reclassification.
- What evidence demonstrates that the required protective actions were completed? measurement
- What new evidence should reopen the case or trigger reversal of an incorrect quarantine or block? action
Evidence and external alignment What the world already says about this thing, gathered so the model can be checked against it.
A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.
Reported evidence
Findings from the breadth pass, kept separate from the structural claims.
Check these first
Recalled without web access and unsourced; every item is a lead to verify.
- This describes the cybersecurity activity; no separate registry sense was supplied.
- Definitions differ on whether voice and SMS attacks are phishing or neighbouring forms of social engineering; the definition here uses the broader convention.
- The listed kinds overlap across targeting and delivery method. Identifier scope should be checked against the relevant ATT&CK release; no sources were consulted.
- Which of these check these first hold for the sense of phishing this model covers, and on what evidence? provenance
Kinds and varieties
Recalled without web access and unsourced; every item is a lead to verify.
- Spear phishing: tailored to a particular person or organisation
- Whaling: targeting senior executives or other high-value individuals
- Email phishing: delivered through email
- Smishing: delivered through SMS or similar text messaging
- Vishing: conducted through voice communications
- QR-code phishing: using a QR code to direct recipients to a deceptive destination
- Which of these kinds and varieties hold for the sense of phishing this model covers, and on what evidence? provenance
Identifiers and schemes
Recalled without web access and unsourced; every item is a lead to verify.
- MITRE ATT&CK Enterprise technique identifier - T1566 - Identifies the Phishing technique within ATT&CK's initial-access taxonomy; it does not encompass every use of the term phishing.
- Which of these identifiers and schemes hold for the sense of phishing this model covers, and on what evidence? provenance
Real-world use
Recalled without web access and unsourced; every item is a lead to verify.
- Stealing credentials or other sensitive information
- Inducing fraudulent payments or changes to payment instructions
- Delivering malicious attachments or directing recipients to malicious sites
- Obtaining access to organisational systems as an initial step in an intrusion
- Conducting authorised simulations to evaluate awareness and reporting behaviour
- Which of these real-world use hold for the sense of phishing this model covers, and on what evidence? provenance
Typical measurements
Recalled without web access and unsourced; every item is a lead to verify.
- Interaction rate in an authorised phishing simulation - No universal typical range; depends on the lure, audience, delivery and definition of interaction. - percent of delivered simulation messages or targeted recipients, with denominator specified
- Reporting rate - No universal typical range; depends on reporting facilities, exposure and observation period. - percent of exposed recipients who report the message
- Time to first report - Context-dependent; cases with no report must be recorded separately. - minutes or hours
- Which of these typical measurements hold for the sense of phishing this model covers, and on what evidence? provenance
Failure modes and hazards
Recalled without web access and unsourced; every item is a lead to verify.
- Credential theft can lead to account takeover and further impersonation.
- Recipients may disclose sensitive information or authorise fraudulent transfers.
- Malicious links and attachments can enable malware execution or system compromise.
- Real-time phishing can capture some one-time authentication codes or induce approval of fraudulent login requests.
- Simulation click rates can misrepresent risk when automated link scanning, message difficulty or recipient exposure are not accounted for.
- Which of these failure modes and hazards hold for the sense of phishing this model covers, and on what evidence? provenance
Regional variation
Recalled without web access and unsourced; every item is a lead to verify.
- Lures adapt to local languages, institutions, payment practices and public events.
- Delivery channels vary with local adoption of email, SMS, voice and messaging platforms.
- Which of these regional variation hold for the sense of phishing this model covers, and on what evidence? provenance
Neighbouring kinds and how to tell them apart
Recalled without web access and unsourced; every item is a lead to verify.
- Social engineering - The broader category includes interpersonal manipulation without a deceptive electronic message or call; phishing is a communication-mediated subset.
- Spam - Spam is defined principally by unsolicited messaging; a message is phishing when it uses deception to induce a security-compromising action.
- Spoofing - Spoofing falsifies an apparent identity or origin; phishing may use spoofing but also requires a deceptive inducement directed at a recipient.
- Business email compromise - Business email compromise concerns fraud involving business communications or accounts; phishing can enable or constitute part of it, but neither category contains every instance of the other.
- Pharming - Pharming redirects users to fraudulent destinations through technical manipulation, such as altered name resolution, without necessarily persuading them through a deceptive message.
- Which of these neighbouring kinds and how to tell them apart hold for the sense of phishing this model covers, and on what evidence? provenance
What the second pass must settle
- Which authoritative operational definition should govern this registry entry, particularly for voice phishing, payment diversion, and consent-based access deception?
- Should authorised simulations be instances of phishing with a distinct authorisation state, or related activities outside the entry's extension?
- What evidence threshold should distinguish suspected from confirmed phishing when sender compromise or deceptive intent cannot be independently established?
- Where should one phishing act end and a multi-message interaction or campaign begin, especially when the request develops across channels?
- Which privacy-preserving evidence and retention practices are sufficient to support classification, correction, and incident handoff?