Definition

A technology offense involving unauthorized access, interference, deception, or unlawful interception using electronic systems. It is defined by authorization status, protected system or data, and the required intent or harm elements where applicable. It does not include authorized access or communications conduct that satisfies applicable consent requirements. It safeguards system and data integrity and commonly supports restitution and forfeiture remedies. The concept is generally stable, though coverage expands as technical methods evolve over time.

Principle

Principle
Phishing relies on impersonation, urgency, or social pressure to bypass ordinary skepticism and security controls; liability derives from the deceptive intent and the induced compromise of confidential information or system integrity.

Demonstration

Demonstration
An attacker sends an email that appears to come from a user's bank asking to 'verify' login details via a provided link; the linked site captures the credentials and the attacker uses them for account takeover.

Misapplication

Misapplication
Labeling routine marketing emails with poor design as phishing without evidence of malicious intent, or conflating benign notification mistakes with deliberate social‑engineering attacks.

Consequence

Consequence
Successful phishing can lead to credential compromise, financial loss, ransomware deployment, large‑scale data breaches, and subsequent criminal prosecutions for fraud, unauthorized access, or related offenses.

Reversal

Reversal
Communications that are transparently authorized and sent by legitimate parties with consent (e.g., verified notifications from a known vendor) are not phishing; voluntary disclosure of credentials by the user also negates deception-based elements.

Boundary

Boundary
Encompasses fraudulent communications intending to elicit secrets or malicious actions; it does not include technical malware distribution absent social engineering, nor all forms of spam or unwanted advertising lacking deceptive impersonation.

Semantic Tension

Semantic Tension
Tension exists between phishing as a social‑engineering vector and malware as a technical vector: phishing is human-targeted deception often used to deliver malware, while technical exploits can operate without deceptive messaging.

Synthesis

Synthesis
Phishing is the deceptive manipulation of human trust to obtain sensitive information or compel actions that enable unauthorized access; it is primarily a social‑engineering crime whose harms multiply when coupled with technical exploits.