Discussion about this post

User's avatar
Interisle Consulting Group's avatar

There are two aspects to targeting and two kinds of victims.

The recipient of an email or text is the primary victim because they are the ones who'll suffer a loss or harm if they fall for the bait and disclose sensitive information.

The organization that's impersonated as part of the deception - Facebook, IRS, USPS, etc. - can be both primary and collateral targets. They are collateral targets when they are used as the bait, e.g., an IRS overdue payment scam.

Organizations are primary targets when the phisher's objective is to find a way into an organization, e.g., an email purportedly from your email admin asking you to reset your password.

When we measure phishing activity, we measure phishing attacks, but also measure "impersonated brands". If you're interested, read https://interisle.net/phishinglandscape2025

Mohib Ur Rehman's avatar

Good read - btw curious, have you ran a phishing campaign, ever?

2 more comments...

No posts

Ready for more?