Phishing is a technique where attackers impersonate a trustworthy source — like a bank or company — usually through email or fake websites, to trick people into revealing sensitive information like passwords or financial details. This lesson covers common phishing tactics (urgent language, fake links, spoofed sender addresses) and the broader concept of social engineering, which relies on manipulating human psychology rather than technical vulnerabilities — often considered one of the most effective attack methods because it targets people, not systems.