従業員が支払いウェブサイトからの電子メール内のリンクをクリックし、連絡先情報を更新するよう要求しました。従業員はログイン情報を入力しましたが、「ページが見つかりません」というエラー メッセージが表示されました。次のどのタイプのソーシャル エンジニアリング攻撃が発生しましたか?
正解:D
Phishing is a type of social engineering attack that involves sending fraudulent emails that appear to be from legitimate sources, such as payment websites, banks, or other trusted entities. The goal of phishing is to trick the recipients into clicking on malicious links, opening malicious attachments, or providing sensitive information, such as log-in credentials, personal data, or financial details. In this scenario, the employee received an email from a payment website that asked the employee to update contact information. The email contained a link that directed the employee to a fake website that mimicked the appearance of the real one. The employee entered the log-in information, but received a "page not found" error message. This indicates that the employee fell victim to a phishing attack, and the attacker may have captured the employee's credentials for the payment website.