Phishing emails appear to come from someone you know, trust, or would want to hear from but are, in fact, sent by someone else entirely (for instance, Russian hackers) to trick you into downloading malware or sharing login credentials or other sensitive information. Phishers can cast a broad net (“Dear Sir, I am a Nigerian prince please send me the details of your bank account …”) or a slightly smaller, more targeted one tailored to a particular organization or group of people (“Dear MIT user, your email is full, please click here to increase your quota …”). They can “spear phish” by sending even more targeted messages directed at particular individuals (“Dear Josephine, please complete the attached form prior to your dissertation defense …”). In general, the more targeted the message—and the falsified sender information—the more likely we are to fall for it. (I’ve never fallen for messages of the first two varieties, but you could fool me in a heartbeat with the third—and no, that’s not an invitation.)
