In plain English
This means telling the right person, organisation, or service that a message may be pretending to come from someone trusted. The concern is that it is trying to get sensitive information or pressure someone into doing something harmful.
In context
Here, "report phishing" denotes an action to notify the relevant service or security team that the message is suspected to be a deceptive message posing as a trusted source in order to obtain sensitive information or cause harmful action.
- Situation
- Responding to phishing, suspicious activity, fraud, and compromise alerts
- What it communicates
- offers an action to flag the message to the service or security team.
Meaning limits
The term alone does not establish whether the suspicion is correct or what result will follow from making the report.
Examples
“After a text claiming to be from his bank asked for his PIN, he called support to report phishing.”
“Staff are told to report phishing to the security team when a message appears to come from a manager and demands a fast payment.”