As technology develops, digital crimes are also increasingly busy with various modes, including phishing. What is phishing? What are phishing actors looking for, and how to avoid it? Come on, let's discuss more in the article! Keep watching until the end!
What is Phishing?
Phishing is a digital crime to ask (lure) someone to reveal confidential information such as usernames and passwords by sending important fake messages, which can be e-mails, websites, or other electronic communications.
How Phishing Works
Phishing typically begins with the perpetrator identifying a target victim and collecting their data by sending fake messages, such as via email or through a fake webpage that looks like a legitimate website.
There are three types of data targeted by phishing:
- Personal data (name, age, address, telephone number)
- Account data (username and password), and
- Financial data (credit card or bank account information).
This data can be directly used by criminals to defraud victims or sold to other parties for irresponsible actions.
Phishing Types
Two types of phishing are popularly used for crimes in cyberspace, namely:
-
Phishing clones
This type of phishing is most often carried out using electronic mail or e-mail that looks official and contains attachments. The attachment is then used to retrieve data from the victim and then send it again to the place desired by the perpetrator.

Sumber : Merdeka.com
-
Spear phishing
In this type of phishing, the perpetrator generally searches for and recognizes data from the target so that the victim will not suspect that he is being attacked. Therefore, this type of phishing has a higher success rate due to its more specific target. The data usually taken from this type of phishing practice is in the form of passwords, credit card numbers, telephone numbers, and bank account numbers.
-
Smishing
Smishing is a form of phishing that uses text messages or SMS messages to send victims that appear to come from an official institution. These messages contain false information about compromised accounts and ask victims to provide personal or financial information.
-
Vishing
Vishing is a type of phishing that uses phone calls to victims. The perpetrator will attempt to obtain personal information or even infiltrate malicious software onto the victim's device.
-
Whaling
Whaling is a type of phishing that targets important individuals or those in high-ranking positions within an organization, such as managers, directors, CEOs, CFOs, or other high-ranking positions. The perpetrator will typically create an official-looking email or message claiming a legal or financial issue requiring immediate action, with the goal of getting victims to provide sensitive information such as tax identification numbers or bank account numbers.
-
Search Engine Phishing
This type of phishing is often referred to as Search Engine Optimization (SEO) Poisoning, where the perpetrator directs victims to fraudulent websites in search engine results. The perpetrator attempts to steal information when a victim interacts with the site.
-
Angler Phishing
This type of phishing exploits social media by creating fake links, cloning websites, or sending instant messages that trick individuals into providing personal information or downloading malware.
-
Deceptive Phishing
Deceptive phishing is a form of phishing attack in which the perpetrator attempts to deceive or trick victims by posing as a trusted or legitimate entity. The perpetrator typically pretends to be a legitimate company or agency and informs victims of a fake cyberattack to manipulate them into clicking on a malicious link to obtain personal information such as passwords, account information, or financial data.
-
Blind Phishing
Blind phishing is a form of phishing in which the perpetrator randomly sends phishing messages to many people because they lack specific information about their target victims. The perpetrator distributes phishing messages to many people in the hope that some will fall for the trap.
-
Web Phishing
Web phishing is a type of phishing attack that uses a fake website designed by the perpetrator to trick visitors into disclosing personal or financial information or data. Typically, the perpetrator creates a web page that mimics the official website of a well-known financial institution, company, or online service.
Phishing features
You can also learn the following phishing traits to avoid them.
-
Request personal information
Phishing is a manipulative crime because usually, the perpetrator asks the victim to fill in highly confidential personal information such as usernames, passwords, OTP codes, debit/credit card numbers, and CVV/CVC. The perpetrator asks for the victim's personal information by sending a link (link) to click on or a fake file to download.
You must remember that even bank employees cannot ask customers for this data. If you get a message asking for this data, it is better to ignore the message, block the sender's number/account, and report it to the bank.
-
Creates a sense of urgency
Phishing actors will usually ask the victim to make a decision as quickly as possible for various reasons, such as a promo that will end soon so that the victim will lose money if they don't take it, there is a suspicious transaction that must be immediately blocked on the card/account, profit opportunities from doing business, and others.
-
Using a fake identity
The third characteristic of phishing is that the perpetrator usually uses a fake identity, such as on behalf of an agency, company, or friend of the potential victim, to make the victim immediately believe the perpetrator's orders to provide sensitive data.
Some time ago, for example, many phishing scams used APK files via messages on behalf of a logistics company. The perpetrator usually creates a website address identical to the original website to make the victim believe it.
For example, there is a fake website that acts on behalf of Bank MAS by creating a website with an identical name, such as bankmass.co.id, while the original website, bankmas.co.id, only use one "s" at the end of the website address.
For that, you should double-check who sent messages to agencies, companies, or your colleagues who are named.
-
Phishing victim targets are not specific
The last feature of phishing is that usually, the perpetrator does not specifically target certain victims. This is indicated by phishing messages, which generally do not specifically state the victim's name. Perpetrators will use common greetings in their messages, such as "Dear Customers," "Dear Sir," "Dear Customers," and others.
How to Avoid Phishing
After knowing the characteristics of phishing, you can avoid it in several ways.
-
Do not click links or pop-ups or download suspicious files
If you receive a suspicious message asking you to click on a link or links, you should not click on the link. It could be that the link is part of a phishing practice sent by the perpetrator to steal your personal data.
Also, be careful when downloading files sent in messages such as emails, as they can contain viruses/malware that can steal sensitive data. Likewise, if a suspicious pop-up appears, don't click and enter your user ID and password in the pop-up.
-
Unknown phone alert
Phishing practices are not only through suspicious links or messages sent by perpetrators but can also be in the form of telephone calls. So, you must also be vigilant when receiving calls from unfamiliar numbers you don't recognize. If forced and have already received the call, listen to what the person calling. If there is a request regarding privacy matters or sending money, you should immediately hang up the phone.
-
Don't share important information
Never share sensitive information such as personal data via a reply to messages such as sms, or chat on social media, email, websites, and telephone if there are suspicious messages or calls on behalf of an agency or company. Remember that an agency or company will not ask customers for sensitive information via SMS, social media, or email.
If you receive a suspicious message or call and act on behalf of Bank MAS, you can contact Bank MAS Call Center at telephone number 021-3000-2500 or via email to customer care@bankmas.co.id
-
Change passwords regularly
The fourth way to avoid phishing is by regularly changing your accounts' passwords on social media and in banking. Changing passwords regularly secure your accounts so they are not easily hijacked by phishing and other crimes.
-
Access websites that use SSL
When you visit a website, make sure the website you are visiting uses has received an SSL (Secure Socket Layer) security certificate as a sign that the website is safe. Websites with SSL usually access the protocol "https://" not "http://."
You can also distinguish it from the padlock image that appears before the URL address.

Source: Shutterstock
-
Install Antivirus
The last way to deal with phishing is that you can install an antivirus on your device to avoid malware. Currently, many antiviruses are available for computers and mobile phones in the Play Store. You can choose to subscribe to a trusted antivirus by looking at the ratings and reviews from other users.
-
Verify emails or messages from unknown parties
If you receive a suspicious email, be wary and verify that it is from a legitimate, official institution. Look for signs such as spelling errors, poor grammar, or an email address that doesn't match the agency's actual email address.
-
Use Two-Factor Authentication
Two-factor authentication is useful when a perpetrator has already discovered the password and email address for an account, such as a bank account. If you have two-factor authentication enabled, the perpetrator may not be able to log in because they will be asked for a code on their phone or biometrics, preventing them from logging in.
-
Save Login Information Carefully
To avoid phishing, be careful about storing login information for your personal and financial accounts, such as usernames, email addresses, passwords, and transaction PINs. Don't leave this information in a public place, such as on a public computer or someone else's cell phone. You can save this login information in a note and store it in a safe place.
-
Report and block fake accounts
If you are contacted by someone claiming to be from a specific institution, such as a bank officer, and asked for your personal information, you can report the account to the relevant institution and have it blocked.
That's a discussion about phishing starting from its meaning, characteristics, and how to avoid it. You can also read other safe transaction tips on the Bank MAS website to prevent different modes of online fraud and keep your digital transactions safe.
Sources:
