Email phishing is a social engineering attack that uses a deceptive email to push a user into clicking, replying, or sharing credentials. It works by imitating trusted senders and using urgent or familiar language to bypass judgment. The goal is usually theft of information, account compromise, or initial network access.
Expanded Definition
Email phishing is not just a generic scam message. In NHI and IAM contexts, it is a delivery mechanism for credential theft, session hijacking, and malicious authorization. The email itself is only the entry point; the real objective is to manipulate a human into granting access that an attacker can later use against services, agents, or privileged workflows. That makes phishing especially dangerous when the target has access to secrets, token-bearing accounts, or approval paths that lead to NHI compromise.
Definitions vary across vendors when phishing is extended beyond direct credential harvesting to include OAuth consent abuse, invoice fraud, and help desk impersonation. For NHI governance, the practical test is whether the message aims to produce an access-relevant action, such as entering a password, approving a login, forwarding a reset link, or disclosing an API key. Guidance in the NIST Cybersecurity Framework 2.0 helps place phishing inside identity and awareness controls rather than treating it as a purely awareness-based issue. The most common misapplication is equating phishing only with suspicious links, which occurs when organisations ignore attachment abuse, reply-chain deception, and consent prompts.
Examples and Use Cases
Implementing phishing controls rigorously often introduces friction for users and support teams, requiring organisations to weigh stronger verification against slower communication and more authentication prompts.
- A finance employee receives a message that appears to come from a trusted supplier asking for an urgent invoice update, but the link leads to a fake login page designed to capture SSO credentials.
- A developer is sent a realistic alert requesting review of a “shared document,” then tricked into approving an OAuth consent screen that grants an attacker mailbox or file access. The CoPhish OAuth Token Theft via Copilot Studio research shows how phishing-style delivery can be used to steal tokens rather than passwords.
- An operator receives an email that mimics an internal security notice and is pushed to disclose a one-time code, enabling session takeover even when the password itself is not reused.
- An engineer replies to a “support” email and pastes an API key into the thread, converting a social engineering event into secret exposure and downstream NHI misuse, a pattern reinforced by the State of Secrets in AppSec findings.
- A cloud administrator clicks a lure tied to a breached vendor message, and the attacker uses the resulting foothold to pursue credentials in a broader chain similar to the DeepSeek breach context.
Industry usage still varies on whether executive impersonation, invoice fraud, and token-consent lures are all called phishing, but they share the same operational pattern: email-driven deception that produces an access action.
Why It Matters in NHI Security
Email phishing matters in NHI security because it is often the first step in compromising credentials, API keys, service accounts, and privileged approval channels. Once a single mailbox or SSO session is compromised, attackers can pivot to password resets, token extraction, agent invocation, or cloud console access. This is why phishing cannot be treated as a standalone awareness problem. It is a control-plane issue that affects identity assurance, access governance, and secret handling at the same time.
NHIMG research shows how quickly exposed credentials are acted on: when AWS credentials are published publicly, attackers attempt access within an average of 17 minutes. That speed demonstrates why phishing is so effective as a precursor to NHI abuse, because the window to detect and contain follow-on activity is very small. The State of Secrets in AppSec also notes that only 44% of developers follow security best practices for secrets management, which increases the blast radius when a phishing email induces disclosure. Organisations typically encounter the true cost only after account takeover, at which point phishing becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-1 | Phishing is addressed through awareness and training tied to human risk reduction. |
| OWASP Agentic AI Top 10 | A2 | Phishing can induce unsafe agent actions, tool use, or credential disclosure. |
| OWASP Non-Human Identity Top 10 | NHI-02 | Phishing frequently seeks secrets and tokens that enable NHI compromise. |
| NIST SP 800-63 | IAL2 | Phishing exploits weak identity proofing and recovery paths around authenticators. |
Constrain agent permissions and require validation before executing externally prompted actions.
Related resources from NHI Mgmt Group
- What should teams do when browser telemetry shows frequent non-email phishing?
- How should security teams defend against phishing when attacks move beyond email?
- Why does malvertising create a different phishing problem than email-based attacks?
- What should organisations do when phishing moves beyond email into texts and social media?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org