A phisher is the person who plans and carries out a phishing attack to trick a victim into giving up credentials, personal data, or financial information. It is not phishing itself, which is the technique or fraud, but the human attacker who uses social engineering to make those lies seem believable. That distinction matters in Human Risk Management programs because it makes it possible to measure and manage behavior, not just assign training.
What is the difference between phishing and phisher?
Phishing is the fraud or deception technique, while a phisher is the person behind it. According to the Government of Argentina, the phisher is the cybercriminal who designs and sends the scams; the Basque Government and the Government of the Canary Islands also distinguish the attack from the person who carries it out. In practice, using the term phisher helps focus analysis on attacker behavior.
Why does this distinction matter in an HRM program?
Because an HRM program needs to understand how the phisher attacks in order to model context, simulate scenarios, and tailor training based on risk. Whalemate works with that logic through advanced simulations, adaptive training, human risk analytics, and an awareness agent. The risk score combines signals from simulations, courses, reports, and behavior, and it is used to prioritize interventions.
