AI Governance Institute
← All news

Credential Phishing

Credential phishing is a social engineering attack in which an attacker tricks someone into revealing login details or authentication credentials by impersonating a trusted person or system. These attacks pose a critical compliance risk because compromised credentials give attackers access to sensitive data, proprietary AI models, training datasets, and governance systems without triggering technical security alerts. Organizations must address credential phishing through user training, multi-factor authentication, email monitoring, and clear reporting procedures to meet obligations under frameworks like SOC 2, ISO 27001, and regulatory standards for data protection.

1 item