What the chuffing heck is mishing?

I have spent most of my professional career fighting the scourge of tech jargon. Mea culpa: I did write an internet jargon dictionary 30 years ago that included acronyms that I had invented, such as IBM (Iโ€™m Buck Naked), but itโ€™s probably best we forget that. Iโ€™d also like to suggest that we forget the current round of cybersecurity-focused jargon that, in my never humble opinion, does more harm than good. Jargon such as mishing.

What the chuffing heck is mishing? Or what is missing, as my spellcheck insisted on correcting me, quite logically as it turns out: what is missing is common sense. Have you worked it out yet?

The context is an email I received informing me of a new threat intelligence report from Zimperium which, in and of itself, is a worthy piece of analysis, looking at malware variants that target mobile credential theft through login and 2FA compromise. Things took a ridiculous turn when Zimperium told me that โ€œthese attacks are powered by mishing campaigns and sideloaded apps that silently harvest access keys from the very devices employees rely on every dayโ€.

What are mishing campaigns, then?

Mishing campaigns, it turns out, are mobileโ€‘focused phishing campaigns. Or, as I prefer to call them, phishing campaigns.ย 

Whatโ€™s wrong with good old-fashioned plain English, for goodnessโ€™ sake? Mishing is as confusing as vishing (voice or video phishing, take your pick – see what I mean about confusing) or quishing (QR code phishing) or smishing (text message phishing, which begs the question why not tishing?) at the end of the day.

Sensational terms just add noise, said Paul Walsh, an internet security veteran who has been in the game as long as me. Walsh, CEO of MetaCert and Co-Founder of the W3C Mobile Web Initiative in 2004, told me that โ€œQuishing is phishing. Smishing is phishing. PDF phishing is phishing. They all use the same trick. They impersonate something trusted, hide a link to a fake page or download and hope you tap it.โ€

Phishing by another name…

And thatโ€™s the point. Introducing new jargon to describe old threats doesnโ€™t somehow make them easier to deal with. Iโ€™d argue it makes it harder. Not least, as it is a distraction from the simple truth that, as Walsh said, all phishing is a one-trick pony.

โ€œMassive breaches are no longer starting on desktops, theyโ€™re starting in your pocket,โ€ said Nicolรกs Chiaraviglio, Chief Scientist at Zimperium. โ€œOrganisations must take mobile security seriously to stop credentialโ€‘stealing malware before it compromises enterprise resources.โ€ That, I canโ€™t argue with, but please, Nicolรกs, letโ€™s keep the message clear and do away with unnecessary jargon.

Mic drop. Rant over. Youโ€™re welcome.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.