Compliance Node Overview
MITRE CAPEC-98 (Phishing) is a social engineering attack pattern in which an attacker masquerades as a legitimate entity to prompt the user to reveal confidential information (very frequently authentication credentials). Likelihood of attack: High. Typical severity: Very High. Maps to CWE-451 (User Interface Misrepresentation of Critical Information) and to MITRE ATT&CK T1566 (Phishing) and T1598 (Phishing for Information). Compliance: PCI DSS v4.0 Requirement 5.4 (anti-phishing controls), NIST SP 800-53 AT-2 (Literacy Training and Awareness), AT-3 (Role-Based Training), NIS2 Article 21(2)(g), DORA Article 13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/98.html
SHA-256 integrity: 3a6017d8becf0a9d2ce8c64e5941a2454d9d56c93cfe0dcb7561416cac796c29
Primary Citations — 8 traced to source
- MITRE CAPEC-98: Phishing (https://capec.mitre.org/data/definitions/98.html)
- CWE-451: User Interface Misrepresentation of Critical Information
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.