Version history
Releases and changes
IDs are stable across releases. We add new entries, refine descriptions, and keep retired entries published.
Current release
Layers
34 techniques (58 sub-techniques), 48 themes (28 sub-themes), and 7 calls to action.
Mapped entries
111 entries carry a mapping to MITRE ATT&CK®.
Crosswalk
Mappings target MITRE Enterprise ATT&CK v19.
Coverage
Contact methods include email, SMS, Teams, phone calls, and website contact forms.
Data snapshot
Framework data as of 9 September 2026 (framework hash 662d5065).
License
CC BY 4.0 for framework content. See License and citation.
Change policy
Stable IDs
An ID always refers to the same concept. Nothing is renumbered.
Refinements
Every change to a description or a mapping is listed in the changelog below with its date. The version number changes when entries are added or retired.
Retirement
An entry that no longer occurs is marked retired rather than deleted, so historical reports still resolve.
Changelog
v1.0, 9 September 2026
First public release: techniques, themes, and calls to action. Crosswalk aligned to Enterprise ATT&CK v19: T1660 named Phishing, T1553 placed under Defense Impairment, Impersonation (T1684.001) used where the entry describes impersonation, Office Files, Attachment Padding, Fake CAPTCHA, Open Redirect, Encoded URL, and Automated Personalization re-mapped. TH0018 description rewritten. Typos fixed in TE0007 and TH0012. Terminal punctuation normalized. Crosswalk reduced to high-confidence mappings on 10 September 2026: generic parents beside a precise sub-technique, attacker preparation the message does not show, and delivery mechanisms on themes were removed, and credential harvesters now map to T1598.003 instead of T1056.003.
Earlier work
PH!SH began as an internal classification used to label reported phishing at scale. This is its first public form.