This is the practice of sending an email to a user falsely claiming to be and established legitimate enterprise, in an attempt to scam the unsuspecting user into surrendering private information such as user names, passwords, and credit card details.