Phishing, pronounced "fishing," is the act of sending a false email claiming to be an established legitimate enterprise in an attempt to scam the recipient into surrendering private information that will be used for identity theft. The email directs the recipient to visit a web site where they are asked to update personal information, such as passwords, social security number, credit union account numbers – this is information that the legitimate organization already has. The web site, however, is a fraudulent site that is set up only to steal information.