GCSE · Computer Science · AQA · Spec 8525

Pharming

You type a shop’s address perfectly — no links, no shortcuts. The page looks exactly right. It’s a fake. You made no mistake. So how did you get there?

Cyber security · Follow the address

One address, three journeys

Your browser can’t connect to a name like www.cloudshop.example. It needs the address of the server that holds the site, so the name has to be looked up first. You never see that lookup happen — and that’s exactly where pharming strikes.

Keep your eye on “server address”. In which step does it go wrong?

Message: www.cloudshop.example — typed correctly, every single time

You type the address→Addresses stored on your computer→DNS server→Site you reach
journey=A · a normal dayyou reach=—server address=not known yet

Output

 

Step 1: Journey A. You type the address perfectly. Now the name has to be looked up to find the server’s address.

1 / 11

Press Next to follow the lookup one step at a time. Three journeys, one address, typed correctly every time.

Step 1 of 11: Journey A. You type the address perfectly. Now the name has to be looked up to find the server’s address..

Watch out: Typing the address yourself doesn’t protect you from pharming. The attack isn’t in what you typed. It’s in the lookup that happens afterwards.

What the fake site is for

?

Reason it through

Why would an attacker go to the trouble of sending you to a fake copy of a website?

Link 1 of 4

First link · your turn

You’ve landed on the fake site. What do you actually see?

2
Locked — reveal the link above first
3
Locked — reveal the link above first
4
Locked — reveal the link above first

Phishing vs pharming

PhishingvsPharming

Two threats with almost the same name. The difference is how the user gets caught out.

Focus

How the user is caught out

Phishing

They’re tricked into following a link in a message.

Pharming

They can type the correct web address and still be sent to the fake site.

The insight

This is the difference people mix up most. Phishing needs the user to take the bait. Pharming works even when the user does nothing wrong.

Where the trick is

Phishing

In the message, which is written to fool the user.

Pharming

Out of the user’s sight, after they’ve typed the address.

Does typing the address yourself help?

Phishing

Yes — if you never follow the link, that trick can’t work.

Pharming

No — the address is right; it’s the lookup that’s been tampered with.

Predict, then check

Two protections, and two different places the attack can happen. Think about where each one works.

Priya’s anti-malware is fully up to date and her computer is completely clean. But the DNS server her computer asks has been compromised. Does her anti-malware keep her away from the fake site?

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

You typed it perfectly. You still ended up on a fake site.

What you need to know

  • Pharming is when a user trying to visit a genuine website is redirected, without knowing it, to a fake website that looks like the real one.
  • Before a browser can connect, the web address has to be turned into the address of the server that holds the site. Pharming tampers with this step.
  • It can happen in two places: malicious code on the user’s computer changes the address information stored there, or a DNS server is compromised so that it sends back the fake site’s address.
  • The fake site collects personal details the user types in — usernames, passwords, bank details — which the attacker can use for fraud or to get unauthorised access to accounts.
  • In phishing, the user is tricked into following a link in a message. In pharming, the user can type the correct web address and still be sent to the fake site.
  • To protect against pharming: keep anti-malware software up to date so it can detect code that changes address settings, and check that a site uses a secure connection with a valid certificate before entering personal details.

The big picture

Pharming sends you to a fake website even when you type the correct web address. It works by tampering with the hidden lookup that turns a web address into the server’s address: either malicious code changes the address information stored on your computer, or a DNS server is compromised. The fake site looks real, so you type in details like passwords or bank details, and the attacker uses them for fraud or to get into your accounts.

Key points

1You can do everything right and still be caught: the attack is in the lookup, not in your typing.
2Two attack points: the addresses stored on your computer, or a DNS server.
3The fake site is a trap for your details, which are then used for fraud or to get into your accounts.
4Phishing: tricked into following a link. Pharming: correct address, wrong destination.
5Anti-malware guards your own computer; checking for a secure connection and valid certificate guards the moment you type your details.

Worked example

Problem

Several students at a school type the correct address for the school’s learning website, and all of them land on the same fake login page. Their computers have been scanned with up-to-date anti-malware and are clean. Explain what has most likely happened, and why the students didn’t notice.

⚠ Watch out

Thinking you’re safe from pharming as long as you type the address yourself. That avoids a phishing link, but pharming tampers with the lookup after you’ve typed — so a perfectly typed address can still take you to the fake site.

🧠

Memory hook

Think of your phone’s contacts. You tap “Mum” and trust the number saved behind the name. If someone secretly swapped it, you’d ring a stranger without doing anything wrong. Pharming swaps the address behind a web address — in your computer’s stored list, or at a DNS server.

✓

Check yourself

Cover the page. In two sentences, explain how someone who types a web address perfectly can still land on a fake site. Then name one protection and the step it guards.

Flashcards

(12)
What is pharming?
A cyber security threat where a user trying to visit a genuine website is redirected, without knowing it, to a fake website that looks like the real one.
Why does a web address have to be looked up before the browser can connect?
The browser needs the address of the server that holds the site, so the web address has to be turned into that server address first.
What does a DNS server do?
It turns web addresses into the addresses of the servers that hold the sites.
Pharming attack point 1: what happens on the user’s own computer?
Malicious code changes the address information stored on the computer, so the web address leads to the fake site’s server.
Pharming attack point 2: what happens at a DNS server?
The DNS server is compromised, so it sends back the fake site’s address instead of the real one.
Why doesn’t a pharming victim notice anything is wrong?
The fake site looks like the real one, and the address bar still shows the address they typed.
What is a pharming site used for?
Collecting personal details the user types in, such as usernames, passwords or bank details.
What can an attacker do with details collected by a pharming site?
Use them for fraud, or to gain unauthorised access to the user’s accounts.
Phishing or pharming: the user types the correct address but still reaches a fake site.
Pharming. In phishing, the user is tricked into following a link in a message.
How does up-to-date anti-malware help against pharming?
It can detect malicious code that changes the address settings stored on your computer.
What should you check before entering personal details on a website?
That the site uses a secure connection with a valid certificate. This can still help when the tampering happened at a DNS server.
In pharming, does the attacker have to hack the real website?
No. The real site can be left alone — the attacker tampers with the lookup so that you’re sent to a different, fake site.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 29 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.