Phishing
Phishing is a type of social engineering attack that aims to deceive the victim and induce them to disclose confidential information or perform harmful actions.
What is Phishing?
What is Phishing?
Phishing is a type of social engineering attack that aims to deceive the victim and induce them to disclose confidential information or perform harmful actions.
Phishing Definition
Phishing is a fraud technique in which an attacker impersonates a trusted person or organization to extract confidential data such as login credentials, credit card numbers, or other sensitive information. The name “phishing” comes from the English word “fishing,” because the attacker “casts the bait,” waiting for the victim to “bite the hook.”
How Does Phishing Work?
A typical phishing attack proceeds as follows:
-
The attacker creates a fake message or website that looks legitimate.
-
The victim receives an email, SMS, or other form of communication that appears to come from a trusted source.
-
The message contains an urgent request or attractive offer, prompting the victim to act.
-
The victim clicks on a link or opens an attachment, leading to a fake site or malware installation.
-
The victim unknowingly shares their data or performs harmful actions.
Types of Phishing Attacks
-
Spear Phishing: Targeted attacks on specific individuals or organizations.
-
Whaling: Attacks targeting high-level executives.
-
Smishing: Phishing via SMS messages.
-
Vishing: Phishing using phone calls.
-
Clone Phishing: Creating copies of legitimate messages with modified links or attachments.
Phishing Examples
-
Fake emails from banks asking to update login credentials.
-
Messages imitating communications from popular social media services.
-
Fake notifications about winnings or unexpected inheritances.
-
Emails with alleged invoices containing malicious attachments.
Differences Between Phishing and Other Social Engineering Attacks
-
Phishing mainly relies on mass distribution of messages, while spear phishing is more targeted.
-
Unlike pharming, phishing requires active victim participation (clicking a link or opening an attachment).
-
Phishing differs from pretexting in that it usually does not require long-term interaction with the victim.
Threats Associated with Phishing
-
Theft of personal and financial data
-
Loss of access to accounts and online services
-
Malware infection
-
Financial losses
-
Organizational security breaches
How to Recognize Phishing?
-
Unexpected requests for confidential information
-
Urgent calls to action
-
Language and grammatical errors in messages
-
URLs that differ from originals
-
Requests to click suspicious links or open attachments
Methods of Protection Against Phishing
-
User education on recognizing phishing attacks
-
Using antivirus and antispam software
-
Regular system and application updates
-
Verifying message senders and URLs
-
Avoiding clicking on suspicious links and opening unexpected attachments
-
Using two-factor authentication
-
Regularly monitoring online account activity
Phishing Trends 2025-2026
AI-powered Phishing
Artificial intelligence is revolutionizing phishing attacks:
- Perfect messages: AI eliminates language and grammar errors - traditional phishing indicators
- Personalization at scale: Automatic content adaptation for each victim (mass spear phishing)
- Deepfake audio: Fake calls from “the boss” ordering transfers (vishing with voice cloning)
- Phishing chatbots: Interactive scams conducting “conversations” with victims
- Dynamic pages: AI adapts phishing pages in real-time
Business Email Compromise (BEC) 2.0
- CEO Fraud with deepfake: Video or audio with cloned CEO voice
- Vendor Email Compromise: Hijacking correspondence with suppliers
- Lateral BEC: Using compromised accounts to attack other employees
New Phishing Vectors
| Vector | 2025-2026 Trend |
|---|---|
| QR phishing (Quishing) | Growing - QR codes in emails, parking lots, restaurants |
| Teams/Slack phishing | Phishing via corporate messengers |
| Phishing-as-a-Service | Ready-made phishing kits on subscription |
| Browser-in-browser | Fake login windows in browser |
| MFA fatigue | Spamming MFA notifications until approval |
Phishing Statistics
- 91% of cyberattacks start with phishing
- 97% of users cannot recognize advanced phishing
- 36% of data breaches result from phishing
- $4.91M average cost of phishing attack for companies (2024)
Related Terms
- Social Engineering - broader category of manipulation attacks
- Vishing - voice phishing by phone
- Smishing - phishing via SMS
- Malware - malicious software often distributed through phishing
- Security Awareness - phishing protection through education
Explore Our Services
Want to protect your organization from phishing? Check out:
- Social Engineering Testing - phishing and vishing simulations
- Security Awareness Training - employee education on attack recognition
- SOC 24/7 - monitoring and responding to phishing incidents
Phishing remains one of the most popular and effective cyberattack methods. In the AI era, the threat is growing - artificial intelligence enables increasingly convincing and personalized attacks. Threat awareness, regular training, and applying appropriate precautions are key to protection against such attacks.
Frequently asked questions
+ What is phishing in simple terms?
Phishing is a social engineering attack where criminals impersonate trusted entities — banks, employers, government agencies, well-known brands — to trick people into revealing sensitive information (passwords, credit card numbers, MFA codes) or performing harmful actions (clicking malicious links, opening infected attachments, transferring money). Most phishing arrives via email, but variants exist for SMS (smishing), phone (vishing), QR codes (quishing), and social media. Phishing remains the #1 initial access vector for cyberattacks worldwide — Verizon DBIR 2025 attributes 36% of breaches to phishing or social engineering.
+ What are the main types of phishing?
Seven common variants: (1) **Email phishing** — generic mass campaigns impersonating banks, shipping companies, government, (2) **Spear phishing** — personalised attack on a specific individual (executive, finance staff), (3) **Whaling** — spear phishing targeting C-level executives, often with fake legal/M&A pretexts, (4) **BEC (Business Email Compromise)** — attacker compromises or impersonates an executive's email and orders fake wire transfers (FBI: $50B in losses 2014-2024), (5) **Smishing** — SMS phishing (fake parcel notifications, banking alerts, BLIK fraud in Poland), (6) **Vishing** — phone-based phishing (fake bank/IT support, often in coordination with email/SMS), (7) **Quishing** — QR-code phishing emerging since 2023, evades email scanners that don't render QR codes.
+ How do you spot a phishing attempt?
Seven warning signs: (1) **Urgency or threat** — 'your account will be closed in 24h', 'pay now to avoid arrest', (2) **Sender address mismatch** — display name says 'PayPal' but email is from `paypa1.com` or a typo domain, (3) **Generic greeting** — 'Dear Customer' instead of your name, (4) **Suspicious links** — hover before click, look for shortened URLs, IP addresses, or unusual top-level domains (.xyz, .top, .ru), (5) **Unexpected attachments** — especially Office documents asking to enable macros, ZIP files, or `.exe`/`.lnk`/`.iso`, (6) **Requests for credentials, MFA codes, or money** through email/SMS — legitimate organisations never ask, (7) **Spelling and grammar errors** — though AI-generated phishing in 2024-2026 has eliminated this signal for sophisticated attacks. When in doubt, contact the organisation through an independent channel.
+ How to protect against phishing?
Layered defence: (1) **Phishing-resistant MFA** — FIDO2 hardware keys, passkeys, certificate-based authentication; SMS-OTP and TOTP can be phished via real-time relay (Evilginx, Modlishka), (2) **Email security gateway** with sandbox detonation and impersonation detection (Defender for Office 365, Proofpoint, Mimecast), (3) **DMARC, DKIM, SPF** properly configured to prevent domain spoofing of your own organisation, (4) **EDR/XDR** to catch malware that slips past email filters, (5) **Awareness training** with monthly phishing simulations and click-rate metrics — top performers reduce click rates from 30% to under 5%, (6) **Reporting button** in email client (one-click 'Report Phishing'), feeding back into SOC and email gateway, (7) **Zero Trust network access** so a compromised account can't reach sensitive systems without further authentication, (8) **Out-of-band confirmation for financial transactions** (always call the second person on a different number to verify wire transfer requests).
+ What should you do if you clicked a phishing link?
Act in the first 30 minutes: (1) **Disconnect from the network** if you ran a downloaded file, (2) **Do not enter credentials** if a fake login page is open — close the tab, (3) **Change passwords from a clean device** (not the suspect computer) for affected accounts; prioritise email, banking, work SSO, (4) **Enable MFA** on every important account if not already, (5) **Report to IT/security team** immediately — they can revoke sessions, check for anomalous logins, scan the device, (6) **Contact the bank** if you entered card or banking credentials — block the card, watch for fraud, (7) **For corporate environments**: report to incident@... mailbox, file with internal IR system, notify your manager. The faster the report, the smaller the blast radius — most successful phishing breaches turn out to have been clicked hours before any reporting.
+ What is BEC (Business Email Compromise)?
BEC is the most damaging form of phishing, focused on tricking organisations into wire transfers or sensitive data disclosure. Two variants: (1) **Email account compromise** — attacker actually controls a real executive's mailbox via phishing or password reuse, monitors email patterns, then sends fraudulent wire transfer requests, (2) **CEO impersonation** — attacker spoofs or look-alikes the CEO's email (`[email protected]` instead of `company.com`) and pressures finance staff. Average BEC loss per incident in 2025 is $137,000; FBI IC3 reports $2.9B+ in BEC losses for 2024 alone. Defences: domain locking, DMARC enforcement, mandatory out-of-band verification for any wire transfer over a threshold (e.g., $10K), executive security training, AI-based email anomaly detection.
+ Is AI making phishing worse?
Yes — AI has lowered the bar for sophisticated phishing significantly. (1) **Generative AI** (ChatGPT, Claude, Gemini) writes grammatically perfect phishing in any language, eliminating the 'broken English' signal that used to flag many attacks. (2) **Voice cloning** (ElevenLabs and similar) creates realistic vishing using 30 seconds of public audio of an executive. (3) **Deepfake video** is being used in BEC — a 2024 Hong Kong case saw a finance worker transfer $25M after a deepfake video conference impersonating the CFO. (4) **Automated personalisation** scrapes LinkedIn and corporate websites at scale, enabling spear phishing for the price of mass phishing. Defences: behaviour-based detection (anomalous patterns, not language), out-of-band confirmation as universal control, executive-specific awareness training, voice/video verification protocols.