Phishing is the most successful and most common form of cyberattack against individuals and organizations. It does not require sophisticated hacking. It does not exploit software vulnerabilities. It exploits human psychology — trust, urgency, authority, and fear. The reason phishing remains so effective after decades is not that defenses have failed to evolve, but that the attacks have evolved too, becoming increasingly sophisticated and personalized. Understanding how phishing works is the single most important step in not falling for it.
Table of Contents
- What Is Phishing?
- Types of Phishing Attacks
- Anatomy of a Phishing Attack
- How to Spot Phishing: Red Flags
- Why Phishing Targets Organizations
- How to Protect Yourself
- What to Do If You Clicked a Phishing Link
- Frequently Asked Questions
What Is Phishing?
Phishing is a social engineering attack in which an attacker impersonates a trusted entity — a bank, a government agency, a company, a colleague, a friend — to deceive a target into taking an action that benefits the attacker. That action is typically revealing credentials (usernames and passwords), providing financial information, transferring money, installing malware by clicking a link or opening an attachment, or granting access to accounts or systems.
The name comes from “fishing” — casting a wide net of fraudulent messages hoping some targets will take the bait. The variation “phishing” with a “ph” is a nod to the “phone phreaking” hacker culture of the 1970s. Modern phishing has evolved from clumsy mass-broadcast emails (“You have won a Nigerian lottery!”) to highly targeted, technically sophisticated attacks that deceive even security-conscious professionals.
The FBI’s Internet Crime Complaint Center (IC3) consistently ranks phishing among the most commonly reported cybercrimes. In its 2023 Internet Crime Report, phishing was the most prevalent attack type by victim count, with over 300,000 complaints filed. The financial impact of phishing-enabled business email compromise alone exceeded $2.9 billion in reported losses in that year.
Types of Phishing Attacks
Email Phishing
The most common form — mass emails impersonating legitimate organizations sent to large lists of recipients. These emails typically create urgency (“Your account has been suspended”, “Verify your payment information immediately”) and direct recipients to fake websites that harvest entered credentials. Modern phishing emails are increasingly convincing, with professional design, correct logos, and plausible sender names that superficially resemble legitimate communications.
Spear Phishing
Spear phishing targets specific individuals using personalized information gathered from LinkedIn, social media, company websites, and data brokers. An attacker targeting a financial controller might research their name, their company, their manager’s name, and recent business activities, then craft an email that references real projects, uses correct internal terminology, and impersonates their manager or a trusted vendor. The personalization makes spear phishing dramatically more convincing than mass phishing and significantly harder to detect.
Whaling
Whaling targets senior executives — the “big fish.” These attacks focus on CEOs, CFOs, and other high-level targets who have the authority to authorize large financial transactions or access sensitive systems. A whaling attack might impersonate a CEO’s attorney instructing the CFO to execute an urgent wire transfer for a confidential acquisition, or impersonate a tax authority requesting immediate payment to avoid legal action. The targets have high authority and are often under significant time pressure, increasing susceptibility.
Smishing and Vishing
Smishing (SMS phishing) uses text messages rather than email. “Your package cannot be delivered. Confirm your address here: [link]” is a classic smishing format. Vishing (voice phishing) uses phone calls — impersonating banks, government agencies (IRS, Social Security Administration), or tech support claiming there is a problem with your account or device. Voice phishing has become increasingly convincing with AI voice cloning, which can synthesize the voice of a target’s family member or colleague from just a few seconds of audio.
Clone Phishing
Clone phishing takes a legitimate email the target has previously received, replaces links or attachments with malicious versions, and resends it claiming to be an updated or corrected version of the original. Because the email is a near-perfect copy of something the target has seen before — often from a sender they communicate with regularly — it is particularly convincing.
Business Email Compromise (BEC)
BEC is the most financially devastating form of phishing. Attackers either compromise an executive’s actual email account (through phishing their credentials first) or create convincingly spoofed addresses, then use the resulting trust to instruct employees or vendors to transfer funds, change payment account details, or provide access credentials. BEC attacks are often entirely text-based with no malicious links, making them invisible to most automated email security filters. The FBI reports BEC as the highest-loss cybercrime category, with billions in annual losses.
Anatomy of a Phishing Attack
Understanding the structure of a phishing attack demystifies why they work. A well-constructed phishing attempt establishes legitimacy through impersonating a trusted brand, creates urgency to override careful deliberation (“You must verify within 24 hours”), triggers fear or other strong emotions that impair rational evaluation, presents a plausible call to action aligned with things the target regularly does (verify their bank account, track a package, reset a password), and provides a convincing-looking destination — a fake website that mirrors the legitimate site’s appearance.
The fake website is technically sophisticated in modern attacks. Attackers register domains that visually resemble the real organization’s domain through typosquatting (paypa1.com instead of paypal.com), subdomain tricks (paypal.security-check.com), or homograph attacks using Unicode characters that look identical to Latin characters at a glance. These sites obtain HTTPS certificates (the padlock icon that many users associate with legitimacy) because certificate authorities issue free certificates without verifying that a site is not phishing.
How to Spot Phishing: Red Flags
Urgency and pressure: Legitimate organizations rarely give you 24-hour ultimatums. Manufactured urgency is a hallmark of manipulation. Slow down whenever a message creates pressure to act immediately.
Sender address mismatches: Check the actual sending email address, not just the display name. “Apple Support” <security@apple-account-alert.net> is not Apple. Hover over sender names to see the actual email address before trusting any communication.
Link destination mismatches: Hover over any link before clicking to see the actual URL it leads to. A link that displays “bankofamerica.com” but actually leads to “bankofamerica.account-verify.net” is phishing. Use browser developer tools or link preview features.
Generic greetings: Mass phishing typically uses “Dear Customer” or “Dear User” because attackers do not know your name. Legitimate organizations you have accounts with typically address you by name. Note that spear phishing defeats this heuristic by using your actual name.
Requests for sensitive information: Legitimate banks, government agencies, and major services never ask for your password, full credit card number, or Social Security number via email or text message. Any request for this information through any channel should trigger extreme skepticism.
How to Protect Yourself From Phishing
Enable multi-factor authentication on all important accounts. Even if a phishing attack successfully steals your password, MFA prevents account takeover without access to your second factor. Hardware security keys (like YubiKey) are phishing-resistant in a way that SMS and app-based codes are not — they only work on the real website, not phishing sites, because the cryptographic protocol verifies the domain.
Verify independently before acting. If you receive a message claiming to be from your bank, your employer, or any other institution that requires action, contact that institution directly through known, verified channels — not through any contact information in the suspicious message. Look up the phone number on the official website or on your card. Call directly. This one habit prevents virtually all financial phishing damage.
Use anti-phishing browser features. Google Safe Browsing (built into Chrome, Firefox, and Safari) maintains a list of known phishing sites and warns you before visiting them. Major email providers use ML-based phishing detection that blocks most mass phishing before it reaches your inbox. According to CISA’s phishing guidance, using up-to-date software and email services with built-in phishing detection is one of the most effective technical protections available.
What to Do If You Clicked a Phishing Link
If you clicked a phishing link but did not enter any information: run an antivirus scan to check for any malware that may have been silently installed, clear your browser cookies and cache, and monitor your accounts for unusual activity. A click alone is lower risk than entering credentials.
If you entered credentials: change the affected password immediately, and change it on any other site where you use the same password. Enable MFA on the compromised account. Contact the legitimate service to alert them. If banking or payment information was entered, contact your bank or card issuer immediately — most have fraud response teams available 24/7 and can freeze accounts and initiate recovery procedures. The faster you act, the more likely financial recovery becomes.
Frequently Asked Questions
Can phishing attacks happen on mobile devices?
Yes, and mobile phishing (smishing) is increasingly common. Mobile screens display less URL information than desktop browsers, making suspicious links harder to evaluate. Email clients on mobile also often hide the sender’s actual email address behind the display name. Mobile phishing via text message (smishing) reaches people through a channel where they are less accustomed to being skeptical than email. All the same principles apply — verify before acting, do not enter credentials through links in messages.
Is the padlock icon proof a site is legitimate?
No. The padlock only means the connection between your browser and the site is encrypted — it says nothing about whether the site itself is legitimate or malicious. Phishing sites routinely obtain HTTPS certificates because they are free and easy to get. “Secure connection” does not mean “safe site.” Check the domain name carefully, not just the padlock.
How do attackers get my email address to target me?
Through data breaches (your email appears in leaked databases), from data brokers who compile public records, through web scraping of sites where your email is listed publicly, and through purchased email lists. Checking HaveIBeenPwned.com shows which breaches your email appeared in. Using unique email aliases (many services like SimpleLogin and Apple Hide My Email support this) for different services limits exposure — if one alias receives spam, you know which service leaked your address and can disable that alias.

