The definition
Phishing is a form of social engineering: manipulating a person into acting against their own interest by exploiting trust, authority, urgency or simple helpfulness. The message claims to come from a bank, a colleague, a courier, a government office or a service you use, and it asks you to do one specific thing - log in, pay something, approve a prompt, open a file.
The name is a deliberate misspelling of fishing, and the metaphor is accurate: bait is cast widely, most of it is ignored, and the attack only needs a small number of people to bite. What separates phishing from other fraud is the impersonation. The message works because it looks like something legitimate you were already half-expecting.
How a phishing attack works
Most campaigns follow the same shape regardless of the brand being impersonated or the channel used to deliver them.
- Research. Names, job titles, email formats and supplier relationships are collected from company websites, social media and previously leaked data.
- Lure. A message is written to create urgency, fear or curiosity - an account locked, an invoice overdue, a parcel held, a document shared.
- Delivery. It is sent at volume or hand-written for one person, usually from a lookalike domain or a compromised legitimate account.
- Hook. A link, an attachment, a QR code or simply a reply routes the target somewhere the attacker controls.
- Capture. Credentials, card details or an approval are collected - or a payment is redirected outright.
- Use. The access is used for fraud, to move deeper into the network, or resold to someone who will.
The step people underestimate is the last one. A stolen password is rarely the end of the incident; it is the beginning of one. The channels these messages arrive through are set out in types of phishing, and the signals that give them away are in how to recognize phishing.
Why it keeps working
Phishing is not a failure of intelligence, and treating it as one is why so many awareness programmes achieve nothing. It works because it exploits conditions that are normal in every workplace.
- Volume. Someone processing two hundred messages a day is pattern-matching, not reading. The message only has to survive a two-second glance.
- Legitimate expectation. An invoice lands at a company that receives invoices. A delivery notice arrives at someone who ordered something.
- Authority. A request that appears to come from a manager or an auditor gets acted on quickly and questioned slowly.
- Time pressure. A deadline removes the pause in which someone would otherwise check.
- Cost asymmetry. The attacker sends ten thousand messages and needs one reply. The defender has to get it right every time.
This is also why technical controls matter more than exhortation. Sender authentication, phishing-resistant sign-in and quick reporting reduce the damage a mistake can do, rather than assuming the mistake will not happen - which is the argument made in how to prevent phishing. If you have already clicked something and want to know what to do next, start with I clicked a phishing link.