Skip to content
Cyber Security Firms

What Is Phishing? How It Works and How to Spot It

Phishing is the attack everyone has seen and most people still fall for, because the good ones do not look like the bad ones. Here is how it works, what gives it away, and what to do when you have already clicked.

Beginner10 min readUpdated
What Is Phishing? How It Works and How to Spot It

Everyone knows what phishing is until the email arrives at 4:50 on a Friday from what looks exactly like the payroll provider, referencing the bonus round that really is happening this month. Knowing the definition does not stop the click. Knowing the mechanism, and the two or three tells that survive even a well-made lure, does.

What Is Phishing?

The word comes from fishing: cast a lure, wait for a bite. The lure is a message that looks like it comes from a bank, a delivery company, a software vendor, your boss or your IT department. The bite is you doing what the message asks. What the attacker wants is almost always one of four things: your password, your approval of a login, a file opened on your machine, or a payment.

It is a form of social engineering, meaning it attacks the person rather than the software, and that is why it survives every technical defense. A filter can catch a malicious link. It cannot catch a plausible request.

How Phishing Attacks Work

The version most people picture is the fake login page, and it is still the most common. The steps are the same whether the target is one person or ten thousand.

The standard credential phishing attack
  1. Lure sentA spoofed sender, a real brand, an urgent subject line
  2. Link clickedIt opens a copy of the real login page on a look-alike domain
  3. Password typedThe fake page records it and often forwards you to the real site
  4. Account accessedUsually within minutes, before the victim notices anything
  5. MFA promptA second factor stops the login here, unless the attacker phishes that too
Step three is where the damage happens. Step five is why multi-factor authentication is the single most effective defense.

Notice what the attacker did not have to do: break any encryption, find any flaw, or defeat any firewall. The person did the hard part for them. That is the whole economic logic of phishing, and it is why the FBI's Internet Crime Complaint Center received 191,561 phishing and spoofing complaints in 2025, more than any other crime type, per the 2025 IC3 Annual Report.

Types of Phishing Attacks

The names multiply, but they describe the same attack aimed at different targets through different channels.

TypeChannelWho it targetsThe tell
Bulk phishingEmailEveryone, by the millionGeneric greeting, a brand you may not even use
Spear phishingEmailOne person or team, researched firstYour name, your role, a real project
WhalingEmailExecutivesLegal, financial or board matters, marked confidential
Business email compromiseEmail, increasingly voiceWhoever moves moneyA changed bank account, an urgent wire, gift cards
SmishingText messageEveryoneA package, a toll, a bank alert, with a short link
VishingPhone callStaff, especially IT and finance"This is IT, we need you to read back the code"
QuishingQR codeAnyone with a phone cameraA code on a poster, parking meter or email "to verify"
Clone phishingEmailSomeone who received a real email recentlyA resend of a genuine message with the link swapped
Consent phishingEmailUsers of Microsoft 365 or Google Workspace"Grant this app access" instead of "type your password"
Push bombingMFA promptsAnyone with app-based MFARepeated approval prompts until one gets tapped

Spear phishing is not a different attack; it is bulk phishing with research. Vishing has become the professional's tool: the extortion group behind many of this year's breaches got into at least one company by phoning employees and talking its way into a single sign-on account, per the Exact Sciences report.

How to Recognize a Phishing Email

Grammar mistakes and odd formatting still appear, and CISA lists them among the indicators, along with generic greetings and links whose real destination does not match the text when you hover. But the well-made ones are clean, branded and correctly spelled, so the reliable tells are structural rather than cosmetic.

Three smaller tells worth knowing. The sender address, not just the display name: "Microsoft Support" with an address at a domain you have never seen. The link's real destination, shown by hovering on a computer or pressing and holding on a phone, which will be a look-alike such as micros0ft-verify.com. And the request itself: no legitimate organization asks you to send a password, a one-time code or a gift card number.

Clicking a link, on its own, usually does nothing beyond confirming to the attacker that your address is live. The damage comes from what happens next.

What happens after the click, and where it is stopped
YouFake siteReal serviceOpen the linkA copied login pageType email and passwordAttacker logs in with themMFA prompt or codeType the code into the fake pageAttacker forwards the code, session opens
The last two rows are the modern attack: a proxy page that relays your one-time code in real time. Passkeys and security keys stop it, because they refuse to work on the wrong domain.

If you typed nothing, you are almost certainly fine. If you typed a password, assume the attacker has it and is using it now. If you opened an attachment and it asked you to enable content, run a program or enter a password, treat the device as compromised until it is checked.

Why Phishing Works

Not because people are stupid. Because the lure arrives when you are busy, borrows something true, and asks for a small action. The 2026 Verizon Data Breach Investigations Report found social engineering attempts on mobile devices succeeding 40 percent more often than the year before, with conversational attacks over text and chat, some of them AI-written, driving the increase. A small screen hides the sender address and the link destination, which are the two things a careful person checks.

The money version is the most expensive. Business email compromise, where the request is a payment rather than a password, cost $3.05 billion in 2025 by the FBI's count, second only to investment fraud.

How to Prevent Phishing Attacks

Myth vs reality
What people believe
If I have multi-factor authentication turned on, I cannot be phished.
What actually happens
Codes sent by text or shown in an app can be phished: the fake page asks for the code and relays it to the real site within seconds, and push prompts can be approved by mistake. MFA still stops the majority of attacks and you should have it everywhere. Only phishing-resistant forms, passkeys and hardware keys, stop the relay attack completely.

Speed matters more than anything else here, because the attacker's window is usually minutes.

Phishing Attacks on Businesses

For a business, phishing is the way most incidents start and the reason "one employee clicked" is the first line of so many breach notices. Two of this year's reports show the professional version.

Key takeaways

  • Phishing is a message that impersonates someone you trust to get a password, an approval, an opened file or a payment. It attacks the person, so no filter fully stops it.
  • The reliable tells are structural: it wants you to act through the message, and it manufactures urgency.
  • A click alone usually does nothing. A typed password is used within minutes; change it now and sign out everywhere.
  • Multi-factor authentication stops most attacks. Only passkeys and security keys stop the real-time relay attack.
  • A password manager that refuses to autofill is telling you the page is fake.
  • Money moves only after a phone call to a number you already had.

Common questions

What is phishing in simple words?

A fake message that pretends to be from someone you trust, such as your bank or your boss, to trick you into giving away a password, opening a file or sending money. The fix is simple too: never act from inside the message, open the real site yourself.

What is an example of phishing?

An email that looks like it comes from your bank, saying your account has been locked and you must click a link to verify your identity. The link opens a copy of the bank's login page on a look-alike address, and anything you type there goes to the attacker.

What happens if I click a phishing link?

Usually nothing on its own, beyond confirming your address is live. The damage comes if you then type a password, approve a login or open an attachment. If you typed a password, change it immediately and sign out of all sessions.

How can I stop phishing emails?

You cannot stop them arriving, but you can make them harmless: multi-factor authentication on every account, a password manager that will not fill a fake page, and the habit of opening sites yourself rather than through links. Report the ones you get so the fake sites are taken down.

What is the difference between phishing and spear phishing?

Bulk phishing goes to millions of people with a generic lure. Spear phishing goes to one person or team, using their name, role and real projects, after the attacker has done some research. Spear phishing succeeds far more often per message.

Can phishing happen by text message or phone?

Yes. Smishing is phishing by text, usually about a package, a toll or a bank alert with a short link. Vishing is phishing by phone, often someone claiming to be IT support who needs you to read back a code. Both are growing faster than email phishing.

Is phishing illegal?

Yes. In the United States it falls under federal wire fraud, identity theft and computer fraud statutes, with state laws on top. Prosecution is rare relative to volume because most attackers operate from abroad, which is why prevention matters more than the law.

Does antivirus protect against phishing?

Partly. It can block a known malicious attachment or a link to a known bad site. It cannot stop you typing your password into a page it has never seen, which is what most phishing is. The defenses that work are multi-factor authentication and the detour habit.

How do I report phishing?

Forward the email to your IT or security team at work. For personal accounts, report to the FTC at reportfraud.ftc.gov and forward the message to the organization being impersonated; most large brands have an address for it. Reporting is what gets fake sites shut down.

Why is it called phishing?

From fishing, with the hacker-culture spelling of the 1990s: cast a lure, wait for a bite. The term dates to attacks on AOL users, and the metaphor has held because the mechanism has not changed.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →