Security

What Is Phishing? How Attackers Turn Trust Into a Security Vulnerability

Learn what phishing is, how phishing attacks work, why social engineering is so effective, and how to recognize common warning signs before credentials, money, or data are stolen.

What Is Phishing? How Attackers Turn Trust Into a Security Vulnerability

Phishing attacks rarely begin by breaking encryption or discovering some obscure software vulnerability.

They begin with a message.

An email says your account will be suspended. A text claims a package cannot be delivered. Someone who appears to be your manager asks for an urgent payment. A caller says they are from your bank and need to verify suspicious activity.

The technical sophistication varies, but the basic strategy is remarkably consistent: convince someone to trust the wrong person long enough to take an unsafe action.

Phishing is a social-engineering attack in which an attacker impersonates a trusted person, company, or service. The attacker creates urgency, fear, curiosity, authority, or some other reason to act quickly, then pushes the victim toward a malicious link, attachment, phone conversation, payment, or request for sensitive information, the broader manipulation pattern described in OWASP’s social engineering overview.

A typical attack looks like this:

Attacker impersonates trusted source

       Sends convincing message

      Creates pressure to act

 Victim clicks / opens / responds

 Fake login page, malware, or request

 Credentials, money, or data stolen

That is what makes phishing different from attacks that depend entirely on technical weaknesses. The vulnerability being targeted is often trust.

A Phishing Message Needs a Convincing Story

Suppose you receive an email that appears to come from a service you use:

Unusual activity has been detected on your account. Verify your identity within 30 minutes to prevent suspension.

There is a button underneath saying Secure My Account.

The message is designed to create two reactions. First, concern: someone may have access to my account. Then urgency: I need to fix this immediately.

Those reactions reduce the chance that you will stop to inspect the message carefully.

Clicking the button might take you to a page that looks almost identical to the real service’s login page. You enter your username and password, perhaps see an error message, and are redirected to the genuine website.

Nothing particularly dramatic appears to have happened.

But the attacker now has the credentials you typed into the fake page.

The deception worked because the attacker did not need to compromise the real company’s login system. They created an imitation and persuaded you to send the credentials somewhere else.

This is the core of phishing: make the malicious action look like the normal action the victim expected to perform.

Urgency, Fear, and Curiosity Are Part of the Attack

Phishing messages often try to interfere with careful decision-making.

Urgency is particularly effective:

  • “Payment required immediately.”
  • “Your account expires today.”
  • “Respond before 5 PM.”
  • “Your package will be returned.”
  • “Approve this request now.”

Fear works similarly. Messages may claim that an account has been hacked, a payment was declined, taxes are overdue, or some other negative consequence is about to occur.

Curiosity can work without any threat at all. An unexpected document called Salary Review, Invoice, Photos, or Confidential Report may be enough to make someone open it.

Attackers also use authority. A message that appears to come from a senior executive, bank, government department, IT administrator, or security team can make the request seem more legitimate.

The exact emotion matters less than the objective: give the victim a reason to act before verifying the situation independently.

A phishing link can lead to several different outcomes.

One common destination is a fake login page. The attacker copies the appearance of a familiar website and places it on a different domain.

The victim sees:

Company logo
Email address field
Password field
Sign In button

but the form sends the information to the attacker.

Other phishing pages ask for payment-card details, banking information, identity documents, recovery codes, or other personal information.

A link can also lead toward a malware infection. The page might claim that a document viewer, security update, browser extension, or application needs to be installed. What the user actually installs is malicious software.

Attachments can serve the same purpose. A malicious document, archive, executable, or other file may attempt to exploit software or convince the recipient to enable functionality that leads to malware execution.

So the phishing message is often just the delivery mechanism. The real objective comes after the click.

Stolen Credentials Can Become Account Takeovers

A stolen password has value because people rarely have only one thing worth protecting.

If an attacker obtains email credentials, for example, the email account may become a route into many other services. Password-reset messages arrive there. Business conversations may reveal sensitive information. Previous emails may contain invoices, customer details, documents, or information useful for further attacks.

The attacker may also try the stolen password against other services, especially if the victim has reused it, which is one reason password entropy and unique credentials matter.

That creates a progression from one convincing message to a much larger compromise:

phishing → credentials stolen → account accessed → additional information collected → further fraud

In a business environment, a compromised account can also be used to send phishing messages internally.

Those messages are particularly dangerous because they come from a real colleague’s account rather than an obviously unrelated sender.

The attacker has effectively stolen not only the account, but some of the trust attached to it.

Phishing Does Not Always Need a Fake Login Page

Credential theft is common, but phishing can have other goals.

An attacker might impersonate a supplier and request that future invoice payments be sent to a different bank account. Someone pretending to be an executive might pressure an employee into making an urgent transfer. A fake support representative might ask for a security code or convince someone to install remote-access software.

In these cases, the attacker may not need malware or a fake website at all.

A sufficiently convincing conversation can be the attack.

This is why phishing belongs under the broader category of social engineering. Technology helps deliver and scale the deception, but the attack ultimately depends on manipulating a person into doing something that benefits the attacker, a pattern also reflected in CISA’s guidance on avoiding social engineering and phishing attacks.

Email Phishing Casts a Wide Net

Email phishing is the familiar form: fraudulent emails are sent in an attempt to steal information, distribute malware, or provoke some other harmful action.

Some campaigns are broad.

An attacker might send thousands or millions of similar messages pretending to represent a bank, delivery company, streaming service, cloud provider, or other recognizable organization.

Most recipients may ignore them.

That does not necessarily matter.

If sending each message costs almost nothing, even a tiny percentage of victims can make the campaign worthwhile.

Broad phishing therefore tends to rely on situations that could plausibly apply to many people: password resets, failed deliveries, invoices, account warnings, refunds, security alerts, and popular online services.

But attackers can become much more specific.

Spear Phishing Targets a Particular Person

Spear phishing is targeted phishing.

Instead of sending the same generic message to thousands of strangers, the attacker researches a particular person or organization and creates a message specifically designed for them.

Imagine an attacker learns from public information that:

  • a company uses a particular supplier;
  • an employee works in accounts payable;
  • the finance director is attending a conference;
  • invoices are commonly exchanged by email.

The attacker can now construct a much more believable story.

A message referring to a real supplier, real colleague, current project, or recent event is less likely to feel random.

Targeting also allows the attacker to choose victims with useful access. Finance employees may be able to authorize payments, administrators may hold powerful credentials, and executives may have access to sensitive information.

This is why oversharing organizational details publicly can sometimes help attackers. Information does not need to be secret to be useful in constructing a convincing deception.

Smishing Moves Phishing Into Text Messages

Smishing is phishing delivered through SMS or similar text messaging.

The medium changes, but the psychology remains familiar.

A text might claim:

Your parcel could not be delivered. Update delivery details here.

Or:

A payment of $950 was attempted. If this wasn’t you, verify your account immediately.

Text messages are useful to attackers because people tend to read them quickly, often on small screens where the complete destination of a link is less obvious, which is part of what makes URL structure worth understanding in practice.

Messages also arrive in a context where short, informal communication feels normal. There may be less information available for evaluating the sender than in a full email.

The defense is still based on verification. If a message claims to come from a delivery company, bank, or other service, you do not have to use the link in the message.

Open the official app or website independently and check there.

Vishing Uses a Human Voice

Vishing, or voice phishing, uses phone calls or voice communication.

The attacker may pretend to be a bank employee, technical-support agent, government official, police officer, company executive, or another trusted person.

Voice creates a different kind of pressure.

A suspicious email can sit in an inbox while you think about it. A caller can respond immediately to doubts, create urgency, answer questions, and push the conversation forward.

They might already know your name, employer, address, or partial account information. That does not prove the caller is legitimate; personal information can come from data breaches, public sources, previous scams, or other compromised accounts.

The attacker may ask for a password, payment, verification code, remote computer access, or some other action.

The safest response to a questionable call is often to end it and contact the organization independently using a number obtained from a trusted source.

The person calling you should not get to decide how you verify that they are genuine.

Warning Signs Matter More in Combination

There is no single visual feature that proves a message is phishing.

Spelling mistakes can be suspicious, but well-written phishing exists. A company logo proves almost nothing because logos are easy to copy. Even the sender’s display name can be misleading.

Instead, look for combinations of signals.

An unusual sender address deserves attention, particularly when the display name claims to be someone familiar. Attackers can also register domains that resemble legitimate ones by changing, adding, or removing a character.

For example, the important difference may be buried inside an otherwise convincing address:

company.com
cornpany.com
company-support.com

Unexpected attachments should also raise questions, especially when the message pressures you to open them quickly.

Links deserve similar attention. The text displayed in an email does not necessarily reveal where the link actually goes. On systems that allow it, inspecting the destination before opening it can expose mismatches, a habit also encouraged in Google’s advice on avoiding suspicious links.

But these are warning signs, not a checklist where passing every item makes a message safe.

A sophisticated phishing message can come from a compromised legitimate account, contain perfect spelling, reference a real project, and use infrastructure that initially appears credible.

When the requested action is sensitive, independent verification is stronger than judging the appearance of the message alone.

Verify Through a Different Channel

Suppose your manager sends an unusual message asking you to urgently transfer a large amount of money.

Replying:

Is this really you?

may not solve the problem.

If the manager’s email account has been compromised, the attacker can simply reply:

Yes. Please do it immediately.

Verification works better when it uses a separate trusted channel.

Call the person using a number you already know. Open the company’s official application yourself. Type the website address manually or use a trusted bookmark. Contact the supplier through previously established details rather than the phone number included in the suspicious message.

This breaks an important part of the attacker’s control.

The original message can make any claim it wants. Independent verification asks a system or person outside that message whether the claim is actually true.

That is particularly important for requests involving money, credentials, account recovery, confidential information, or changes to payment details.

MFA Makes Stolen Passwords Less Useful

Multi-factor authentication (MFA) provides an additional layer of protection when phishing successfully captures a password.

If logging in requires both a password and a second factor, stealing only the password may not be enough for account takeover.

But MFA does not make phishing disappear.

Attackers can create fake login flows that also request one-time authentication codes and relay them to the legitimate service in real time. Push-notification attacks may attempt to wear users down until someone approves a login request. Session tokens can also become valuable targets.

Phishing-resistant authentication methods such as passkeys and FIDO security keys can provide stronger protection because authentication is cryptographically tied to the legitimate service rather than relying on a reusable secret that can simply be typed into a fake page, as emphasized in the FIDO Alliance’s passkey overview.

Still, MFA of almost any sensible form is generally much better than relying on a password alone.

The correct lesson is not “MFA stops phishing.”

It is MFA can reduce what an attacker can do with a stolen password, with some MFA methods providing much stronger phishing resistance than others.

Spam Filters Remove Attacks Before Users See Them

Email providers and organizations use spam and phishing filters to identify suspicious messages before they reach users, often as part of the kind of layered protection discussed in zero trust security.

These systems can examine sender reputation, authentication information, links, attachments, message patterns, known malicious infrastructure, and other signals.

Blocking the message before anyone sees it is obviously preferable to relying on every recipient to recognize the deception.

But filtering is an imperfect classification problem.

Attackers continuously change domains, wording, infrastructure, attachments, and techniques. Filters also have to avoid blocking large amounts of legitimate email.

Some phishing will therefore get through.

That is why effective protection combines technical filtering with safer authentication, endpoint security, sensible business processes, and user awareness.

Reporting a Phishing Message Helps More Than Deleting It

Deleting a suspicious message protects one inbox.

Reporting it can help protect everyone else.

In a workplace, a reported phishing message may allow the security team to search for similar emails sent to other employees, block malicious domains, investigate whether anyone clicked the link, and determine whether an account has already been compromised.

That speed matters.

If one person reports the attack five minutes after delivery, defenders may be able to remove it from hundreds of other inboxes before more people interact with it.

Reporting also gives security systems better information about which attacks are reaching users, and Microsoft’s phishing reporting guidance reflects how common that workflow has become in real mail systems.

After reporting, the suspicious message can be deleted according to the organization’s process.

If someone has already clicked, entered credentials, opened an attachment, or approved an unexpected authentication request, reporting becomes even more important. Hiding the mistake only gives the attacker more time.

Phishing Works Because Trust Is Necessary

The uncomfortable thing about phishing is that the underlying human behavior is not irrational.

We need to trust messages.

Businesses could not function if every employee spent an hour independently investigating every email. People routinely receive legitimate password resets, invoices, delivery notifications, shared documents, security warnings, and requests from colleagues.

Attackers take advantage of that normal behavior.

Good phishing defense therefore should not depend on turning everyone into a permanently suspicious investigator. It should make high-risk actions easier to verify and harder to perform accidentally.

Payment changes can require independent confirmation. Sensitive systems can use phishing-resistant MFA. Email systems can filter known attacks. Employees can have a clear reporting process, while permissions can limit what one compromised account is able to reach, especially when those accounts protect systems using passwordless login.

That changes the problem from:

Can we teach every person to spot every fake message?

to:

Can we design the system so one convincing message does not become a major breach?

That is a much stronger security objective.

Phishing is a social-engineering attack that turns trust, urgency, fear, curiosity, or authority into a path toward stolen credentials, malware, fraudulent payments, or sensitive data. The most effective defense is not simply learning what a fake email looks like; it is independently verifying sensitive requests, using stronger authentication, filtering suspicious messages, limiting the damage a compromised account can cause, and reporting attacks quickly when they get through.

Top