Phishing is a social engineering attack in which someone poses as a trusted person or organization, such as a colleague, a bank, a software vendor or a delivery company, to get the recipient to do something harmful: enter a password on a fake login page, open a malicious attachment, approve a payment or share sensitive data. It is one of the most common ways attackers get their first foothold in a business.
At a glance
- Phishing exploits people rather than software flaws, so technical controls reduce it but cannot remove it entirely.
- Email is the main channel, but text messages, phone calls, QR codes and chat apps are also used.
- Common goals are stolen credentials, malware installation and fraudulent payments.
- Defense combines email filtering, sender authentication, multi-factor authentication, training and an easy way to report suspicious messages.
What problem it solves
Phishing is a threat, so for buyers the real question is which risks it creates. A common outcome is a stolen password. With it, an attacker can read a mailbox, send convincing emails from a real account, reach shared files and, if the account has broad access, move further into the network. Phishing is also a frequent first step in business email compromise (BEC) and in attacks that end in malware or ransomware.
For a mid-sized company the challenge is scale. A few hundred employees each receive many emails a day, attackers only need one person to act, and well-made phishing pages can be hard to tell from the real thing. That is why no single tool is treated as a complete answer.
How it works
The lure. The attacker sends a message designed to create urgency or curiosity: an unpaid invoice, a shared document, a password expiry notice, a missed delivery, a message from an executive. Mass campaigns go to thousands of people; spear phishing is tailored to one person or team using details found online or from an earlier breach.
The hook. The message asks the recipient to click a link, scan a QR code, open a file, call a number or reply. Links usually lead to a fake login page that looks like Microsoft 365, Google, a bank or another familiar service. More advanced kits sit between the user and the real site, passing the login through and capturing the session as well as the password.
The payoff. The attacker uses what they collected: logging in as the victim, installing malware, redirecting a payment or harvesting more contacts for the next round.
Defenses. A secure email gateway (SEG) or the filtering built into your email platform scans messages and links. Sender authentication standards such as DMARC make it harder to spoof your own domain. Multi-factor authentication (MFA) limits what a stolen password is worth, especially phishing-resistant methods. Security awareness training (SAT), often with simulated phishing, teaches people what to look for and, just as important, how to report it.
When it matters for buyers
- When phishing emails regularly reach inboxes. Built-in filtering may need tuning or an added layer.
- When cyber insurance renews. Insurers often ask about MFA, email security and phishing training.
- When an account has been taken over. That usually means reviewing authentication methods, not just resetting a password.
- When finance handles payments by email. Phishing that leads to payment fraud is costly and often unrecoverable.
- When staff use many channels. Text, chat and phone-based lures need policy and training, not only email tools.
See our security awareness training overview for the people side of the defense.
Questions to ask vendors
- What does your product catch that our email platform’s built-in filtering does not, and how do you show that?
- How do you handle links that turn malicious after the email is delivered?
- Can users report suspicious messages in one click, and what happens to the report?
- Do you cover channels beyond email, such as Teams, Slack or text messages?
- How do you measure whether training is changing behavior, beyond click rates?
- Which MFA methods do you support or recommend, and which hold up against real-time phishing kits?
- How quickly can a reported message be pulled from every other inbox?
How it differs from business email compromise
Phishing is the broad technique of impersonation to trick someone into acting. Business email compromise is a specific fraud that often uses phishing along the way: the attacker impersonates or takes over a business email account to redirect payments or obtain sensitive data. Many BEC messages contain no link or attachment at all, only a plausible request, so filters tuned for classic phishing can miss them. Treat phishing defenses as the foundation and add payment verification procedures to address BEC.
