What Is Phishing?

Also called: Phishing attack

Related problems: Employees keep clicking on suspicious links; Fake login pages stealing staff passwords; Scam emails getting past our email filtering; Cyber insurer asking about phishing training and email security

Phishing is a social engineering attack in which someone poses as a trusted person or organization, such as a colleague, a bank, a software vendor or a delivery company, to get the recipient to do something harmful: enter a password on a fake login page, open a malicious attachment, approve a payment or share sensitive data. It is one of the most common ways attackers get their first foothold in a business.

At a glance

  • Phishing exploits people rather than software flaws, so technical controls reduce it but cannot remove it entirely.
  • Email is the main channel, but text messages, phone calls, QR codes and chat apps are also used.
  • Common goals are stolen credentials, malware installation and fraudulent payments.
  • Defense combines email filtering, sender authentication, multi-factor authentication, training and an easy way to report suspicious messages.

What problem it solves

Phishing is a threat, so for buyers the real question is which risks it creates. A common outcome is a stolen password. With it, an attacker can read a mailbox, send convincing emails from a real account, reach shared files and, if the account has broad access, move further into the network. Phishing is also a frequent first step in business email compromise (BEC) and in attacks that end in malware or ransomware.

For a mid-sized company the challenge is scale. A few hundred employees each receive many emails a day, attackers only need one person to act, and well-made phishing pages can be hard to tell from the real thing. That is why no single tool is treated as a complete answer.

How it works

The lure. The attacker sends a message designed to create urgency or curiosity: an unpaid invoice, a shared document, a password expiry notice, a missed delivery, a message from an executive. Mass campaigns go to thousands of people; spear phishing is tailored to one person or team using details found online or from an earlier breach.

The hook. The message asks the recipient to click a link, scan a QR code, open a file, call a number or reply. Links usually lead to a fake login page that looks like Microsoft 365, Google, a bank or another familiar service. More advanced kits sit between the user and the real site, passing the login through and capturing the session as well as the password.

The payoff. The attacker uses what they collected: logging in as the victim, installing malware, redirecting a payment or harvesting more contacts for the next round.

Defenses. A secure email gateway (SEG) or the filtering built into your email platform scans messages and links. Sender authentication standards such as DMARC make it harder to spoof your own domain. Multi-factor authentication (MFA) limits what a stolen password is worth, especially phishing-resistant methods. Security awareness training (SAT), often with simulated phishing, teaches people what to look for and, just as important, how to report it.

When it matters for buyers

  • When phishing emails regularly reach inboxes. Built-in filtering may need tuning or an added layer.
  • When cyber insurance renews. Insurers often ask about MFA, email security and phishing training.
  • When an account has been taken over. That usually means reviewing authentication methods, not just resetting a password.
  • When finance handles payments by email. Phishing that leads to payment fraud is costly and often unrecoverable.
  • When staff use many channels. Text, chat and phone-based lures need policy and training, not only email tools.

See our security awareness training overview for the people side of the defense.

Questions to ask vendors

  • What does your product catch that our email platform’s built-in filtering does not, and how do you show that?
  • How do you handle links that turn malicious after the email is delivered?
  • Can users report suspicious messages in one click, and what happens to the report?
  • Do you cover channels beyond email, such as Teams, Slack or text messages?
  • How do you measure whether training is changing behavior, beyond click rates?
  • Which MFA methods do you support or recommend, and which hold up against real-time phishing kits?
  • How quickly can a reported message be pulled from every other inbox?

How it differs from business email compromise

Phishing is the broad technique of impersonation to trick someone into acting. Business email compromise is a specific fraud that often uses phishing along the way: the attacker impersonates or takes over a business email account to redirect payments or obtain sensitive data. Many BEC messages contain no link or attachment at all, only a plausible request, so filters tuned for classic phishing can miss them. Treat phishing defenses as the foundation and add payment verification procedures to address BEC.

Frequently Asked Questions

Is phishing only done by email?
No. Email is the most common channel, but the same trick arrives by text message (often called smishing), phone call or voicemail (vishing), collaboration apps such as Teams or Slack, QR codes and social media. Defenses that only cover email leave the other channels to training and policy.
What is spear phishing?
Spear phishing is a targeted form of phishing aimed at a specific person or small group, using details such as names, projects or vendors to make the message believable. Mass phishing casts a wide net; spear phishing is crafted for the recipient.
Does multi-factor authentication stop phishing?
It makes stolen passwords much less useful, but it does not stop phishing outright. Some phishing kits relay the login in real time and capture the session, and push-approval prompts can be abused by attackers who send repeated requests. Phishing-resistant methods such as FIDO2 security keys or passkeys hold up better.
What should an employee do after clicking a phishing link?
Report it right away through the agreed channel, without fear of blame. If a password was entered, change it and have IT end active sessions. Fast reporting gives the security team a chance to block the same message for everyone else and check whether anything else happened.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.