Phishing is a form of online fraud in which attackers impersonate a trusted organization or person to trick victims into revealing passwords, payment data or installing malware.
How phishing works
The victim receives a message that looks like it comes from a bank, a delivery service, a colleague or a popular platform. It creates urgency – a blocked account, an unpaid invoice, a parcel on hold – and leads to a fake login page or a malicious attachment. Main forms:
- mass phishing sent to millions of addresses;
- spear phishing tailored to a specific person or company;
- smishing (SMS and messengers), vishing (phone calls) and quishing (QR codes);
- AiTM phishing, where a proxy page steals the session and bypasses one-time codes (man-in-the-middle).
Phishing-as-a-service kits sell ready-made copies of popular sites, and generative AI helps criminals write convincing texts in any language.
Why phishing matters for security
Phishing is one of the most common first steps of cyberattacks: it delivers stolen credentials, infostealers and remote access trojans that later lead to data breaches and ransomware. It is a core technique of social engineering and of business email compromise.
How to protect yourself
- Do not follow links in unexpected messages – open the site or app yourself.
- Check the sender’s address and the real domain in the address bar.
- Use passkeys or FIDO2 security keys; they do not work on fake domains. A password manager will not autofill on a look-alike site either.
- Organizations: enforce SPF, DKIM and DMARC, filter mail and links, and make reporting phishing easy.