Phishing is a form of social engineering in which a criminal impersonates a trusted person or organization to steal credentials, financial information, money, or access to a device. The approach may arrive by email, text, phone, social media, a QR code, or a fake website. The defining feature is deception, not the communication channel.
The FTC describes phishing as messages that appear to come from a company or person the recipient knows and that pressure the recipient to click a link, open an attachment, or provide information.
Stages of a phishing attack
Most phishing attempts follow four stages:
- Impersonation: the attacker copies the identity of a bank, delivery company, employer, retailer, government agency, or known contact.
- Plausible context: the message refers to an account problem, package, refund, invoice, job, tax issue, or security alert.
- Pressure to act: urgency, fear, scarcity, or authority reduces the time available to verify the request.
- Exploitation: the target enters credentials, sends money, installs software, approves a login, or grants remote access.
Correct personal details do not prove that a message is legitimate. Names, addresses, account fragments, and information about relatives can come from public sources, social media, or previous data breaches.
Common types of phishing
- Email phishing: a broad or targeted email leads to a fake login, attachment, or payment request.
- Spear phishing: a customized message uses information about a specific person or organization.
- Smishing: phishing delivered by text message, often involving package delivery, tolls, financial alerts, or account warnings.
- Vishing: voice phishing through a call or voicemail.
- QR phishing: a QR code hides the destination until a phone scans it.
- Business email compromise: an attacker impersonates an executive, vendor, or employee to redirect a payment or obtain sensitive files.
- Search and advertising phishing: a fake support page or login appears in sponsored results or online ads.
How to identify a phishing attempt
Look for a request that was not expected, a sender address that does not match the organization, a suspicious destination, an unusual attachment, or pressure to bypass normal procedures. Requests for passwords, one-time codes, gift cards, cryptocurrency, remote access, or a transfer to a âsafeâ account deserve immediate skepticism.
Professional grammar and design are not proof of legitimacy. Generative AI can produce convincing messages, images, and voices. Verify the underlying identity and request instead of judging appearance alone.
The CISA phishing guidance recommends resisting the urge to act, reporting the message, and deleting it. When a message claims to come from a company, open the official app or type the known address rather than using the included link.
Does phishing always use a fake link?
No. A phishing message can request a reply, a phone call, an attachment, a QR scan, a payment, a multifactor-authentication approval, or installation of remote-access software. A real cloud-storage link can also host a malicious document or form.
Links remain common because they can send the target to a copied sign-in page. Learn how to tell if a link is safe and how to identify a fake website before entering information.
Why phishing messages are convincing
Successful phishing usually combines a believable story with a familiar routine. A delivery notice may arrive while the recipient is expecting a package. A fake payroll request may use an employee’s real job title. An account alert may copy the colors, wording, and sign-in flow of a service the target uses every day.
Attackers also exploit normal security habits. A message may claim that a password must be reset, a suspicious login must be reviewed, or two-factor authentication must be restored. The subject sounds protective, but the included button leads to a page controlled by the attacker. The safest response is to perform the stated task through the real app or independently located website.
How targeted phishing differs from mass phishing
Mass campaigns send similar messages to many people and rely on volume. Targeted campaigns research a particular employee, family, vendor relationship, or transaction. They may imitate an existing email thread, mention a real coworker, or wait until an executive is traveling before requesting a transfer.
This additional detail can make spear phishing harder to recognize, but the verification principles remain the same. Confirm sensitive requests using a known phone number or a separate conversation. Organizations should require established approval procedures for payments, password resets, access changes, and release of confidential information.
How to reduce the risk of phishing
Use a unique password for every important account so that one stolen credential cannot unlock several services. Turn on multifactor authentication, preferably with a phishing-resistant method when the service supports it. Keep phones, browsers, email apps, and security software updated.
Avoid publishing unnecessary personal and workplace details that could strengthen an impersonation attempt. For organizations, regular reporting exercises, clear escalation channels, email authentication, and payment-verification procedures can reduce both the likelihood and impact of an attack. Security awareness should teach people how to verify a request, not merely how to spot spelling errors.
What to do when you receive phishing
Stop the interaction and preserve the message if it may be needed as evidence. Verify the claim through a separate channel, report the email or account to the platform, and notify the organization being impersonated through its official fraud channel. Do not forward a live malicious link to friends or coworkers.
Report consumer fraud through ReportFraud.ftc.gov. Internet-enabled crime can also be reported to the FBI Internet Crime Complaint Center when appropriate.
What to do if you already responded
The response depends on the action:
- Password entered: change it from a trusted device, end unfamiliar sessions, and enable two-factor authentication.
- Security code shared or login approved: contact the service, secure recovery methods, and review account activity.
- Payment sent: contact the bank, card issuer, or payment provider immediately.
- Identity information submitted: use IdentityTheft.gov to build a recovery plan.
- File or app installed: disconnect from sensitive accounts, run trusted security checks, and remove suspicious software.
- Work account involved: contact the organizationâs security team promptly.
How security tools help with phishing
Link analysis and real-time protection can warn about some known malicious destinations. Malware scanning can identify certain harmful files or apps. Credential monitoring can alert users when registered information appears in known breaches. These tools reduce risk, but they cannot verify every sender, request, or payment story.
Frequently asked questions about phishing
Is phishing a crime?
Phishing can involve identity theft, fraud, unauthorized access, and other federal or state offenses. Victims should report the incident through the channels appropriate to the conduct and loss.
What is the difference between phishing and spam?
Spam is unsolicited bulk communication. Phishing is designed to deceive a target into giving up information, access, or money. A message can be both spam and phishing.
Does phishing happen only by email?
No. It also occurs through text messages, phone calls, social media, QR codes, ads, search results, and collaboration platforms.
Can opening a phishing email infect a phone?
Simply viewing a modern email is usually lower risk than opening an attachment, following a link, granting permission, or installing software. Keep the device and email app updated and report the message.
How can I verify a message from my bank?
Open the official banking app or call the number on the back of the card. Do not use the number or link supplied in the suspicious message.
Can phishing use real personal information?
Yes. Accurate information can make the message more convincing but does not establish that the sender or request is legitimate.