Back to Learning Hub

What Is Phishing?

Last updated: 2026-08-133 min read

What phishing is, the forms it takes, why it works on careful people, and the two habits that stop most of it.

Phishing is a fraudulent message that impersonates someone you trust in order to make you act — click a link, open an attachment, hand over a password, or move money. It is the most common way attackers get into organizations, because it targets the one part of your defences that cannot be patched.

The name is deliberate: the attacker casts bait and waits. Most people ignore it. Enough do not.


How it actually works

Nearly every phishing attempt follows the same three steps.

Impersonation. The message appears to come from a brand you use, a colleague, or a supplier — someone whose messages you process without much thought.

A believable pretext. A password expiry, an unpaid invoice, a failed delivery, a shared document. It has to be something that could plausibly be true right now.

A single requested action. Click here. Open this. Confirm that. The whole message exists to produce one small action that feels routine.

The goal is usually credentials. A convincing fake login page costs nothing to build, and a working password is worth more to an attacker than malware — it walks through the front door and sets off nothing.

The main forms

  • Mass phishing. The same message sent to thousands, relying on volume. AI now makes these far more convincing, removing the typos people were taught to look for.
  • Spear phishing. Aimed at one person and written with real details about them — their manager, their project. Rare, and far more effective. See how organizations defend against it.
  • Whaling. Spear phishing aimed at executives, usually carrying an urgent financial request.
  • Beyond email. The same playbook runs over SMS, WhatsApp, voice calls, and QR codes. The channel changes; the psychology does not.

Why it works on careful people

Phishing is not a test of intelligence, and treating it as one is why so many programs fail.

It exploits familiarity — a known sender lowers scrutiny automatically. It exploits authority — few people interrogate a request that appears to come from a senior figure. And it exploits urgency — a deadline compresses the gap between reading and acting, which is exactly the gap where you would have noticed something.

Add the fact that most people process email quickly, between other tasks, and the surprise is not that phishing works. It is that it does not work more often.

What actually stops it

Slow down on anything that asks for a credential or a payment. That single category covers most successful attacks.

Verify on a second channel. If a request involving money or access seems unusual, phone the sender on a number you already have — never the one in the message.

Practise before it matters. Recognition is a skill, and simulations are how it gets rehearsed rather than tested for the first time during a real attack.

Worth knowing: multi-factor authentication helps but is not a guarantee. Attackers bypass it with AiTM proxies and prompt bombing, so it belongs alongside good habits, not instead of them.

Most incidents do not begin with a software flaw. They begin with a human moment, which is also where they are easiest to prevent.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.