What is phishing? How it works and how to spot it
Phishing is a cyberattack that uses fraudulent messages — by email, text or phone call — that impersonate a trusted source, in order to trick people into revealing credentials or sensitive data, or into opening a malicious link or attachment. It works because it targets people rather than systems, which makes it a form of social engineering and the most common way attackers get a first foothold. This article explains how a phishing attack works, why it is so effective, the main variants in plain terms, and the defences that genuinely help.
How a phishing attack works
A phishing attack follows a simple pattern: the attacker sends a message that looks legitimate, creates a reason to act quickly, and points the victim at something harmful. That might be a fake login page that captures a password, an attachment that installs malicious software, or a request to approve a payment or share data. The message usually imitates a bank, a colleague, a delivery company or an internal IT team — someone the recipient already trusts.
Once an attacker has working credentials, they can sign in as the victim, which is why phishing so often sits at the start of larger incidents, including ransomware. Our what is ransomware explainer covers what can follow.
Why phishing is so effective
Phishing is effective because it bypasses technical controls by persuading a person to do the work for the attacker. It borrows urgency, fear, authority or curiosity — “your account will be closed”, “the CEO needs this now” — to short-circuit careful thinking. That is exactly what social engineering is: manipulating people rather than breaking technology. Our what is social engineering article covers the wider family of techniques, of which phishing is the most common.
It is also cheap to attempt at scale, and a single successful message is enough. That asymmetry is why defence has to combine awareness with technical safeguards rather than relying on either alone.
The main variants
The core idea is the same everywhere; what changes is the channel and how targeted the message is:
- Phishing — broad, generic messages sent to many people in the hope that some will respond.
- Spear phishing — a message tailored to one person or team, using real details about them to look convincing.
- Whaling — spear phishing aimed at senior executives or other high-value targets.
- Smishing — phishing delivered by SMS or messaging apps.
- Vishing — phishing by voice call, where the attacker poses as a bank, support desk or colleague.
How to defend against phishing
The first defence is scepticism: pause on any unexpected message that pushes you to act urgently, and check the sender’s real address and where a link actually leads before you click. When in doubt, verify through a separate channel — call the person or visit the site directly rather than using the contact details in the message.
The most important technical safeguard is multi-factor authentication, because a stolen password alone is then not enough to sign in. Our what is multi-factor authentication explainer covers how it works. Email filtering, reporting buttons and regular awareness training add further layers, and least-privilege access limits the damage if someone is caught out.
Where phishing fits in cloud security
In the cloud, a phished account can unlock an entire environment, so protecting identities is central to security there. Phishing awareness and identity protection are part of the broader picture in our what is cloud security article. If you want to study this in depth, ISC2 Certified in Cybersecurity and the AWS Certified Security – Specialty both cover the threat landscape, and our /revision library covers that syllabus lesson by lesson.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Sources
Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.
- ISC2 Certified in Cybersecurity exam outline — ISC2
- AWS Certified Security – Specialty (SCS-C03) exam guide — Amazon Web Services