SaveMyCert
Cloud basics

What is phishing? How it works and how to spot it

Phishing is a cyberattack that uses fraudulent messages — by email, text or phone call — that impersonate a trusted source, in order to trick people into revealing credentials or sensitive data, or into opening a malicious link or attachment. It works because it targets people rather than systems, which makes it a form of social engineering and the most common way attackers get a first foothold. This article explains how a phishing attack works, why it is so effective, the main variants in plain terms, and the defences that genuinely help.

How a phishing attack works

A phishing attack follows a simple pattern: the attacker sends a message that looks legitimate, creates a reason to act quickly, and points the victim at something harmful. That might be a fake login page that captures a password, an attachment that installs malicious software, or a request to approve a payment or share data. The message usually imitates a bank, a colleague, a delivery company or an internal IT team — someone the recipient already trusts.

Once an attacker has working credentials, they can sign in as the victim, which is why phishing so often sits at the start of larger incidents, including ransomware. Our what is ransomware explainer covers what can follow.

Why phishing is so effective

Phishing is effective because it bypasses technical controls by persuading a person to do the work for the attacker. It borrows urgency, fear, authority or curiosity — “your account will be closed”, “the CEO needs this now” — to short-circuit careful thinking. That is exactly what social engineering is: manipulating people rather than breaking technology. Our what is social engineering article covers the wider family of techniques, of which phishing is the most common.

It is also cheap to attempt at scale, and a single successful message is enough. That asymmetry is why defence has to combine awareness with technical safeguards rather than relying on either alone.

The main variants

The core idea is the same everywhere; what changes is the channel and how targeted the message is:

  • Phishing — broad, generic messages sent to many people in the hope that some will respond.
  • Spear phishing — a message tailored to one person or team, using real details about them to look convincing.
  • Whaling — spear phishing aimed at senior executives or other high-value targets.
  • Smishing — phishing delivered by SMS or messaging apps.
  • Vishing — phishing by voice call, where the attacker poses as a bank, support desk or colleague.

How to defend against phishing

The first defence is scepticism: pause on any unexpected message that pushes you to act urgently, and check the sender’s real address and where a link actually leads before you click. When in doubt, verify through a separate channel — call the person or visit the site directly rather than using the contact details in the message.

The most important technical safeguard is multi-factor authentication, because a stolen password alone is then not enough to sign in. Our what is multi-factor authentication explainer covers how it works. Email filtering, reporting buttons and regular awareness training add further layers, and least-privilege access limits the damage if someone is caught out.

Where phishing fits in cloud security

In the cloud, a phished account can unlock an entire environment, so protecting identities is central to security there. Phishing awareness and identity protection are part of the broader picture in our what is cloud security article. If you want to study this in depth, ISC2 Certified in Cybersecurity and the AWS Certified Security – Specialty both cover the threat landscape, and our /revision library covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

Phishing is when an attacker sends a fake message pretending to be someone you trust, to trick you into giving up passwords or data, or into clicking a malicious link or attachment. It can arrive by email, text message or phone call.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is public key infrastructure (PKI)?
Cloud basics
What is ransomware? How it works and how to protect against it
Cloud basics
What is social engineering? Common techniques and defences
Cloud basics
What is the CIA triad? Confidentiality, integrity and availability