Phishing

Phishing is a technique that deceives individuals into revealing sensitive information, such as passwords or credit card details, by impersonating trustworthy entities through fraudulent websites, emails, or SMS messages.

What is Phishing?
How Modern Phishing Attacks Work
Common Types of Phishing Attacks
Why Phishing Is Difficult to Stop
How Is Phishing Detected?

What is Phishing?

Phishing is a social engineering technique designed to exploit trust. Attackers typically impersonate a legitimate organization, service, colleague, or other trusted party, with the goal of persuading victims to reveal sensitive information, transfer money, grant access, or take another action that benefits the attacker.

Phishing has been a persistent cyber threat for more than three decades, evolving from early credential-stealing scams in the 1990s into highly scalable, multi-channel campaigns. While phishing has traditionally been associated with email, modern phishing attacks extend far beyond the inbox - using cloned websites, fraudulent domains, social media, SMS, QR codes, and AI-generated content.

Today's phishing attacks commonly target:

  • User credentials 

  • Authentication tokens 

  • Financial information

  • Employee access 

  • Customer accounts 

  • Payment workflows 

Attackers increasingly rely on fraudulent domains, cloned websites, fake social media accounts, malicious mobile apps, and rapidly changing infrastructure to evade traditional security controls.

How Modern Phishing Attacks Work

Modern phishing campaigns are designed to impersonate trusted brands and manipulate users into revealing credentials, authentication codes, or financial information.

Attackers commonly use:

  • Fraudulent domains 

  • Fake login pages 

  • Social engineering 

  • SMS phishing 

  • QR code phishing 

  • AI-generated impersonation content 

  • Multi-channel phishing campaigns 

Many phishing operations follow a similar lifecycle:

  • Register fraudulent domains 

  • Deploy cloned phishing websites 

  • Launch impersonation campaigns 

  • Harvest credentials or MFA tokens 

  • Rotate infrastructure and relaunch 

Rather than relying on a single phishing page, attackers increasingly operate large-scale phishing ecosystems designed for resilience and rapid redeployment.


Common Types of Phishing Attacks

Social Media Phishing

Attackers increasingly use fake social media accounts and impersonation profiles to target customers and employees.

These campaigns often involve:

  • Fake customer support accounts 

  • Impersonated brand profiles 

  • Fraudulent giveaways or promotions 

  • Cryptocurrency scams 

  • Direct-message phishing links 

  • Social engineering campaigns 

Social media phishing attacks are particularly effective because attackers can quickly create and rotate accounts while leveraging trusted platforms to build credibility and evade detection.

Example 

A fake Facebook profile page impersonating customer support for EVRi:



Email Phishing

Email phishing attacks use spoofed messages and malicious links to direct users to credential harvesting websites or fraudulent login pages.

Common phishing themes include:

  • Account verification 

  • Password resets 

  • MFA prompts 

  • Invoice requests 

  • Delivery notifications 

Example

A phishing email prompting recipient to confirm a hotel reservation, linking to a malicious website.



Spear Phishing

Spear phishing attacks target specific individuals or organizations using personalized messaging and impersonation techniques.

Attackers frequently leverage:

  • Publicly available information 

  • Executive impersonation 

  • Stolen branding 

  • AI-generated communication 

Smishing (SMS Phishing)

Smishing attacks use SMS messages to distribute phishing links or impersonate trusted organizations.

These attacks increasingly target:

  • Banking users 

  • Mobile device users 

  • MFA workflows 

  • Delivery and logistics customers 

Example

A darcula smishing iMessage impersonating USPS: 



Source: Reddit /r/phishing

Quishing (QR Code Phishing)

QR phishing attacks use malicious QR codes to redirect users to phishing websites or credential harvesting infrastructure.

QR phishing campaigns are increasingly used to bypass traditional email filtering and mobile security controls.

Example 

A QR code linked to a malicious website, distributed via a phishing email impersonating Microsoft:



Business Email Compromise (BEC)

BEC attacks impersonate executives, vendors, or employees to initiate fraudulent payments or steal sensitive information.

Unlike traditional phishing campaigns, BEC attacks often rely heavily on social engineering rather than malware.

AI-Generated Phishing

Attackers increasingly use AI tools to:

  • Generate convincing phishing emails 

  • Clone brand messaging 

  • Localize phishing campaigns 

  • Create realistic fake login pages 

  • Scale phishing operations rapidly 

AI-generated phishing lowers the barrier to entry for attackers while increasing the sophistication and volume of phishing campaigns.

Example

A fake Roblox website generated by an attacker using an AI-powered website cloning service called Same.



Why Phishing Is Difficult to Stop

Phishing remains one of the most effective and widely used attack techniques because attackers can quickly adapt the infrastructure behind their campaigns. Domains can be replaced, websites moved between hosting providers, page content modified, social media accounts recreated, and the same phishing kit redeployed elsewhere after an individual asset is blocked or taken down. They may also reuse underlying infrastructure across multiple campaigns.

As a result, stopping phishing often requires looking beyond an individual message or URL and understanding the wider collection of domains, websites, hosting infrastructure, redirects, accounts, and other assets supporting the campaign.

How Is Phishing Detected?

Phishing detection identifies phishing attempts by analyzing the domains, websites, hosting infrastructure, phishing kit fingerprints, user reports, and other signals associated with malicious activity.

Modern detection increasingly looks beyond known bad URLs to uncover the infrastructure and recurring attacker behavior behind emerging phishing campaigns.

For a deeper explanation of the technologies and signals involved, see Phishing Detection.


Related terms 


Phishing Resources