Phishing remains one of the most common and effective methods cyber criminals use to compromise individuals and organisations. Despite growing awareness, it continues to succeed because it targets human psychology rather than technical vulnerabilities. Here’s what phishing actually involves, the different forms it takes, and how to recognise and avoid it.
Phishing Explained Simply
Phishing is a type of cyber attack where criminals impersonate a trusted person, brand, or organisation — typically via email, text message, or phone call — to trick victims into revealing sensitive information, clicking malicious links, or downloading malware. The name is a deliberate play on “fishing,” reflecting the way attackers cast out bait (a convincing but fake message) hoping victims will bite.
How Phishing Attacks Typically Work
A phishing attack usually follows a similar pattern: the attacker sends a message designed to look like it’s from a legitimate source, such as a bank, delivery company, employer, or well-known online service. The message typically creates a sense of urgency or fear — a suspicious login attempt, an unpaid invoice, a locked account — pushing the recipient to act quickly without carefully checking the message’s legitimacy. It then directs the victim to click a link (often to a convincing but fake website designed to steal login credentials), open a malicious attachment, or reply with sensitive information directly.
Common Types of Phishing
- Email phishing: The most common form, sent in bulk to large numbers of recipients, hoping a small percentage will fall for it.
- Spear phishing: A more targeted attack aimed at a specific individual or organisation, often using personal details to appear more convincing.
- Whaling: A form of spear phishing specifically targeting senior executives or high-profile individuals, often to authorise fraudulent payments or access sensitive company data.
- Smishing: Phishing carried out via SMS text message, often impersonating delivery companies, banks, or government agencies.
- Vishing: Phishing conducted over the phone, where attackers impersonate legitimate organisations to extract information verbally.
- Clone phishing: Where a legitimate, previously delivered email is duplicated and resent with malicious links or attachments substituted in.
Common Warning Signs of a Phishing Attempt
- A sense of urgency or pressure to act immediately, often with threats of an account being closed or a fine being incurred.
- Generic greetings (“Dear Customer”) rather than your actual name, though more sophisticated attacks increasingly personalise this.
- Suspicious sender addresses that closely mimic, but don’t exactly match, a legitimate organisation’s actual domain.
- Poor spelling, grammar, or formatting inconsistent with the organisation being impersonated, though this is becoming less reliable as attacks become more sophisticated.
- Requests for sensitive information — passwords, payment details, personal data — that a legitimate organisation wouldn’t normally ask for via email or text.
- Links that, when hovered over (without clicking), reveal a web address that doesn’t match the organisation the message claims to be from.
- Unexpected attachments, particularly file types like .exe, .zip, or macro-enabled documents.
How to Protect Yourself Against Phishing
- Pause before acting on urgent requests, particularly those involving money, passwords, or personal data. Legitimate organisations rarely demand instant action via email or text.
- Verify independently: If a message claims to be from your bank or employer, contact them directly using a known, official phone number or website, rather than using the contact details provided in the suspicious message itself.
- Check links carefully before clicking, hovering over them where possible to preview the actual destination URL.
- Enable multi-factor authentication on your accounts, so a stolen password alone isn’t enough to grant an attacker access.
- Keep software updated, as this helps protect against malware that phishing attempts may try to install.
- Report suspicious messages to your IT team, email provider, or the organisation being impersonated, helping prevent others from falling victim.
Phishing in the Workplace
Businesses are a particularly attractive target for phishing, given the potential access to company funds, sensitive data, and wider systems a single compromised account can provide. Regular staff training, simulated phishing exercises, and clear reporting procedures are among the most effective defences, since even the best technical filters won’t catch every attempt, making a well-informed workforce a critical last line of defence.
Final Thoughts
Phishing remains a persistent threat precisely because it exploits trust and urgency rather than technical weaknesses, making awareness and healthy scepticism your most powerful defences. Taking a moment to verify unexpected or urgent requests, rather than reacting immediately, will protect you against the overwhelming majority of phishing attempts, whatever form they take.
