Skip to content
eastbaycyber

What Is Phishing?

Glossary 6 min read
EC
East Bay Cyber Editorial Team Updated
Definition

At its core, phishing is an impersonation attack. The attacker pretends to be a trusted person, company, or service to influence the target’s behavior.

Phishing is a social engineering attack that tricks people into giving up credentials, sensitive information, money, or access. It usually starts with a message that looks legitimate, often by email, but phishing also appears in text messages, phone calls, chat apps, and fake websites. The attacker’s goal is usually to get the target to trust the message long enough to click, reply, log in, or approve something harmful.

If you are learning adjacent security concepts, see what is zero trust and what is defense in depth for related context.

How phishing works#

Most phishing attacks follow a familiar pattern.

Impersonation

The attacker makes the message appear credible. That might involve:

  • Spoofing a sender display name
  • Registering a lookalike domain
  • Copying brand logos and formatting
  • Hijacking a real email account
  • Referencing a real vendor, coworker, or service

The goal is to lower suspicion quickly.

Pretext

The message creates a believable reason for action. Common examples include:

  • Password expiration notices
  • Shared document alerts
  • Package delivery updates
  • Payroll or HR messages
  • Vendor invoice requests
  • Executive requests for urgent payment
  • Account security warnings

A good pretext feels routine enough to be believable and urgent enough to push action.

Action request

The victim is asked to do something immediately, such as:

  • Click a link
  • Open an attachment
  • Enter credentials
  • Approve a login prompt
  • Reply with account data
  • Transfer funds
  • Change payment details

Urgency is a major part of the tactic. The attacker wants the target to act before stopping to verify.

Outcome

If the target complies, the attacker may:

  • Steal usernames and passwords
  • Capture session tokens
  • Deliver malware or ransomware
  • Access email or cloud accounts
  • Redirect payments
  • Use the compromised account for follow-on attacks

The technical method may vary, but the core principle stays the same: use trust and pressure to trigger unsafe action.

Common types of phishing#

Phishing is not just one technique. It shows up in several common forms.

Credential phishing

This is the classic fake login page attack. The victim clicks a link, lands on a site that looks real, and enters credentials. The attacker captures them and attempts to log in.

Attachment-based phishing

The message includes a risky file, often disguised as an invoice, spreadsheet, or report. The file may contain malware or instructions that push the user to enable risky features.

Business email compromise

Business email compromise, or BEC, usually focuses on fraud rather than malware. The attacker impersonates or compromises a business account to request wire transfers, payroll changes, gift card purchases, or sensitive data.

Smishing

Smishing is phishing by SMS or messaging app. These messages often pose as banks, shipping companies, employers, or security teams.

Vishing

Vishing is phishing by phone call or voicemail. Attackers may pose as IT support, financial institutions, or executives to pressure the target into revealing information or granting access.

MFA fatigue and approval abuse

Some phishing campaigns are designed to bypass multi-factor authentication by stealing session cookies, using real-time login proxy pages, or pushing repeated MFA prompts until the user accepts one.

Why phishing is so effective#

Phishing succeeds because it blends technical deception with believable human context.

Attackers often rely on:

  • Familiar brands or coworkers
  • Time pressure
  • Fear of account lockout
  • Financial urgency
  • Curiosity about shared files or documents
  • Routine business processes

Not every phishing message is sloppy or obvious. Some are highly targeted and convincing, especially when aimed at finance staff, administrators, executives, or support teams.

When you will encounter phishing#

You will encounter phishing anywhere people use digital communication, which means nearly every modern organization.

Email and messaging platforms

Phishing most often arrives by email, but it also appears in Slack, Teams, SMS, WhatsApp, and social media direct messages. As work spreads across more platforms, phishing follows.

Identity and access incidents

When organizations investigate account compromise, phishing is often part of the root cause. Stolen credentials, token theft, and fake login pages frequently sit behind unauthorized access.

Financial fraud attempts

Accounts payable, payroll, procurement, and executive support staff are common targets for payment fraud, invoice scams, and vendor impersonation.

Security awareness programs

If an organization runs phishing simulations or suspicious email reporting, users will encounter the term regularly. Training matters, but it is only one layer of defense.

SOC and incident response workflows

Security teams see phishing during alert triage, mailbox review, endpoint analysis, and identity investigations. One phishing report often leads to broader questions:

  • Did anyone else receive it?
  • Did anyone click?
  • Were credentials entered?
  • Was an account used afterward?
  • Did the attacker send more messages internally?

Small business environments

Small and midsize businesses frequently encounter phishing through fake Microsoft 365 logins, payroll scams, invoice requests, and vendor impersonation. In many SMB environments, phishing is one of the most likely attack paths.

How organizations defend against phishing#

Effective defense usually requires multiple layers rather than one tool.

Email security controls

Secure email gateways and cloud email protections help block known malicious links, attachments, spoofing, and impersonation attempts. These controls reduce exposure but do not catch everything.

Identity protections

Strong passwords, MFA, conditional access, and session protections make credential theft less useful to attackers. A password manager like Try 1Password → can also help users avoid password reuse and reduce the chance of entering credentials into fake sites.

Endpoint protection

If a phishing message delivers malware or leads to suspicious scripts, endpoint security becomes important. Tools such as Get Malwarebytes → may help reduce risk from malicious downloads or post-click activity on user devices.

User reporting and response

Users should have a simple way to report suspicious messages. Security teams need a process to review reports, remove malicious mail from other inboxes, reset compromised accounts, and investigate follow-on activity.

Layered security architecture

Phishing defense works best as part of a broader layered model. That is why concepts like least privilege, access control, segmentation, and monitoring matter even after a phish gets through.

Conclusion#

Phishing is one of the most common and effective ways attackers gain access, steal money, or compromise accounts. It works by exploiting trust, urgency, and routine business behavior rather than relying only on software flaws.

That is why defending against phishing takes more than user awareness alone. Organizations need layered protections across email, identity, endpoints, reporting, and response so that one click does not become a full compromise.

Last verified: 2026-05-13

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.