Skip to Main Content
PhishingComplete guide

What is phishing? How it works, and how to recognise it

Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.

Subash Poudel5 min read

The short answer

  1. Phishing is an attempt to get you to hand over a credential, a payment, or access to a device by impersonating someone you trust.
  2. It arrives by email, text, phone call, QR code and social media. The channel changes; the request underneath does not.
  3. Every phishing message wants one of four things - a password, a one-time code, a payment, or an installation.
  4. Phishing and spoofing was the most-reported cybercrime category in the FBI's 2025 Internet Crime Report.
  5. The reliable defence is not spotting fakes, it is refusing to act from inside an unexpected message.

Phishing is an attempt to get you to hand over something valuable — a password, a one-time code, a payment, or permission to install software — by pretending to be a person or organisation you already trust.

That is the whole of it. Everything else about phishing is decoration: the branding, the pretext, the channel it arrives through, the particular emergency it invents this month. Those change constantly. What sits underneath them has been the same for thirty years.

Understanding that distinction is what makes the difference between memorising a list of red flags that expires within a year, and having a defence that still works against an attack that has not been invented yet.

Why it works

Phishing does not attack a system. It attacks a judgement call, and it picks the moment when your judgement is cheapest.

The message arrives while you are between two other things. It looks like something you were half-expecting — a delivery, an invoice, a password reset, a message from your manager. It asks for one small action that would take fifteen seconds. Nobody is fooled by a phishing email they read carefully. They are fooled by one they glance at.

This is also why "just be careful" fails as advice. Carefulness is a resource that runs out, and phishing is specifically timed to arrive when yours has.

The scale of it

Most reportedphishing and spoofing was the top cybercrime category by complaint volume in 2025FBI IC3, 2025 Internet Crime Report
1,008,597complaints received by the FBI's IC3 in 2025, up from 859,532 in 2024FBI IC3, 2025 Internet Crime Report
~1 millionphishing attacks observed in a single quarter, Q1 2025Anti-Phishing Working Group, 2025

The Anti-Phishing Working Group recorded 1,003,924 phishing attacks in the first quarter of 2025 alone — its largest quarterly figure since late 2023. Payment and banking targets together accounted for 30.9% of them.

Those numbers are worth holding lightly, though. Reported phishing is a fraction of attempted phishing, and attempted phishing is cheap enough that volume is not really the constraint. The useful takeaway is not that the number is large but that it is stable: this technique keeps being used because it keeps working.

The four things every phishing message wants

Strip away the branding and the story, and every phishing attempt is asking for one of four things. This is the most durable thing you can learn about the subject, because a new pretext is easy to invent and a fifth category is not.

The askWhat it looks likeWhat the attacker gets
A credential"Confirm your password to keep your account active"Direct access to the account
A one-time code"Read me the code we just texted you"Access despite two-factor authentication
A payment"Your invoice is overdue", "settle the unpaid toll"Money, usually irreversibly
An installation"Open the attached document", "install this support tool"Access to the device itself

The forms it takes

Phishing is named after email because that is where it started, but attackers follow attention, and attention moved to phones. The same attack now arrives through whichever channel you are least defended on.

  • Email phishing — the original, still the highest volume, and the form most likely to be filtered before you see it.
  • Smishing — text message. Shorter, so there is less to inspect, and link previews are harder to check on a phone.
  • Vishing — a phone call, increasingly with a cloned voice. Live conversation removes your time to think.
  • Quishing — a QR code, which hides the destination behind an image your eye cannot parse.
  • Spear phishing — targeted at you specifically, using real details about your life or job.

Attackers are sending millions of emails a day containing QR codes, according to the APWG, precisely because a QR code defeats the "hover the link and read the destination" habit that a decade of security training built.

How to actually defend against it

The instinct is to get better at spotting fakes. That is a losing race — fakes improve, and generative tools removed the spelling mistakes that used to do half the work of detection for us.

The winning move is structural: stop acting from inside unexpected messages.

  1. Verify through a channel you chose. Not the link, not the phone number in the message. Type the address yourself, or use the number on the back of your card. This single habit neutralises almost every variant, because the entire attack depends on you using the path the attacker supplied.
  2. Treat urgency as a reason to slow down. The deadline exists to stop you doing what you are doing right now: thinking about it. The feeling of pressure is itself the signal.
  3. Use phishing-resistant authentication. A passkey cannot be handed to a fake site, because it will not present itself to the wrong domain. This moves the problem out of the realm of human vigilance entirely.
  4. Use a password manager. It will not autofill your bank password on a lookalike domain, which makes it a rather good phishing detector that never gets tired.

If you think you have already fallen for one

Speed matters far more than thoroughness. Change the password on the affected account first, then any account sharing that password, then turn on two-factor authentication, then review recent account activity. A password changed within the first ten minutes usually ends the incident.

The full sequence, including what to do if you entered card details or opened a downloaded file, is in I clicked a phishing link — what should I do?

Practise on real examples

Reading about phishing and recognising it under time pressure are different skills. Our inbox drill puts you in front of genuine scam messages and asks you to sort them.

Try it free

Frequently asked questions

What is phishing in simple terms?
Phishing is a message that pretends to come from someone you trust — a bank, an employer, a delivery company, a colleague — in order to get you to hand over something valuable. That is usually a password, a one-time code, a payment, or permission to install software. The message is the bait; the credential or payment is the catch.
Is phishing only email?
No. The same attack arrives by text message (smishing), phone call (vishing), QR code (quishing), social media DM, and messaging apps like WhatsApp. Email is where the technique started and where the name comes from, but attackers follow attention, and attention moved to phones.
How can I tell if a message is phishing?
Check four things in order — the sender's actual domain rather than the display name, whether the message manufactures a deadline, where the link really points, and what it is ultimately asking you to do. A message that fails any of the four is worth verifying through a channel you chose yourself.
What happens if I click a phishing link?
Clicking alone is usually not the harmful step. The damage comes from what you do next — entering credentials, approving a login prompt, or opening a downloaded file. If you only clicked, close the page. If you entered anything, change that password immediately, then any account sharing it, then enable two-factor authentication.
Why is phishing still so effective?
Because it targets a person's judgement rather than a system's defences, and because it is skimmed rather than read. A phishing message arrives while you are between two other tasks, resembles something you were half-expecting, and asks for one small action. Careful readers are not fooled; busy ones are.

Sources

  1. 2025 Internet Crime Report FBI Internet Crime Complaint Center (IC3), 2026
  2. Cryptocurrency and AI Scams Bilk Americans of Billions Federal Bureau of Investigation, 2026
  3. Phishing Activity Trends Report, 1st Quarter 2025 Anti-Phishing Working Group, 2025
  4. Phishing attacks - defending your organisation UK National Cyber Security Centre, 2025

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.