Skip to content
TechBone
Security & privacy

Phishing: Definition & explanation

In a nutshell

Phishing is a fraud technique where attackers use fake emails, texts, or websites to steal sensitive data like passwords or credit card details. Messages impersonate trusted senders such as banks or online services.

How does Phishing work?

Phishing works on a simple principle: attackers send messages that appear to come from a trusted source – a bank, a delivery service, or a known online shop. The message usually includes an urgent call to action, such as confirming account details or clicking a link due to alleged suspicious activity. The link leads to a fake website that closely mimics the original. If the victim enters credentials there, they go straight to the attackers. Alternatively, phishing emails carry malicious attachments that install malware when opened. Modern variants also use SMS (smishing), calls (vishing), or social media messages. Spear phishing is particularly dangerous: attackers research a specific target to make the message more personal and convincing. Warning signs include spelling errors, unusual sender addresses, generic greetings, or artificial time pressure. Protective measures include two-factor authentication, passkeys instead of passwords, and general skepticism toward unexpected links and attachments. A VPN doesn't directly prevent phishing but stops data interception on unsecured networks.

Advantages of Phishing

  • Recognizable through typical warning signs
  • Awareness training significantly reduces success rate
  • 2FA prevents account takeover despite stolen data
  • Passkeys make classic phishing ineffective
  • Spam filters block many attempts automatically

Disadvantages of Phishing

  • Can lead to identity theft
  • Financial losses from stolen credentials
  • Increasingly sophisticated, AI-generated forgeries
  • Even experienced users can be fooled
  • Companies suffer reputational and data damage

Frequently asked questions

Typical signs include an unusual sender address, spelling mistakes, generic greetings, and artificial urgency. Check links by hovering over them before clicking, and never open unexpected attachments.

Guides with Phishing

No linked guides for this term yet.

Related terms