What is phishing? | Transmit Security

Glossary

What is phishing?

Phishing is a social-engineering attack that tricks victims into revealing credentials or sensitive data via fake messages and sites.
by Transmit Security

Phishing is a social-engineering attack in which criminals impersonate a trusted entity (a bank, employer, or well-known brand) to trick victims into revealing credentials, personal data, or payment details, or into taking a harmful action like clicking a malicious link or authorizing a payment. Decades old and still the way a huge share of breaches begin, phishing works because it targets human trust rather than a technical flaw.

Phishing is the entry point for an enormous share of breaches and fraud. Credentials harvested through phishing feed account takeover; malware delivered through phishing enables deeper compromise; and increasingly, phishing manipulates victims directly into authorizing scams.

How phishing works

The classic pattern: the victim receives a message that appears to come from a trusted source, crafted to create urgency, fear, or curiosity ("your account is locked," "confirm this payment"). It directs them to a convincing fake website or to reply with sensitive information. When the victim enters their credentials on the fake site, the attacker captures them, and with real-time phishing kits, relays them (and any one-time code) to the genuine site instantly, defeating traditional MFA.

The types of phishing

  • Email phishing: mass deceptive emails, the classic form.
  • Spear phishing: targeted phishing tailored to a specific individual using personal details.
  • Whaling: spear phishing aimed at executives or high-value targets.
  • Smishing: phishing via SMS text messages.
  • Vishing: phishing by voice call, often impersonating support or authorities.
  • Clone phishing: copying a legitimate message and swapping in malicious links.
  • Adversary-in-the-middle (AiTM): real-time proxy phishing that captures and relays credentials and MFA codes live.

Why phishing works so well

Phishing exploits universal human psychology: trust in authority, urgency, fear of loss, and the sheer volume of legitimate messages people process daily. A single convincing message among hundreds can succeed. It’s also cheap and scalable, and it adapts: as one lure loses effectiveness, attackers craft new ones. Crucially, phishing sidesteps most technical defenses because the victim voluntarily hands over the information, the system sees a legitimate login with correct credentials.

AI and the escalation of phishing

Generative AI has sharpened phishing dramatically. The old tell-tale signs (awkward grammar, clumsy phrasing) are disappearing as AI produces flawless, personalized messages at scale. AI can research targets, mimic writing styles, generate convincing fake sites, and even power voice-cloning for vishing. This lowers the skill barrier and raises the success rate, making phishing more dangerous than ever and accelerating the shift toward defenses that don’t depend on users spotting a fake.

How to defend against phishing

The most durable defense is removing what phishing steals. Phishing-resistant authentication (passkeys/FIDO2) is transformative: because a passkey is cryptographically bound to the legitimate site’s origin, it simply won’t work on a phishing page, and there’s no code to relay, defeating even real-time AiTM attacks. Beyond authentication, defenses include email security and filtering, user awareness (helpful but not sufficient alone, since expert phishing fools even careful people), and detecting the downstream signs of a successful phish through device and behavioral monitoring. Stopping phishing at its origin (before a single customer falls victim) increasingly means making the credentials phishing targets worthless.

Recognizing phishing: and why it’s not enough

Traditional advice teaches people to spot phishing: check the sender address, hover over links, watch for urgency, distrust unexpected requests for credentials or payment, and verify through a known channel. This guidance still has value, and awareness training reduces click rates at the margin. But leaning on human vigilance as the primary defense is a losing strategy, for two reasons. First, AI-generated phishing has erased the obvious tells, the misspellings and awkward phrasing people were taught to look for. Second, everyone has a bad moment; expecting every employee and customer to correctly judge every message forever is unrealistic, and blaming victims who were expertly manipulated is both unfair and ineffective. The durable answer is technical: make credentials unphishable (passkeys), filter malicious messages before they arrive, and detect compromise fast when a phish does succeed. Education plus technology beats education alone by a wide margin.

Frequently asked questions

How can I recognize a phishing message?

Watch for unexpected requests for credentials or payment, urgency or fear, mismatched sender addresses, and suspicious links. But note AI has removed many classic tells.

Is security awareness training enough to stop phishing?

No. It helps at the margin, but expert and AI-generated phishing fools careful people; technical defenses like passkeys are the durable fix.

What is phishing?

A social-engineering attack that impersonates a trusted entity to trick victims into revealing credentials or data or taking a harmful action.

What are the types of phishing?

Email phishing, spear phishing, whaling, smishing (SMS), vishing (voice), clone phishing, and real-time adversary-in-the-middle phishing.

Can phishing defeat MFA?

Yes, real-time phishing proxies capture and relay one-time codes; phishing-resistant methods like passkeys defeat this because the credential is origin-bound.

How is AI making phishing worse?

It produces flawless, personalized messages and fake sites at scale and enables voice cloning, raising success rates and lowering the skill barrier.

What’s the best defense against phishing?

Phishing-resistant authentication (passkeys/FIDO2), since it removes the phishable credential entirely, backed by email security and monitoring.

Related: Social Engineering · Spear Phishing · Smishing & Vishing · Passkeys · Account Takeover (ATO) · Credential Stuffing

Request a Demo

By clicking the button, you agree to the Terms and Conditions