Glossary
Phishing is a social-engineering attack in which criminals impersonate a trusted entity (a bank, employer, or well-known brand) to trick victims into revealing credentials, personal data, or payment details, or into taking a harmful action like clicking a malicious link or authorizing a payment. Decades old and still the way a huge share of breaches begin, phishing works because it targets human trust rather than a technical flaw.
Phishing is the entry point for an enormous share of breaches and fraud. Credentials harvested through phishing feed account takeover; malware delivered through phishing enables deeper compromise; and increasingly, phishing manipulates victims directly into authorizing scams.
The classic pattern: the victim receives a message that appears to come from a trusted source, crafted to create urgency, fear, or curiosity ("your account is locked," "confirm this payment"). It directs them to a convincing fake website or to reply with sensitive information. When the victim enters their credentials on the fake site, the attacker captures them, and with real-time phishing kits, relays them (and any one-time code) to the genuine site instantly, defeating traditional MFA.
Phishing exploits universal human psychology: trust in authority, urgency, fear of loss, and the sheer volume of legitimate messages people process daily. A single convincing message among hundreds can succeed. It’s also cheap and scalable, and it adapts: as one lure loses effectiveness, attackers craft new ones. Crucially, phishing sidesteps most technical defenses because the victim voluntarily hands over the information, the system sees a legitimate login with correct credentials.
Generative AI has sharpened phishing dramatically. The old tell-tale signs (awkward grammar, clumsy phrasing) are disappearing as AI produces flawless, personalized messages at scale. AI can research targets, mimic writing styles, generate convincing fake sites, and even power voice-cloning for vishing. This lowers the skill barrier and raises the success rate, making phishing more dangerous than ever and accelerating the shift toward defenses that don’t depend on users spotting a fake.
The most durable defense is removing what phishing steals. Phishing-resistant authentication (passkeys/FIDO2) is transformative: because a passkey is cryptographically bound to the legitimate site’s origin, it simply won’t work on a phishing page, and there’s no code to relay, defeating even real-time AiTM attacks. Beyond authentication, defenses include email security and filtering, user awareness (helpful but not sufficient alone, since expert phishing fools even careful people), and detecting the downstream signs of a successful phish through device and behavioral monitoring. Stopping phishing at its origin (before a single customer falls victim) increasingly means making the credentials phishing targets worthless.
Traditional advice teaches people to spot phishing: check the sender address, hover over links, watch for urgency, distrust unexpected requests for credentials or payment, and verify through a known channel. This guidance still has value, and awareness training reduces click rates at the margin. But leaning on human vigilance as the primary defense is a losing strategy, for two reasons. First, AI-generated phishing has erased the obvious tells, the misspellings and awkward phrasing people were taught to look for. Second, everyone has a bad moment; expecting every employee and customer to correctly judge every message forever is unrealistic, and blaming victims who were expertly manipulated is both unfair and ineffective. The durable answer is technical: make credentials unphishable (passkeys), filter malicious messages before they arrive, and detect compromise fast when a phish does succeed. Education plus technology beats education alone by a wide margin.
How can I recognize a phishing message?
Watch for unexpected requests for credentials or payment, urgency or fear, mismatched sender addresses, and suspicious links. But note AI has removed many classic tells.
Is security awareness training enough to stop phishing?
No. It helps at the margin, but expert and AI-generated phishing fools careful people; technical defenses like passkeys are the durable fix.
What is phishing?
A social-engineering attack that impersonates a trusted entity to trick victims into revealing credentials or data or taking a harmful action.
What are the types of phishing?
Email phishing, spear phishing, whaling, smishing (SMS), vishing (voice), clone phishing, and real-time adversary-in-the-middle phishing.
Can phishing defeat MFA?
Yes, real-time phishing proxies capture and relay one-time codes; phishing-resistant methods like passkeys defeat this because the credential is origin-bound.
How is AI making phishing worse?
It produces flawless, personalized messages and fake sites at scale and enables voice cloning, raising success rates and lowering the skill barrier.
What’s the best defense against phishing?
Phishing-resistant authentication (passkeys/FIDO2), since it removes the phishable credential entirely, backed by email security and monitoring.
Related: Social Engineering · Spear Phishing · Smishing & Vishing · Passkeys · Account Takeover (ATO) · Credential Stuffing