The message arrives from a supplier, the bank, the chief executive or the IT department, it is urgent, and it asks for one small thing: log in here, approve this invoice, open this document, buy these vouchers. The address is close enough, the branding is exact, and the person receiving it has forty other emails and a meeting in five minutes. That is not a failure of intelligence. It is a professional deception aimed at a busy human, and the industry's own testing shows that a well-crafted message will be clicked by some fraction of any workforce, trained or not.
- Credential phishing: a login page that looks like yours, which harvests the password and, increasingly, relays the one-time code in real time.
- Business email compromise: no link, no malware, just a message from a spoofed or compromised executive account asking finance to change a supplier's bank details or pay an invoice today.
- Malicious attachments and links: a document or download that installs something; less common than it was, because modern mail filtering catches most of it.
- Spear phishing: the same, aimed at a specific person with researched detail. The message mentions your real project and your real colleague.
- Voice and text variants: a phone call from the bank's fraud team, a text from the courier. Same deception, different channel, often used to complete an attack that email started.
Controls that work after the click
Phishing-resistant authentication, meaning hardware keys or passkeys bound to the real site, so a harvested password and a relayed code buy nothing. A payment process in which no single person can change a supplier's bank details or approve an unusual transfer, however senior the requester appears. Mail authentication standards deployed on your own domain, so that a message claiming to be from you fails at the recipient's filter. And a reporting culture in which the person who clicked and reported it within a minute is thanked, because that minute is when containment is cheap.
Awareness training has a place and a limit. It lowers the click rate and raises the report rate, both of which matter, and it cannot reach zero because the attacker only needs one click in a thousand. Programmes that punish clickers drive reporting underground, which is the single worst outcome, since a click reported in one minute is an incident and a click hidden for a week is a breach. The security certifications test the vocabulary of phishing at every level; the practical lesson is that the controls belong in the systems, not in the inbox.
