Skip to content
Getting Digital

Phishing

Also: spear phishing, business email compromise, credential phishing, smishing, vishing

Phishing is an attack that deceives a person into revealing credentials, approving a payment or running malicious content, usually through a message that impersonates someone they trust.

Our take. Blaming the user who clicked is the organisation excusing itself. People will always click, because the messages are designed by professionals to be clicked, and the controls that work are the ones that make a click harmless: phishing-resistant authentication, payment processes that need a second person, and a report button that is praised rather than punished.

The message arrives from a supplier, the bank, the chief executive or the IT department, it is urgent, and it asks for one small thing: log in here, approve this invoice, open this document, buy these vouchers. The address is close enough, the branding is exact, and the person receiving it has forty other emails and a meeting in five minutes. That is not a failure of intelligence. It is a professional deception aimed at a busy human, and the industry's own testing shows that a well-crafted message will be clicked by some fraction of any workforce, trained or not.

  • Credential phishing: a login page that looks like yours, which harvests the password and, increasingly, relays the one-time code in real time.
  • Business email compromise: no link, no malware, just a message from a spoofed or compromised executive account asking finance to change a supplier's bank details or pay an invoice today.
  • Malicious attachments and links: a document or download that installs something; less common than it was, because modern mail filtering catches most of it.
  • Spear phishing: the same, aimed at a specific person with researched detail. The message mentions your real project and your real colleague.
  • Voice and text variants: a phone call from the bank's fraud team, a text from the courier. Same deception, different channel, often used to complete an attack that email started.

Controls that work after the click

Phishing-resistant authentication, meaning hardware keys or passkeys bound to the real site, so a harvested password and a relayed code buy nothing. A payment process in which no single person can change a supplier's bank details or approve an unusual transfer, however senior the requester appears. Mail authentication standards deployed on your own domain, so that a message claiming to be from you fails at the recipient's filter. And a reporting culture in which the person who clicked and reported it within a minute is thanked, because that minute is when containment is cheap.

Awareness training has a place and a limit. It lowers the click rate and raises the report rate, both of which matter, and it cannot reach zero because the attacker only needs one click in a thousand. Programmes that punish clickers drive reporting underground, which is the single worst outcome, since a click reported in one minute is an incident and a click hidden for a week is a breach. The security certifications test the vocabulary of phishing at every level; the practical lesson is that the controls belong in the systems, not in the inbox.

In practice

A finance clerk receives an email from the managing director's address, sent while the director is known to be travelling, asking for an urgent payment to a new supplier before the end of the day and apologising for the short notice. Everything about it is plausible, and in an organisation where the director's word is enough, the payment goes out and is unrecoverable within hours. In an organisation where any new supplier or changed bank detail requires a second approver and a call-back to a known number, the clerk follows the process, the director's phone rings, and the email is reported. The clerk's judgement was the same in both cases; the process decided the outcome.

Often confused with

Ransomware
Phishing is a way in; ransomware is one thing an attacker does once inside. Many ransomware incidents begin with a phishing email, but phishing more often ends in a stolen credential or a fraudulent payment than in encrypted files.
Multi-Factor Authentication (MFA)
Multi-factor authentication is the control that most directly blunts credential phishing, and only its phishing-resistant forms defeat a live relay. The two are usually discussed together because the attack defines which factor is good enough.
Incident Response
A reported phishing click is where incident response begins. The response's speed depends almost entirely on how quickly and how safely the person who clicked felt able to say so.

Key takeaways

  • Professionals design the messages; some fraction of any workforce will click.
  • Make the click harmless: resistant authentication, dual-control payments, mail authentication, fast reporting.
  • Punishing clickers hides incidents; thanking reporters shortens them.

Certifications that test this

Vendor exams whose syllabus covers this concept — facts, cost and a preparation path on each page.

More courses from these shelves

A rotating selection from the course directory, drawn from the subcategories where this concept is taught rather than picked for it. Details, price and the provider link are on the course page.

ISO/IEC 42001: Artificial Intelligence Management System

ISO/IEC 42001: Artificial Intelligence Management System is a comprehensive course designed for professionals looking t…

Udemy

C_THR82: SuccessFactors Performance & Goals Implementation

Are you ready to pass the SAP Certified Associate - SAP SuccessFactors Performance and Goals (C_THR82) exam and take yo…

Udemy

Networking Full Course & Network + certification

This Class of Full Networking Fundamentals, will be fully illustrated with video lessons and sample to which it will ma…

Udemy

Python And Django Framework For Beginners Complete Course

Learn Python From Scratch Beginner to Expert Python.Start from the Python basics and go all the way to creating your ow…

Udemy

The Ultimate AWS Networking Training Course: All In One

Unlock the Future of Cloud: Master AWS Networking and Propel Your Career Forward!In a world powered by the cloud, Amazo…

Udemy

Salesforce Certified Data Cloud Consultant Practice Exams

Get certified with Salesforce Data Cloud Consultant certification by practicing actual exam type questions. This Course…

Udemy

FAQ

Does security awareness training work?
Partly. It lowers click rates and, more usefully, raises report rates. It does not reach zero and cannot, so it is a complement to controls that make a click harmless rather than a substitute for them.
How do I recognise a phishing email?
Urgency, an unusual request, a sender address that is close but not exact, a link whose real destination differs from its text, and pressure to bypass a normal process. The best messages show none of these, which is why the honest answer is to verify unusual requests through a channel the message did not provide.
What should I do if I clicked?
Report it immediately, to whoever handles security, and change the password if you entered one. The speed of the report is what limits the damage; nobody competent will blame you, and a good organisation will thank you.

Sources

The primary text this definition rests on. Read it before you trust ours.

Last reviewed 13 September 2026 · Getting Digital