Phishing

Phishing

Phishing is a fraud attempt in which someone poses as a trustworthy entity via email, SMS, or a fake website in order to obtain passwords, account data, or money. The attack doesn't target technical vulnerabilities, but rather the credulity and haste of recipients.

Phishing is a scam on the internet. Someone sends you a message and pretends it comes from your bank, a parcel delivery service, or a school platform. The message usually says that something urgently needs to be resolved, followed by a link. If you click on it, you land on a replica page that looks deceptively similar to the original. If you type your password there, it doesn’t go to the bank, but straight to the fraudsters. The name plays on the English word for angling: bait is cast out, and whoever bites ends up on the hook.

The most common way into other people’s accounts

Most successful attacks on companies and private individuals don’t begin with a brilliant hacking trick. They begin with someone voluntarily handing over a password. Security reports from major providers have named phishing as the most common entry point for years. An attacker doesn’t need a software vulnerability if they can convince the person in front of it.

The damage rarely stops at one account. Whoever has access to an email inbox can have passwords reset for other services. In companies, a stolen access is often just a door opener. What follows is data theft or ransomware that encrypts all files. Individual cases have cost corporations sums in the hundreds of millions.

It’s important to distinguish this from a virus. A virus is malicious software that nests itself on the device. Phishing, on the other hand, is pure deception and works even if your computer is completely clean and up to date. An antivirus scanner alone therefore doesn’t protect you.

The bait and the fake page

A phishing attempt almost always follows the same pattern. First comes the message with a made-up reason: a parcel can’t be delivered, the account has supposedly been locked, an invoice is outstanding. Then comes time pressure, often with a 24-hour deadline. Whoever feels under pressure checks things less carefully. The link ultimately leads to a copy of the real website, sometimes recreated pixel for pixel.

The most important thing to check is the address in the browser. Fraudsters use domains that resemble the original, for example with an extra hyphen or a swapped sequence of letters. The sender of an email can also be forged and says little on its own. Good protection comes from two-factor authentication: in addition to the password, a second piece of proof is required, such as a code from an app. Even a stolen password is then usually no longer enough.

There are more targeted variants. In so-called spear phishing, attackers research their victim beforehand. They know the boss’s name, ongoing projects, or the item that was ordered. Such messages appear far more credible than mass emails. Language models, i.e. AI systems that write fluent text, have made this work considerably easier.

From parcel SMS to fake phone calls

In everyday life, most people encounter phishing as an SMS about a supposed parcel delivery or as an email about a streaming subscription. Messages via WhatsApp also count, such as the well-known scam involving a family member’s new phone number. The term smishing has become established for the SMS route, and vishing for phone calls. The underlying principle remains the same in all cases.

In the news, phishing usually comes up in connection with larger data breaches. It’s often said that attackers gained access via a compromised employee account. That is typically a phishing case. Banks and authorities therefore regularly issue warnings and emphasize a simple principle: they never ask for passwords or card details via a link.

A common misconception is that you can recognize phishing by poor grammar. That used to be true a few years ago, but it’s outdated today, since AI tools produce flawless text in any language. Fake calls with imitated voices are even circulating now. Only one thing is reliable: never follow the included link, but instead open the page yourself in the browser or call the genuine number to check.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.