What is phishing?
Phishing is an attack that uses deceptive messages, websites or communications to trick people into trusting something controlled by an attacker.
The goal may be to steal passwords, payment information or personal data, distribute malware, gain access to an account or persuade the victim to perform another action that benefits the attacker.
What is phishing?
Phishing is primarily a form of social engineering. Instead of attacking a system directly, an attacker attempts to manipulate the person using that system.
A phishing message may appear to come from a bank, delivery company, employer, social network, cloud service, government organization or even someone the recipient already knows.
The attacker wants the victim to believe there is a legitimate reason to act quickly. The message might claim that an account has been locked, a payment failed, a package cannot be delivered or an important document needs immediate review.
The technical link or website matters, but the attack often succeeds because the message creates enough urgency, curiosity, fear or familiarity to make the victim act before carefully checking it.
How a phishing attack works
A phishing campaign can vary greatly, but many attacks follow the same basic sequence.
- The attacker chooses a target or group of targets.
- A believable message or scenario is created.
- The attacker sends an email, text message, social-media message or another form of communication.
- The message encourages the victim to click a link, download a file, enter credentials or perform another action.
- The attacker collects information, delivers malicious content or attempts to access the victim's account.
- Stolen access may then be used for account takeover, fraud, further phishing or movement into other systems.
Typical phishing flow
Why phishing attacks are effective
Phishing works because attackers exploit normal human behavior. People receive large numbers of messages, use many online accounts and often make decisions quickly.
Attackers commonly build phishing messages around emotional triggers that encourage immediate action.
- Urgency: “Your account will be suspended today.”
- Fear: “A suspicious login was detected.”
- Curiosity: “Someone shared a confidential document with you.”
- Authority: A message appears to come from a manager, bank or official service.
- Reward: The recipient is promised a refund, prize or unexpected payment.
Any message that creates pressure to act immediately deserves additional scrutiny. Legitimate organizations may send urgent notices, but urgency should never replace verification.
Common types of phishing attacks
Phishing is not limited to ordinary email. Attackers adapt the same deception techniques to different platforms and targets.
Email
Mass messages pretending to come from trusted organizations.
Targeted
Personalized attacks aimed at a specific individual or organization.
SMS
Phishing delivered through text messages or mobile messaging.
Other forms include voice phishing, often called vishing, social-media phishing, fake support messages, business email compromise and QR-code phishing.
The delivery method changes, but the central idea remains the same: convince the victim that an attacker-controlled request is legitimate.
How to recognize a phishing attempt
Modern phishing can look convincing, so there is rarely one universal sign. Instead, look for several indicators that do not fit the expected context.
- The sender address does not match the organization it claims to represent.
- The message creates unusual urgency or pressure.
- You are asked to sign in through an unexpected link.
- The visible link text and actual destination do not match.
- The domain contains misspellings or extra words.
- An unexpected attachment is included.
- The message asks for passwords, verification codes or sensitive data.
- The request is unusual for the person or company supposedly sending it.
secure-account-example-login.com
A domain can contain familiar brand words without belonging to that brand. Always identify the actual registered domain rather than trusting words placed elsewhere in the URL.
What happens when you click a phishing link?
Clicking a phishing link does not always produce the same outcome. The result depends on what the attacker has configured.
A link may lead to a fake login page designed to capture credentials. It might redirect through several domains, display a fraudulent payment form, encourage a software download or simply confirm that the recipient interacted with the message.
- Credentials may be submitted to an attacker-controlled server.
- Personal or payment information may be collected.
- The victim may be encouraged to download malicious software.
- The attacker may attempt to capture authentication codes.
- The phishing infrastructure may redirect to a legitimate website afterward to reduce suspicion.
Simply visiting a suspicious page does not necessarily mean an account has been compromised, but it should still be treated seriously. Risk increases significantly when credentials, files or sensitive information are submitted or downloaded.
How attackers create convincing phishing pages
A phishing page may visually imitate a real login portal almost perfectly. Logos, colors, buttons and page layouts are easy to reproduce, which means appearance alone is a weak security signal.
The important difference is usually the infrastructure behind the page: the domain, hosting location, scripts, network requests and destination receiving the submitted information.
Easy to copy
Logos and page layouts can closely resemble the real service.
Harder to fake
The actual domain often reveals that the page is unrelated to the real service.
Not proof
A phishing website can also use HTTPS and display a padlock.
This is why inspecting the address bar is more important than judging a page based only on how professional it looks.
How to protect yourself from phishing
Phishing defense is strongest when several habits and technical protections work together.
- Avoid signing in through unexpected links in messages.
- Navigate directly to important websites when possible.
- Inspect sender addresses and domains carefully.
- Use unique passwords for different accounts.
- Enable multi-factor authentication where available.
- Keep browsers, operating systems and security software updated.
- Verify unusual requests through a separate trusted communication channel.
- Treat unexpected attachments and downloads cautiously.
A password manager can also reduce some phishing risk because it may refuse to autofill credentials on a domain that does not match the legitimate saved website.
What to do if you clicked a phishing link
Your response should depend on what happened after the click. Do not assume the worst, but do not ignore it either.
- Close the suspicious page.
- Do not submit any additional information.
- If you entered a password, change it through the legitimate website or application.
- Change the same password anywhere else it was reused.
- Review recent account activity and active sessions.
- Enable or review multi-factor authentication.
- If a file was downloaded or executed, perform appropriate security checks on the device.
- Report the incident to the relevant organization or security team when appropriate.
If the affected account belongs to your employer or another organization, contact its security or IT team promptly. Early reporting can help prevent a single phishing event from becoming a larger incident.
How to analyze a suspicious URL
Before opening an unknown link, inspect the URL itself.
- Identify the actual domain.
- Look for misspellings and deceptive brand names.
- Inspect subdomains carefully.
- Be cautious with shortened URLs.
- Look for misleading characters or unusual formatting.
- Consider why and how you received the link.
For a deeper breakdown of URL inspection techniques, read ThreatHawk's guide to checking whether a URL is safe .
Inspect suspicious links with ThreatHawk
ThreatHawk URL Analyzer can help inspect suspicious URLs before you decide whether to trust them.
Analyze a suspicious URL before opening it.
Inspect URL structure, suspicious keywords, deceptive brand patterns and available reputation information using ThreatHawk's browser-based URL Analyzer.
Final takeaway
Phishing succeeds when an attacker convinces someone to trust the wrong message, website or request.
The most effective defense is not memorizing one visual warning sign. It is learning to verify the sender, inspect the actual domain, question unexpected urgency and avoid providing sensitive information through links you did not expect.
When something feels unusual, verify it through a trusted path before acting. A few seconds of inspection can prevent a much longer incident-response exercise later.
Phishing FAQ
Is phishing a type of malware?
Not necessarily. Phishing is primarily a social-engineering technique. Some phishing attacks deliver malware, while others focus on stealing credentials, payment information or other sensitive data.
Can you get hacked just by opening a phishing email?
Simply reading an ordinary phishing email usually does not mean an account or device has been compromised. The greater risk typically comes from clicking malicious links, downloading or executing files, or submitting information.
Does HTTPS mean a website is safe?
No. HTTPS protects the connection between your browser and the website, but a malicious website can also use HTTPS. Always verify the actual domain and context of the page.
Can phishing happen through SMS?
Yes. Phishing delivered through SMS or text messages is commonly called smishing. The message may contain malicious links, fake delivery notices, payment requests or account warnings.
What is spear phishing?
Spear phishing is a more targeted form of phishing in which attackers customize the message for a specific person, organization or role using information that makes the request appear more believable.
How can I check whether a link is safe?
Inspect the real domain, spelling, subdomains and context before opening it. ThreatHawk's URL Analyzer can also help identify suspicious URL characteristics and available reputation information.