<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=9291417&amp;fmt=gif">

An Introduction to Phishing

Ajay Unni
Ajay Unni CEO,StickmanCyber
September 22, 2026 5 min read

Phishing is a longstanding type of cyberattack and continues to be a widespread threat. Even though this type of social engineering has been around for a long period of time it has constantly evolved, becoming more and more sophisticated over time. This article aims to provide readers with an in-depth introduction to Phishing including its origin, how it works and its goals.

What is Phishing?

Phishing is a social engineering tactic that consists of an attacker sending a person a fraudulent message via email, instant message or text message, in the hope that they will click a malicious link, open an attachment or reveal sensitive information. This can lead to malware infection, including ransomware, or the theft of personal or organisational information.

A Brief History of Phishing 

Phishing as the name suggests was coined based on the analogy of a fisherman throwing a line and hook with bait attached to it, in the hopes that unwary fish bites. The term rose in popularity in the 1990s amongst hackers who targeted AOL users and their login credentials.

Notable historical examples of phishing and related fraud:

  1. Two U.S. internet companies - Between the years 2013 and 2015, two U.S.-based internet companies were induced to transfer over US$120 million in a business email compromise scheme. The attacker impersonated an Asian computer hardware manufacturer and used fraudulent emails and documents to divert payments, according to the U.S. Department of Justice.
  2. Crelan Bank - In January 2016, the bank in Belgium reported an international fraud with damage of up to €70 million. Crelan stated that no customers were affected.
  3. FACC - The Austrian aerospace parts manufacturer reported that its 2015/16 “Fake President” fraud resulted in an illicit outflow of €52.8 million and a recognised loss of €41.9 million after funds were frozen. In March 2025, FACC received €10.8 million of the frozen funds back.

These historical cases illustrate the financial impact of impersonation and fraudulent payment requests. Verizon’s 2020 Data Breach Investigations Report identified phishing among the top five threat action varieties in breaches.

Phishing Kits

A Phishing kit consists of tools that make it easy for individuals who have little to no technical skill to launch a phishing exploit. Phishing kits include website resources and tools that can be deployed on a server, the attacker can then send out emails to their targets. Phishing kits can also allow individuals to spoof brands that are well known around the world, to increase the chances of the target clicking on the malicious link.

The Goal Of Phishing Attacks 

There are a number of different types of phishing attacks, but what remains constant is they all incorporate elements of disguise, whether it is tricking users into thinking an email is coming from a trusted source, or luring a user to visit a fake website designed to look like one they frequently visit. 

There are two key purposes of a phishing attack:

  1. Divulge sensitive information - these messages are designed to manipulate targets into sharing sensitive information - such as login credentials that enable access to systems. For example: a criminal can send out large amounts of emails out to numerous individuals masquerading as a bank, hoping that one of the recipients is an actual customer, the email usually will include a link that leads the target to a fake website that is disguised to imitate the actual login page of the bank. The unaware user will enter their login details which may allow the criminal behind the phishing attack to access their account, depending on the additional authentication controls in place.
  2. Infect systems with Malware - phishing attacks may also be designed to get a target’s system infected with Malware. For instance, an attacker may send a victim an email with a file attached that has malicious code embedded into it designed to install malware onto the victim’s system. 

Phishing attacks can be targeted at individuals, like employees in a certain organization, in which case attackers will design their messaging to better manipulate their targets. Phishing attacks can also be untargeted and sent out to large numbers of individuals. An analogy to help understand this is; a fisherman who uses a line and hook with specific bait designed to catch a specific family of fish, versus a fisherman who uses a net.

COVID-19 and the effect of similar crises

Attackers who utilise phishing attacks or any social engineering tactic for that matter, rely on an element of urgency in their attack strategy in the hopes that it can stop targets from being analytical and reduce their skepticism or doubt regarding the legitimacy of the requests being made by the attacker. 

During the COVID-19 pandemic, ASD’s Australian Cyber Security Centre reported an increase in COVID-19 themed scams, online frauds and phishing campaigns. Crises can give attackers opportunities to impersonate trusted employers, banks or government agencies and exploit people’s search for reliable information.

How to Prevent Phishing 

One important way to reduce your risk of falling for phishing attacks is educating yourself on what to look out for. There are so many examples of phishing attacks and methods online that you can familiarize yourself with so you can improve the chances of identifying an attempt when you are the target.

Other than educating and training yourself, there are a number of tips that can help you avoid falling victim to a phishing attack:

  1. Crosscheck URLs and email addresses for spelling mistakes
  2. Watch out for spoof website pages that are designed to imitate popular websites you regularly visit
  3. Email hijacking is a real threat. Even if the email address checks out, if the message or request is suspicious, contact the sender through a separate trusted channel, such as a known phone number, to verify. Do not use contact details supplied in the suspicious message.
  4. Control how much you share online, attackers may use information you share online like your date of birth, address, mobile phone number etc. against you. 

As an organisation you can protect employees by

  1. Conducting penetration tests or vulnerability assessments to identify and fix vulnerabilities in your systems that can be used against an employee and the organization in a phishing attack. 
  2. Monitor web traffic on all devices 
  3. Screen communications for suspect links 
  4. Security awareness and training for all employees

The above methods are just a few ways to protect yourself against phishing attacks, phishing attacks are constantly evolving as attackers get smarter and more sophisticated in their trickery. It is vital that you stay informed on the latest trends in the cybersecurity landscape

StickmanCyber's team is equipped to help your employees recognise such attempts, and prevent social engineering attacks. 

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment