Blog

What Is Phishing? How It Works and How to Prevent It

Written by Ajay Unni | Sep 22, 2026, 1:34:22 AM

Phishing is a longstanding type of cyberattack and continues to be a widespread threat. Even though this type of social engineering has been around for a long period of time it has constantly evolved, becoming more and more sophisticated over time. This article aims to provide readers with an in-depth introduction to Phishing including its origin, how it works and its goals.

What is Phishing?

Phishing is a social engineering tactic that consists of an attacker sending a person a fraudulent message via email, instant message or text message, in the hope that they will click a malicious link, open an attachment or reveal sensitive information. This can lead to malware infection, including ransomware, or the theft of personal or organisational information.

A Brief History of Phishing 

Phishing as the name suggests was coined based on the analogy of a fisherman throwing a line and hook with bait attached to it, in the hopes that unwary fish bites. The term rose in popularity in the 1990s amongst hackers who targeted AOL users and their login credentials.

Notable historical examples of phishing and related fraud:

  1. Two U.S. internet companies - Between the years 2013 and 2015, two U.S.-based internet companies were induced to transfer over US$120 million in a business email compromise scheme. The attacker impersonated an Asian computer hardware manufacturer and used fraudulent emails and documents to divert payments, according to the U.S. Department of Justice.
  2. Crelan Bank - In January 2016, the bank in Belgium reported an international fraud with damage of up to €70 million. Crelan stated that no customers were affected.
  3. FACC - The Austrian aerospace parts manufacturer reported that its 2015/16 “Fake President” fraud resulted in an illicit outflow of €52.8 million and a recognised loss of €41.9 million after funds were frozen. In March 2025, FACC received €10.8 million of the frozen funds back.

These historical cases illustrate the financial impact of impersonation and fraudulent payment requests. Verizon’s 2020 Data Breach Investigations Report identified phishing among the top five threat action varieties in breaches.

Phishing Kits

A Phishing kit consists of tools that make it easy for individuals who have little to no technical skill to launch a phishing exploit. Phishing kits include website resources and tools that can be deployed on a server, the attacker can then send out emails to their targets. Phishing kits can also allow individuals to spoof brands that are well known around the world, to increase the chances of the target clicking on the malicious link.

The Goal Of Phishing Attacks 

There are a number of different types of phishing attacks, but what remains constant is they all incorporate elements of disguise, whether it is tricking users into thinking an email is coming from a trusted source, or luring a user to visit a fake website designed to look like one they frequently visit. 

There are two key purposes of a phishing attack:

  1. Divulge sensitive information - these messages are designed to manipulate targets into sharing sensitive information - such as login credentials that enable access to systems. For example: a criminal can send out large amounts of emails out to numerous individuals masquerading as a bank, hoping that one of the recipients is an actual customer, the email usually will include a link that leads the target to a fake website that is disguised to imitate the actual login page of the bank. The unaware user will enter their login details which may allow the criminal behind the phishing attack to access their account, depending on the additional authentication controls in place.
  2. Infect systems with Malware - phishing attacks may also be designed to get a target’s system infected with Malware. For instance, an attacker may send a victim an email with a file attached that has malicious code embedded into it designed to install malware onto the victim’s system. 

Phishing attacks can be targeted at individuals, like employees in a certain organization, in which case attackers will design their messaging to better manipulate their targets. Phishing attacks can also be untargeted and sent out to large numbers of individuals. An analogy to help understand this is; a fisherman who uses a line and hook with specific bait designed to catch a specific family of fish, versus a fisherman who uses a net.

COVID-19 and the effect of similar crises

Attackers who utilise phishing attacks or any social engineering tactic for that matter, rely on an element of urgency in their attack strategy in the hopes that it can stop targets from being analytical and reduce their skepticism or doubt regarding the legitimacy of the requests being made by the attacker. 

During the COVID-19 pandemic, ASD’s Australian Cyber Security Centre reported an increase in COVID-19 themed scams, online frauds and phishing campaigns. Crises can give attackers opportunities to impersonate trusted employers, banks or government agencies and exploit people’s search for reliable information.

How to Prevent Phishing 

One important way to reduce your risk of falling for phishing attacks is educating yourself on what to look out for. There are so many examples of phishing attacks and methods online that you can familiarize yourself with so you can improve the chances of identifying an attempt when you are the target.

Other than educating and training yourself, there are a number of tips that can help you avoid falling victim to a phishing attack:

  1. Crosscheck URLs and email addresses for spelling mistakes
  2. Watch out for spoof website pages that are designed to imitate popular websites you regularly visit
  3. Email hijacking is a real threat. Even if the email address checks out, if the message or request is suspicious, contact the sender through a separate trusted channel, such as a known phone number, to verify. Do not use contact details supplied in the suspicious message.
  4. Control how much you share online, attackers may use information you share online like your date of birth, address, mobile phone number etc. against you. 

As an organisation you can protect employees by

  1. Conducting penetration tests or vulnerability assessments to identify and fix vulnerabilities in your systems that can be used against an employee and the organization in a phishing attack. 
  2. Monitor web traffic on all devices 
  3. Screen communications for suspect links 
  4. Security awareness and training for all employees

The above methods are just a few ways to protect yourself against phishing attacks, phishing attacks are constantly evolving as attackers get smarter and more sophisticated in their trickery. It is vital that you stay informed on the latest trends in the cybersecurity landscape

StickmanCyber's team is equipped to help your employees recognise such attempts, and prevent social engineering attacks.