Background: phishing attacks
Phishing is a form of social engineering and a scam in which attackers deceive people into revealing sensitive information or installing malware. Phishing can be used for credential theft, session hijacking, malware delivery, or command execution. Some attacks transparently relay authentication to a legitimate site, allowing the attacker to capture credentials and authenticated sessions. Phishing is a common initial-access method, and Large language models can automate personalized phishing at low cost.
Common forms include general email phishing, targeted spear phishing and whaling, voice phishing (vishing), and SMS phishing (smishing). Other forms use QR codes or relay authentication through an adversary-in-the-middle.
Measures to prevent or reduce the impact of phishing attacks include legislation, user education, public awareness, and technical security measures.
1 source for this section
Email phishing
Phishing attacks, often delivered via email, attempt to trick individuals into giving away sensitive information or login credentials. General phishing is sent broadly, whereas spear phishing targets a particular person or group. The goal of the attacker can vary, with common targets including financial institutions, email and cloud productivity providers, and streaming services. The stolen information or access may be used to steal money, install malware, or spear phish others within the target organization. Compromised streaming service accounts may also be sold on darknet markets.
Such attacks can involve messages that appear to be from a trusted source, such as a bank or government agency. The messages may redirect to a counterfeit login page that collects credentials.
6 sources for this section
- 1Phishing — Wikipedia, revision 1376047697
- 2Jansson, K.; von Solms, R. (November 9, 2011). "Phishing for phishing awareness". Behaviour & Information Technology. 32 (6): 584–593. doi:10.1080/0144929X.2011.632650. ISSN 0144-929X. S2CID 5472217.
- 3Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9.
- 4Furnell, Steven; Millet, Kieran; Papadaki, Maria (July 2019). "Fifteen years of phishing: can technology save us?". Computer Fraud & Security. 2019 (7): 11–16. doi:10.1016/S1361-3723(19)30074-0. S2CID 199578115.
- 5"Spoofing and Phishing". Federal Bureau of Investigation. Retrieved May 30, 2026.
- 6Waddell, Kaveh (February 11, 2016). "The Black Market for Netflix Accounts". The Atlantic. Retrieved March 21, 2021.
Spear phishing
Spear phishing attacks can be more effective than general phishing attempts because they are tailored to specific individuals and use personal or organizational information to increase credibility. Whaling is a form of targeted phishing directed at senior decision-makers with access to valuable information. Automation can make personalized messages inexpensive enough to use at scale.
A field experiment sent simulated phishing emails to 100 younger and 58 older adults over 21 days. In this sample, 43% of participants clicked at least one simulated phishing link, and older women recorded the highest click rate among the four age-and-gender groups studied. Susceptibility declined among younger participants during the study but remained stable among older participants.
The Russian government-run Threat Group-4127 (Fancy Bear; GRU Unit 26165) used spear phishing against targets associated with Hillary Clinton's 2016 presidential campaign and the Democratic National Committee. SecureWorks linked the group to a separate 2015 campaign that targeted more than 1,800 Google accounts and used the spoofed domain accoounts-google.com.
7 sources for this section
- 1Phishing — Wikipedia, revision 1376047697
- 7Alsharnouby, Mohamed; Alaca, Furkan; Chiasson, Sonia (2015). "Why phishing still works: User strategies for combating phishing attacks". International Journal of Human-Computer Studies. 82: 69–82. doi:10.1016/j.ijhcs.2015.05.005. Retrieved May 6, 2026.
- 3Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9.
- 8Czybik, Stefan; Kouam, Anne Josiane; Heubl, Peter; Nold, Jan Magnus; Rieck, Konrad (2026). "A Large-Scale Study of Personalized Phishing using Large Language Models". 35th USENIX Security Symposium. USENIX Association. pp. 1687–1706. ISBN 978-1-939133-58-8. Retrieved September 20, 2026.
Voice phishing (vishing)
Vishing, or voice phishing, uses telephone or Voice over IP calls to deliver the lure. Attackers may make automated calls, use text-to-speech, and claim that fraudulent activity has occurred on the recipient's account. They may spoof the caller number so that it appears to come from a bank or other institution. The victim is then prompted to enter sensitive information or connected to a person who uses social-engineering tactics to obtain it. A 2008 study found that voice phishing could exploit greater trust in voice telephony than in email.
4 sources for this section
- 1Phishing — Wikipedia, revision 1376047697
- 3Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9.
- 12Griffin, Slade E.; Rackley, Casey C. (September 26, 2008). "Vishing". Proceedings of the 5th Annual Conference on Information Security Curriculum Development. InfoSecCD '08. New York: Association for Computing Machinery. pp. 33–35. doi:10.1145/1456625.1456635. ISBN 978-1-60558-333-4.
- 13Wang, Xinyuan; Zhang, Ruishan; Yang, Xiaohui; Jiang, Xuxian; Wijesekera, Duminda (September 22, 2008). "Voice pharming attack and the trust of VoIP". Proceedings of the 4th International Conference on Security and Privacy in Communication Networks. SecureComm '08. ACM. pp. 1–11. doi:10.1145/1460877.1460908. ISBN 978-1-60558-241-2.
SMS phishing (smishing)
Smishing is phishing delivered through SMS or MMS, often through an impersonating message, a malicious link, or a malware lure. The victim may be asked to click a link, call a phone number, or provide private information such as login credentials. The limited display of URLs on mobile devices can make illegitimate links harder to identify.
4 sources for this section
- 1Phishing — Wikipedia, revision 1376047697
- 3Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9.
- 14"Scam Glossary". Federal Communications Commission. Retrieved April 29, 2026.
- 15Mishra, Sandhya; Soni, Devpriya (August 2019). "SMS Phishing and Mitigation Approaches". 2019 Twelfth International Conference on Contemporary Computing (IC3). IEEE. pp. 1–5. doi:10.1109/IC3.2019.8844920. ISBN 978-1-7281-3591-5. S2CID 202700726.
The source notesEvidence & further reading15 sources
- Phishing — Wikipedia, revision 1376047697 Wikipedia contributors · Reference source · accessed 2026-09-22
- Jansson, K.; von Solms, R. (November 9, 2011). "Phishing for phishing awareness". Behaviour & Information Technology. 32 (6): 584–593. doi:10.1080/0144929X.2011.632650. ISSN 0144-929X. S2CID 5472217. tandfonline.com · Reference source · link imported 2026-09-22
- Thomopoulos, George A.; Lyras, Dimitrios P.; Fidas, Christos A. (2024). "A systematic review and research challenges on phishing cyberattacks from an electroencephalography and gaze-based perspective". Personal and Ubiquitous Computing. 28: 449–470. doi:10.1007/s00779-024-01794-9. doi.org · Reference source · link imported 2026-09-22
- Furnell, Steven; Millet, Kieran; Papadaki, Maria (July 2019). "Fifteen years of phishing: can technology save us?". Computer Fraud & Security. 2019 (7): 11–16. doi:10.1016/S1361-3723(19)30074-0. S2CID 199578115. researchgate.net · Reference source · link imported 2026-09-22
- "Spoofing and Phishing". Federal Bureau of Investigation. Retrieved May 30, 2026. fbi.gov · Reference source · link imported 2026-09-22
- Waddell, Kaveh (February 11, 2016). "The Black Market for Netflix Accounts". The Atlantic. Retrieved March 21, 2021. theatlantic.com · Reference source · link imported 2026-09-22
- Alsharnouby, Mohamed; Alaca, Furkan; Chiasson, Sonia (2015). "Why phishing still works: User strategies for combating phishing attacks". International Journal of Human-Computer Studies. 82: 69–82. doi:10.1016/j.ijhcs.2015.05.005. Retrieved May 6, 2026.