What Is Phishing? (Plain-English Explainer)
%201.png)
Key Takeaways
Imagine getting an email from your bank saying your account has been locked, and all you need to do is click a link and verify your details. The email looks real. The logo is right. The language sounds urgent. So you click.
That's phishing. And it's the #1 cybercrime reported to the FBI every single year.
In 2024, phishing and spoofing topped the FBI's Internet Crime Complaint Center (IC3) list as the most frequently reported cybercrime in the United States. And it's getting harder to spot: a 2025 study found that AI-generated phishing emails achieve a 54% click-through rate, compared to just 12% for traditionally crafted ones.
This guide breaks it all down, what phishing is, how it works, the different types you need to know, and exactly how to protect yourself. No jargon, no fluff.
What is phishing? (the plain-English definition)
Phishing (pronounced "fishing") is a type of cyberattack where criminals impersonate a trusted person or organization to trick you into handing over sensitive information (like passwords, credit card numbers, or Social Security numbers) or into clicking a link that installs harmful software on your device.
The name is a deliberate play on "fishing." Attackers cast a wide net, often sending thousands or millions of messages at once, baiting people to "bite."
The target? Your information, your money, or access to your accounts and systems.
In plain English: Phishing is when someone pretends to be someone you trust (your bank, your boss, Amazon, the IRS) to trick you into giving something up.
A brief history: where did phishing come from?
Phishing isn't new. It dates back to the mid-1990s, when hackers targeted AOL users by posing as company employees and asking for account passwords. The term itself was coined around 1996 by hackers who used the "ph" spelling as a nod to early hacker culture ("phone phreaking").
Three decades later, the tactics are far more sophisticated, but the core trick remains the same: pretend to be someone you're not, and exploit human trust.
How does phishing work?
Understanding the mechanics helps you spot it faster.
Step 1: The attacker picks a target. They decide who to go after, it could be millions of random email addresses (bulk phishing) or a single high-value person like a company executive (spear phishing).
Step 2: They build the bait. The attacker crafts a convincing message meant to look like it's from a legitimate source. They may clone a real company's logo, email style, and even the domain name (e.g., support@paypa1.com instead of paypal.com).
Step 3: They create urgency or fear. Phishing messages almost always pressure you to act right now. "Your account will be suspended." "Unusual activity detected." "You've won a prize, claim it within 24 hours." The goal is to get you to act before you think.
Step 4: You take the bait. You click the link, download the attachment, or reply with your information.
Step 5: The damage is done. Your credentials are stolen, malware is installed, or your bank account is drained, often before you realize anything went wrong.
Types of phishing attacks
Phishing isn't one-size-fits-all. Here are the most common varieties.
Email phishing (the classic). Mass emails sent to thousands of people at once, impersonating banks, retailers, government agencies, or tech companies. The most common type. Example: a fake "Your Amazon order has been flagged" email with a link to a convincing-but-fake login page.
Spear phishing (targeted). Unlike bulk phishing, spear phishing targets a specific individual, often using personal information found on LinkedIn or social media to make the message feel authentic. Example: an email that appears to be from your company's CFO, asking you to wire funds to a vendor account.
Whaling (targeting executives). A form of spear phishing aimed at C-suite executives, board members, or senior managers. The attacks are more elaborate and the paydays are bigger.
Smishing (SMS phishing). Phishing via text message. Example: "USPS: Your package couldn't be delivered. Update your address here: [link]"
Vishing (voice phishing). Phone calls from fake "representatives" of banks, the IRS, or tech support, meant to panic you into revealing information or making a payment.
Clone phishing. Attackers take a legitimate email you've already received and create a near-identical copy, but replace the links or attachments with malicious ones.
Pharming. Rather than luring you to click a bad link, pharming redirects you from a legitimate website to a fake one, even if you typed the real URL correctly.
Angler phishing (social media). Attackers create fake customer service accounts and respond to people complaining about a brand, redirecting them to phishing sites.
Real-world phishing examples
The Google and Facebook wire fraud ($100 million). Between 2013 and 2015, a Lithuanian hacker named Evaldas Rimasauskas defrauded both Google and Facebook out of a combined $100 million by posing as Quanta Computer, a legitimate vendor both companies used. He sent fake invoices via email, and both companies paid. It remains one of the most well-known phishing-related frauds in history.
The 2020 Twitter Bitcoin scam. In July 2020, attackers used spear phishing to compromise Twitter employee credentials, then used their internal access to hijack high-profile accounts (including Barack Obama, Elon Musk, and Apple) to post a Bitcoin scam that netted over $120,000 in cryptocurrency within hours.
Business email compromise, every day. BEC attacks, a form of spear phishing targeting businesses, caused average losses of $150,000 per incident in 2024, according to Hoxhunt's Phishing Trends Report, with 64% of businesses reporting they faced at least one BEC attack that year.
8 warning signs of a phishing message
Whether it's an email, text, or phone call, watch for these red flags:
- Urgency and panic language, "Act now or your account will be closed!"
- Generic greetings, "Dear Customer" instead of your actual name
- Suspicious sender address, The domain looks slightly off (e.g.,
@paypa1.com,@amazon-support.net) - Unexpected requests, Your bank will never ask for your full password via email
- Suspicious links, Hover over links before clicking; the URL shown may not match the destination
- Unexpected attachments, Especially
.zip,.exe, or Office files from unknown senders - Too-good-to-be-true offers, You didn't enter a contest. You didn't win a gift card.
- Poor spelling and grammar, While AI has improved this, many phishing messages still contain errors
Why is phishing so effective?
Phishing works because it exploits human psychology, not technical vulnerabilities. Attackers weaponize:
- Authority, Messages that appear to come from the IRS, your boss, or a law enforcement agency trigger compliance.
- Fear and urgency, Tight deadlines override careful thinking.
- Curiosity, "See who viewed your profile" or "You have a new voicemail" triggers an automatic response.
- Trust, Familiar branding and tone lower your guard.
- Scarcity, "Limited time offer" or "Only 1 spot left" triggers impulsive action.
In 2024, phishing click rates tripled compared to 2023, rising to 8.4 clicks per 1,000 users per month, even as security training increased (Netskope, reported by CSO Online, January 2025). The psychology clearly still works.
The AI factor: why phishing is getting harder to spot
Here's the uncomfortable truth: phishing is getting better, and AI is the reason.
Criminals are now using generative AI tools to:
- Write phishing emails in flawless, natural language (no more obvious grammar mistakes)
- Personalize messages at scale using scraped social media data
- Clone voices for vishing attacks using just a few seconds of audio
- Generate convincing deepfake videos for fraud
The numbers tell the story:
- Phishing attacks increased by 4,151% since the launch of ChatGPT (SlashNext, 2025)
- In 2024, 73.8% of phishing emails used some form of AI assistance (
KnowBe4, 2025) - Hoxhunt recorded a 14x surge in AI-generated phishing attacks by end of 2025
This means the old advice of "just look for bad spelling" is no longer enough.
How to protect yourself from phishing
For individuals
Use multi-factor authentication (MFA). Even if a phisher steals your password, MFA stops them from getting in. Enable it on every important account, email, banking, social media.
Think before you click. Hover over links to preview the actual URL. When in doubt, go directly to the website by typing the address yourself.
Verify independently. If an email or call asks you to take urgent financial action, hang up and call the organization directly using a number from their official website, not the one provided by the caller.
Use a password manager. Password managers can detect fake websites. If your manager doesn't autofill on a login page you're used to, something may be off.
Report phishing.
- Forward phishing emails to reportphishing@apwg.org
- Report to the FTC at reportfraud.ftc.gov
- Report to the FBI at ic3.gov
For businesses
Train employees regularly. Security awareness training, especially simulated phishing exercises, significantly reduces click rates over time.
Use email authentication protocols. Technologies like SPF, DKIM, and DMARC help prevent attackers from spoofing your domain.
Enforce least-privilege access. Limit what each employee can access. If credentials are compromised, the damage is contained.
Create clear reporting processes. Make it easy and blame-free for employees to report suspicious emails without fear of embarrassment.
For real-time protection across your browser and your phone, get a free security scan with Guardio today and stay protected from phishing attacks.
What to do if you've been phished
Acted too fast and think you fell for it? Don't panic, act quickly.
- Change your passwords immediately, especially on the affected account and any others that share that password
- Enable MFA if you haven't already
- Contact your bank if financial information was shared
- Scan your device for malware using reputable security software
- Report the incident to the FTC, IC3, or your company's IT/security team
- Check your accounts for unauthorized activity over the next few days
Conclusion
Phishing is the most common cybercrime in the world, and one of the most dangerous, not because it's technically sophisticated, but because it's psychologically sophisticated. It works by exploiting trust, urgency, and human instinct.
The good news: with the right awareness, phishing is also one of the most preventable threats. Slow down. Verify before you click. When something feels off, even a little, it probably is.
The best defense against phishing is a healthy habit of skepticism. Not paranoia, just a pause before you act.
Get started with a free scan and see where you're exposed before a phisher finds out first.
FAQs
What's the difference between phishing and spam?
Spam is unsolicited bulk email, usually advertising, but not necessarily malicious. Phishing is specifically meant to deceive you into taking an action that compromises your security, handing over a password, clicking a malicious link, or transferring money. All phishing is a form of spam, but not all spam is phishing.
Can phishing happen over text message?
Yes, phishing over text message is called smishing (SMS phishing). It's increasingly common because people tend to trust text messages more than emails. A typical smishing message impersonates a delivery service, bank, or government agency and asks you to click a link or call a number.
Is phishing illegal?
Yes. Phishing is a federal crime in the United States, prosecutable under the Computer Fraud and Abuse Act (CFAA), wire fraud statutes, and the Identity Theft Enforcement and Restitution Act. Convictions can carry prison sentences of up to 20 years depending on the charges and scale of the fraud.
Can phishing affect businesses, not just individuals?
Yes, businesses are frequently the primary target. Business Email Compromise (BEC), a form of spear phishing, caused average losses of $150,000 per incident in 2024, according to Hoxhunt's Phishing Trends Report. Any organization, large or small, is a potential target.
How do I know if an email is really from my bank?
Your bank will never ask for your full password, PIN, or Social Security number via email. When in doubt, don't click any link in the message. Instead, call the number on the back of your card or go directly to your bank's official website by typing the URL yourself.
What makes AI-generated phishing emails more dangerous?
AI-generated phishing emails are harder to detect because they're written in flawless, natural language with no obvious spelling errors or awkward phrasing. They can also be personalized at scale using scraped social media data. A 2025 study found AI-generated phishing emails achieve a 54% click-through rate, compared to just 12% for traditionally crafted ones.
What should I do immediately after clicking a phishing link?
Act fast, the first few minutes matter most.
- Close the tab immediately (don’t interact further).
- Do not enter any login details, even partial information helps scammers.
- Run a security check in your Guardio dashboard to confirm no malicious extensions or downloads were triggered.
- Change your password immediately if you entered credentials anywhere on the site.
If you did enter information, follow the full recovery steps in this guide on what to do after clicking a phishing link.
Phishing ScamsSCAM ALERT: 110 Million Netflix Subscribers Targeted





