Skip to content
Cyber SecurityAdvanced

What Is Phishing and How Does It Work? Types of Phishing Attacks and How to Identify a Phishing Email

Phishing is a social-engineering cyberattack in which an attacker impersonates a trusted person, company, website, government agency, bank, cloud provider, c...

BI
Bison Technical Team Enterprise IT specialists
Updated 24 Aug 2026 16 min read 0 total views

Phishing is a social-engineering cyberattack in which an attacker impersonates a trusted person, company, website, government agency, bank, cloud provider, colleague, vendor, or other legitimate entity to trick a victim into performing an action that benefits the attacker.

Instead of attacking a computer system directly, phishing frequently attacks the human decision-making process.

Advertisement

The attacker may try to persuade the victim to:

  • Enter a username and password into a fake website.
  • Reveal banking or credit/debit card information.
  • Provide an OTP or other authentication information.
  • Approve an unexpected MFA notification.
  • Download a malicious attachment.
  • Install malware or remote-access software.
  • Scan a malicious QR code.
  • Transfer money to a fraudulent bank account.
  • Change a vendor's payment details.
  • Reveal confidential business information.
  • Grant a malicious application access to a Microsoft 365, Google, or other cloud account.

This makes phishing one of the most important threats for both individual users and organizations.


1. How Does a Phishing Attack Work?

Although phishing campaigns vary considerably, a typical attack follows several stages.

Stage 1: Target Selection

An attacker first decides whom to target.

A campaign may be sent indiscriminately to thousands or millions of email addresses, or the attacker may carefully research a specific employee or organization.

Attackers can gather information from sources such as:

  • Company websites
  • Social-media profiles
  • Public directories
  • Previously breached databases
  • Job portals
  • Corporate announcements
  • Professional networking websites
  • Compromised email accounts

The more information attackers collect, the more convincing a targeted phishing message can become.


Stage 2: Creating a Believable Pretext

The attacker creates a story designed to make the recipient act.

Common phishing themes include:

"Your Microsoft 365 password expires today."

"Your Google account has been suspended."

"You have an outstanding invoice."

"Your bank account requires immediate verification."

"A document has been shared with you."

"Your mailbox storage is full."

"Unusual activity was detected on your account."

"Please review the attached purchase order."

"Your payment has failed."

The objective is usually to create urgency, fear, curiosity, authority, or financial motivation.


2. Delivery of the Phishing Message

Email remains one of the most common delivery mechanisms, but phishing is not limited to email.

Attackers may use:

  • Email
  • SMS
  • WhatsApp or other messaging services
  • Social-media messages
  • Phone calls
  • QR codes
  • Fake advertisements
  • Search-engine results
  • Fake websites
  • Collaboration platforms
  • Cloud file-sharing invitations

Therefore, users should not assume that phishing always arrives as an email.


3. The Victim Is Directed to Take an Action

The message normally contains something the attacker wants the victim to interact with.

Examples include:

  • Sign In
  • Verify Account
  • View Document
  • Download Invoice
  • Reset Password
  • Review Activity
  • Confirm Payment
  • Scan QR Code

The button may visually appear legitimate while actually pointing to an attacker-controlled website.

For example, a message could say:

Microsoft 365 – Your session has expired. Sign in again.

The displayed button might look genuine, but clicking it could open a fraudulent Microsoft login page.


4. Fake Login Page Captures Credentials

Credential phishing is particularly common.

The attacker creates a website that resembles a genuine service such as:

  • Microsoft 365
  • Outlook
  • Gmail
  • Google Workspace
  • Dropbox
  • OneDrive
  • Banking portal
  • Income-tax portal
  • Social-media service

The victim enters:

Email address: user@company.com
Password: ********

Instead of authenticating the user, the fake page sends those credentials to the attacker.

The attacker can then attempt to access the genuine account.


5. What Happens After Credentials Are Stolen?

A compromised account may allow attackers to:

  • Read confidential email.
  • Download files.
  • Steal customer information.
  • Search previous invoices.
  • Reset passwords for other services.
  • Impersonate the account owner.
  • Send additional phishing messages.
  • Change email forwarding rules.
  • Create malicious inbox rules.
  • Attempt financial fraud.
  • Access connected cloud services.

A compromised corporate mailbox can be particularly dangerous because messages sent from a genuine account may appear trustworthy to colleagues, customers, and suppliers.


Different Types of Phishing Attacks

1. Email Phishing

This is the traditional phishing technique.

Attackers distribute fraudulent emails pretending to represent trusted organizations.

Typical subjects include:

Password Expiration Warning

Microsoft Account Security Alert

Invoice Attached

Payment Confirmation Required

Google Account Verification

These campaigns may be distributed to large numbers of recipients.


2. Spear Phishing

Spear phishing is a targeted phishing attack.

Instead of sending the same message to thousands of people, the attacker researches a particular person or organization.

For example:

Hello Accounts Team,
Please review the attached revised invoice for yesterday's purchase.

If the attacker knows the company, department, supplier, or employee name, the message becomes much more convincing.


3. Whaling

Whaling is targeted phishing aimed at senior executives or other high-value individuals.

Possible targets include:

  • CEO
  • CFO
  • Directors
  • Partners
  • Senior managers
  • Finance heads
  • Business owners

The attacker may impersonate a lawyer, bank, government agency, vendor, or another executive.


4. Business Email Compromise (BEC)

Business Email Compromise is a serious form of email-enabled fraud.

Attackers may compromise or impersonate:

  • CEO
  • Director
  • Customer
  • Vendor
  • Accountant
  • Finance manager

A typical request might say:

Please transfer ₹8,50,000 to the attached account today. The supplier has changed its banking details.

Because BEC attacks may contain no malware or obviously malicious attachment, traditional antivirus alone may not detect them.

Organizations should independently verify unusual payment instructions and bank-account changes.


5. Clone Phishing

In clone phishing, attackers copy a genuine email previously received by the victim and create a modified version.

They may replace:

  • Legitimate attachment → malicious attachment
  • Genuine link → phishing link

Because the message resembles an authentic previous communication, it can be difficult to detect.


6. Smishing – SMS Phishing

Smishing uses SMS or mobile messages.

Examples:

Your bank KYC has expired. Update immediately.

Your package could not be delivered. Pay ₹25 to reschedule.

The included link directs the victim to a malicious website.


7. Vishing – Voice Phishing

Vishing uses telephone or voice communication.

The attacker may pretend to be from:

  • Bank
  • Technical support
  • Police
  • Government department
  • Tax department
  • Telecom company
  • Credit-card department

Attackers may attempt to obtain passwords, OTPs, card details, or convince the victim to install remote-access software.


8. QR Code Phishing or Quishing

QR-code phishing has become an important attack technique.

A message may contain a QR code saying:

Scan to verify your Microsoft 365 account.

The QR code can lead to a credential-stealing website.

One advantage for attackers is that the URL is not immediately visible to the user, and the interaction often moves from a protected corporate computer to a mobile phone.

Treat unexpected authentication QR codes with caution.


9. Credential Phishing

Credential phishing specifically attempts to steal:

  • Username
  • Password
  • PIN
  • Security information
  • Authentication details

Fake Microsoft 365 and Google sign-in pages are common examples.


10. OAuth or Consent Phishing

Not every phishing attack needs to steal your password.

An attacker may persuade you to authorize a malicious cloud application.

The application may request permissions such as:

  • Read email
  • Read contacts
  • Access files
  • Access profile information

If permission is granted, the malicious application may retain access until the authorization is revoked.

This is why users should carefully inspect application permission requests.


11. MFA Phishing

Multi-factor authentication significantly improves security, but attackers increasingly attempt to bypass or abuse it.

Techniques can include:

  • Fake MFA pages
  • Stolen session tokens
  • Adversary-in-the-middle phishing
  • MFA push fatigue
  • Social engineering for OTPs

Never approve an MFA request that you did not initiate.


12. Invoice Phishing

Invoice phishing is especially dangerous for businesses.

Attackers send fake:

  • Invoices
  • Purchase orders
  • Payment reminders
  • Bank-account changes
  • Statements

Accounts departments should verify unexpected banking changes through a separate trusted communication channel.


13. Attachment-Based Phishing

Attackers may send malicious or deceptive attachments including:

  • ZIP archives
  • Office documents
  • HTML files
  • PDFs
  • Executable files
  • Script files
  • Disk-image files

An attachment may directly deliver malware or simply contain a link to a phishing website.


14. Social-Media Phishing

Attackers create fake accounts or compromise genuine ones.

Messages may claim:

Your account will be disabled.

Copyright violation detected.

Verify your account immediately.

The provided link then steals credentials.


15. Search-Engine Phishing

Attackers may create fraudulent websites designed to appear in search results or use malicious advertising.

Users searching for:

  • Bank login
  • Software download
  • Technical support
  • Cloud login
  • Customer-care number

may accidentally visit the fraudulent site.

For sensitive services, using a known bookmark or manually verified official address can reduce risk.


How Can I Identify a Phishing Email?

No single indicator proves that an email is phishing. Instead, examine multiple signals.

1. Carefully Check the Sender's Email Address

Do not trust only the displayed sender name.

An email might display:

Microsoft Security

but originate from an unrelated domain.

Similarly, an attacker may impersonate:

Accounts Department

while using an external email address.

Always inspect the complete sender address when a message requests a sensitive action.


2. Watch for Look-Alike Domains

Attackers register domains designed to resemble legitimate domains.

For example, visually similar letters, additional words, hyphens, or spelling variations may be used.

The safest approach is not simply asking:

"Does this URL look familiar?"

Instead ask:

"Is this the exact domain I expect?"


3. Check Links Before Clicking

On a desktop computer, hover your mouse pointer over a link without clicking it.

Examine the actual destination.

Be cautious of:

  • Misspelled domains
  • Unrelated domains
  • Strange subdomains
  • URL-shortening services
  • Unexpected redirects

Important

A URL beginning with HTTPS is not automatically trustworthy.

HTTPS primarily indicates that the connection to that website is encrypted. Attackers can also obtain HTTPS certificates for malicious websites.


4. Look for Artificial Urgency

Phishing frequently attempts to prevent careful thinking.

Examples include:

Your account will be closed in 30 minutes.

Payment required immediately.

Your mailbox will be deleted today.

Final security warning.

Urgency alone does not prove fraud, but unexpected urgency combined with requests for passwords, payments, or account changes is a significant warning sign.


5. Be Suspicious of Unexpected Attachments

Ask yourself:

  • Was I expecting this file?
  • Do I know the sender?
  • Does the attachment match the conversation?
  • Why is this person sending me this document?
  • Can I verify it independently?

Do not open suspicious files merely because antivirus software is installed.


6. Look for Unusual Requests

Be particularly cautious when an email unexpectedly asks you to:

  • Reset your password.
  • Verify your account.
  • Enter banking information.
  • Provide an OTP.
  • Approve an MFA request.
  • Change supplier bank details.
  • Transfer money.
  • Purchase gift cards.
  • Install software.
  • Enable macros.
  • Scan a QR code.
  • Grant cloud application permissions.

Verify such requests independently.


7. Grammar and Spelling Can Help — But Are Not Reliable

Historically, phishing messages frequently contained obvious grammatical mistakes.

That is no longer a reliable detection method.

Modern attackers can create highly professional messages using templates, translation systems, generative AI, or text copied from legitimate organizations.

A perfectly written email can still be phishing.


Advanced Technical Checks for Phishing Emails

Technical users and administrators can examine the message headers.

Important authentication technologies include:

SPF – Sender Policy Framework

SPF helps determine whether the sending mail server is authorized to send email for a domain.

DKIM – DomainKeys Identified Mail

DKIM uses cryptographic signatures to help verify that a message was authorized by the signing domain and was not improperly modified after signing.

DMARC – Domain-based Message Authentication, Reporting and Conformance

DMARC builds on SPF and DKIM and allows domain owners to specify how receiving systems should handle messages that fail authentication and alignment checks.

However, a message passing SPF, DKIM, or DMARC should not automatically be considered safe. Attackers can send phishing from compromised legitimate accounts or domains they legitimately control.


How to Protect Yourself Against Phishing

A layered security strategy is more effective than relying on a single product.

Important controls include:

  1. Enable multi-factor authentication.
  2. Prefer phishing-resistant authentication methods where supported.
  3. Use modern spam and phishing filtering.
  4. Keep operating systems and browsers updated.
  5. Use endpoint security.
  6. Train employees to recognize phishing attempts.
  7. Implement SPF, DKIM, and DMARC for business domains.
  8. Independently verify financial requests.
  9. Restrict unnecessary application permissions.
  10. Use password managers.
  11. Report suspicious messages to the IT/security team.
  12. Maintain reliable backups for important business information.

Why Password Managers Can Help Detect Phishing

Password managers provide an additional practical benefit.

Suppose your password manager normally recognizes:

https://accounts.example.com

but you accidentally visit a look-alike domain.

The password manager may not automatically offer the stored credentials because the domain does not match.

This should be treated as a warning rather than manually copying the password into the suspicious website.


What Should You Do If You Receive a Phishing Email?

If you suspect phishing:

Do not click links.

Do not open attachments.

Do not reply to the sender.

Do not call telephone numbers provided in the suspicious message.

Instead:

  1. Verify the request through an independently obtained contact method.
  2. Report the message using your organization's phishing-reporting mechanism.
  3. Notify IT/security if it is a corporate account.
  4. Delete or quarantine the message after reporting it.

What If You Already Clicked the Phishing Link?

Clicking a link does not necessarily mean that your account has been compromised.

However, you should stop interacting with the website and notify your IT/security administrator if the device belongs to an organization.

If you downloaded or executed a file, additional endpoint investigation may be necessary.


What If You Entered Your Password on a Phishing Website?

This should be treated as a potential account compromise.

Take action immediately:

  1. Open the genuine website manually rather than using the suspicious link.
  2. Change the compromised password.
  3. Change the same password anywhere else it was reused.
  4. Enable or review MFA.
  5. Sign out/revoke active sessions where supported.
  6. Review recent login activity.
  7. Check account recovery information.
  8. Review mailbox forwarding and inbox rules for email accounts.
  9. Review authorized applications and OAuth permissions.
  10. Notify your IT/security administrator for business accounts.

Changing the password is important, but organizations should also investigate whether the attacker obtained an authenticated session or modified account settings.


What If You Approved an Unexpected MFA Request?

Immediately:

  • Change the account password.
  • Review active sessions.
  • Revoke suspicious sessions where supported.
  • Check recent login history.
  • Review MFA methods registered to the account.
  • Remove unfamiliar authentication methods.
  • Notify your IT/security team.

Never approve a login request simply to stop repeated MFA notifications.


Special Warning for Accounts and Finance Departments

Finance teams are frequent phishing and BEC targets because they can authorize payments.

Employees should independently verify:

  • New bank accounts
  • Changed bank details
  • Urgent payment requests
  • Unusual refunds
  • Large transfers
  • Confidential payroll requests

For example, if a supplier emails:

"Our bank account has changed. Please use this new account for all future payments."

Do not rely solely on the email.

Contact the supplier using a previously known and trusted telephone number or other independent channel before changing payment details.


Phishing vs Spam

Spam and phishing are not necessarily the same.

Spam is generally unsolicited bulk communication and may primarily involve advertising.

Phishing is intended to deceive a victim into revealing information, granting access, downloading malicious content, or taking another harmful action.

A phishing email may be spam, but not every spam email is phishing.


Phishing vs Malware

Phishing is primarily an attack technique based on deception.

Malware is malicious software.

They are frequently used together.

For example:

Phishing Email → Malicious Attachment → Malware Infection

or

Phishing Email → Fake Login Page → Credential Theft

Therefore, phishing does not necessarily contain malware.


Phishing Attack Example

Consider the following scenario:

An employee receives:

Subject: Microsoft 365 Password Expiration Notice

The email states:

Your Microsoft 365 password expires today. Click below to retain access.

The employee clicks Keep My Password.

A website opens that closely resembles Microsoft's login page.

The employee enters:

Email → Password → MFA information

The fraudulent site captures the information.

The attacker may then attempt to access the genuine Microsoft 365 account and use the compromised mailbox to send more convincing phishing messages.

This illustrates why visual appearance alone cannot establish that a login page is genuine.


Phishing Prevention Checklist for Businesses

Businesses should consider implementing:

  • Email filtering
  • Endpoint protection
  • MFA
  • Phishing-resistant authentication where practical
  • SPF
  • DKIM
  • DMARC
  • User security-awareness training
  • Phishing simulations
  • External-sender warnings where appropriate
  • URL protection
  • Attachment scanning
  • Cloud application monitoring
  • Conditional access policies
  • Login-risk monitoring
  • Restricted administrator privileges
  • Incident-response procedures
  • Reliable backups

Technical controls and employee awareness should work together.


Frequently Asked Questions (FAQ)

1. What is phishing?

Phishing is a social-engineering attack in which an attacker impersonates a trusted entity to trick a victim into revealing information or performing a harmful action.

2. How does phishing work?

Attackers typically send deceptive messages containing malicious links, attachments, QR codes, or requests. The victim is persuaded to provide credentials, make a payment, install software, or grant access.

3. What is the most common form of phishing?

Email phishing remains one of the most widely encountered forms, although SMS, voice, QR-code, social-media, and cloud-based phishing are also important threats.

4. What is spear phishing?

Spear phishing is a targeted attack customized for a specific individual, department, or organization.

5. What is whaling?

Whaling is targeted phishing focused on executives and other high-value individuals.

6. What is smishing?

Smishing is phishing delivered through SMS or similar mobile messaging.

7. What is vishing?

Vishing is phishing performed through telephone or voice communication.

8. What is quishing?

Quishing is phishing that uses QR codes to direct victims to malicious websites or other fraudulent destinations.

9. Can phishing emails look completely genuine?

Yes. Modern phishing messages can closely imitate legitimate corporate emails, branding, language, signatures, and login pages.

10. Does HTTPS mean a website is safe?

No. HTTPS means that communication with the website is encrypted. A malicious website can also use HTTPS.

11. Can an antivirus detect every phishing attack?

No. Endpoint security can detect many malicious files and websites, but phishing may rely entirely on social engineering or legitimate-looking websites.

12. Can MFA stop phishing?

MFA significantly improves account security, but some sophisticated phishing techniques attempt to steal session tokens, capture authentication information, or trick users into approving authentication requests.

13. Should I provide an OTP to a bank employee?

Never provide authentication information merely because an unsolicited caller or message requests it. Follow the bank's official security guidance and independently verify suspicious requests.

14. What should I do if I clicked a phishing link?

Stop interacting with the site. If you entered no information, close it and report the message. For a corporate device, notify IT/security, especially if anything was downloaded or executed.

15. What should I do if I entered my password?

Change it immediately through the genuine service, revoke suspicious sessions, review MFA and account settings, and notify your IT/security administrator if it is a business account.

16. Why are finance departments targeted?

Finance personnel can authorize payments, access financial information, and change supplier banking details, making them attractive targets for BEC and invoice fraud.

17. Can phishing come from a genuine email account?

Yes. If a legitimate mailbox is compromised, attackers can use the genuine account to send phishing messages.

18. How can organizations reduce phishing attacks?

Organizations should combine email filtering, MFA, phishing-resistant authentication, SPF/DKIM/DMARC, endpoint security, security-awareness training, monitoring, and incident-response procedures.

19. Should I trust an email because SPF, DKIM, and DMARC pass?

Not automatically. These controls are important for email authentication, but a legitimate account or attacker-controlled authenticated domain can still send malicious messages.

20. How can I verify a suspicious email?

Do not use contact information contained in the suspicious message. Visit the organization's official service independently or contact the person/company through previously verified contact information.


Conclusion

Phishing has evolved from poorly written mass emails into sophisticated social-engineering campaigns involving fake login portals, compromised accounts, QR codes, cloud applications, MFA manipulation, invoice fraud, and highly targeted business email compromise.

The most effective defense is therefore not simply to look for spelling mistakes.

Before clicking, downloading, authenticating, approving MFA, changing bank information, or transferring money, ask:

Was I expecting this request?

Is the sender's actual address correct?

Is the destination domain exactly correct?

Why is this request urgent?

Can I verify it through another trusted channel?

For organizations, the strongest approach combines technical controls, strong authentication, email security, employee awareness, independent financial verification, monitoring, and a well-defined incident-response process.

A few seconds spent verifying a suspicious request can prevent credential theft, account takeover, malware infection, data loss, and substantial financial fraud.

#Tags

#Phishing #PhishingAttack #PhishingEmail #PhishingScam #CyberSecurity #CyberSecurityAwareness #EmailSecurity #OnlineSecurity #InternetSecurity #SocialEngineering #SpearPhishing #Whaling #Smishing #Vishing #Quishing #QRPhishing #ClonePhishing #CredentialPhishing #BusinessEmailCompromise #BEC #CEOScam #EmailFraud #CyberFraud #EmailSpoofing #DomainSpoofing #FakeEmail #FakeWebsite #MaliciousLink #MaliciousAttachment #CredentialTheft #PasswordSecurity #AccountSecurity #AccountTakeover #IdentityTheft #MFA #MultiFactorAuthentication #SPF #DKIM #DMARC #Microsoft365Security #GoogleWorkspaceSecurity #GmailSecurity #OutlookSecurity #PhishingProtection #PhishingPrevention #SecurityAwareness #CyberAttack #InformationSecurity #DataSecurity #CyberSafety

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “What Is Phishing and How Does It Work? Types of Phishing Attacks and How to Identify a Phishing Email”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.