What Is Phishing
Phishing is tricking someone into revealing credentials or running malware by pretending to be a trusted sender. It works because it targets people, not systems, and no firewall stops a user who willingly types their password into a convincing fake. The main defence is recognising the red flags, backed by technical controls.
How phishing works
An attacker sends a message that looks legitimate, a bank, a colleague, a service, and creates urgency. The victim clicks a link to a fake login page or opens a malicious attachment. The attacker harvests the credentials or gains a foothold. The whole attack bypasses technical defences by targeting the human.
The main types
| Type | How it differs |
|---|---|
| Email phishing | Mass, generic, low effort |
| Spear phishing | Targeted at one person with research |
| Whaling | Targeted at executives |
| Smishing | Via SMS |
| Vishing | Via voice call |
| Clone phishing | A copy of a real message with a swapped link |
Red flags to spot
- Urgency and threats: act now or lose access
- Sender address that is close but not exact
- Links that do not match the text when you hover
- Unexpected attachments
- Requests for credentials or payment
- Generic greetings on supposedly personal mail
A real example, dissected
A mail from your bank warns your account is locked and links to a login page. The address is bank-secure-verify.com, not the real domain. The page is a pixel perfect copy. You log in, the attacker captures it, and forwards you to the real site so nothing seems wrong. Every step is designed to bypass suspicion.
How organisations defend
- Email authentication: SPF, DKIM, DMARC
- Link and attachment sandboxing
- Multi factor authentication, so stolen passwords are not enough
- User training and simulated phishing
- A fast, blame free reporting process
On the analyst side, investigating reported phishing is core SOC work, covered in what a SOC analyst does.
Why it still works in 2026
Because it targets people. AI has made phishing messages cleaner and voice cloning has made vishing more convincing. The technical controls help, but recognition remains the front line.
Learn to test and defend
Understanding phishing from both sides makes you better on either. Structured training in the SOC analyst syllabus.
Enroll in SOC
Live instructor led training with hands on labs and a verifiable certificate. Or start free on Hacklido.
Enroll in SOC