Skip to content
atlas
← Back to the entry

What it is

Phishing is an attempt to trick someone into doing something that benefits an attacker - typing a password into a fake page, opening a harmful attachment, approving a payment or handing over information - by sending a message that pretends to come from someone trustworthy. The name is a play on “fishing”: bait is cast widely, and the sender only needs a few people to bite.

Phishing is a form of social engineering: it attacks human judgement rather than technical weaknesses. That is exactly why it is so persistent. Firewalls and patches do not help much when the legitimate user opens the door from the inside. Phishing is a frequent first step in larger attacks, including ransomware and data breaches.

How it works

Variants

The basic trick is always the same, but it comes in many forms:

Variant What characterises it
Bulk phishing The same generic message sent to thousands: “Your parcel is delayed”, “Your mailbox is full”
Spear phishing Targeted at a specific person or group, using details from LinkedIn, the company website or earlier leaks to look credible
Whaling Spear phishing aimed at senior executives, whose access and authority are especially valuable
Business Email Compromise (BEC) / CEO fraud The attacker poses as - or has taken over the mailbox of - a manager or supplier and asks for an urgent transfer or a change of bank details. Often no link or attachment at all
Smishing Phishing via SMS or messaging apps
Vishing Phishing by phone call - for example a fake “IT support” or “bank” asking the victim to read out a code or approve a login, including with MitID
Quishing A QR code in an email or on a poster leading to a fake page; it moves the victim to a phone, often outside the company’s protections
Clone phishing A copy of a genuine email the victim has received before, with the link or attachment swapped for a malicious one

Some attacks also use an adversary-in-the-middle technique: the fake login page relays everything to the real service in real time and captures not only the password but also the one-time code and the resulting session. This is why ordinary MFA reduces, but does not eliminate, the risk.

The psychology

Phishing messages exploit a handful of predictable levers:

Red flags

No single sign is conclusive, but these should make anyone pause:

Well-crafted spear phishing may have none of the classic spelling mistakes. The most reliable defence is therefore process: verify unusual requests through a different, known channel.

What it means for an organisation and a coordinator

Phishing sits right at the intersection of technology, people and process - the core territory of a coordinator or awareness role.

Common misunderstandings

Atlas is in beta.