Skip to main content

Phishing.

Phishing is the social-engineering attack that tricks a user into clicking a malicious link, opening a malicious file or revealing credentials. Variants: spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice), BEC (business email compromise). Training matters; phishing-resistant MFA matters more.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCybersecurity operationsAll entries

The Cyber Academy take

Phishing is the social-engineering attack that tricks a user into clicking a malicious link, opening a malicious file or revealing credentials. Variants: spear phishing (targeted), whaling (executives), smishing (SMS), vishing (voice), BEC (business email compromise). Training matters; phishing-resistant MFA matters more.

Why phishing remains the dominant entry point

Phishing endures because it attacks the person, not the perimeter. Every other control can be perfectly configured and the attacker still only needs one employee to click a link, open a file or type a password into a convincing fake. The message arrives through a trusted channel, usually email but increasingly SMS and voice, and borrows the look and tone of a brand, a colleague or an internal system the victim already expects to hear from.

Because the payload often lives behind a freshly registered domain or a legitimate-looking cloud login page, signature-based filters and reputation lists frequently arrive too late. The economics also favour the attacker: a single template can be sprayed to thousands of recipients at almost no cost, and a single success can yield credentials that unlock everything else.

What practitioners watch for is the shift from volume to precision. Mass phishing is a wide net, but the costly incidents usually start with a tailored message that has clearly done its homework on the target, the org chart and the moment.

The variants that matter in practice

Phishing is a family, not a single technique. The social-engineering logic stays constant while the channel and the target change.

  • Spear phishing: a targeted message crafted for a specific person or team, using real names, projects and context to lower suspicion.
  • Whaling: spear phishing aimed at executives and other high-value approvers, where one compromised account carries outsized authority.
  • Smishing: phishing delivered by SMS, often a fake delivery, bank or MFA-reset prompt that exploits the smaller screen and the habit of trusting texts.
  • Vishing: phishing by voice call, where an attacker pressures the victim in real time, increasingly aided by spoofed numbers and synthetic audio.
  • Business email compromise: a pretexting subtype that targets payment and data processes directly, usually with no malicious link or attachment at all.

What actually reduces the risk

Awareness training is necessary but not sufficient. People will always click some fraction of the time, so the goal is to remove the value of a click rather than to demand perfection from users. The decisive technical control is phishing-resistant multi-factor authentication, meaning factors bound to the legitimate domain, such as FIDO2 security keys or passkeys, which a fake login page cannot replay. Layered behind that sit the controls that catch what slips through.

  • Phishing-resistant MFA on every account that matters, so a harvested password alone is not enough to log in.
  • Email authentication with SPF, DKIM and DMARC to raise the cost of domain spoofing, paired with a secure email gateway and link rewriting or sandboxing.
  • Continuous, scenario-based awareness training plus simulated phishing, measured to improve over time rather than to punish individuals.
  • A frictionless reporting button and a fast response process, because the people who report are the early-warning system for the ones who clicked.

Where phishing fits in standards and regulation

Phishing sits squarely inside the scope of an information security management system. Under an ISO/IEC 27001 ISMS the relevant treatment combines awareness training, access control and the technical email and authentication controls, all selected through risk assessment rather than bolted on by reflex. European guidance from ENISA and national authorities such as ANSSI consistently rank phishing among the top initial-access techniques and publish practical countermeasures. When a successful phish exposes personal data, for example through a compromised mailbox, it can also trigger personal data breach obligations under the GDPR, which means legal and the data protection function belong in the response plan alongside IT and security.

For practitioners the lesson is that phishing defence is layered and shared. No single tool or training campaign closes it. The durable posture combines people, process and authentication design so that a click, which will eventually happen, does not become a breach.

Frequently asked questions

01What is the difference between phishing and spear phishing?

Phishing is the broad category of social-engineering messages cast widely to harvest clicks or credentials. Spear phishing is a targeted variant crafted for a specific person or team, using real names, projects and context to lower suspicion and raise the success rate.

02Does multi-factor authentication stop phishing?

Ordinary MFA helps but can be phished or relayed in real time. Phishing-resistant MFA, such as FIDO2 security keys or passkeys bound to the legitimate domain, is what reliably defeats credential phishing because a fake login page cannot replay the factor.

03Is awareness training enough to prevent phishing?

No. Training lowers the click rate but never eliminates it, so it must be paired with technical controls. The goal is to remove the value of a click through phishing-resistant MFA, email authentication and fast reporting, not to demand a perfect human firewall.

04What are smishing and vishing?

Smishing is phishing delivered by SMS, often a fake delivery, bank or MFA-reset prompt. Vishing is phishing by voice call, where an attacker applies real-time pressure, increasingly aided by spoofed caller IDs and synthetic audio.

05Can a phishing incident be a notifiable data breach?

Yes. If a successful phish exposes personal data, for example through a compromised mailbox, it can trigger personal data breach obligations under the GDPR. The response plan should involve legal and the data protection function alongside IT and security.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.