Definition

Phishing is a form of cyberattack in which attackers use forged emails, websites or messages to obtain confidential data such as passwords or credit card details. Victims are deceived because the attacker poses as a trusted sender.

At a glance

Phishing targets people, not technology (social engineering).

Most common channels: email, SMS (smishing), phone (vishing), QR code (quishing).

The most effective defence: multi-factor authentication plus awareness plus technical filters.

What is Phishing?

Phishing is the most common form of social engineering – instead of exploiting a technical weakness, attackers manipulate people. A forged message creates urgency or trust and leads the victim to hand over credentials or open a malicious attachment.

The term comes from “fishing”: attackers cast a lure and wait to see who bites. Classic phishing is sprayed at scale, while modern campaigns are increasingly targeted and AI-assisted – linguistically flawless and tailored to the recipient. For companies, phishing is the most common way in for data breaches and ransomware; regulatory frameworks such as DORA and NIS2 therefore explicitly require awareness measures and reporting paths. The decisive point: phishing cannot be solved by technology alone – the last line of defence is an informed person.

Real-world examples

  • Fake bank email: “Your account has been locked – please confirm your details.” The link leads to a rebuilt login page.
  • CEO fraud: An email in the name of the management asks accounting for an urgent transfer.
  • Loss scenario: Stolen credentials open the way to a ransomware incident – a reportable loss under NIS2.

Variants in detail (6)

Smishing Phishing over SMS or messengers

Smishing is a form of phishing over SMS or messaging apps – usually a link to a forged page.

Vishing Phishing over a phone call (voice)

Vishing is phishing over a phone call, in which attackers talk the victim into disclosing confidential data.

Quishing Phishing through manipulated QR codes

Quishing is phishing through manipulated QR codes that lead to forged websites.

Spear phishing A targeted attack on one person or role

Spear phishing is a targeted phishing attack on a specific person or role that draws on personal information.

Whaling Spear phishing aimed at senior executives

Whaling is a form of spear phishing that specifically targets senior executives.

Clone phishing A copy of a genuine email with a malicious link

Clone phishing copies a legitimate email and replaces links or attachments with malicious versions.

Common misconception

Myth “You can always spot phishing by the bad spelling.”

Reality Modern, AI-assisted phishing mail is linguistically flawless and often personalised. Checking the sender and the link target is far more reliable.

Frequently asked questions

What is the difference between phishing and spear phishing?

The difference is effort: bulk phishing plays the numbers, spear phishing invests research in a single target – and is much harder to spot. Rule of thumb: the more personal a message feels, the more carefully it deserves checking. CISA collects examples of both.

Is phishing a criminal offence?

Yes. In Germany phishing meets the elements of offences such as computer fraud (§ 263a StGB) and unlawful access to data (§ 202a StGB).

Why do trained employees still fall for phishing?

Because phishing attacks behaviour, not knowledge: time pressure, authority and routine switch off critical checking. That is why simulations and simple reporting paths work better than theory alone – the BSI argues the same.