What Is Phishing?
Phishing is a social-engineering attack that impersonates a trusted person, organization, or service to persuade a victim to reveal information, open malicious content, authorize access, or complete a fraudulent action. Delivery can use email, websites, search ads, social media, messaging, QR codes, or collaboration tools.
Modern phishing often uses accurate branding, compromised accounts, active email threads, and real cloud services. Some campaigns capture passwords and session cookies through adversary-in-the-middle infrastructure, while others deliver malware or redirect payments without stealing a credential.
Key Takeaways
- Credential phishing and fake login pages is a central category or technique.
- Reliable assessment requires source, ownership, timing, and operational context.
- Detection should connect external evidence with identity, device, network, and business signals.
- Response should protect affected people and remove reusable access paths.

How Phishing Works
The sequence above provides a practical operating model. Individual steps can overlap, repeat, or involve different people and services, so each stage should be validated against available evidence.
Modern phishing often uses accurate branding, compromised accounts, active email threads, and real cloud services. Some campaigns capture passwords and session cookies through adversary-in-the-middle infrastructure, while others deliver malware or redirect payments without stealing a credential.
Common Types and Techniques
- Credential phishing and fake login pages
- Spear phishing and executive impersonation
- Malware delivery and fake software
- Adversary-in-the-middle and QR-code phishing
Security, Privacy, and Business Risks
- Account takeover and session theft
- Business email compromise and payment fraud
- Malware, ransomware, and data theft
- Customer impersonation and brand damage

Warning Signs and Validation
Check sender and reply-to domains, link destinations, page ownership, authentication results, mailbox rules, OAuth grants, new sessions, device changes, and follow-on financial or administrative activity.
Prevention and Response
Use phishing-resistant MFA, email authentication, secure browsers, attachment controls, domain monitoring, least privilege, staff training, safe reporting, session protection, and rapid credential and token revocation.
How SOCRadar Can Help
SOCRadar combines external intelligence, Dark Web visibility, brand monitoring, attack-surface discovery, and contextual enrichment to help teams identify exposure and investigate activity connected to phishing.
Explore SOCRadar Brand Protection or request a demo to strengthen external threat detection and response.
Frequently Asked Questions
What Is Phishing and How Is It Different From Other Social Engineering?
Phishing is a social-engineering attack that impersonates a trusted person, organization, or service to steal information, deliver malware, or trigger a fraudulent action. It is usually delivered at scale through email, but the same technique also appears in SMS, voice calls, chat apps, QR codes, and fake search ads. What sets it apart is the digital lure, such as a fake login page or a malicious file, that converts trust into account access, payments, or data theft.
What Are the Most Common Types of Phishing Attacks?
Frequent variants include:
- Credential phishing: fake login pages that harvest passwords and, with adversary-in-the-middle kits, session cookies.
- Spear phishing and executive impersonation: tailored messages aimed at specific people, roles, or payment processes.
- Malware delivery: malicious attachments, fake software updates, and trojanized installers.
- QR-code phishing: codes that move victims to a mobile browser, often away from desktop email scanning.
Can Phishing Bypass MFA?
Yes. Adversary-in-the-middle proxy pages can capture passwords and session cookies in real time, consent phishing abuses OAuth approval prompts, and MFA fatigue or account recovery abuse pressures users into granting access. Phishing-resistant methods such as passkeys and FIDO2 security keys block credential relay, but a session that was already stolen still needs to be revoked separately.
Why Does a Password Reset Not Always End an Account Takeover?
Depending on the platform and its session controls, a stolen session cookie can remain valid after the password changes. Effective containment also includes forcing sign-out across all sessions, revoking refresh tokens, removing attacker-created mailbox rules, and reviewing OAuth grants and new device registrations.
What Warning Signs Suggest a Message Is Phishing?
Look for sender or reply-to domains that do not match the claimed organization, link destinations that differ from the displayed text, login pages hosted on unrelated or recently registered domains, and unusual urgency around payments or credentials. Authentication results such as DMARC add context, but a passing check does not guarantee a message is safe.
What Should a User Do After Clicking a Phishing Link or Entering Credentials?
Stop entering information, report the message to the security team or help desk, and follow the organization’s incident procedure. If credentials were submitted, reset the password and revoke active sessions and tokens; if a file may have run, disconnect the device for analysis. Teams should check for new mailbox rules, OAuth grants, unfamiliar sessions, and follow-on financial or administrative activity.
Do SPF, DKIM, and DMARC Stop Phishing?
Email authentication mainly prevents attackers from directly spoofing your domain, which removes one common lure. It does not stop look-alike domains, compromised supplier accounts, or content-based spear phishing sent through legitimate mail services. Layer it with mailbox filtering, link and attachment analysis, and low-friction user reporting.
How Does Phishing Lead to Business Email Compromise and Payment Fraud?
Attackers steal mailboxes or insert themselves into active threads, then redirect invoices, change payment details, or request transfers while impersonating executives, employees, or vendors. Because these messages originate from a real, trusted account, they often pass technical checks, so payment changes should require out-of-band verification through a known contact.
How Can Organizations Reduce Phishing Risk?
Deploy phishing-resistant MFA, enforce SPF, DKIM, and DMARC, apply least privilege, and use secure browsers and attachment controls. Combine these with training that encourages safe, penalty-free reporting, monitor for look-alike domains and cloned login pages, and keep session protection and rapid token revocation ready for incidents.
