In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on security tools, phishing remains the number one way threat actors break into organizations. So let's actually define phishing in a way that goes beyond the textbook and reflects what's happening right now in the wild.

I've spent years watching organizations get compromised not because of zero-day exploits, but because someone clicked a link in a convincing email. If you're searching for a clear definition of phishing, you're already asking the right question. Here's the answer — along with everything you need to recognize, prevent, and respond to these attacks.

How Security Professionals Define Phishing

Phishing is a social engineering attack where a threat actor impersonates a trusted entity — a bank, a coworker, a SaaS vendor — to trick you into surrendering credentials, financial information, or access. The attack usually arrives via email, but it also shows up through text messages (smishing), phone calls (vishing), and even QR codes (quishing).

What separates phishing from spam is intent. Spam tries to sell you something. Phishing tries to steal something. The attacker crafts a message designed to create urgency, fear, or curiosity — then directs you to a fake login page, a malicious attachment, or a fraudulent wire transfer request.

NIST defines phishing as "a technique for attempting to acquire sensitive data, such as bank account numbers, through a fraudulent solicitation in email or on a web site, in which the perpetrator masquerades as a legitimate business or reputable person." You can review their full glossary entry at NIST's Computer Security Resource Center.

Why Phishing Still Works in 2026

Every year, I hear someone say, "People should know better by now." They're wrong. According to the Verizon Data Breach Investigations Report, the human element is involved in roughly 68% of breaches. Phishing is the primary delivery mechanism for ransomware, credential theft, and business email compromise.

Here's why it keeps working:

  • AI-generated content has eliminated typos. The grammatical errors that once gave away phishing emails are gone. Threat actors now use large language models to write flawless, personalized messages.
  • Credential theft feeds a cycle. Stolen credentials from one breach are used to craft more convincing phishing emails for the next target. It's a self-reinforcing loop.
  • People are busy. The average employee processes over 120 emails per day. Attackers exploit that cognitive overload by embedding malicious links inside routine-looking messages.
  • Multi-factor authentication bypass kits are now commoditized. Tools like EvilProxy allow attackers to intercept MFA tokens in real time, meaning even security-conscious users can be compromised after clicking a phishing link.

The 5 Types of Phishing You'll Actually Encounter

When you define phishing, you have to acknowledge it's not a single attack — it's a family of techniques. Here are the variants I see most often in real incident response engagements:

1. Email Phishing (Bulk)

The classic. Thousands of identical emails sent with a generic lure — a fake invoice, a shipping notification, a password reset. Low effort per target, but high volume means someone always clicks.

2. Spear Phishing

Targeted at a specific individual using personal details scraped from LinkedIn, company websites, or previous data breaches. These are significantly harder to detect because they reference real projects, real colleagues, real deadlines.

3. Business Email Compromise (BEC)

The attacker compromises or spoofs an executive's email account, then requests a wire transfer or sensitive data from a subordinate. The FBI IC3 reports that BEC caused over $2.9 billion in losses in 2023 alone. You can review the latest data at ic3.gov.

4. Smishing and Vishing

Phishing via SMS or voice calls. Package delivery scams, fake fraud alerts from your bank, IRS impersonation — these all bypass email filters entirely. Deepfake voice technology has made vishing particularly dangerous for organizations in 2026.

5. Quishing

QR code phishing. Attackers place malicious QR codes on parking meters, restaurant menus, or inside PDF attachments. When scanned, they redirect to credential-harvesting pages. This vector has surged because most email security tools can't inspect QR codes.

What Does a Phishing Attack Actually Look Like?

This section exists because too many articles define phishing in abstract terms. Here's a real-world scenario I've walked clients through dozens of times:

An employee receives an email that appears to come from Microsoft 365 support. The subject line reads: "Action Required: Unusual sign-in activity detected." The email includes the Microsoft logo, correct formatting, and a blue "Review Activity" button. The sender address is [email protected] — close enough that a busy person doesn't notice the "1" replacing the "i."

The employee clicks. They land on a pixel-perfect replica of the Microsoft login page. They enter their email and password. The page then prompts for their MFA code, which they provide. Behind the scenes, a reverse proxy relays those credentials to the real Microsoft login in real time — giving the attacker full access to the employee's mailbox, SharePoint, and Teams.

Total time from click to compromise: 14 seconds.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's Cost of a Data Breach Report found the global average cost of a data breach reached $4.88 million in 2024. Phishing was the most common initial attack vector. For small and mid-sized businesses, a single successful phishing attack can mean regulatory fines, class-action exposure, lost customer trust, and operational downtime that lasts months.

I've seen a 200-person company lose $400,000 to a single BEC attack because no one questioned an email that appeared to come from the CFO. No malware was involved. No firewall was breached. Just a convincing email and a lack of verification procedures.

This is why security awareness training isn't optional — it's your most cost-effective control. If your organization hasn't implemented structured phishing awareness training, you're relying on luck. Luck is not a security strategy.

How to Protect Your Organization From Phishing

Technology alone won't save you. You need a layered defense that combines tools, training, and process. Here's what actually works:

Technical Controls

  • Email authentication: Deploy SPF, DKIM, and DMARC on every domain you own. This prevents attackers from spoofing your domain in phishing campaigns.
  • Phishing-resistant MFA: Move beyond SMS and app-based OTPs to FIDO2 security keys or passkeys. These are immune to reverse-proxy attacks.
  • Zero trust architecture: Never assume a user is legitimate just because they authenticated once. Continuous verification of identity, device, and context is essential.
  • DNS filtering: Block access to known malicious domains at the network level before a user's browser ever loads the phishing page.

Human Controls

  • Regular phishing simulations: Test your employees with realistic scenarios monthly, not annually. Track click rates, report rates, and time-to-report.
  • Verification procedures: Any request involving money, credentials, or sensitive data should require out-of-band verification — a phone call, a Slack message, a walk down the hall.
  • Security awareness training: Build a culture where reporting a suspicious email is rewarded, not punished. Comprehensive cybersecurity awareness training gives employees the knowledge to spot social engineering before it succeeds.

Process Controls

  • Incident response playbooks: Every organization needs a documented phishing response plan. Who gets notified? How do you quarantine the email? How do you reset compromised credentials?
  • Least privilege access: If a phished employee only has access to what they need for their role, the blast radius shrinks dramatically.

Quick Reference: How to Define Phishing

Phishing is a social engineering attack in which a threat actor sends a deceptive message — typically via email — impersonating a trusted source to trick the recipient into revealing credentials, installing malware, or authorizing fraudulent transactions. It is the most common initial attack vector in data breaches worldwide and the primary delivery method for ransomware and credential theft.

Your Next Step

If you've read this far, you understand that knowing how to define phishing is just the starting line. The real work is building organizational resilience — through technology, training, and culture. Threat actors are evolving their tactics every day. Your defenses need to evolve faster.

Start with your people. Equip them with practical, scenario-based training that reflects real threats. Explore our phishing awareness training for organizations and our comprehensive cybersecurity awareness training program to build a workforce that recognizes and reports phishing before it becomes a breach.