Phishing
A social engineering scam that deceives users into revealing sensitive information.
Phishing is a type of scam and social engineering attack in which tricksters get people to hand over private data or install harmful software like viruses, ransomware, or adware. It is the most common kind of cybercrime worldwide, and the danger has grown much worse because generative AI now lets attackers run very convincing, automatic, and highly targeted phishing campaigns on a scale never seen before. The word "phishing" first appeared in 1995 in the AOHell cracking toolkit, though it might have been used earlier in the hacker magazine *2600*. It comes from "fishing," referring to using bait to "fish" for sensitive details.
To stop or lessen the damage from phishing, people use laws, training, public awareness campaigns, and technical security tools. Awareness has become more important at home and at work. Among businesses, phishing attacks went from 72% in 2017 to 86% in 2020, and hit 94% in 2023. Phishing takes many forms: email spam, voice phishing (vishing), targeted phishing (spear phishing and whaling), SMS phishing (smishing), QR code phishing (quishing), cross-site scripting, and man-in-the-middle attacks on two-factor authentication.
Email phishing is the most common type. Attackers send bulk emails to a wide audience, pretending to be a trusted source like a bank or government agency. The messages lead to fake login pages where victims type in their credentials. The stolen info or access can be used to steal money, install malware, or spear phish others in the same organization. Compromised streaming accounts are sometimes sold on darknet markets.
Spear phishing is more effective because it targets specific people using personal or company details to seem believable. It often goes after executives or finance staff who handle sensitive data. Attackers may use email, SMS, and phone calls together to create urgency. Accounting and audit firms are especially at risk. In 2016, the Russian group Fancy Bear (GRU Unit 26165) targeted Hillary Clinton’s campaign with spear phishing on over 1,800 Google accounts using a fake domain. A study found that 43% of people aged 18–25 and 58% of older users clicked on simulated phishing links in daily emails over 21 days. Older women were the most likely to click, and while younger users got better over time, older users did not.
Voice phishing, or vishing, uses VoIP to make automated calls to many people, often with text-to-speech, claiming fake account activity. The caller ID is spoofed to look like a real bank. Victims are told to enter sensitive info or are connected to a live scammer. Vishing works because people trust phone calls more than email.
SMS phishing, or smishing, uses text messages with a link, phone number, or email address. The attacker may pretend to be a government officer, customer support, shipper, colleague, boss, or a wrong number. Smishing messages often come from unusual numbers, and mobile browsers make it hard to spot fake links. These scams rely on social engineering, like pretending to be a bank or customer service.
Page hijacking redirects users to malicious sites by breaking into legitimate web pages, often with cross-site scripting. Hackers may insert exploit kits like MPack into compromised sites to attack visitors. They can also add hidden inline frames that load exploit kits. This method is sometimes used with watering hole attacks on companies.
QR code phishing, or quishing, takes advantage of QR codes. Scammers embed a malicious website link in a code, and when victims scan it, they give up sensitive data.
- first_recorded
- 1996
- prevalence_2023
- Removed (unverifiable vague statistic)
Lore & Background
It is a variation of fishing, referring to the use of lures to 'fish' for sensitive information. Phishing attacks have become increasingly sophisticated, often transparently mirroring the targeted site to allow attackers to observe everything while the victim navigates, traversing additional security boundaries. Phishing techniques and vectors include email spam, vishing (voice phishing), targeted phishing (spear phishing, whaling), smishing (SMS), quishing (QR code), cross-site scripting, and Man-in-the-Middle (MitM) 2FA attacks.
Reader's Guide
The integration of generative AI has intensified the threat, enabling automated, hyper-targeted campaigns at unprecedented scale. Measures to prevent or reduce impact include legislation, user education, public awareness, and technical security measures. The importance of phishing awareness has increased in both personal and professional settings. Phishing's evolution from simple email scams to sophisticated techniques like MitM phishing—using tools such as Evilginx to bypass two-factor authentication—demonstrates its growing complexity. As QR codes become more widely used, quishing has emerged as a significant concern, with scammers exploiting convenience to trick users. The UK's National Cyber Security Centre rates quishing risk as lower than other lure types, but the trend indicates growing sophistication. Phishing's legacy lies in its persistent adaptation, forcing continuous vigilance and critical thinking from users and organizations alike.
Did You Know?
- Evilginx, originally created as an open-source tool for penetration testing, has been repurposed by cybercriminals for Man-in-the-Middle phishing attacks that bypass two-factor authentication.
Gallery






Frequently Asked Questions
What is Phishing?
Phishing is a social engineering scam in which an attacker tricks a victim into voluntarily surrendering confidential data or unknowingly installing malicious software such as ransomware, viruses, or adware. Rather than exploiting a technical vulnerability, it relies entirely on manipulating the target's trust and judgment.
How does Phishing carry out its attack?
The attacker crafts a message that impersonates a trusted sender, luring the recipient into clicking a malicious link, downloading a payload, or typing in credentials. The entire operation hinges on psychological deception delivered through a digital channel rather than brute-force intrusion.
When was Phishing first recorded in the canon?
The earliest documented instance of Phishing traces back to 1996, placing it among the older entries in the Crime and Deviance catalog. Nearly three decades later it still ranks as the single most prevalent form of cybercrime worldwide.
Why does Phishing anchor the 25-29 arc?
Its status as the most widespread category of cybercrime gives it a central, recurring role in the series. The integration of generative AI has further amplified its threat by enabling automated, hyper-personalized lures at a scale that was previously unachievable.
What distinguishes Phishing from other social engineering crimes?
While broader social engineering can involve in-person manipulation or long con narratives, Phishing is specifically defined by a bait-and-switch digital message that prompts a single impulsive action—clicking, downloading, or entering credentials. That narrow, repeatable delivery vector is what sets it apart in the catalog.
More in Crime And Deviance 1-24
Spotted an error? Know more?
This is a living reference — every entry is fact-audited, and reader corrections feed straight into our audit queue. Suggest an edit · See this site's audit record
