← All resources

What Is Phishing?

July 22, 2026 · Greg Brainerd

A fingerprint scan on a smartphone

Phishing is a scam where an attacker pretends to be someone trustworthy, a coworker, a well-known company, your bank, in order to trick you into clicking a bad link, opening a malicious attachment, or typing your password into a fake login page. It’s the single most common way businesses get breached, not because people are careless, but because phishing is built to exploit exactly the moments when nobody’s careful.

How it works

A phishing message usually creates urgency: your account will be suspended, a package couldn’t be delivered, an invoice is overdue, a coworker needs a document signed right now. The link goes to a page that looks like a real login screen but isn’t, and whatever you type there goes straight to the attacker. Some phishing emails skip the link entirely and carry an infected attachment instead.

The more targeted version, spear phishing, uses real names, real job titles, and real details pulled from LinkedIn or a company website to make the message feel personal instead of generic. It’s harder to spot because it doesn’t look like spam.

How to defend against it

Slow down on anything urgent. Hover over links before clicking to see where they actually go, and never enter a password after clicking a link in an email, go to the site directly instead. Multi-factor authentication is the single best backstop: even if a password gets phished, MFA usually stops the attacker from getting in with it. Layer that with email security that filters known phishing attempts before they land, and a culture where employees feel safe reporting a suspicious email instead of quietly deleting it and hoping it wasn’t a problem.

Frequently Asked Questions

What’s the difference between phishing and spear phishing?

Regular phishing is broad and generic, the same fake “your account is suspended” email sent to thousands of people. Spear phishing is targeted, built around real details about you or your business to make the message feel personal and trustworthy. Spear phishing has a much higher success rate because it doesn’t look like the mass-blast spam people are trained to ignore.

Hover over it without clicking and check where it actually leads, phishing links often use a domain that’s close to the real one but slightly off. Be suspicious of any link that asks you to log in after you clicked it rather than after you navigated there yourself, and when in doubt, go to the site directly by typing the address instead of clicking through.

Does phishing lead to business email compromise?

Often, yes. A phished password is one of the most common ways an attacker gains real access to a mailbox, which they can then use to run a convincing business email compromise scam from an account that’s actually real, not spoofed. That’s part of why phishing defense and BEC defense overlap so much.

Is antivirus software enough to stop phishing?

No. Most phishing doesn’t rely on malware at all, it relies on tricking a person into handing over credentials or approving a payment, which antivirus software has no way to see. The real defense is a combination of email filtering, MFA, and a team trained to pause and verify.

Build a phishing-resistant team

If you want to see where your business is exposed to phishing and other email-based threats, read about the risks that don’t show up until it’s too late, or book a free discovery call and we’ll walk through it with you.

Schedule a Discovery Call

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.