Skip to content
Bellator Cyber Guard
Learn38 min readDeep Dive

What Is Phishing? How to Spot and Avoid Scams

Phishing causes $4.88M in average breach costs. Learn what is phishing, how every attack type works, and how to protect your business in 2026.

By Bellator Cyber Guard Security Team
What Is Phishing? How to Spot and Avoid Scams - what is phishing

What Is Phishing?

What is phishing? It is a cyberattack that exploits human trust and psychology rather than software vulnerabilities. When attackers want to breach a company, steal financial credentials, or deploy ransomware, the fastest path is almost never through an unpatched firewall. It is through a person. That gap between technical defenses and human decision-making is exactly what phishing attacks exploit.

Attackers impersonate trusted entities including banks, software vendors, government agencies, and colleagues to trick victims into revealing credentials, clicking malicious links, downloading malware, or authorizing fraudulent payments. Standard network monitoring tools cannot always detect these attacks in progress because nothing technically malicious may be happening. A legitimate user is simply being convinced to take an action. That is why security experts classify phishing as a form of social engineering: it targets trust and emotion rather than code, and it works on IT professionals just as readily as it works on employees with no technical background.

According to the IBM Cost of a Data Breach Report, phishing accounts for 15% of all data breaches, and phishing-caused breaches carry an average financial impact well above the overall average for other breach types. The Verizon 2025 Data Breach Investigations Report (DBIR) consistently identifies phishing as the most common initial access vector in successful breaches. Every industry, every business size, and every geography faces this threat.

Three trends are making phishing attacks more dangerous heading into 2026. AI-generated content eliminates the grammar errors and awkward phrasing that once made fake emails easy to spot. Deepfake voice cloning makes phone scams nearly indistinguishable from real executive calls. And adversary-in-the-middle (AitM) proxy attacks now bypass multi-factor authentication in real time by intercepting authentication sessions before they complete. Understanding these attack types and building defenses against each of them is the single most valuable cybersecurity investment any organization can make.

Phishing By The Numbers

$4.88M
Avg. Phishing Breach Cost

IBM Cost of a Data Breach Report 2024

15%
Of All Data Breaches

Caused by phishing attacks (IBM)

$2.9B
Annual BEC Losses

Business Email Compromise losses in 2023 (FBI IC3)

Types of Phishing Attacks

Phishing has evolved far beyond the obvious "Nigerian prince" email. Modern attacks come in many forms, each engineered to exploit a different context, channel, or level of trust. Understanding these variations is the first step in recognizing threats across your inbox, text messages, phone calls, and even QR codes.

Email Phishing

The most common form, email phishing sends mass messages impersonating trusted brands including Microsoft, Amazon, your bank, or a government agency. These attacks cast a wide net, relying on volume rather than personalization. Modern email phishing increasingly uses AI-generated content that eliminates the grammar errors and awkward phrasing that once made fake messages easy to spot. Attackers use spoofed sender addresses, cloned company branding, and urgent language to pressure victims into clicking malicious links or downloading infected attachments. Phishing campaigns also ramp up around high-traffic retail events like Amazon Prime Day, when consumers are primed to expect shipping notifications and account alerts, making them less likely to pause before clicking.

Spear Phishing

Spear phishing targets specific individuals or organizations with highly personalized messages. Attackers research their victims on LinkedIn, company websites, and social media to craft messages that reference real projects, colleagues, or business relationships. Success rates run up to 10 times higher than mass phishing campaigns precisely because the messages feel genuine. In 2016, Russian intelligence operatives used a fake password-reset email to access the Clinton presidential campaign's email accounts, ultimately exposing thousands of internal messages. That attack succeeded not through any technical exploit but through a single click from a campaign staffer who believed the email was legitimate. For a closer look at how attackers craft these lures, see our guide to recognizing and avoiding phishing scams.

Whaling

Whaling targets high-value individuals including executives, CFOs, attorneys, and decision-makers with access to sensitive data or financial authority. These attacks often impersonate board members, legal counsel, or business partners requesting urgent wire transfers or confidential information. The FBI's Internet Crime Complaint Center (IC3) reports the average whaling attack results in losses exceeding $130,000. Attackers use publicly available information about executive travel schedules, board meetings, and business transactions to time their attacks when targets are most distracted and least likely to stop and verify before acting.

Smishing, Vishing, BEC, Social Media, and QR Code Attacks

Smishing (SMS Phishing)

Smishing delivers phishing attacks via text message. Common tactics include fake package delivery notifications, bank fraud alerts, and two-factor authentication (2FA) warnings designed to steal credentials. Mobile devices make smishing particularly effective because URLs are harder to inspect on small screens, and users extend more trust to text messages than email. The U.S. Postal Service is one of the most impersonated organizations in smishing campaigns targeting American consumers. For tax professionals, smishing attacks frequently impersonate the IRS or state revenue departments during filing season, referencing real deadlines or specific software platforms to appear credible.

Vishing (Voice Phishing)

Vishing uses phone calls to manipulate victims into revealing information or authorizing fraudulent payments. Attackers spoof caller ID to appear as legitimate organizations, use AI voice cloning to impersonate executives, and create elaborate pretexts around account security, technical support, or legal threats. The Anti-Phishing Working Group (APWG) documented a 260% increase in vishing incidents between 2022 and 2023, driven largely by VoIP technology that enables attackers to make millions of automated calls per day at minimal cost. In 2025, the FBI documented over 400 cases of deepfake vishing attacks resulting in losses exceeding $50 million, a figure that is expected to climb as voice cloning tools become cheaper and more accessible.

Business Email Compromise (BEC)

BEC attacks use actually compromised email accounts to send fraudulent messages from real, trusted addresses. Unlike traditional phishing that impersonates organizations with spoofed addresses, BEC exploits legitimate accounts, making detection difficult for both technical filters and human recipients. In one widely cited case, attackers stole over $100 million from Facebook and Google over two years by posing as a legitimate hardware vendor and submitting fraudulent invoices that employees approved through normal processes.

The FBI's Internet Crime Complaint Center consistently identifies BEC as the most financially damaging cybercrime category it tracks. BEC typically targets finance departments with fraudulent wire transfer requests, payroll redirection schemes, or W-2 data theft. These attacks often involve weeks of account monitoring before the attacker executes the fraud at precisely the right moment. Understanding financial security controls is a practical first defense for anyone with authority over payments or payroll.

Social Media Phishing

Social media phishing uses fake profiles, direct messages, and sponsored posts to reach victims where email security tools cannot. Attackers create fake brand pages on LinkedIn, Facebook, and Instagram to collect credentials through imitation login portals. LinkedIn is particularly targeted for corporate credential theft because profiles contain detailed employment information that makes personalized lures easy to craft. Quizzes requesting personal information, fake job offers, and direct messages containing malicious links are all common social media phishing tactics. Standard email filtering provides no protection here, which makes user awareness the primary defense channel.

QR Code Phishing (Quishing)

QR code phishing, often called quishing, embeds malicious URLs inside QR codes placed in emails, printed materials, or physical locations like parking meters and EV charging stations. Most email security tools cannot scan QR code contents before the user's device processes them. Because the malicious link is embedded in an image rather than a clickable text URL, quishing bypasses email URL scanners entirely. This evasion capability has made quishing increasingly common, particularly in attacks targeting Microsoft 365 credentials. For a deeper look at the phishing toolkits that automate this technique, see our analysis of phishing-as-a-service and Browser-in-the-Middle attacks.

How to Recognize a Phishing Attempt

  • The sender address does not match the organization the message claims to represent
  • The message creates urgency or threatens account suspension, legal action, or a missed deadline
  • Hovering over a link reveals a URL that differs from the displayed text or goes to an unexpected domain
  • The greeting is generic such as Dear Customer rather than your actual name
  • You received an unexpected attachment, especially an executable, ZIP, or Office file requesting macros
  • The request asks you to bypass a normal process, such as wiring money without a second approval
  • The email asks you to confirm credentials through a link rather than by going directly to the official site
  • The message contains a QR code in an unsolicited email asking you to scan and log in

What to Do If You Clicked a Phishing Link

1

Change Compromised Passwords Immediately

Change the password on the affected account and every other account where you reused the same credential. Credential reuse turns one compromised account into many. A password manager generates and stores unique credentials for every account, eliminating the reuse risk entirely.

2

Enable MFA on the Affected Account First

Enable multi-factor authentication right away, prioritizing your email account above all others. Even if attackers have your password, MFA requires a second verification factor they cannot easily obtain. Email access lets attackers reset passwords on every connected service, making it the highest-priority account to secure.

3

Contact Your Bank if Financial Data Was Entered

Most banks provide zero-liability protection when fraud is reported promptly. Monitor statements closely for 60 days. If your Social Security number or other personal financial data was exposed, place a fraud alert with Equifax, Experian, and TransUnion.

4

Run a Full Malware Scan and Disconnect if Needed

If you downloaded an attachment, disconnect your device from the network before scanning to prevent potential spread to other devices. Malware installed through phishing can establish backdoor access, install keyloggers to capture future passwords, or serve as a foothold for ransomware deployment across your network.

5

Report to IT and Document the Incident

For business accounts, notify your IT team or managed security provider immediately. Document the phishing message, any attacker correspondence, and a complete timeline of events. This documentation supports insurance claims, law enforcement reporting, and your organization's incident response process.

6

Report the Attack to the Appropriate Agency

Forward phishing emails to reportphishing@apwg.org. Report IRS-themed scams to phishing@irs.gov. File complaints for financial fraud at the FBI's IC3 at ic3.gov. Your report helps agencies track active campaigns and may protect other potential victims from the same attack.

Building Organizational Phishing Resilience

The most effective defense against phishing combines regular security awareness training with realistic phishing simulations. Organizations that run monthly simulations see phishing click rates drop from approximately 30% to under 5% within a year. Training must cover current attack trends rather than generic awareness and should show employees real examples of phishing emails targeting your specific industry and role.

Effective programs follow the NIST NICE Framework approach: knowledge reinforcement through repeated exposure, realistic simulations without punishment, and immediate feedback when users click simulated phishing links. Sessions should be brief (10-15 minutes monthly), engaging, and relevant to actual threats your organization faces. Punishment-based approaches backfire because employees who fear consequences stop reporting suspicious emails, which eliminates your early warning system. According to the Ponemon Institute, organizations where employees actively report phishing reduce breach costs by an average of $186,000 per incident.

Your incident response capability matters as much as prevention. Under NIST SP 800-61 guidelines, response to a phishing-related incident must be swift, coordinated, and documented. Our guide to incident response planning for tax practices covers how to structure this process. If your business experienced a breach that originated with phishing, our guide on what to do after a data breach covers notification obligations, regulator reporting, and remediation steps in detail.

Technical Controls That Add Essential Defense Layers

Deploy email filtering solutions that scan attachments for malware, analyze URLs for known phishing indicators, and quarantine suspicious messages before they reach inboxes. Modern Secure Email Gateways (SEGs) use machine learning to detect zero-day phishing attempts that signature-based filters miss. Pair this with URL rewriting, which routes every link in incoming email through a real-time security scanner that checks destinations against threat intelligence feeds at the moment of click, not at delivery time.

Implement DMARC, DKIM, and SPF email authentication protocols to prevent spoofing of your own domain. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers how to handle messages that fail authentication checks. Organizations with enforced DMARC policies block approximately 90% of domain spoofing attempts. The FTC recommends DMARC implementation in its Safeguards Rule compliance guidance for financial institutions. Start with a monitoring policy (p=none) to inventory all legitimate email sources, then advance to quarantine, and finally to reject once all authorized senders are confirmed.

Endpoint Detection and Response (EDR) tools complement email security by catching malware that gets through filtering and establishing persistent threat monitoring beyond the email gateway. Remote and hybrid teams face additional exposure because home networks typically lack enterprise-grade email filtering. Our guide to remote work security for small teams covers the controls needed when your workforce operates outside the office perimeter. If you are evaluating security solutions, our comparison of EDR vs. MDR vs. XDR covers the tradeoffs between each approach for small and mid-sized businesses.

Bottom Line

Security awareness training with realistic phishing simulations is the highest-return investment most organizations can make against phishing. Technical controls stop known attacks. Trained employees stop the novel ones that technical tools have never seen before. Both are necessary, and neither alone is sufficient.

Advanced Phishing Techniques to Watch in 2026

Attackers continuously update their methods to bypass security controls and exploit new technologies. The techniques gaining ground in 2025 and 2026 require defenses that go well beyond traditional email filtering and periodic awareness training.

AI-Generated Phishing Content

Large language models let attackers generate perfectly grammatical, contextually appropriate phishing emails at scale. AI eliminates the spelling and grammar errors that once served as reliable detection signals. More concerning, AI can analyze a target's writing style from public posts and generate personalized messages that match their communication patterns, making spear phishing more convincing and far less resource-intensive to produce in volume. Organizations can no longer treat linguistic red flags as a primary detection strategy. Awareness training needs to shift toward verification behavior rather than email analysis. For context on how AI is changing the security threat environment, see our analysis of AI gateway security risks and cloud IAM access controls.

Deepfake Voice and Video Phishing

AI voice cloning creates convincing audio deepfakes of executives requesting wire transfers or credential resets. Video deepfakes are an emerging threat for collaboration platforms, with attackers impersonating executives in Microsoft Teams or Zoom calls to authorize fraudulent transactions. The MITRE ATT&CK framework now includes techniques for social engineering via deepfake media under technique T1598.

Organizations should establish out-of-band verification procedures for any high-risk request made via phone or video call: a callback to a known, previously confirmed number, a pre-arranged code word system, or mandatory secondary approval from a separate person. These procedural controls defeat deepfake attacks regardless of how realistic the audio or video becomes, because they require verification through a channel the attacker cannot control.

Adversary-in-the-Middle (AitM) Phishing

AitM phishing intercepts authentication sessions in real time. Attackers create proxy sites that sit between the victim and the legitimate login page, capturing credentials and session cookies simultaneously. Because the attacker relays the one-time code to the real service while stealing the authenticated session, standard MFA provides no protection against this technique. The comparison below shows which MFA methods provide genuine AitM protection. Defense requires phishing-resistant MFA methods, specifically FIDO2 security keys or passkeys that are cryptographically bound to the legitimate domain and cannot be proxied. For organizations running Microsoft 365, enabling Conditional Access policies that require FIDO2 authentication for administrative and finance roles is a practical first step against AitM attacks targeting those high-risk accounts.

Phishing Defense Is a Documented Compliance Requirement

Tax preparers handling 11 or more returns annually must maintain a Written Information Security Plan (WISP) under IRS Publication 4557 that addresses phishing threats and email security controls. Healthcare organizations must provide phishing-specific security awareness training under HIPAA Security Rule Section 164.308(a)(5). Financial institutions must implement technical safeguards against unauthorized access under the FTC Safeguards Rule (16 C.F.R. Part 314). Across these industries, phishing defense is a documented obligation with enforcement consequences, not a discretionary best practice.

Phishing Defense for Tax Professionals and Regulated Industries

Tax Professionals

Tax professionals face an elevated phishing threat because they hold exactly what attackers want: Social Security numbers, financial records, direct deposit information, and access credentials for tax preparation software connected to millions of returns. The IRS identifies tax preparers as a top-targeted group and requires them to maintain documented security programs under IRS Publication 4557.

A Written Information Security Plan (WISP) is the IRS-required foundation for phishing defense at tax practices. The WISP must document your email security controls, employee training program, incident response procedures, and acceptable use policies. Tax preparers handling 11 or more returns annually are required to maintain a compliant WISP, and the IRS has signaled increased enforcement attention on preparers without documented security programs. Our complete guide to IRS Written Information Security Plans walks through every required element. You can also download a free WISP template built specifically for tax preparers to get started immediately. For identity theft prevention resources built for tax professionals, visit our tax identity theft prevention page.

Healthcare Organizations

Healthcare organizations face parallel requirements under HIPAA Security Rule Section 164.308(a)(5), which mandates security awareness training that specifically addresses phishing and malicious software. The Office for Civil Rights (OCR) has cited inadequate phishing training as a contributing factor in multiple enforcement actions resulting in civil monetary penalties. Our HIPAA cybersecurity requirements guide covers phishing defense obligations specific to covered entities and business associates. For dental practices specifically, our HIPAA guide for dental offices addresses the phishing risks particular to that setting, including patient portal credential theft and billing fraud.

Financial Institutions and FTC-Regulated Businesses

Financial institutions and businesses subject to the FTC Safeguards Rule must implement safeguards specifically addressing phishing under 16 C.F.R. Part 314. The rule requires multi-factor authentication, employee training, and technical controls to detect and prevent unauthorized access, all directly applicable to phishing defense. Our guide to the FTC Safeguards Rule for financial and tax businesses covers the requirements that took effect after the 2023 rule amendments. Businesses that have not reviewed their safeguards obligations since those updates should do so now, as enforcement activity has increased steadily since then.

Across all regulated industries, what is phishing represents not just a security threat but a compliance and legal exposure. A single successful phishing attack that results in a breach can trigger notification obligations, regulatory investigations, and civil penalties that far exceed the cost of prevention. The FTC, IRS, and OCR have all demonstrated willingness to pursue enforcement actions where organizations lacked documented, implemented phishing defenses. Our personal cybersecurity resources offer additional guidance for individuals managing their own security alongside professional compliance obligations.

Not Sure Where Your Phishing Defenses Stand?

Our security team evaluates your email security controls, employee training program, and technical defenses, then gives you a prioritized action plan with no obligation.

Get Your Free Cybersecurity Evaluation

Our experts will evaluate your phishing defenses, email security controls, and employee training program, then provide actionable recommendations tailored to your industry and compliance requirements.

Frequently Asked Questions About Phishing

Phishing is a cyberattack where criminals impersonate a trusted person or organization to trick you into handing over passwords, financial information, or access to your accounts. Unlike hacking that exploits software bugs, phishing exploits human trust and decision-making. The name references fishing: attackers cast a lure and wait for someone to bite.

Email phishing is the most common form, accounting for the majority of phishing attempts. These mass campaigns impersonate well-known brands like Microsoft, Amazon, or financial institutions and trick recipients into clicking malicious links or entering credentials on fake login pages. Business Email Compromise (BEC), a more targeted variant, is the most financially damaging form, causing billions in annual losses according to the FBI's Internet Crime Complaint Center.

Warning signs include a sender address that does not match the claimed organization, urgent language threatening negative consequences, generic greetings like "Dear Customer" instead of your actual name, links whose hover destination does not match the displayed URL, unexpected attachments, and requests to bypass normal approval processes. AI-generated phishing now passes many of these checks, which is why verification behavior matters more than email analysis. When in doubt, go directly to the organization's official site rather than clicking any link in the message.

Yes. Adversary-in-the-Middle (AitM) phishing attacks use proxy sites that sit between you and the legitimate login page, capturing your one-time code and session cookie in real time. This bypasses SMS-based 2FA and TOTP authenticator apps completely. The only MFA methods that resist AitM attacks are FIDO2 security keys and passkeys, which are cryptographically bound to the legitimate domain and fail authentication automatically when a proxy redirects you to a different site.

Act quickly: (1) Change the compromised password immediately, plus any account where you reused the same credential. (2) Enable multi-factor authentication on the affected account, starting with your email. (3) If you entered financial information, call your bank right away. (4) If you downloaded an attachment, disconnect your device from the network and run a full malware scan. (5) Notify your IT team or managed security provider if this involved a work account. (6) Report the phishing attempt to reportphishing@apwg.org or, for IRS-themed scams, to phishing@irs.gov.

Yes. The IRS requires tax preparers who handle 11 or more returns annually to maintain a Written Information Security Plan (WISP) under IRS Publication 4557. A compliant WISP must document email security controls, employee training requirements, and incident response procedures, all of which directly address phishing threats. The IRS has increased enforcement attention on preparers without documented security programs.

Regular phishing sends mass messages to thousands or millions of recipients, relying on volume to catch victims. Spear phishing targets a specific individual or organization with personalized messages that reference real projects, colleagues, or business relationships. Spear phishing success rates run up to 10 times higher than mass campaigns because the messages feel genuine. Whaling is a form of spear phishing that specifically targets executives and other high-authority individuals.

Traditional phishing impersonates an organization using spoofed email addresses or lookalike domains. Business Email Compromise (BEC) uses actually compromised email accounts to send fraudulent messages from real, legitimate addresses. This makes BEC harder to detect because the message comes from a genuine account that passes all authentication checks. BEC typically targets finance teams with fraudulent wire transfer requests, payroll redirection, or W-2 data theft requests.

Quishing embeds a malicious URL inside a QR code rather than a clickable text link. Because the link is encoded in an image, most email security tools cannot scan and analyze it before the user's device processes it. When the victim scans the code, they are taken to a phishing page that harvests credentials. Quishing is increasingly common in attacks targeting Microsoft 365 users and has appeared in physical environments including parking meters and EV charging stations.

The most effective approach combines regular security awareness training with realistic phishing simulations. Organizations that run monthly simulations see click rates drop from around 30% to under 5% within a year. Training should use current examples relevant to your industry, run in short sessions (10-15 minutes), and avoid punishing employees who click, since punishment reduces voluntary reporting. Pair training with technical controls: email authentication (DMARC, DKIM, SPF), Secure Email Gateways with URL rewriting, and phishing-resistant MFA (FIDO2 security keys or passkeys) for high-risk accounts.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Phishing & email security

Recognize manipulation, protect email accounts, and give people a clear way to report suspicious messages.

Learn first. Decide when you are ready.

Keep learning—or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.