Sixwatch logo dark

What Is Phishing? How Attacks Work and How to Stop Them

Table of Contents

What is phishing? Phishing is a type of cyberattack in which a criminal sends a fraudulent message, usually an email, that pretends to come from someone you trust, in order to trick you into clicking a malicious link, opening an infected attachment, entering your login credentials, or sending money. It’s the most common way businesses get breached, because it doesn’t attack your systems. It attacks the person reading the email. Most ransomware incidents, most business email compromise losses, and most data breaches start with a single phishing message that worked.

what is phishing example of a spoofed login email

In this guide

How phishing works

Every phishing attack follows the same four steps:

  1. The lure. A message arrives that looks legitimate: an invoice from a vendor, a password-reset notice from Microsoft, a shipping alert, a message from the CEO, a voicemail notification. The sender name, logo, and formatting are copied from the real thing.
  2. The pressure. The message creates a sense of urgency or fear. “Your account will be suspended.” “Payment overdue.” “I need this handled before my flight.” Urgency short-circuits the careful reading that would expose the fake.
  3. The action. You’re asked to click a link, open an attachment, enter credentials on a login page, approve an MFA prompt, or send a payment or gift cards.
  4. The payoff. The attacker now has your password, control of your email account, malware on your machine, or your money. From there: reading your mail to find payment conversations, sending more phishing from your account, or launching ransomware.

The attack works because the message looks right and arrives at a busy moment. Technical defenses stop most of them. Training stops most of the rest. Nothing stops all of them, which is why the response plan matters.

Why phishing matters for businesses

  • Phishing is a leading initial entry point in ransomware attacks and the starting point of nearly every business email compromise case.
  • The FBI’s Internet Crime Complaint Center reports business email compromise, which almost always starts with phishing, as one of the most financially damaging cybercrimes — $3.04 billion in reported losses in its 2025 annual report, second only to investment fraud.
  • A single compromised email account gives an attacker your contacts, your invoices, your payment history, and a trusted sender address to attack everyone you do business with.
  • AI has removed the last easy tell. Phishing emails used to have bad grammar. Now they’re fluent, personalized, and generated at scale.

For a small business, one successful phish can mean a wire transfer to the wrong bank, weeks of ransomware recovery, or a breach notification to every client.

The 9 types of phishing attacks

Type How it works Typical target
Email phishing Mass emails impersonating a brand or service Anyone; volume-based
Spear phishing Targeted at a specific person using details about them: their role, vendors, projects, colleagues Finance staff, executives, HR
Whaling Spear phishing aimed at executives, or impersonating them CEOs, CFOs, and the people who take their instructions
Business email compromise (BEC) Attacker takes over or impersonates a real account to redirect payments, change payroll deposits, or request wire transfers Accounts payable, payroll, controllers
Vishing (voice phishing) Phone calls impersonating IT support, a bank, or a vendor; increasingly using AI-cloned voices Help desks, executives’ assistants, anyone
Smishing (SMS phishing) Text messages with malicious links: package deliveries, bank alerts, “CEO” requests Mobile users
Clone phishing A real email you already received is copied with the link or attachment swapped for a malicious one Anyone who gets attachments
Pharming / credential harvesting pages A fake login page that captures usernames and passwords, often a perfect copy of the Microsoft 365 sign-in Everyone with an email account
MFA fatigue / prompt bombing After stealing a password, the attacker sends repeated MFA push notifications until the user approves one Users on push-based MFA

Two newer variations to know: QR code phishing (quishing), where the malicious link is a QR code that bypasses email link scanning, and consent phishing, where the user is asked to “grant access” to a malicious app in Microsoft 365, which needs no password at all.

Real phishing examples

The vendor with new bank details. A construction company receives an email from a subcontractor it pays monthly. The email address is real; the subcontractor’s account was compromised weeks earlier. It says the company changed banks and attaches an updated ACH form on real letterhead. The next $62,000 payment goes to the attacker’s account. Nobody notices until the subcontractor calls asking where the money is.

The Microsoft password reset. An office manager receives “Your password expires today” from what looks like Microsoft. The link goes to a login page identical to the real one. She enters her credentials. Within an hour the attacker has set up a rule in her mailbox that forwards every email mentioning “invoice” or “payment” to an outside address and deletes the forwarded copies. The rule runs for three months.

The CEO who needs gift cards. A new employee gets a text from “the CEO”: “Are you at your desk? I need a favor, in a meeting and can’t talk.” The employee replies. The CEO asks her to buy $2,000 in gift cards for client thank-yous and send photos of the codes. She does.

The MFA push at 6 a.m. An accountant’s phone buzzes with a Microsoft Authenticator approval request. Then another. Then another. Assuming it’s a glitch, he taps Approve to make it stop. The attacker who bought his password on the dark web is now in his mailbox.

Sixwatch engineers working in the network operations center

Phishing red flags

Train employees to pause on any message with these characteristics:

  • Urgency or threat: account suspension, legal action, missed payment, a deadline in hours
  • A request involving money or credentials: wire transfers, bank detail changes, gift cards, password confirmation
  • Sender mismatch: display name says “Microsoft,” the address is a random domain; or a lookalike domain (rnicrosoft.com, company-inc.com instead of company.com)
  • Unexpected attachments, especially .zip, .html, .iso, or Office files asking to “enable content”
  • Links that don’t match: hover shows a different destination than the text
  • Generic greeting (“Dear Customer”) from someone who should know your name, or oddly specific personal details from someone who shouldn’t
  • A change in normal process: a vendor who always invoices through a portal now emails a PDF; a CEO who never texts suddenly does
  • Pressure to keep it quiet: “Don’t loop in accounting, I’ll explain later”
  • Login pages reached from an email link. Legitimate services rarely need you to log in from an email.

The single most effective habit: verify money and credential requests through a different channel. Call the vendor on the number you already have. Walk to the CEO’s office. It takes two minutes and defeats nearly every phishing attack that gets through the filters.

How to protect your business from phishing

  1. Multi-factor authentication on every account, using phishing-resistant methods (authenticator app with number matching, or hardware keys) rather than SMS or plain push. See multi-factor authentication.
  2. Email security filtering that goes beyond spam: link rewriting and scanning, attachment sandboxing, impersonation detection, and BEC detection that flags unusual payment language.
  3. DMARC, SPF, and DKIM configured for your domain so attackers can’t send email that appears to come from you.
  4. Security awareness training with simulated phishing at least quarterly, so employees practice recognizing attacks before the real one arrives. See security awareness training.
  5. A payment verification policy: any change to vendor banking details or any wire over a threshold requires voice confirmation on a known number. Written, enforced, no exceptions for executives.
  6. Endpoint detection and response on every device, so a clicked attachment is caught before it becomes ransomware.
  7. Conditional access and mailbox monitoring: block logins from unexpected countries, alert on new forwarding rules and new MFA devices.
  8. Least privilege: the account that gets phished shouldn’t be an admin.
  9. An easy way to report. A “Report phishing” button in Outlook, and a culture where reporting is praised, not punished.
  10. An incident response plan for the click that gets through.

What to do if someone clicked

Speed matters more than blame.

  1. Report it immediately to IT or your managed security provider. Don’t wait to see if anything happens.
  2. If credentials were entered: reset the password now, revoke active sessions, check for new mailbox rules and MFA devices, and review sent items for anything the attacker sent.
  3. If an attachment was opened: disconnect the device from the network and let the security team check it. Don’t power it off; evidence lives in memory.
  4. If money was sent: call the bank immediately to attempt a recall, then file a report with the FBI at ic3.gov. Recovery is possible in the first 24 to 72 hours and rare after.
  5. Check who else got it. Phishing rarely targets one person.
  6. Notify affected parties if data was exposed, per your legal and contractual obligations.
  7. Do a post-incident review. What let it through, and what stops the next one.

Anti-phishing tools compared

Tool What it does Typical cost Stops
Built-in email filtering (Microsoft 365, Google) Basic spam and malware blocking Included Bulk, obvious phishing
Advanced email security (Microsoft Defender for Office 365 P2, Proofpoint, Mimecast, Abnormal) Link scanning, attachment sandboxing, impersonation and BEC detection $3 – $8 / user / mo Most targeted phishing and BEC
Phishing-resistant MFA Blocks credential use even when the password is stolen $0 – $6 / user / mo Credential phishing, MFA fatigue
Security awareness training platforms (KnowBe4, Proofpoint, Hoxhunt) Training plus simulated phishing and reporting $2 – $6 / user / mo The human click
DMARC monitoring Enforces domain authentication, reports spoofing attempts $0 – $200 / mo Attackers impersonating your domain
EDR / MDR Catches malware after a click $8 – $25 / device / mo Payload execution
Managed cybersecurity service All of the above, configured and monitored $50 – $150 / user / mo The whole chain

Common mistakes

  • Relying on “our people know better.” Everyone clicks eventually. The question is what happens next.
  • SMS or basic push MFA. Both are routinely defeated by phishing kits.
  • Punishing the person who clicked. It guarantees the next click goes unreported.
  • No payment verification policy, or one the CEO is exempt from. Attackers impersonate the CEO for that reason.
  • Training once a year. Skills fade in weeks; attacks change monthly.
  • Not monitoring mailbox rules. Forwarding rules are how attackers stay in after a password reset.

Sixwatch team planning an IT roadmap

How Sixwatch stops phishing

Sixwatch’s managed cybersecurity includes the full anti-phishing chain for businesses across Tampa Bay and Cincinnati: advanced email security with BEC detection, phishing-resistant MFA, DMARC enforcement, quarterly simulated phishing with training, mailbox monitoring for forwarding rules and suspicious logins, and endpoint detection for the click that gets through.

When an employee reports a suspicious email or admits a click, our 30-minute emergency remote response puts an engineer on it before the attacker has time to act. Founder John Owens has spent 25+ years watching phishing evolve, and our 5.0 Google rating includes clients whose “I think I clicked something” call ended with nothing lost.

Book a 15-minute call or request a proposal.

Frequently asked questions

What is phishing in simple terms? A fake message, usually an email, designed to trick you into giving up a password, opening malware, or sending money to a criminal.

What is the difference between phishing and spear phishing? Phishing is sent in bulk to many people. Spear phishing is targeted at one person or company using details about them, which makes it far more convincing.

What is the most common type of phishing? Credential phishing: a fake login page, usually mimicking Microsoft 365 or Google, that captures usernames and passwords.

What happens if I click a phishing link? Depending on the attack, you may land on a fake login page, trigger a malware download, or nothing visible may happen while a script runs. Report it immediately; the damage is usually preventable if action is taken within minutes.

How do I know if an email is phishing? Check the actual sender address, hover over links before clicking, and be suspicious of urgency, money requests, and unexpected attachments. When in doubt, verify through a phone call to a known number.

Can MFA stop phishing? Phishing-resistant MFA (authenticator apps with number matching, or hardware security keys) stops most credential phishing. SMS codes and simple push approvals can be bypassed.

What is business email compromise? An attack where a criminal uses a real or impersonated business email account to redirect payments or request fraudulent transfers. It’s the most costly form of phishing.

How do businesses prevent phishing? Layered defenses: email security filtering, phishing-resistant MFA, DMARC, regular training with simulations, a payment verification policy, endpoint detection, and a response plan.

Glossary

  • BEC: Business email compromise; payment fraud via a compromised or impersonated account.
  • Credential harvesting: Collecting usernames and passwords through fake login pages.
  • DMARC / SPF / DKIM: Email authentication standards that prevent domain spoofing.
  • Lookalike domain: A domain registered to resemble a real one (micros0ft.com).
  • MFA fatigue: Repeated MFA prompts sent until the user approves one.
  • Payload: The malware delivered by a phishing attachment or link.
  • Quishing: Phishing via QR codes.
  • Smishing / vishing: Phishing via SMS / voice calls.
  • Spear phishing: Targeted phishing using personal or company details.
  • Whaling: Phishing aimed at or impersonating executives.

Want to know how many of your employees would click? Book a 15-minute call · Request a proposal

IT Consulting in Port Charlotte, FL

October 9, 2026

What Is Ransomware? How It Works, Whether to Pay, and How to Stop It

October 8, 2026

Cybersecurity Services in Port Charlotte, FL

October 7, 2026

Managed IT Services Pricing: What Businesses Actually Pay in 2026

October 6, 2026

Managed IT Services in Port Charlotte, FL

October 5, 2026

Cloud Services in Bradenton, FL

September 30, 2026

What Is a Managed Service Provider (MSP)?

September 29, 2026

IT Outsourcing in Bradenton, FL

September 28, 2026

IT Consulting in Bradenton, FL

September 25, 2026

What Is Cybersecurity? A Plain-English Guide for Business Owners

September 24, 2026

Cybersecurity Services in Bradenton, FL

September 23, 2026

Managed IT Services: What They Are, What’s Included, and What They Cost

September 22, 2026

Managed IT Services in Bradenton, FL

September 16, 2026

Cloud Services in Fort Myers, FL

September 11, 2026

IT Outsourcing in Fort Myers, FL

September 9, 2026

IT Consulting in Fort Myers, FL

September 7, 2026

Cybersecurity Services in Fort Myers, FL

September 4, 2026

Managed IT Services in Fort Myers, FL

September 2, 2026

Cloud Services in Sarasota, FL

August 28, 2026

IT Outsourcing in Sarasota, FL

August 26, 2026

IT Consulting in Sarasota, FL

August 24, 2026

Cybersecurity Services in Sarasota, FL

August 21, 2026

Managed IT Services in Sarasota, FL

August 19, 2026

IT Support in Sarasota, FL

August 17, 2026

Cloud Services in Naples, FL

August 14, 2026

IT Outsourcing in Naples, FL

August 12, 2026

IT Consulting in Naples, FL

August 10, 2026

Cybersecurity Services in Naples, FL

August 7, 2026

Managed IT Services in Naples, FL

August 5, 2026

Cloud Services in St. Petersburg, FL

July 31, 2026

IT Outsourcing in St. Petersburg, FL

July 29, 2026

IT Consulting in St. Petersburg, FL

July 27, 2026

Cybersecurity Services in St. Petersburg, FL

July 24, 2026

Managed IT Services in St. Petersburg, FL

July 22, 2026

Cloud Services in Clearwater, FL

July 17, 2026

IT Outsourcing in Clearwater, FL

July 15, 2026

IT Consulting in Clearwater, FL

July 13, 2026

Best Cybersecurity Services in Clearwater, FL | Sixwatch

July 10, 2026

Managed IT Services in Clearwater, FL

July 8, 2026

Best Cloud Services in Cincinnati | Sixwatch

July 3, 2026

IT Outsourcing in Cincinnati | Sixwatch

July 1, 2026

Cybersecurity Services in Cincinnati | Sixwatch

June 29, 2026

IT Consulting in Cincinnati | Sixwatch

June 29, 2026

Managed IT Services in Cincinnati | Sixwatch

June 24, 2026

IT Support in Cincinnati | Sixwatch

June 22, 2026

Cloud Services in Tampa, FL | Sixwatch

June 19, 2026

IT Outsourcing in Tampa, FL | Sixwatch

June 17, 2026

IT Consulting in Tampa, FL | Sixwatch

June 15, 2026

Cybersecurity Services in Tampa, FL | Sixwatch

June 12, 2026

Managed IT Services Tampa, FL | Sixwatch

June 10, 2026