(518) 292-4500|sales@logical.net|M-F 8am-5pm · 24/7 SOC
MSP 501 Winner 2025Client Portal →
Threats & Attacks

What is Phishing?

Phishing is a social engineering attack that uses fraudulent messages, usually email, sometimes text or voice, to trick users into revealing credentials, clicking malicious links, or installing malware.

How Phishing works

Three-step view of how it operates in practice.

  • Target. Attackers identify a victim and research context — recent vendor payments, common travel, org chart. Personalization dramatically increases success.
  • Deliver. A crafted message lands in the inbox, mimicking a trusted brand, executive, or vendor. Links and attachments are the payload carriers.
  • Exploit. The victim clicks, enters credentials on a fake site, or runs the attachment. The attacker uses stolen credentials or installed malware to pivot.

Why Phishing matters

Phishing remains the most common way attackers first get inside an organization, and the chain from one harvested password to a compromised mailbox to redirected payments can run its course in days. The defensive math favors small businesses for once: filtering, a reporting button, and a no-blame culture are inexpensive, and together they convert your whole staff from attack surface into a detection network.

Phishing vs spear phishing vs smishing vs vishing

  • Bulk phishing. Mass-produced fraud sent to thousands of inboxes — fake delivery notices, account alerts, invoice lures. Low effort per message; the volume does the work.
  • Spear phishing. A message researched and written for one recipient, referencing real colleagues, vendors, or projects. Far fewer messages, far higher success rate.
  • Smishing. The same con over text message, a package held, a bank alert, a 'boss' asking for a quick favor. Effective because texts feel personal and phones hide sender detail.
  • Vishing. Fraud by voice call, often posing as IT support or a bank, increasingly aided by caller-ID spoofing and AI-cloned voices. The medium changes; the manipulation is identical.

Common Phishing mistakes

  • Punishing the people who click. Shame-based training teaches one lesson: hide it. The employee who clicks and reports within minutes has done the security team an enormous favor — build a culture where fast reporting is praised, because it is your true early-warning system.
  • Measuring clicks instead of reports. Click rate on simulations tells you who fell for one email once; report rate tells you whether the organization raises alarms. Track and celebrate reporting — it's the metric that shortens real incidents.
  • Making reporting hard. If flagging a suspicious message means finding an address and writing an email, most people won't bother. A one-click report button in the mail client, with a fast human acknowledgment, is worth more than another training video.
Related terms

Need this in your environment?

We turn these controls on for Capital Region organizations every day. Let's talk about yours.