SardineCon SF/2026

Learn More

O que é Phishing?

SUBSCRIBE

Phishing is the use of deceptive messages, classically email, that pretend to be from a trusted party to trick people into revealing credentials or data, or installing malware. It is the most common entry point for account takeover and business email compromise, and modern kits relay logins in real time to capture one-time codes as they are typed.

What is phishing, in plain English?

Phishing is impersonation at scale. An attacker sends a message that looks like it comes from a bank, an employer, a delivery company, or a colleague, and uses urgency or fear to push the recipient into acting: click this link, log in here, confirm your details, open this file. The message and the page it leads to are built to look genuine, so the victim hands over exactly what the attacker wants.

The payload is usually one of three things: stolen credentials, stolen personal data, or installed malware. Credentials feed account takeover. Personal data feeds identity fraud. Malware opens the device for later theft. Modern phishing kits go a step further with real-time relay, sitting between the victim and the real site so that even a one-time code entered by the victim is forwarded and used within seconds, defeating basic two-factor authentication.

In the fraud stack, phishing is the most common starting point for a chain of harm. It is the front door to account takeover, business email compromise, and many payment scams. Almost everything else in scams and social engineering connects back to it in some way.

The main variants of phishing

Variant

How it is delivered

Spear phishing

Targeted at a specific person, using researched detail to look personal and credible.

Whaling

Spear phishing aimed at executives or high-value targets who can authorize payments.

Smishing

Phishing delivered by text message, often a fake delivery, bank, or toll alert.

Vishing

Phishing by voice call, impersonating a bank, agency, or support line.

Quishing

Phishing through a malicious QR code that hides the real destination.

How a phishing attack works

  1. Bait — Send the lure. A message impersonating a trusted party arrives with an urgent hook: a locked account, a failed delivery, an unpaid invoice.
  2. Hook — Drive the click. The victim clicks a link to a spoofed login page or opens an attachment that installs malware.
  3. Capture — Steal the input. Credentials and one-time codes are collected, and real-time kits relay them to the genuine site before they expire.
  4. Exploit — Cash out. The attacker logs in, takes over the account, redirects a payment, or sells the data on.

What it looks like in practice

In practice

An accounts-payable clerk gets an email that appears to come from a known supplier, referencing a real open invoice and saying the bank details have changed. The linked page mirrors the supplier portal and asks the clerk to confirm their login to view the updated remittance.

The clerk enters their credentials and a one-time code, which a relay kit forwards to the real system instantly. The attacker now controls the mailbox, watches for the next invoice, and inserts new payee details. The single phished login became the seed of a business email compromise that redirected a five-figure payment.

Why it matters for operators

Phishing sits upstream of a large share of fraud losses, so reducing it pays off across account takeover, business email compromise, and scam payments at once. The hard truth is that awareness alone is not enough: well-built lures fool careful people, and real-time relay kits erode the protection of SMS and app-based codes. That is why the strongest programs combine email authentication such as SPF, DKIM, and DMARC, easy user reporting, and phishing-resistant multi-factor like FIDO2 and passkeys that break when the domain is wrong.

The practical framing for teams is defense in depth. Assume some phishing will succeed, then make the stolen credential worth as little as possible: bind logins to the real domain, score device and session risk, and watch for the takeover behaviors that follow a successful phish rather than relying only on stopping the click.

What to watch for

  • Urgency and fear. Messages that pressure fast action over a locked account, a missed payment, or a delivery problem are the classic hook.
  • Lookalike domains and senders. Slight misspellings, extra words, or display names that do not match the underlying address.
  • Credential prompts after a link. Login pages reached through a message rather than a bookmark deserve extra scrutiny.
  • Real-time code use. A one-time code entered and consumed within seconds, followed by a payee change or new device, points to a relay kit.
  • Post-login anomalies. New device enrollment, mailbox rules, or beneficiary edits soon after a login can mark a phished account.

Quick questions

Does multi-factor authentication stop phishing?

It helps, but basic SMS and app-based codes can be defeated by real-time relay kits that forward the code as the victim types it. Phishing-resistant methods like FIDO2 and passkeys are far stronger because they bind the login to the correct domain.

What is the difference between phishing and spear phishing?

Phishing is usually bulk and generic. Spear phishing is targeted at a specific person, using researched details to look personal and credible, which makes it far more convincing and harder to catch.

How do SPF, DKIM, and DMARC help?

They are email-authentication standards that let receivers verify a message really came from the domain it claims. Properly enforced, they block a large share of spoofed sender addresses before the message reaches an inbox.

Why is phishing called the entry point for other fraud?

The credentials, data, or access it steals are the raw material for account takeover, business email compromise, and payment redirection. Stopping phishing removes fuel from many downstream fraud types at once.

Is quishing really phishing?

Yes. Quishing is phishing delivered through a malicious QR code. The code hides the real destination and often slips past email link scanners, but the goal, credential theft or malware, is the same.

What should a user do with a suspected phish?

Do not click or reply. Report it through the organization's reporting button or channel, and if a link was already clicked, change the password and alert security so the account can be watched for takeover.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

O que saber junto com Phishing