Some people try to trick you. They send fake notes to steal things. They might use a fake text. They might use a fake call. This can happen on your phone. Be very careful with links. Do you know what to look for?
Some people try to trick you online. They use fake notes to steal things. This is called phishing. It is like using a lure to fish for secrets.
They might send a fake email. They can also send a fake text. Some even use fake phone calls.
These tricks can look very real. They may look like your bank. They might even look like a real site. 
A fake note might say there is a problem. It might make you feel rushed. This makes you want to click fast.
Always be careful with links. Do not click if you are not sure. You can stay safe by being smart.
Phishing is a way that people try to trick others online. They want to steal secrets like passwords or money. The name comes from fishing. Just like a fisher uses a lure, these people use fake messages to catch victims. 
There are many ways to do this. Some people send many emails at once. This is called bulk phishing. Others use spear phishing. This is a targeted attack. The attacker uses personal facts to trick one specific person. They might even call you on the phone. This is called vishing. Some use text messages, which is called smishing.
These tricks can be very smart. Some attackers use a "middleman" method. This is called Man-in-the-Middle phishing. They sit between you and a real website. They can even grab your login tokens to get into your account. This helps them bypass security steps like two-factor authentication. They might also use fake QR codes. This is called quishing. 
Phishing is a big problem for businesses. In 2023, 94% of businesses faced these attacks. You can stay safe by being careful with links.
Phishing is a type of scam used to trick people. It is a form of social engineering. This means attackers use clever tricks to fool you. They want to steal private information like passwords. They might also try to install malware on your device. Malware is bad software like viruses, worms, or ransomware. 
There are many ways these scams work. In a bulk attack, scammers send many emails to many people. They often pretend to be a bank or a streaming service. Some attacks are more personal and are called spear phishing. These use your own information to seem real.
Some phishing tricks are very advanced. A new method is called adversary-in-the-middle, or AiTM. This attack intercepts your session tokens to act like you. 
We can look back to see how this started. The term phishing was first recorded in 1995. It appeared in a toolkit called AOHell. Some think it was used earlier in a magazine called 2600. In the 1990s, hackers used AOL to steal credit card info. 
Phishing is a growing problem for everyone. Attacks on businesses rose from 72% in 2017 to 86% in 2020. By 2023, that number rose even higher to 94%.
Phishing is a sophisticated form of social engineering and cybercrime. It involves attackers using deceptive tactics to trick individuals into revealing sensitive data. These targets often include login credentials or financial details. Attackers may also use these methods to install malware on a device. This includes harmful software like viruses, worms, adware, or ransomware. 
The mechanism of a phishing attack often relies on deception and urgency. An attacker might send a fraudulent message that looks like it is from a trusted source. This could be a bank, a government agency, or a streaming service. The message typically contains a link to a fake login page. When a victim enters their information, the attacker captures those credentials. Some modern attacks are even more transparent and mirror the target site perfectly. This allows the attacker to observe the victim as they navigate the site. They can even traverse security boundaries alongside the victim.
There are many distinct types of phishing attacks used by criminals. Bulk phishing involves sending mass messages to a wide audience without specific targeting. In contrast, spear phishing is a highly targeted attack. It uses personalized messaging and specific personal information to increase success rates. These often target executives or people in financial departments. For example, the Russian-run Threat Group-4127 once targeted over 1,800 Google accounts during a political campaign. 
Advanced attackers now use Man-in-the-Middle (MitM) techniques to bypass security. In a MitM attack, an intermediary tool intercepts communication between a user and a real service. One such tool is Evilginx, which was originally made for ethical hacking. It acts like a middleman by passing information between the victim and the legitimate website. Because it does not store passwords directly, it is harder for security systems to detect. This method allows attackers to grab session tokens and cookies instantly. By doing this, they can bypass two-factor authentication (2FA) and access accounts. Microsoft Entra has noted a rise in these adversary-in-the-middle (AiTM) attacks recently.
Attackers also use link manipulation to hide their true destination. They may use misspelled URLs or subdomains to deceive the human eye. One method is called IDN spoofing or a homograph attack. This uses visually identical characters from different alphabets to create fake addresses. For instance, a Cyrillic "а" can replace a Latin "a" in a web address. A victim might think they are visiting a legitimate site when they are not. Even digital certificates like SSL may not protect a user. This is because phishers can purchase valid certificates for their fraudulent sites.
Phishing is a rapidly growing threat to both individuals and organizations. The frequency of attacks on businesses has climbed significantly over recent years. In 2017, phishing attacks affected 72% of businesses. This number rose to 86% in 2020. By 2023, the rate of attacks on businesses reached 94%. 
The history of phishing dates back to the early 1990s. The term was first recorded in 1995 within a cracking toolkit called AOHell. Some believe the term may have appeared earlier in the magazine 2600. In the early days, hackers used AOL to steal credit card information. They used tools like AOHell to impersonate AOL staff members. These attackers would send instant messages to users to request their passwords. Today, while the tools have changed, the core goal remains the same. Protecting against these threats requires a combination of legislation, education, and technical security.
🖼️ Images & Media (5)
More to explore
✨ What else?
Related topics you might enjoy
🔬 Go deeper
More advanced topics to explore
What is Nepedia?
A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.