What is Phishing?
Online fraud: fake emails fishing for your passwords. The bait looks genuine, but the hook is in the fine print.
Phishing is a fraud attempt where someone pretends to be a trusted sender to trick you into handing over sensitive information. The name comes from "fishing" — the attacker casts bait (an email that looks genuine) and hopes you bite. Just like fishing, many hooks are sent in the hope that someone gets caught.
The classic example is an email that appears to come from your bank, a courier, or Microsoft: "Your account is blocked — click here to log in." The link leads to a fake page that is a copy of the real one. Type in your password there and it goes straight to the scammer.
Phishing comes in several forms. There are targeted variants (spear phishing) where the attacker tailors the email specifically to you or your business, and CEO fraud where someone pretends to be the boss and asks an employee to pay an urgent invoice. What they share is playing on stress, authority, or curiosity.
Why is phishing important for your business?
Most data breaches and ransomware attacks start with phishing. A single employee clicking wrong can open the door to the entire company's systems. That makes people, not technology, the most common weak link — and that is where you should invest effort.
By training staff to recognise warning signs, backed up with two-factor authentication, you dramatically reduce the risk. A business with alert staff is simply a much harder target.
Phishing in practice
Imagine your finance manager receives an email that appears to come from you as CEO: "Hi, I am in a meeting — can you quickly pay this invoice? Urgent." The address looks almost right, but one letter is wrong. Under stress it is easy to miss.
A business with clear procedures — for example, always calling to confirm payments above a certain amount — stops the fraud immediately. That small extra check can save both money and trust.
Common questions about Phishing
What does phishing mean?
Phishing is a fraud attempt where someone pretends to be a trusted sender to trick you into giving up passwords or other sensitive information. It usually happens via fake emails with false links.
How do you recognise a phishing email?
Common warning signs are urgency and pressure, spelling mistakes, a sender address that almost but not quite matches, and links leading to unknown sites. If you are unsure, contact the sender through a known channel instead of clicking.
What should you do if you clicked a phishing email?
Change the password on the affected account immediately, enable two-factor authentication, and notify your IT contact. If you entered card details, contact your bank straight away.
Related terms
2FA / MFA
Two-factor or multi-factor authentication. Password plus SMS code or app. Stops most account takeovers. Turn it on. Now.
Data Breach
When the wrong person gets access to the right data. Like someone unauthorised walking into your archive — except you never hear the door.
DORA
The EU's digital resilience test for financial services. Not the explorer — the rules that stop banks and fintech from collapsing when IT fails.
End-to-End Encryption
Data is encrypted at the sender and only decrypted at the recipient. Middlemen only see unreadable text.
EU Hosting
Keeping your data in Europe. Like choosing a storage unit in the neighbourhood instead of one in a country whose rules you do not know.
NIS2
The EU's updated cyber security rules that say "raise your game — or else". Forces thousands of businesses to take security seriously, with fines as the wake-up call.