Attack technique

Phishing

Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.

Definition

Phishing is a form of social engineering in which an attacker impersonates a legitimate organization or individual, usually over email but also by SMS, voice call, instant messaging, or QR code, to deceive a target into taking a harmful action. That action is typically disclosing login credentials, entering payment or personal data on a fake page, approving a fraudulent transaction, or opening an attachment or link that installs malware. Phishing exploits human trust and urgency rather than technical vulnerabilities, which makes it one of the most common entry points for data breaches and financial fraud.

A phishing attack usually follows a predictable pattern. The attacker crafts a message that mimics a familiar brand or internal sender, often a bank, a payroll system, a government agency, or an IT helpdesk. The message creates pressure through urgency, fear, or curiosity, for example a warning that an account will be suspended, an unexpected invoice, or a delivery that needs confirmation. It then directs the target to a malicious link, a credential-harvesting page, or an attachment. Once the victim enters their details or runs the file, the attacker captures the credentials or gains a foothold in the network.

Phishing comes in several variants distinguished by channel and targeting. Spear-phishing is aimed at a specific person using personalized details, while whaling targets senior executives. Vishing uses phone calls, smishing uses SMS, and quishing uses QR codes. Clone-phishing replays a legitimate message with a swapped malicious link. Business email compromise impersonates an executive or supplier to authorize fraudulent payments. Despite the different channels, the underlying technique is the same: abuse trust to provoke an unsafe action.

Phishing matters because it is the dominant route into most organizations. A single employee who clicks a link and enters a password can expose an entire network, and in regulated sectors such as banking and government, the consequences include financial loss, regulatory penalties, and reputational damage. Because attackers continually refine their lures, technical filters alone are never enough. Lasting defense depends on layered email security, multi-factor authentication, and a workforce trained to recognize and report suspicious messages.

At a glance

Severity
High
Prevalence
Very common
Primary targets
Employees at every level, via email and other messaging channels

How it works

  1. 1

    Impersonation: the attacker crafts a message that mimics a familiar brand or internal sender, such as a bank, payroll system, or IT helpdesk.

  2. 2

    Pressure: the message manufactures urgency, fear, or curiosity, for example a warning that an account will be suspended or an unexpected invoice.

  3. 3

    Malicious action: it directs the target to a fake login page, malicious link, or infected attachment.

  4. 4

    Capture: once the victim enters their details or opens the file, the attacker captures credentials or gains a foothold in the network.

  5. 5

    Exploitation: the stolen access is used for fraud, data theft, or as a launchpad for further attacks such as business email compromise.

Warning signs

  • Urgent or threatening language demanding immediate action
  • Sender address that looks almost right but is slightly off
  • Generic greeting instead of your actual name
  • Unexpected attachment or a link that does not match the claimed sender
  • Requests to confirm a password, OTP, or payment detail by email

How to defend

  • Pause before clicking; verify urgent requests through a separate channel
  • Check the sender's actual email address, not just the display name
  • Hover over links to preview the destination before clicking
  • Enable phishing-resistant multi-factor authentication
  • Report suspicious messages instead of deleting them silently

Real-world example

An employee at a Jakarta bank receives an email claiming to be from the IT helpdesk, warning that their Microsoft 365 account will be suspended within 24 hours unless they verify their password. The link opens a convincing fake login page hosted on a lookalike domain. Believing the warning, the employee enters their credentials, unknowingly handing them to the attacker.

How Claro helps

Claro helps organizations measure and reduce phishing risk by running realistic, locally relevant phishing simulations and pairing every result with just-in-time training in English and Bahasa Indonesia. Instead of tracking training completion alone, Claro scores real behavior across simulations, reporting rates, and repeat-clicker trends, then feeds that into a human risk score and compliance evidence aligned with OJK, ISO 27001, and Indonesian data protection requirements. The goal is durable behavior change: people who can spot and report phishing, not just employees who passed a course.

Frequently asked questions

What is Phishing?

Phishing is a cyberattack where an attacker poses as a trusted person or organisation to trick you into revealing sensitive information, such as passwords or one-time codes, or into clicking a malicious link. It most often arrives by email, but also by SMS, chat, and phone.

What is the difference between phishing and spear phishing?

Phishing is sent broadly to many recipients using generic bait, while spear phishing is personalized and targeted at a specific person or organization using researched details. Spear phishing has lower volume but much higher success rates because the message feels relevant.

How can I tell if an email is phishing?

Look for urgency or threats, a sender address that does not quite match the claimed organization, generic greetings, unexpected attachments or links, and requests for credentials or payment details. When in doubt, verify through a known channel rather than replying to the message.

Does spam filtering stop phishing?

Spam filters catch a meaningful share of phishing but not all of it, especially well-crafted or newly registered lookalike domains. Because attackers constantly adapt, layered defenses such as multi-factor authentication and trained, vigilant employees are essential alongside technical filters.

What should I do if I clicked a phishing link?

Do not enter any information on the page, disconnect from the network if on a work device, change any passwords you may have exposed, and report the incident to your security team immediately so they can assess and contain any damage.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo