Skip to content

Phishing

Phishing uses a deceptive message to influence a target into taking an action that benefits the attacker. The action may expose credentials, money, information, systems, or access, or may establish a foothold for later activity.

Email remains a common delivery channel, although phishing also appears through collaboration tools, messaging platforms, social media, file-sharing services, ticketing systems, and other business applications. The claimed source may be a trusted person, internal function, supplier, service provider, government body, or technology platform.

Phishing gains credibility by placing a request inside a familiar communication pattern or routine workflow. Branding, known names, expected notifications, and business context can reduce scrutiny before the sender, destination, or requested action is independently verified, and a professionally written message may carry few obvious anomalies to interrupt that.

Phishing adapts to the communication channel and process being targeted. Account alerts, invoices, shared documents, delivery notifications, payment requests, security notices, meeting invitations, and internal business messages can all carry the same underlying structure.

A phishing message normally establishes a claimed source, supplies a reason for contact, and directs the target towards an action. Tailoring adds real organisational context: an existing thread, a ticket reference, a supplier name, or familiar branding lifted from legitimate correspondence. The surface wording changes from one campaign to the next, but this underlying arrangement of source, reason, and requested action holds across variants, particularly where the action touches credentials, money, access, or sensitive information.

Phishing often combines the following elements:

ElementWhat it meansExamples
Claimed sourceThe person, function, organisation, or service the message appears to represent.Supplier, executive, IT support, cloud service, courier, HR, finance, customer, service provider.
Reason for contactThe context given for the message and requested action.Account issue, invoice, shared file, delivery update, security alert, payment change, document review.
Requested actionThe action the message seeks from the target.Open a link, open an attachment, approve a request, enter credentials, make a payment, disclose data.
Delivery mechanismThe mechanism through which the action is presented or reached.Email link, attachment, QR code, shared document, login page, calendar invitation, chat message, file transfer.
Legitimacy detailThe copied, spoofed, or genuine context that makes the message appear credible.Logos, signatures, real names, supplier details, previous thread text, ticket numbers, familiar branding.
Pressure or influenceThe condition used to increase compliance or reduce scrutiny.Urgency, authority, fear, curiosity, routine, convenience, financial pressure, account lockout warning.

Phishing indicators often appear as inconsistencies between the message, sender, process, or destination. Authentic branding and polished language do not remove the significance of an anomalous request or contact path.

IndicatorWhat to look for
Unexpected messageThe message arrives without an established context or requests action unrelated to current activity.
Sender mismatchDisplay name, email address, domain, reply-to address, or sending service differs from the claimed source.
Link mismatchVisible link text, destination preview, shortened URL, QR destination, or login page does not align with the claimed organisation or service.
Unexpected attachmentAn unanticipated file, invoice, document, archive, macro-enabled file, or file-sharing notification accompanies the request.
Credential requestPasswords, MFA codes, recovery codes, tokens, account approvals, device approvals, or login through an unfamiliar page are requested.
Payment or supplier changePayment, bank detail, invoice, purchase order, payroll, gift card, or supplier record changes are introduced through the message.
Urgency or fearAccount closure, missed deadlines, failed payments, security incidents, delivery problems, legal action, or business disruption are used to accelerate action.
Process bypassApproval, procurement, finance, IT, helpdesk, document release, or supplier validation processes are expected to be bypassed.
Unusual tone or timingWording, timing, formality, urgency, or request style differs from the claimed sender or established process.
Verification resistanceCallback, escalation, ticketing, manager confirmation, or another approved verification path is discouraged.