Home Glossary What is Phishing?
Glossary · Cybersecurity 101

What is Phishing?

Phishing is responsible for over 90% of successful breaches — and modern variants can bypass multi-factor authentication entirely.

Glossary · Phishing

Phishing is the use of deceptive communications to trick people into revealing credentials or executing malicious content — responsible for over 90% of successful cyberattacks.

Phishing is a category of social engineering attack in which an attacker impersonates a trusted entity — a bank, a vendor, a colleague, a government agency — to deceive a target into taking a harmful action: clicking a malicious link, opening a malicious attachment, providing credentials, or authorizing a fraudulent wire transfer.

The Verizon 2025 Data Breach Investigations Report found phishing involved in over 91% of successful breaches. It remains the most effective initial access vector not because defenses haven't improved, but because human psychology — the tendency to trust familiar-looking communications and to act quickly on urgent requests — is more reliable for attackers than technical exploits.

Types of phishing attacks

  • Phishing: Mass campaigns sent to thousands of targets, using generic lures (package delivery, password reset, invoice) that will land for some percentage of recipients
  • Spearphishing: Targeted attacks crafted for a specific individual, incorporating personal details gathered from LinkedIn, company websites, or previous breaches to appear credible
  • Business Email Compromise (BEC): Attacks targeting employees with authority over financial transactions — CFOs, accounts payable staff, controllers — to authorize fraudulent wire transfers
  • Vishing (voice phishing): Phone-based social engineering, increasingly using AI voice cloning to impersonate executives or IT staff
  • Smishing (SMS phishing): Phishing via text message, often impersonating package carriers, banks, or government agencies
  • Adversary-in-the-Middle (AiTM): Advanced technique using proxy servers to capture MFA session tokens after authentication, bypassing multi-factor authentication entirely

Why MFA isn't enough against modern phishing

Traditional MFA (one-time codes sent by SMS or generated by an authenticator app) is effective against basic credential theft but increasingly ineffective against sophisticated phishing. Adversary-in-the-Middle attacks position a proxy server between the victim and the legitimate service. The victim authenticates — including providing their MFA code — to the proxy, which forwards the credentials to the real site and captures the authenticated session token. From the victim's perspective, the login worked normally. The attacker has the session token.

Phishing-resistant MFA — hardware security keys and FIDO2 passkeys — is not susceptible to AiTM attacks and represents the current best practice for high-risk accounts.

Traditional MFA (SMS codes, authenticator apps) stops basic credential theft but is increasingly bypassed by adversary-in-the-middle attacks. Phishing-resistant MFA using hardware security keys (FIDO2) is not susceptible to these attacks. For high-risk accounts — executives, finance staff, IT administrators — phishing-resistant MFA is the current best practice.

Phishing is a mass campaign sent to many targets with a generic lure. Spearphishing is a targeted attack crafted for a specific individual, incorporating personal details to appear credible. Spearphishing is far more likely to succeed and is used in targeted attacks against specific organizations.

Stop the next attack before it starts.

Free 30-minute consultation — no commitment, no jargon, no sales pressure.

Schedule nowView pricing
Free monthly threat briefing
Chattanooga-specific threat intelligence, delivered to your inbox. No spam, unsubscribe anytime.