Email is common; phishing lures also appear in text messages, social media, search advertisements, QR codes, and collaboration platforms, while voice-based phishing is commonly called vishing.
Some campaigns imitate a familiar organization at scale; spear phishing is tailored to a particular person or group. Modern attacks may steal credentials through a convincing sign-in page, obtain MFA approval, deliver malware, redirect a payment, or persuade support staff to reset an account.
Key points
Common signalsUnexpected urgency, unusual requests, changed payment details, misleading addresses, suspicious destinations, or pressure to bypass procedure.
Technical controlsFiltering, attachment isolation, domain authentication, safe browsing, phishing-resistant MFA, conditional access, and endpoint monitoring.
Process controlsIndependent verification, payment approval, secure recovery, easy reporting, and fast investigation of reported messages.
Important limitationAwareness training helps, but it cannot make every person identify every deception; systems and workflows must tolerate human error.