One hopper feeding four outlet arms of different fittings that send out many identical lures, with a single narrow return tube carrying one capsule back to a locked vault.

Phishing

Phishing is an attempt to get someone to hand over information, money or access by pretending to be a party they trust. It is not a single technique. MITRE ATT&CK scatters it across six tactics, and the named variants differ by channel, by who is targeted, by objective, and by mechanism.

Look at what people actually ask about phishing. Something becomes obvious quickly. The most common questions are not "what is phishing". They are "what happens if I clicked a link but did not enter my details", "will I get hacked if I opened the email", and "how do I check whether I was phished".

Those are the questions of someone who has already done the thing, and they are asked in the first person and the past tense. Almost every page in a full capture of both major search engines is written for the reader who has not clicked yet.

So this page does three things, in this order. It answers the question the frightened reader arrived with. Then it explains why the published lists of phishing types disagree with one another. Then it reports what the only credible public count actually measures, which is not what most people assume.

A bolted vault door stands untouched while a crest-stamped plate clipped over a small reception hatch takes in a slip and hands a key plate back out.

Explain it like I'm 10

Someone pretends to be a person or a company you trust, and asks you for something. A password. A payment. A click on a link. That is the whole thing.

The trick is the pretending, not the technology. Nothing has to be hacked for this to work, because the plan is to get you to hand it over.

The word is a joke spelling of "fishing", and the metaphor is exact. Bait goes out to a lot of people, most of them ignore it, and the few who bite are the catch. It has survived thirty years as a name because it describes the method honestly.

Phishing Quiz

Test your knowledge about Phishing - maybe you already know everything about it.

EasyQuestion 1 of 3

What is phishing an attempt to get someone to hand over?

Three lanes of increasing depth: one ending at an opened envelope with the gate shut, one resting against a socket with no keyway, one with a key fully seated and four repair fittings clamped along it.

If you have just clicked something

Start here, because this is what most people arrive wanting to know, and the answer is more reassuring than the panic suggests.

Opening an email is not the same as being compromised. Reading a message, on its own, does not hand anything over. If you opened something, looked at it, felt uneasy and closed it, the most likely outcome is that nothing happened at all.

Clicking a link without typing anything is a far better position than clicking and typing. A link on its own loads a page. Most of the harm in phishing comes from what you enter into that page, or from a file you go on to open, rather than from the visit itself.

That is the honest general answer. Here is what to do, in order, if you went further than looking.

  1. If you entered a password, change it now on that account, and change it anywhere else you have used the same one. This is the step that matters most and it is the one people delay.
  2. Turn on multi-factor authentication on that account if it is not already on.
  3. If it was a work device or a work account, tell whoever runs IT immediately. Do not wait until you have worked out whether it was serious. Reporting early is more useful than reporting correctly, and a security team would rather hear about ten false alarms than miss one real one.
  4. If money or financial details were involved, contact the bank or card provider directly, using a number you look up yourself.
  5. Report it. In the United States, the Federal Trade Commission publishes consumer guidance on phishing and runs the federal identity-theft reporting route. Most countries have an equivalent national reporting service.

#### The official routes exist and are hard to find

Something the search results make obvious once you look for it. Six separate government bodies publish guidance on this term across the capture used for this article: the FTC, the FBI, CISA, the US Office of the Comptroller of the Currency, the Canadian Centre for Cyber Security and the Canadian Anti-Fraud Centre.

Not one of them appears in either engine's visible top ten. All six sit inside collapsed question blocks, below vendor pages and an encyclopedia entry. The advice they give is free, unconflicted and written by the bodies that also take the reports, and a person in a hurry will scroll past every one of them. That is a ranking outcome rather than a conspiracy, and it is fixable in one step: if you need to report something, search for the agency by name rather than searching for the crime.

One thing worth saying plainly, because the tone of a lot of security writing implies the opposite. Falling for a phishing message is not evidence that you were careless. The UK's National Cyber Security Centre puts it in its own published guidance: "No training package, including phishing simulations, can teach users to spot every phishing attempt." That is a national security agency saying that nobody catches all of them, and it is written into guidance for organisations rather than offered as consolation.

If that was what you came for, you are done, and the rest of this page is about how the category is organised.

A worn plinth with a rotary dial and a horn, tubed to a newer plinth with a casting arm and a baited hook, both carrying identical prefix plates.

Where the word comes from

This gets asked often enough to deserve an answer. The reference works date the term to 1995, first recorded in a cracking toolkit used against an early consumer internet service, with the suggestion that it may have circulated earlier in a hacker magazine. That dating is attributed here as reported rather than asserted, because it rests on secondary sources rather than a primary record.

The spelling is the interesting part. The "ph" follows phreaking, a 1970s term for manipulating telephone systems, which was itself a play on "phone freak". So the word carries a small piece of history: it was coined by people who had already been renaming things with "ph" for twenty years.

Four rotary dials each set to a different position, feeding one tube down to a rail with a single slot where a plate is jammed at an angle.

Why no two lists of phishing types agree

This one is checkable in about thirty seconds. One major search engine's own answer for this term lists four types of phishing. Its own question block, on the same screen, asks "what are the three types of phishing?". Other pages in the same results list five, six, eight. No two of them agree, and none of them explains why.

The reason is not that some lists are wrong. It is that the lists are answering four different questions at once and presenting the answers as one series.

  • Channel. What carries the message. Email, text, voice call, QR code, chat platform.
  • Target selection. How many people, and chosen how. MITRE's own threshold is worth quoting because it is broader than the common one: "In spearphishing, a specific individual, company, or industry will be targeted by the adversary."
  • Objective. What the attacker wants at the end. Access to a system, information for later, or money directly.
  • Mechanism. What the victim is actually asked to do. Click a link, open a file, call a number, paste a command, approve a prompt.

A name from one axis is not an alternative to a name from another. Spear phishing and smishing are not rivals on a list; a targeted text message is both at once, and most real messages are one value from each of the four columns. That is why the lists never reconcile: they are flattening a four-dimensional thing into one line.

The same message, placed on all four axes

Take one message: a text sent to a single named finance manager, asking her to ring a number about an unpaid invoice.

Its channel is SMS, so it is smishing. Its target selection is one specific person chosen deliberately, so it is spear phishing. Its objective is a payment, so it is business email compromise. Its mechanism is a callback, so it is callback phishing.

One message, four correct names, none of them wrong and none of them sufficient. Any list that asks you to file it under a single heading is asking the wrong question. The useful habit is not choosing the label but reading all four values, because each one points at a different control.

There is a practical consequence, too. Channel share moves fast. In a single quarter of 2025, the Anti-Phishing Working Group recorded the use of SMS for phishing rising while the use of QR codes fell by 9 percent. A list of types is a snapshot of what was popular when it was written, not a stable taxonomy.

One feed tube entering a hub whose eight sockets are all different fittings, with capsules leaving through every one of them.

Types of phishing

These are the variants covered in this glossary, grouped by the axis that actually names each one. Read them as examples of the argument above rather than as a list to memorise.

Email phishing

The default case, and the one the word means when nobody qualifies it. A message arrives by email, impersonating a brand, a colleague or an institution, and asks the recipient to click, open or reply. It is untargeted in the classic form: the same message goes to very large numbers of people, and the economics work because sending costs almost nothing. Everything else on this list is email phishing with one variable changed. It is on the channel axis, and it is the value that every other channel is measured against.

Smishing

Phishing delivered by text message. The channel change matters more than it sounds, because a text has no attachment, no sender domain to inspect, and very little room for the visual cues people are trained to look for. It also arrives on a device that is usually personal, often held in one hand, and rarely covered by the filtering that protects a work inbox. Regulators publish more consumer guidance about this variant than about any other, and the advice on it is unusually consistent across countries.

Vishing

Phishing carried out by voice call. The attacker rings, impersonates someone the target would normally help, and talks them into an action. What separates it from the rest of the list is that it is a live conversation, so the attacker can adapt in real time to whatever the victim says. That makes it harder to defend with content inspection and easier to defend with process. The documented cases are dominated by callers impersonating internal IT rather than banks, which is not what the public image of the technique suggests.

Quishing

Phishing that uses a QR code in place of a visible link. The code is the point: it moves the click from a screen where a link can be inspected to a camera on a device that may not be managed, and it defeats scanning that works on visible URLs. It appears both in emails, usually inside an attachment, and physically in the world on stickers and posters. It is a channel variant with a device-switching side effect, and that side effect is the part that matters to an organisation.

Spear phishing

Not a channel at all, which is why it sits awkwardly on most lists. Spear phishing describes target selection: the message is aimed at a specific individual, company or industry, and is written using information gathered about them beforehand. It can be delivered by any channel on this page. The research that exists suggests the personalisation is what raises the response rate, and that generating it is no longer the constraint it once was. Whaling, a term this glossary treats as a narrower case, is spear phishing aimed at senior executives.

Business email compromise

An objective, not a delivery method. BEC describes phishing whose goal is a payment or a change to where payments go, usually by impersonating an executive, a colleague or a supplier. It frequently involves no malicious link or attachment at all, which is why it passes filters designed to find them. It is the variant with the clearest financial measurement attached to it, because national reporting bodies count fraud losses by crime type. If a phishing message is trying to move money rather than steal credentials, this is the name for it.

Callback phishing

A mechanism variant, also called TOAD. The email carries a phone number instead of a link, and the victim places the call, which means the attacker has to staff a phone line rather than just send messages. The lure is typically a low-value invoice or subscription notice, and the absence of any link is what gets it through email filtering. It is the only variant on this list where the attacker's costs rise with the number of victims, because each one requires a conversation.

ClickFix

The other mechanism variant, and the most recent. A page or an attachment presents a fake error or a fake verification step, and instructs the person to run a command on their own machine to fix it. Nothing is downloaded through a channel that inspects downloads, because the victim carries the payload across that boundary by hand. The framework files it under execution rather than initial access, which is a precise way of saying that whatever brought the person to the page is a separate problem with a separate name.

A very large counting drum and a small one fed by the same intake, above which a collection funnel has a fine filter collar with capsules backing up against it.

How much phishing there actually is

Not one page in a full capture of both major search engines carries a phishing volume figure of any kind. The number exists, and it says something more interesting than the usual framing.

The Anti-Phishing Working Group publishes a quarterly Phishing Activity Trends Report. The edition published on 18 February 2026 states it plainly: "Phishing attacks occurred at a high but steady pace in 2025. During 2025, APWG observed 3.8 million phishing attacks, which was up slightly from 3.76 million in 2024."

Steady. Not surging, not exploding, not up several hundred percent. Up slightly, on a very large base.

Before that figure travels any further, it needs its definition attached, because it does not mean what most people will assume. The report is explicit that it counts unique reported phishing websites: "APWG measures reported phishing sites, which is a more relevant metric than URLs. A synonym for sites is attacks." So 3.8 million attacks means 3.8 million distinct reported phishing sites. Not victims, not emails, not people who lost money.

#### What the monthly numbers look like

The underlying detail is more concrete than the headline. In the final three months of 2025 the monthly counts of unique reported phishing websites ran 269,558 in October, 287,995 in November and 295,691 in December, against 16,284, 14,980 and 14,091 distinct email campaigns in the same months. A total of 866 unique brands were identified across the quarter.

Hold those two series next to each other. Sites outnumber campaigns by roughly twenty to one, which is a reminder that a single campaign stands up many pages, and that counting pages and counting campaigns produce very different-looking numbers from the same activity.

The quarterly shape matters as well. The fourth quarter of 2025 saw 853,244, down 4 percent from 892,494 in the third quarter, and down from 1,130,393 in the second quarter, which the report describes as the largest quarterly total since Q2 2023.

One variant inside the same report, moving in the other direction

The same edition carries a separate series contributed by one of its member companies, covering business email compromise specifically. The number of wire transfer BEC attacks it observed rose 136 percent between the third and fourth quarters of 2025, and the average sum requested was $50,297, up 4.5 percent on the previous quarter.

Two qualifiers travel with that. It is one contributing company's view rather than the consortium's, and it counts attempts rather than losses, which makes it a different measurement from the national fraud-loss reporting that usually gets quoted for this variant.

The composition is striking on its own terms: in that quarter gift card requests made up 59 percent of the scam types recorded, against 17 percent asking for a wire transfer.

The instrument is being obstructed, and its keepers say so

The same report contains a paragraph that should temper any confident statement about phishing volume, including the one above.

Its record of spam campaigns fell from 81,710 in the third quarter to 45,355 in the fourth, a 45 percent drop in three months. The explanation is not that campaigns stopped:

"Email systems are preventing users from forwarding phishing lure emails and sending phishing URLs to APWG and similar organizations, because the mail systems perceive those as harmful. This cuts into the number of successful reports to reportphishing@apwg.org, one of APWG's main collection methods."

Read that again. The controls built to stop phishing are now stopping people from sending phishing samples to the organisation that counts phishing. The instrument is being degraded by the thing it measures the defence against, and the people holding the instrument are the ones telling you.

That does not make the figure useless. It makes it a floor rather than a total, and it means a year-on-year comparison is being drawn across a collection method that changed during the period. No adjusted series was located.

One spindle feeding six separate filing bays, two of them identical except that one receives a foothold block and the other a record slip, with only one tube collared.

Phishing is not one tactic

The field talks about phishing as a way in. The framework does not agree, and this is the part that is hardest to see from any single page about any single variant.

Object

What it covers

Tactic

T1566 Phishing

Messages sent to gain access, with four spearphishing sub-techniques

Initial Access

T1598 Phishing for Information

The same messages, sent to collect information rather than execute code

Reconnaissance

T1534 Internal Spearphishing

Phishing sent from an already-compromised internal account

Lateral Movement

T1204.004 Malicious Copy and Paste

The victim runs a command themselves

Execution

T1684 Social Engineering

Impersonation and email spoofing as methods

Stealth

T1657 Financial Theft

The objective, where the money actually moves

Impact

Two rows there answer each other. T1566 and T1598 have the same four sub-technique names between them - attachment, link, service, voice - and differ in nothing except what the attacker is trying to get. Identical delivery, identical channels, identical social engineering, filed under two different tactics because one collects information and the other delivers a foothold.

That is the objective axis, made structural. The framework separates on it because separating on it is what makes a technique mappable to a defence; the field's type lists do not, which is why the same names keep appearing in different places on different lists.

Six tactics. A technique is filed by what it achieves rather than by what it looks like, which is why the same phone call is reconnaissance when it collects information and initial access when it delivers a foothold.

The practical consequence is uncomfortable. A control inventory that maps phishing to one technique has covered a fraction of it, and the parts most likely to be missed are the least intuitive ones: the message that arrives from a real colleague's real account, and the objective at the far end, which is filed under impact alongside ransomware.

One detail argues for checking a mapping rather than remembering it. The social engineering technique above was created on 14 April 2026, and the identifier it replaced has been retired and now redirects. A mapping written eighteen months ago points at something that no longer exists.

A scale with no pan, a rack of blank reading plates, a gauge whose mounting rail has shifted with loose bolts, and an empty ranking comb.

What this page cannot tell you

No public figure was located for how many people are successfully phished. The count above counts sites. National crime datasets count reported losses by category. Neither answers the question most readers actually have, which is how often this works.

The count itself sits on a moving instrument, by its keeper's own account, and no adjusted series exists. Any year-on-year phishing comparison, including the one on this page, carries that uncertainty.

No source ranks the variants by share on a basis that allows comparison, which is part of why the type lists disagree. This page has not ranked them either, and the order above is by classification axis rather than by frequency.

The etymology is attributed rather than established. It rests on reference works rather than a primary record.

And the guidance in the third section is general consumer guidance, sourced to the bodies that publish it. It is not incident response for an organisation, and anyone dealing with a compromise at work should be talking to the people who run their systems rather than reading a glossary.

A readout with four pointers held in one row, beside a recorder ribbon carrying a level trace with a fixed stop bar under it.

The short version

If you clicked something: opening an email is not the same as being compromised, and clicking without typing is much better than clicking and typing. Change the password if you entered one, turn on multi-factor authentication, tell IT if it was a work account, and report it through your national reporting route.

Phishing is one method with many names, and the names describe four different things: the channel, how the target was chosen, what the attacker wants, and what the victim is asked to do. That is why no two lists agree, and why a message can be several types at once.

The framework files phishing under six separate tactics, so mapping it to one is mapping a fraction of it.

And the number to quote, if you quote one, is that a specialist body observed 3.8 million reported phishing sites in 2025 against 3.76 million in 2024, and called the pace steady. It counts sites rather than victims, and the body that publishes it says email security is now blocking the samples it depends on. Both halves of that sentence should travel together.