What is Phishing?

Last updated

Phishing is one of the most common cyberattacks: criminals send fake emails that look like messages from trusted organisations to steal passwords, payment details, or access to systems. For businesses, the human factor is the biggest vulnerability.

How does phishing work?

An attacker sends an email that appears to come from a bank, government agency, colleague, or software vendor. The recipient is asked to click a link, open an attachment, or enter login credentials. Once that happens, the attacker has what they need.

Modern phishing attacks are nearly indistinguishable from legitimate messages. They feature correct logos, professional language, and domain names that closely resemble real addresses (e.g. rnicrosoft.com instead of microsoft.com).

Types of phishing

Phishing (mass)

Large volumes of fake emails sent to random recipients, targeting banking credentials or passwords.

Spear phishing

A targeted attack on a specific person or organisation, with personalised content drawn from public information.

CEO fraud

The attacker impersonates a director or manager and requests an urgent transfer or sensitive data from an employee.

Smishing & vishing

Phishing via SMS (smishing) or phone (vishing). Criminals pose as a bank or government to extract credentials.

Phishing examples

Concrete phishing examples help employees spot suspicious messages faster. These are common scenarios in Dutch businesses:

  • Fake Microsoft alert: An email from "Microsoft Security" asks you to confirm your password via a link. The domain is "microsoftsecurity.net" instead of "microsoft.com".
  • False supplier invoice: You receive a PDF attachment from a known supplier asking you to open an invoice. The attachment contains malware.
  • PostNL parcel notification: A text message says your parcel is being held and asks for a small fee via a link. The link leads to a cloned payment page.
  • CEO fraud by email: Your director sends an urgent request to transfer money to a new account number. The email address reads "director@companynaan.nl", with a typo in the domain name.
  • Fake IT helpdesk: An email from your "IT department" asks you to sign in to an internal portal to renew your account. The link leads to an external website imitating the company login page.

Want to know how vulnerable your organisation is to attacks like these? A phishing simulation shows you, with your own employees, safely and under control. See also our explanation of what a phishing simulation costs.

Warning signs of phishing

  • Unknown or suspicious sender address, despite a familiar display name
  • Urgency: "your account will be blocked", "respond within 24 hours"
  • Links that don't match when you hover over them
  • Requests to enter passwords, PINs, or payment details
  • Unexpected attachments with unusual file types (.zip, .exe, .docm)
  • Spelling errors or unusual formatting in the email

Consequences of phishing for businesses

A single successful phishing attack can lead to a data breach, ransomware infection, financial fraud, or prolonged system outages. For an SME, the average damage per incident can run into tens of thousands of euros, excluding reputational harm and regulatory fines.

Research shows: phishing was the most common initial attack vector for the fourth consecutive year, accounting for 17% of all breaches (IBM Cost of a Data Breach 2026). Technical measures filter many messages, but the human factor remains the greatest vulnerability.

How to protect your organisation

Technical measures such as spam filters, MFA, and email authentication (SPF, DKIM, DMARC) are essential but not sufficient on their own. The strongest defence is a resilient employee who recognises phishing before clicking.

The most effective way to achieve this is a phishing simulation: a controlled, realistic fake attack on your own organisation. Employees learn by experience, not from a policy document.

Further reading on phishing

Go deeper in our knowledge base:

Frequently asked questions about phishing

What types of phishing are there?

There are four common types of phishing. Mass phishing is the classic attack, sending large volumes of fake emails to random recipients to steal banking details or passwords. Spear phishing is a targeted variant in which the attacker goes after a specific person or organisation using personalised content. CEO fraud (also known as BEC, or business email compromise) means the attacker poses as a director or manager to push an employee into making an urgent payment or sharing sensitive data. Smishing and vishing are forms of phishing by text message or telephone.

What is a phishing email?

A phishing email is a fake email designed to look like a message from a trusted organisation, such as a bank, government body or software supplier. The sender wants to tempt the recipient into clicking a fraudulent link, opening a malicious attachment, or entering credentials on a cloned website. Modern phishing emails contain correct logos, professional language and domain names that resemble genuine addresses. That makes them hard to tell apart from legitimate messages without targeted training.

What are the consequences of phishing?

A successful phishing attack can lead to a data breach, a ransomware infection, financial fraud or prolonged system downtime. For small and medium-sized businesses the average loss per incident runs into tens of thousands of euros, on top of reputational damage, customer loss and possible GDPR fines. Because the human element played a role in 62% of all data breaches (Verizon DBIR 2026), training employees to recognise phishing is the most direct way to reduce that risk.