Hook, Line, and Scammer: What Is Phishing—and How to Spot It

June 3, 2026

What is phishing? Phishing is a cyberattack where criminals impersonate a trusted person or organization—via email, text, phone, or even physical mail—to steal passwords, financial information, or access to your systems. It’s the #1 entry point for data breaches, and it works because it targets people, not technology.

Imagine a calm, breezy riverbank, cooler full of cold drinks, nothing but time. That’s fishing at its finest.

Phishing—spelled with a “ph”—is the other kind. A lot less relaxing.

Phishing is one of the most common cyber threats facing businesses today, and it’s getting harder to spot every year. The good news: your team can learn to recognize it. Here’s everything you need to know.

What Is Phishing?

Phishing is a type of social engineering attack where cybercriminals pose as someone you trust—your bank, your boss, a vendor you work with—to get you to hand over sensitive information or click a malicious link.

The name is a play on “fishing”: criminals cast a wide net and wait for someone to bite. They’re looking for credit card numbers, social security numbers, login credentials—or they want you to wire money or buy gift cards. And you’re already a target— cybercriminals don’t pick victims selectively.

Phishers pose as trusted figures—your bank, the IRS, even your own CEO. While people with less digital experience are often targeted, anyone can fall victim. It only takes one click.

How Common Is Phishing?

Phishing isn’t a niche threat—it’s the most commonly reported cybercrime year after year, according to the FBI’s Internet Crime Complaint Center. These aren’t lone hackers— organized cybercrime operations run phishing campaigns at industrial scale. A single successful attack can mean days of downtime, significant financial loss, and serious reputational damage.

And the attacks are getting smarter. AI tools now let criminals craft messages so convincing they fool even experienced employees. The era of obvious phishing emails full of misspellings is mostly over.

The Most Common Types of Phishing Attacks

Not all phishing looks the same. Here’s a breakdown of the most common types your team should know:

Attack TypeHow It WorksCommon Example
Email phishingMass emails impersonating a trusted brandFake “your account is suspended” from PayPal
Spear phishingTargeted attack using real details about youAn email appearing to come from your actual CEO
SmishingPhishing via text — keep your phone secureFake USPS delivery notification with a suspicious link
VishingPhishing via phone callFake IRS agent demanding immediate gift card payment
Business Email CompromiseSpoofed executive email used to authorize fraudUrgent “wire transfer” request from a fake CFO

How to Spot a Phishing Email: 5 Red Flags

Email is still the most common delivery method. Criminals design messages to look like they’re coming from credible sources. Here’s what to watch for:

  1. A suspicious sender address. A real PayPal email comes from @paypal.com. A phishing email might come from @paypa1.com. Always check the full address, not just the display name.
  2. Urgency or fear as a pressure tactic. “Your account will be closed in 24 hours.” Phishing emails create panic to override your judgment. That pressure is a social engineering tactic—slow down before you respond.
  3. Links that don’t go where they say. Hover over any link to preview the actual URL. On mobile, hold your finger on the link. If the destination doesn’t match—don’t click.
  4. Unexpected or suspicious attachments. Phishing emails often install malware or ransomware when opened. If you weren’t expecting a file—don’t open it. Call the sender first.
  5. Something just feels off. Generic greetings, awkward phrasing, or a request your coworker would never make. Trust your instincts and verify before acting.

It’s always better to apologize to your coworker for not trusting their strange email than to explain to your CEO why the e-commerce platform is down.

Phishing Red Flags—Quick Reference

What You SeeWhat It Might MeanWhat to Do
Mismatched sender addressSpoofed or fraudulent senderDon’t reply—verify through a separate channel
Urgent language or threatsPressure tacticSlow down—legitimate companies don’t operate this way
Suspicious or mismatched URLLeads to a fake siteHover to preview; when in doubt, don’t click
Unexpected attachmentPotential malware or ransomwareDon’t open—confirm via phone first
Generic greeting (“Dear Customer”)Mass phishing campaignCompanies you work with know your name
Gift card or wire transfer requestClassic fraud signalAlways verify over the phone before acting

What to Do If You Receive a Phishing Email

Getting a phishing email doesn’t mean you’ve been compromised—yet. What you do next is what matters.

  • Don’t click anything. Not the links, not the
    “unsubscribe” button, not the attachments.
  • Don’t reply. Responding confirms your email is active.
  • Report it. Forward to your IT team or use the built-in
    “Report Phishing” option. You can also report to the FTC at ReportFraud.ftc.gov.
  • Delete it. Remove from your inbox and trash.
  • If you already clicked: Contact your IT team immediately. Change your passwords—starting
    with email and financial accounts. Speed matters.

The Fix? Training.

Here’s the reality: no spam filter catches everything. The most sophisticated security stack won’t save your business if one click could compromise your entire network.

Humans are the last line of defense—and the most frequently exploited vulnerability. Understanding what hackers do with your data once they have it is what makes training feel real.

The only real fix is training your team to recognize the patterns. There are 9 types of cybersecurity training your team needs—and most businesses are only doing one or two. Check out how Stratti makes it manageable , or call us at (530) 342-8999.

Phishing FAQ

What is phishing in simple terms?

Phishing is when a cybercriminal pretends to be someone trustworthy—a bank, a coworker, a government agency—to trick you into giving up sensitive information like passwords or login credentials. It usually arrives as an email, but can also come via text, phone call, or physical mail.

What is the most common type of phishing attack?

Email phishing is the most common type. These attacks send mass emails impersonating well-known brands—banks, shipping companies, tech platforms—with links to fake websites designed to capture your login credentials.

Can phishing happen through text messages?

Yes. Phishing via text is called “smishing.” A common example is a fake package delivery notification asking you to click a link—which then captures your personal information.

What should I do if I clicked a phishing link?

Don’t panic—but act fast. Disconnect from the internet, change your passwords immediately (email and financial accounts first), and contact your IT team right away. The faster you respond, the better your chances.

What’s the difference between phishing and spear phishing?

Regular phishing is a mass attack sent to thousands. Spear phishing is targeted— attackers research a specific person or company and craft a personalized message using real details to make it convincing.

How can I protect my business from phishing?

The most effective protection combines employee training, simulated phishing tests, and technical safeguards like email filtering, multi-factor authentication, and endpoint protection. Phishing defense works in layers. Stratti can assess where your business is most vulnerable and build a plan that fits your team. Get in touch to get started.

Written by Brent Largent

Managed IT Services Expert • Stratti

Brent and the Stratti team have spent over a decade helping small and mid-sized businesses across Chico, Roseville, and the greater Sacramento area navigate cybersecurity threats, managed IT, and technology strategy. When IT works, you don’t notice it—and that’s exactly how they like it.

Ready to protect your team from phishing?

Stratti helps small and mid-sized businesses build cybersecurity training programs that actually stick. Let’s find out where you’re most vulnerable—and what to do about it.

(530) 342-8999 • (916) 290-4511 • stratti.com/get-in-touch

We use cookies to enhance your experience, analyze site traffic, and provide personalized content. By continuing to use this website, you agree to our use of cookies.