• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

What Is Phishing? How It Works, Types, and How to Spot It in 2026

Published on: June 15, 2026
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 528 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Meta Employee Count Statistics 2026: Headcount, Layoffs and AI Reallocation
SM Energy Breach Exposed SSNs, Full Toll Still Undisclosed
How AI Agents Are Shaping the Future of Work
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 768 Articles
Barry Elad is a seasoned journalist and analyst specializing in finance, technology, AI, and founder of SQ Magazine. He explores the world o...
LATEST POSTS:
Google Lyria 3.5 Raises the Bar for AI-Generated Music
Gemini Spark Debuts in India With a Powerful AI Agent
Cursor Debuts ₹649 India Plan as AI Price Battle Heats Up
What Is Phishing
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Phishing was the most-reported internet crime in the United States in 2024, with the FBI’s Internet Crime Complaint Center logging 193,407 phishing and spoofing complaints that year. So what is phishing? Phishing is a form of social engineering in which criminals try to get people to open harmful links, emails, or attachments that request personal information or infect devices, according to the US Cybersecurity and Infrastructure Security Agency.

The mechanics are simple, the volume is enormous, and the window to react is measured in seconds. What follows covers how phishing works, the seven main types, the red flags that give an attack away, and the exact steps to take if you clicked.

Key Takeaways

  • The FBI IC3 received 193,407 phishing and spoofing complaints in 2024, more than any other crime type, with $70,013,036 in reported losses.
  • Phishing appeared in 15% of breaches analyzed in the Verizon 2025 Data Breach Investigations Report.
  • The median time for a user to click a phishing link is just 21 seconds, and the median time to submit data is 28 seconds.
  • The UK’s NCSC groups phishing red flags into five levers: authority, urgency, emotion, scarcity, and current events.
  • Microsoft research found that multi-factor authentication can block more than 99.2% of account-compromise attacks.
  • The NCSC Suspicious Email Reporting Service has taken in more than 55.7 million reported scams, leading to 250,000 scams removed.

What Is Phishing?

Phishing is a form of social engineering, and according to the US Cybersecurity and Infrastructure Security Agency, it ranked as the most-reported crime type to the FBI IC3 in 2024 with 193,407 complaints. Phishing messages, the “bait,” usually arrive as an email, text, direct message on social media, or phone call, designed to look like they come from a trusted source, per CISA.

The UK’s National Cyber Security Centre frames it the same way: criminals use scam emails, text messages, or phone calls to trick victims into visiting a malicious website or handing over bank and personal details. The US Federal Trade Commission and Microsoft describe the same mechanics from the consumer and account-security angles.

CISA splits the attack into two core tactics. The first is credential theft, where the attacker sends an email with a link to an imposter site that convinces the victim to enter a username and password, sometimes also requesting MFA codes in what is called MFA bypass. The second tactic is malware deployment, where harmful links or attachments are used to infect devices.

Why it matters: CISA classifies phishing as social engineering rather than a purely technical exploit. That framing matters because the target is the person, not the software. A patched, fully updated device still falls if the human at the keyboard is persuaded to type a password into the wrong box.

How Phishing Works, Step by Step

The Verizon Data Breach Investigations Report found the median time for a user to click a phishing link is just 21 seconds, with a median time to submit data into the fake form of 28 seconds. Phishing follows a short, repeatable sequence, and its danger lies in that speed: under a minute separates a delivered email from a stolen credential.

The sequence runs in four beats:

  • Bait. The attacker sends a message impersonating a brand, colleague, or agency.
  • Trust. The message is built to look like it comes from a trusted person or organization, prompting a response.
  • Action. The victim clicks a link, opens an attachment, or replies with information.
  • Harvest. A credential-theft attack lands the victim on an imposter site that captures the username and password, while a malware attack runs code on the device.

Because the click-to-compromise window is so narrow, awareness training alone cannot carry the load. That speed is survivable according to Microsoft research, which found MFA can block more than 99.2% of account-compromise attacks. Speed is the reason layered technical controls matter as much as user education. If a credential can be stolen in 28 seconds, the realistic defense is making the stolen credential useless once it leaves the keyboard. This is the gap that controls such as multi-factor authentication are built to close, a pattern the broader phishing email statistics reinforce across organizations.

The Main Types of Phishing

CISA documents several named offshoot variants beyond ordinary phishing, including spear phishing, whaling, smishing, and vishing, separated mainly by channel and target. Adding clone and angler phishing brings the common total to seven variants worth knowing. Knowing the category helps you recognize an attack even when the wording is convincing.

  • Email phishing is the mass-volume baseline, blasting generic lures to large lists.
  • Spear phishing is targeted. The attacker researches the victim’s job role and contacts to craft a highly personalized message that is harder to detect.
  • Whaling aims at the top. Whaling is a type of spear phishing that targets senior executives, often to facilitate a financial scam such as wire-transfer fraud, and primarily focuses on financial institutions and payment services.
  • Smishing is phishing carried out via SMS text message.
  • Vishing is voice phishing carried out over the phone, often using Voice over Internet Protocol so callers can spoof legitimate numbers.
  • Clone phishing copies a real email and swaps benign links for malicious ones.
  • Angler phishing impersonates customer-support accounts on social media to harvest credentials.
TypeChannelTargetDistinctive trait
Email phishingEmailMass audienceGeneric, high volume
Spear phishingEmailSpecific personResearched, personalized
WhalingEmailSenior executivesWire-transfer and finance focus
SmishingSMS textMobile usersMalicious link in a text
VishingPhone callAnyoneVoIP-spoofed caller ID
Clone phishingEmailPrior correspondentsLegitimate email cloned
Angler phishingSocial mediaAccount holdersFake support agents

Source: CISA, UK NCSC

Voice-based attacks deserve their own attention given how convincing spoofed calls have become; the voice phishing statistics show how fast that channel is growing.

Newsletter
Don’t chase tech news. We track it for you.

One weekly briefing with the launches, AI developments, and breaches that matter. No filler.

How to Spot a Phishing Email: Red Flags

The UK’s NCSC groups the manipulation tactics behind phishing into five signs: authority, urgency, emotion, scarcity, and current events, which makes psychological pressure, not spelling mistakes, the most reliable thing to watch for. The US Federal Trade Commission documents the matching stories scammers tell, including claims of suspicious activity or log-in attempts, a problem with your account or payment, a request to confirm personal information, a fake invoice, or a link to make a payment that carries malware.

The five NCSC levers map to concrete tells:

  • Authority: Criminals pretend to be important people or organizations to pressure you.
  • Urgency: Messages give a limited time to respond, such as “within 24 hours” or “immediately”.
  • Emotion: Messages try to make you panicked, fearful, hopeful, or curious, often with threatening language.
  • Scarcity: Offers of something in short supply, like tickets, money, or a cure.
  • Current events: Messages that exploit news stories, big events, or seasonal moments like tax reporting.
Red flagWhat it looks like in an email
Authority“This is your bank’s security team” with an official-looking logo
Urgency“Your account will be closed in 24 hours”
EmotionThreats, alarming warnings, or too-good-to-be-true rewards
Scarcity“Only 3 spots left, claim your refund now”
Current eventsTax-season refunds, parcel-delivery notices, breach alerts

Source: UK NCSC

The takeaway: The NCSC advises that a bank or other official source will never ask you to supply personal information via email or call to confirm full account details. This single rule defeats most credential-phishing attempts. If a message demands that you confirm a password, card number, or one-time code, the message itself is the warning sign.

How do you spot a phishing email quickly?

Check the NCSC’s five manipulation signs first: authority, urgency, emotion, scarcity, and current events. Then verify independently. If you have any doubt, contact the organization directly using the contact details from their official website, not any links or phone numbers printed in the message itself.

What to Do if You Clicked a Phishing Link

Clicking a phishing link is recoverable if you move quickly and in order. The FTC advises that if you clicked a link or opened an attachment, you should update your security software and run a scan, then take further steps if any information was shared. Acting in the first few minutes limits how much an attacker can do with what they captured.

A practical triage sequence:

  1. Disconnect the device from the network to interrupt any download in progress.
  2. Change the exposed password from a different, clean device, starting with email and banking.
  3. Turn on multi-factor authentication so a stolen password alone is not enough.
  4. Scan the device with updated security software, per the FTC’s guidance.
  5. Report the message through the channels in the next section.
  6. Monitor accounts and statements for unfamiliar activity.

If sensitive data was handed over, escalate. The FTC directs anyone who believes a scammer has their Social Security, credit card, or bank account number to go to IdentityTheft.gov for specific recovery steps. Understanding what happens to your data after a breach clarifies why fast password rotation matters.

How to Protect Yourself From Phishing

The strongest single defense against phishing is turning on multi-factor authentication. Microsoft research found that MFA can block more than 99.2% of account-compromise attacks, and the company reported that 99.9% of compromised accounts did not have MFA enabled. MFA helps reduce risk even when a password is stolen, because the attacker still lacks the second factor.

The FTC’s baseline protection checklist is short and effective:

  • Use security software and set it to update automatically.
  • Keep your phone updated by setting its software to update automatically.
  • Turn on multi-factor authentication on your accounts.
  • Back up your data. The FTC advises backing up your data, so you can recover if a device is ever compromised.

A password manager strengthens this further by generating unique credentials per site, which limits the blast radius when one password leaks. Our password statistics track how passkeys and MFA adoption are shifting the credential-theft picture.

For organizations, layered controls and staff training compound, and our guide on how to secure your business from cyber attacks sets out a practical sequence. Employees who had recent security training reported simulated phishing emails at a rate of 21%, a fourfold increase over the roughly 5% rate among untrained employees, per Verizon, so training measurably raises the odds that an attack gets flagged rather than clicked.

By the numbers: Microsoft found MFA blocks more than 99.2% of account-compromise attacks, and trained employees report phishing at 21% versus about 5% untrained. Together these point to the same conclusion: phishing defense works best as a stack, where a missed click is caught by a second factor and a reporting habit.

Where to Report a Phishing Email

Reporting a phishing email does more than clear your inbox; it feeds takedown systems that remove the scam for everyone. In the UK, suspicious emails can be forwarded to the Suspicious Email Reporting Service at report@phishing.gov.uk. The scale of that effort is significant: the service has received more than 55.7 million reported scams, leading to 250,000 scams being removed across 443,000 URLs.

In the United States, the FTC and the Anti-Phishing Working Group run parallel channels:

  • Forward phishing emails to ReportPhishing@apwg.org.
  • Forward phishing text messages to SPAM (7726).
  • Report the attempt to the FTC at ReportFraud.ftc.gov.

Across SQ Magazine’s phishing coverage, the same pattern recurs: the scams that get removed fastest are the ones that get reported, not just deleted. A deleted email protects one inbox; a reported one can pull a malicious URL offline before it reaches the next thousand.

What is phishing in simple terms?

Phishing is a scam where criminals pretend to be a trusted company or person to trick you into giving up passwords, money, or personal data, or into installing malware. The NCSC describes it as criminals using scam emails, texts, or calls to make victims visit a malicious site or hand over bank and personal details.

Are phishing emails dangerous if you do not click anything?

Simply receiving a phishing email is generally not harmful on its own, because the risk comes from acting on it. CISA notes the danger arises when victims open harmful links, emails, or attachments that request personal information or infect devices. Deleting or reporting the message without clicking helps reduce that risk.

How common is phishing?

Phishing is extremely common. It was the most-reported crime type to the FBI IC3 in 2024, with 193,407 complaints, and it appeared in 15% of breaches analyzed by Verizon.

Conclusion

Phishing remains the most-reported internet crime for a reason: it targets people, scales cheaply, and works in seconds. The data sets the stakes plainly, with 193,407 complaints reaching the FBI IC3 in 2024 and a median click time of 21 seconds leaving almost no room to second-guess a convincing message. The defense is layered rather than singular: recognize the five NCSC red flags, slow down before acting, and let technical controls catch what attention misses.

For everyday readers, the highest-value move is turning on multi-factor authentication, which Microsoft credits with blocking more than 99.2% of account-compromise attacks, and building the habit of reporting suspicious messages so takedown systems can act. Phishing techniques will keep evolving toward AI-generated lures that read flawlessly, which makes the behavioral signals and the second-factor backstop more important, not less. The publications and agencies tracking this field expect the social-engineering core to stay constant even as the surface polish improves.

This article has been reviewed and fact-checked by Barry Elad. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity

References

  • CISA, Recognize and Report Phishing (Secure Our World)
  • UK NCSC, Spot Phishing Scams (Five Manipulation Signs)
  • UK NCSC, Phishing Scams Collection (SERS Reporting Statistics)
  • FTC Consumer Advice, How to Recognize and Avoid Phishing Scams
  • FBI IC3 2024 Internet Crime Report (PDF)
  • Verizon 2025 Data Breach Investigations Report (PDF)
  • Microsoft Research, How Effective Is Multifactor Authentication at Deterring Cyberattacks?
  • CISA, Phishing: What's in a Name? (Variant Definitions)
  • UK NCSC, Phishing Attack Types (Spear, Whaling, Smishing, Vishing)
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Scam Statistics
Cybersecurity

Scam Statistics 2026: How Much Money’s Lost and What’s Coming Next

Hackers Exploiting Microsoft 365 Oauth Login System
Cybersecurity

Surge in Microsoft 365 Attacks as Hackers Abuse OAuth Device Code Flow

Cybersecurity Statistics
Cybersecurity

Cybersecurity Statistics 2026: The Latest Threats, Costs & AI Defenses

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Microsoft Detects 8.3 Billion Email Phishing Threats in Q1 2026
WhatsApp Scams in 2026: Common Types and How to Spot Them
Phishing and Wallet Drainer Incidents Statistics 2026: Losses, Victims & Attack Vectors

Table of Contents

  • Key Takeaways
  • What Is Phishing?
  • How Phishing Works, Step by Step
  • The Main Types of Phishing
  • How to Spot a Phishing Email: Red Flags
  • What to Do if You Clicked a Phishing Link
  • How to Protect Yourself From Phishing
  • Where to Report a Phishing Email
  • What is phishing in simple terms?
  • Are phishing emails dangerous if you do not click anything?
  • How common is phishing?
  • Conclusion
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Gen Z Social Media Statistics
  • TikTok vs. Instagram Statistics
  • LLM Hallucination Statistics
  • Spotify User Statistics
  • Apple Customer Loyalty Statistics
  • Data Breach Tracker
  • Patch Tuesday Dashboard
  • AI Model Tracker
  • AI Funding Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cybersecurity
Internet
How Many Times Per Day Does The Average Person Check Social Media Statistics
How Many Times Per Day Does the Average Person Check Social Media Statistics 2026: Latest Insights
Outlook Statistics
Outlook Statistics 2026: Users, Market Share, Security & M365 Seats
YouTube Music Statistics
YouTube Music Statistics 2026: Subscribers, Revenue and Library
Disney+ Statistics
Disney+ Statistics 2026: Subscribers, ARPU, Revenue and Bundle Data
Netflix vs Disney+ vs Amazon Prime Statistics
Netflix vs Disney+ vs Amazon Prime Statistics 2026: Viewer Insights
Social Media Demographics By Platform
Social Media Demographics by Platform Statistics 2026: A Definitive Guide
Technology
Meta Employee Count Statistics
Meta Employee Count Statistics 2026: Headcount, Layoffs and AI Reallocation
Google Employee Count Statistics
Google Employee Count Statistics 2026: Headcount and Layoffs
Canva Employee Count Statistics
Canva Employee Count Statistics 2026: Workforce Data
Google Sheets vs Excel Statistics
Google Sheets vs Excel Statistics 2026: Market Share and AI
Figma Vs Canva Statistics
Figma vs Canva Statistics 2026: Revenue, Users, AI
Webex Statistics
Webex Statistics 2026: Users, Revenue, Market Share
Artificial Intelligence
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
How Many People Work At Midjourney
How Many People Work At Midjourney 2026: Lean Team, Big Revenue
Grammarly AI Statistics
Grammarly AI Statistics 2026: Users, Revenue, Funding, Rebrand
Copilot Statistics
Copilot Statistics 2026: Users, Adoption, Revenue and Market Share
Gaming
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics
Gamers Statistics 2026: Players, Habits & Global Data
Cybersecurity
Signal Statistics
Signal Statistics 2026: Users, Finances and Encryption Adoption
Password Statistics
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics
API Security Breach Statistics 2026: Hidden Threats
Categories
  • Cybersecurity
  • Artificial Intelligence
  • Internet
  • Technology
  • Gaming
Cybersecurity
Sm Energy Breach Exposed Ssns
SM Energy Breach Exposed SSNs, Full Toll Still Undisclosed
Claude Cowork Sandbox Escape On Mac
Claude Cowork Sandbox Escape Exposed 500,000 Mac Users
Nvidia Launches Open Secure Ai Alliance
NVIDIA Launches Open Secure AI Alliance With Dozens of Tech Firms
Russian Zimbra Zero Day Espionage Campaign
CISA Warns of Russian Zimbra Zero-Day Espionage Campaign
Origin Energy Confirms Customer Data Breach
Origin Energy Confirms Customer Data Breach
Stadler Rail Rejects 12 3 Million Ransom
Stadler Rail Rejects $12.3 Million Ransom After Supplier Breach
Artificial Intelligence
Google Launches Lyria 3 5 Model
Google Lyria 3.5 Raises the Bar for AI-Generated Music
Gemini Spark Debuts In India
Gemini Spark Debuts in India With a Powerful AI Agent
Cursor Launches Start Plan In India
Cursor Debuts ₹649 India Plan as AI Price Battle Heats Up
Openai Brings Chatgpt Voice To The Desktop App
OpenAI Brings ChatGPT Voice to the Desktop App
Claude Enables Voice Mode
Anthropic Adds Model Choice to Claude Voice Mode For All Users
Openai Opens Chatgpt Health To All Us Users
OpenAI Opens ChatGPT Health to All US Users Amid Lawsuit
Internet
Russia S Fsb Charges Telegram Founder Durov With Terrorism
Russia’s FSB Charges Telegram Founder Durov With Terrorism
Aws Cloudfront Outage Triggers Global 5xx Errors
AWS CloudFront Outage Triggers Global 5xx Errors
Whatsapp Launches Username Reservation Feature
WhatsApp Opens Username Reservations for Its 3 Billion Users
Chrome 149 Update Fixes Serious Vulnerabilities
Google Chrome 149 Fixes 18 Serious Security Flaws
Meta Hands Whatsapp Reins To Cred Founder Kunal Shah
Meta Hands WhatsApp Reins to CRED Founder Kunal Shah
Major X Outage Disrupts Users Worldwide
Major X Outage Disrupts Users Worldwide, Service Restored
Technology
Whatsapp Web Calling With Call Transfer
WhatsApp Web Now Supports Video and Audio Calls with Transfer
Apple Launches 17 99 Iphone Leases With Klarna
Apple Launches $17.99 iPhone Leases With Klarna In The USA
Meta Launches Seller App For Facebook Marketplace
Meta Launches Seller App for Facebook Marketplace
Google Adds Selfie Video Sign In For Account Recovery
Google Adds Selfie Video Sign-In for Account Recovery
Apple Maps Comes To Ford S Electric Vehicles In 2027
Apple Maps Comes to Ford’s Electric Vehicles in 2027
Microsoft Fixes Dell Windows 11 Shutdown Overheating Bug
Microsoft Fixes Dell Windows 11 Shutdown, Overheating Bug
Gaming
Gta Vi Official Cover Art
GTA 6 Pre-Orders Start June 25, New Cover Art Unveiled
Epic Games Teases Unreal Engine 6 For Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Launched For Nintendo Switch 2 Edition
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Game Crosses 40m Downloads
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Pubg Black Budget Closed Alpha Launched
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter Strike 2 Skin Market Crashes After Valve Update
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Newsletter

Too much tech noise?

We respect your time. One high-signal briefing a week — tech, AI, and security. Nothing else.

Newsletter

The SQ Briefing

We track tech, AI, and security 24/7. You get a 5-minute weekly summary.