Cybercriminals often use manipulation and emotions of users instead of technically advanced attacks. Therefore, cybersecurity awareness and the ability to recognize threats are crucial for both companies and private users today.
What is phishing and how does it work?
Phishing is a method of impersonating a trusted person, company or institution to obtain information such as passwords, logins, SMS codes or PESEL numbers. Most often, a phishing attack uses fake emails, phishing websites or dangerous links leading to impersonating websites.
What is phishing? We define it as user manipulation and the use of victims’ emotions, e.g. fear, time pressure or curiosity. Cybercriminals create phishing emails resembling messages from banks, courier companies or shopping platforms. According to the CERT Polska report, which we discussed in detail in this article, in 2025, cybercriminals most often used scenarios based on trust in well-known institutions and everyday services. To increase their credibility, hackers also use fake profiles and fake websites.
Types of phishing – email, vishing, smishing, spear phishing, whaling
Phishing attacks can take various forms depending on the communication channel used and the target of cybercriminals. Email phishing remains the most popular, in which the user receives a message containing a dangerous link or attachment leading to phishing.
In addition, common types of phishing include:
- smishing – phishing carried out via SMS messages
- vishing – phishing for information over the phone
- spear phishing – a personalized attack aimed at a specific person in an organization or department, in which the criminal impersonates a trusted person or institution (boss, contractor),
- whaling – phishing aimed at management staff (so-called big fish),
- url phishing – a type of phishing in which criminals create fake websites (banks, shops, offices) to obtain confidential data.
Cybercriminals develop phishing campaigns to look like genuine business messages or messages from friends. Therefore, phishing in the company remains one of the greatest threats to reputation and business continuity.
How to protect yourself against phishing?
Protecting against phishing requires, above all, regular user education to increase their ability to recognize and block the threat. Safe habits, exercising caution and following safety procedures are key. The user should be able to verify the senders of messages, avoid suspicious links and check the addresses of websites before logging in.
Organizations are increasingly implementing anti-phishing educational programs and phishing tests that help assess the level of cybersecurity awareness of teams. An example is Practical Anti-Phishing Training, in which the SECAWA team coordinates the entire training: prepares realistic phishing simulation scenarios, conducts test campaigns and analyzes the results.
The educational program should be supported by technical controls such as email filtering, protection against malicious links and attachments, multi-factor authentication, email-domain security and an easy way to report suspicious messages. As a result, the organization not only trains employees, but also strengthens the technical layers of protection against phishing.
The following also remain an important element of protection:
- anti-spam filtering, strong passwords, multi-factor authentication, regular system updates and reporting phishing to the appropriate security team.
It is also worth analyzing phishing statistics in Poland because they show the scale of the threat and the most frequently used attack methods.
What to do if you are a victim of phishing?
If you have been a victim of phishing, you should change your passwords and secure your accounts as soon as possible – e.g. with two-factor authentication. It is also worth scanning the device with an antivirus program.
If financial data or logins are disclosed, it is worth contacting the bank and reporting the incident to the appropriate services or security department. A quick response helps limit the effects of a phishing attack and reduce the risk of further fraud.
FAQ – phishing
What is phishing?
Phishing is a cyberattack that involves impersonating trusted people or institutions in order to obtain data, passwords or financial information.
How to recognize phishing?
Phishing can be recognized, among others, by: after suspicious links, time pressure in emails or text messages, language errors and messages encouraging you to provide data or click on a link.