Phishing Definition: Phishing is a form of online fraud in which an attacker sends a message that pretends to come from a trusted person or organisation, such as a bank, an exchange or a colleague, to trick you into revealing a password, making a payment or installing harmful software. The message works by borrowing someone else’s identity and adding a reason to act quickly, so the victim hands over access willingly instead of the attacker breaking in.

What Is Phishing?

Most online theft starts not with a hacker cracking a system but with an ordinary-looking message: a delivery notice, a bank security alert, a supplier invoice. The sender is fake, and the goal is to get you to do one thing, whether that is typing a password into a copied login page, opening an attachment or sending money.

That is phishing in its broadest sense. It is a category of social engineering, meaning an attack on human trust rather than on software. Email is the classic channel, but the same trick arrives by text message, phone call, social media, chat apps and fake adverts in search results.

The idea is easy to grasp. What makes phishing hard to stop is scale and cost: sending a million fake emails costs an attacker almost nothing, and the Anti-Phishing Working Group (APWG) recorded more than one million phishing attacks in a single quarter for the first time in Q1 2022.

Where Does the Word Phishing Come From?

Hackers coined the word in the mid-1990s on AOL, the largest US online service of that era. Tools such as AOHell, released in 1995, helped users impersonate AOL staff and message customers asking them to “verify” their account passwords. The term first appeared in writing on a Usenet newsgroup in January 1996.

Spelling it with “ph” was a nod to “phreaking”, the older hobby of hacking telephone networks. Fishing itself supplies the metaphor: the attacker casts bait into a large pool and waits for someone to bite.

How Does Phishing Work?

Once you know the basic idea, the mechanics follow a pattern that has barely changed in 30 years. A phishing message has four parts. First, a borrowed identity: the logo, tone and sender name of a brand you already trust. Second, a trigger, such as a locked account, an unpaid bill or a large refund.

Third comes a deadline that discourages you from stopping to check, often “within 24 hours”. Fourth is a single action: click this link, open this file, call this number. Each part removes a moment of doubt.

Consider a hypothetical campaign against users of a crypto exchange. An attacker sends 100,000 emails claiming a suspicious login and asking users to “secure your account”. If 3% click, that is 3,000 visits to a copied login page, and if 10% of those visitors type their password and code, the attacker holds 300 accounts.

At an average balance of $2,000, those 300 accounts expose $600,000, from a campaign that cost perhaps a few hundred dollars to run. This arithmetic explains why phishing never goes away: even a tiny success rate pays when sending is almost free. The step-by-step mechanics of such a campaign are covered in the phishing attack entry.

How to Recognise a Phishing Message

You rarely need technical skill to spot phishing. You need a habit of checking five things before you act:

  • The real sender address and link destination, not the display name. Hover over links, or long-press on a phone, to see where they actually go.
  • Pressure. Legitimate firms rarely threaten to close your account within hours.
  • Requests no genuine company makes, such as asking for your password, a one-time code or a wallet recovery phrase.
  • A change of payment details, especially in an email thread that otherwise looks normal.
  • Generic greetings and small visual errors, although a clean message proves nothing.

When in doubt, ignore the message and open the service yourself through a typed address or saved bookmark. A real problem will show up there. Reporting helps too: many countries run forwarding services, such as the UK’s [email protected], and the APWG collects samples at [email protected].

Types of Phishing

Mass phishing is the classic form described above: one generic message sent to as many people as possible.

Spear phishing targets one person or a small team with details gathered from social media or earlier leaks, such as a manager’s name or a real project. Whaling is spear phishing aimed at executives who can approve large payments.

Smishing and vishing move the same trick to SMS and phone calls, where there is no sender address to inspect.

Business email compromise targets company payments. Between 2013 and 2015 a Lithuanian man, Evaldas Rimasauskas, sent Google and Facebook fake invoices in the name of a real hardware supplier and collected more than $100 million before he was caught. He pleaded guilty in 2019 and received a five-year prison sentence.

Phishing vs. Spam

Phishing Spam
Goal Steal credentials, money or access Sell something or drive traffic
Sender identity Impersonates a trusted brand or person Often unknown but not disguised
Typical request Log in, pay, open a file, share a code Buy, click, subscribe

Not every unwanted email is phishing. Spam is annoying but honest about what it wants, while phishing lies about who is asking.

Why Is Phishing Important for Traders?

Trading accounts are ideal phishing targets because they hold money that can move within minutes. An attacker who logs in to an account on a centralized exchange can add a new withdrawal address and drain the balance before you read the alert. In crypto the loss is usually final, since blockchain transfers cannot be reversed by a bank.

Defences reduce the risk but do not remove it. Codes sent by SMS or typed into an app can be relayed by a fake page in real time. Security keys and passkeys tied to the real website, a stronger form of two-factor authentication, block that relay because they refuse to sign in on a lookalike domain.

Self-custody raises the stakes further. No legitimate wallet, exchange or support agent ever needs your seed phrase, so any page or person asking for it is a phishing attempt by definition. Some phishing does not ask for secrets at all and instead installs malware through an attachment, which is why unexpected files deserve the same suspicion as unexpected links.

Key Takeaways

  • Phishing is fraud by impersonation: the attacker borrows a trusted identity so that you hand over access, money or data yourself.
  • Most phishing messages combine a familiar sender, an alarming trigger, a short deadline and one requested action.
  • Phishing persists because sending costs almost nothing, so even a success rate below 1% of recipients can be profitable.
  • The safest response to any urgent message is to ignore its links and reach the service through an address you type or bookmark yourself.
  • Phishing-resistant sign-in methods such as security keys and passkeys block many attacks that one-time codes cannot stop, but no tool replaces the rule that nobody legitimate asks for passwords or recovery phrases.
FAQ section

Is it dangerous to just open a phishing email?

Opening an email in a modern mail client is rarely enough to cause harm on its own. The risk starts when you click a link, open an attachment, enable macros or reply with information.

What should I do if I clicked a phishing link?

If you entered a password, change it at once from the real website and sign out of other sessions. Turn on app-based or hardware-key two-factor authentication, check for new withdrawal addresses or forwarding rules, and contact the provider. If you typed a wallet recovery phrase anywhere, treat that wallet as lost and move the funds to a new one immediately.

Can phishing be done without a link?

Yes. Some messages ask you to reply with details, call a phone number, pay a fake invoice to new bank details or send crypto to a supplied address. A message with no link can be the more convincing kind, because it passes many automatic filters.

Why do phishing emails often have spelling mistakes?

Some are written carelessly, and crude mistakes may also filter out careful readers. Good spelling proves nothing, though, since translation and AI writing tools now produce clean text in any language.

Rug Pull
Rug Pull Definition: A rug pull is a type of crypto scam whe...
Net Profit
Net Profit Definition: Net profit (also called net income, b...
BEP-2
BEP-2 Definition: BEP-2 is the technical token standard for ...
Bitcoin Dominance
Bitcoin Dominance Definition: Bitcoin dominance is Bitcoin's...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.