Phishing
Published September 20, 2026
Phishing is a social engineering scam where attackers impersonate banks, tech companies, or coworkers to trick people into handing over passwords and account access. The word first appeared in the 1994 AOL hacking tool AOHell and grew into one of the defining forms of internet fraud, from Russian botnet operations to the viral 2017 Google Docs email attack.
Overview
Phishing works by baiting targets with familiar-looking messages, then routing them to look-alike login pages that harvest their credentials1. The 'ph' spelling follows the old hacker convention seen in 'phreaking,' and the metaphor casts the target as a fish taking a lure7. Common formats include fake bank fraud alerts, spoofed shipping notices, and 'someone shared a document with you' emails pointing to domains that mimic real brands.
Attackers copy real corporate email layouts, register visually similar domains, and rely on urgency such as 'your account will be suspended' wording to short-circuit careful reading7. Later variants added SMS ('smishing'), voice calls ('vishing'), and targeted spear phishing tied to specific individuals or companies, but the core trick of impersonating a trusted sender is still the same.
Origin & Background
How It Spread
Frequently Asked Questions
References (7)
- 1
- 2
- 3
- 4
- 5
- 6
- 7