Phishing

1994termclassic

Published September 20, 2026

Phishing is a social engineering scam where attackers impersonate banks, tech companies, or coworkers to trick people into handing over passwords and account access. The word first appeared in the 1994 AOL hacking tool AOHell and grew into one of the defining forms of internet fraud, from Russian botnet operations to the viral 2017 Google Docs email attack.

Overview

Phishing works by baiting targets with familiar-looking messages, then routing them to look-alike login pages that harvest their credentials1. The 'ph' spelling follows the old hacker convention seen in 'phreaking,' and the metaphor casts the target as a fish taking a lure7. Common formats include fake bank fraud alerts, spoofed shipping notices, and 'someone shared a document with you' emails pointing to domains that mimic real brands.

Attackers copy real corporate email layouts, register visually similar domains, and rely on urgency such as 'your account will be suspended' wording to short-circuit careful reading7. Later variants added SMS ('smishing'), voice calls ('vishing'), and targeted spear phishing tied to specific individuals or companies, but the core trick of impersonating a trusted sender is still the same.

Origin & Background

Platform
AOL (via AOHell tool)
Date
1994

A 1987 presentation at the International HP Users Group described the technique before it had a name, and the term itself is usually credited to hacker Khan C. Smith in the early 1990s. The earliest archived use appears in AOHell, a 1994 Windows tool that automated attacks on America Online accounts and included a built-in function for stealing passwords5. The 'ph' spelling followed the older 'phreaking' convention used by phone-system hackers7.

How It Spread

Frequently Asked Questions