What is phishing, and why does it still work?
Phishing remains one of the most common forms of online fraud, and one of the hardest to eliminate through technology alone. Criminals try to steal personal or corporate information — passwords, payment card numbers, banking credentials — by posing as a trusted person or institution: a bank, a well-known website, a supplier, or even a colleague.
A typical example is an email that appears to come from your bank, asking you to click a link and enter your login details on a site that looks almost identical to the real one. The moment those details are entered, they fall into the hands of criminals, who can then access accounts and move funds.
For a security team, the technical part of phishing is only half the problem. The other half is human behaviour under time pressure — which is exactly what security awareness training and phishing simulation are designed to address.
Five common phishing types your security awareness programme should cover
Employees rarely fail to recognise phishing because they don’t know the word — they fail because they don’t recognise the specific pattern in front of them. These five variants are worth covering explicitly in any awareness programme.
1. Email spoofing
Email spoofing falsifies the sender’s address so a message appears to come from a trusted source — a well-known contact or a legitimate company. The aim is to trick recipients into clicking a malicious link or handing over sensitive information. A classic example: an email that looks like it’s from your manager, asking you to forward a confidential document urgently.
2. URL phishing (link manipulation)
Also known as link manipulation, this places a malicious link in an email, text message or on a website designed to look trustworthy. Clicking takes the user to a fake site that mimics a familiar one, where they are asked to enter login details or personal information — which is then harvested by the attacker.
3. Clone phishing
This technique copies a legitimate email, attachment or link, then swaps in a malicious version disguised within otherwise genuine-looking content. Because it resembles a message the recipient may have seen before — from their bank, a social platform or a colleague — it is particularly effective at lowering guard. Clicking the cloned link can lead to a credential-harvesting site or trigger a malware download.
4. Invoice scams
With invoice scams, the victim receives a fake invoice that appears to come from a trusted supplier — correct logos, correct layout — except the payment details have been altered to an account controlled by the attacker. If the invoice is paid, the funds go straight to the scammer rather than the real supplier. This variant is particularly relevant for finance and procurement teams, and often intersects with wider governance and financial-control questions.
5. Catphishing
Catphishing uses a false identity on social media or dating platforms to build a relationship with the victim, then exploits that trust for financial gain or to extract personal information. It relies on emotional manipulation over an extended period rather than a single deceptive email, which makes it a useful case study for teams building broader social-engineering awareness, not just email hygiene.
General red flags every employee should learn to spot
- Be alert and sceptical: never click a link in an email, text message or social post reflexively, even if it appears to come from a known sender. Check the sender and the URL first.
- Verify the source independently: if a message’s authenticity is in doubt, go directly to the alleged sender’s website or contact them through a separate, trusted channel.
- Never share sensitive information by email, text or instant message: passwords, card details and banking information should never be requested this way by a legitimate organisation.
- Use strong, unique passwords per account, and change them regularly.
- Keep endpoint protection up to date, to catch malware that may be downloaded inadvertently from a phishing site.
- Treat urgency and “too good to be true” offers as a warning sign, not a reason to act quickly.
Type-specific checks to build into your security awareness training
Email spoofing
- Check that the sender’s address matches the alleged domain exactly — watch for minor misspellings or look-alike domains.
- Be cautious with generic salutations (“Dear customer”, “Dear user”); legitimate senders usually address people by name.
- Flag spelling and grammar mistakes, which are more common in spoofed messages than in genuine corporate communication.
URL phishing
- Hover over a link before clicking to check the actual destination address.
- Confirm the site uses https:// wherever sensitive information is requested.
- Enable browser security features such as pop-up blockers and phishing filters.
Clone phishing
- Treat attachments or links in previously seen emails with the same scrutiny as a new message, especially if the request feels slightly off.
- Contact the alleged sender through a separate channel to confirm they actually sent it.
Invoice scams
- Verify payment details — account number and beneficiary — against the record already on file for that supplier.
- Confirm any change of payment details by phone, using a number you already have on file, not one provided in the email.
Catphishing
- Be cautious of contacts online who move quickly to build emotional closeness.
- Search the person’s name and run a reverse image search on their profile picture.
- Suggest a video call if identity is in doubt — real-time interaction is harder to fake convincingly.
- Never share address, phone number or financial details with someone met only online.
How phishing simulation strengthens your human firewall
Reading about phishing types is a starting point, not a training programme. The organisations that reduce click-through rates over time typically combine three elements: a baseline phishing simulation to measure current exposure, targeted security awareness training on the specific patterns their employees actually encounter, and a clear, low-friction way for staff to report suspicious messages to the security team.
FAQ: phishing and security awareness training
What is phishing? Phishing is a social-engineering attack in which criminals impersonate a trusted person or organisation, by email, text or website, to trick someone into revealing credentials, payment details or other sensitive information.
What is the difference between phishing and spear phishing? Phishing is typically sent broadly to many recipients using a generic pretext. Spear phishing targets a specific individual or organisation, using personal or company detail to make the message far more convincing.
How does phishing simulation help prevent attacks? A phishing simulation sends realistic but harmless test messages to employees, measures who clicks or reports them, and turns the results into targeted follow-up training — replacing a general sense of risk with a measured baseline the organisation can actually improve.
What should an employee do if they suspect a phishing email? Do not click any link or open any attachment. Report the message to the security team or IT department through the organisation’s usual reporting channel, and avoid forwarding it to colleagues in the meantime.
Talk to an Approach Cyber security awareness expert
Curious how exposed your organisation currently is to these five phishing patterns?
–> Discover Approach Cyber’s phishing & security awareness services and talk to an expert about assessing your team’s readiness — dedicated pages for structured security awareness training and phishing simulation programmes are in development and will be linked here once live.