Skip to content

What is phishing in cyber security? Types, risks, and prevention

Discover what phishing attacks are, and how the King's NCSC-certified Advanced Cyber Security MSc can help you prevent them.

Most of us have received an email asking us to urgently reset a password or confirm a delivery we weren’t expecting. The email claims to be from a legitimate company, but on closer inspection, we notice typos or suspiciously long URL links. If you've had this before, you've already encountered phishing first-hand.

Phishing is one of the world's most common (and most effective) cyber attacks. Instead of hacking systems directly, attackers manipulate people. They impersonate trusted organisations, colleagues, services, or even loved-ones to trick victims into revealing sensitive information.

A core part of modern cyber security is understanding what phishing is, how it works, and how cyber security professionals defend against it. For those looking to enter the field, phishing and social engineering are fundamental areas of study.

Let’s take a closer look.

Are you looking to advance your career in cyber security and tackle new and emerging cyber threats? Explore the King’s Advanced Cyber Security MSc.

What is phishing?

Phishing in cyber security refers to a type of social engineering attack where a malicious actor tricks someone into sharing sensitive information, installing malware, or giving access to a system.

Typically, attackers pretend to be a trusted organisation or individual. They may impersonate a bank, a delivery service, a colleague, or even a government body.

Their goal is simple: to manipulate human trust rather than exploit technical vulnerabilities.

Phishing can target:

  • Login credentials
  • Banking or payment details
  • Personal data
  • Corporate systems and networks

It’s extremely widespread. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 77% of organisations surveyed reported that cyber-enabled fraud and phishing has increased in the past year. 73% of respondents also said that they or someone in their network had been personally affected by cyber-enabled fraud (Source: WEF, 2026).

Because phishing targets people rather than technical vulnerabilities, it's one of the easiest ways for attackers to gain initial access to systems.

Common phishing attack types with examples

There are many forms of phishing. Below, we've listed some of the most common types that affect us in 2026. We’ve also added examples of what these attacks look like in action.

Email phishing

The most common type of phishing.

Chris receives an email claiming to be from his local postal service. It says he must pay a small delivery fee to receive a parcel and includes a link to a payment page.

He clicks the link and enters his card details and email address. The website looks legitimate but is controlled by cyber criminals, who steal his information.

On closer inspection, the logo is slightly pixelated. Hovering over the link reveals the letter O in “post office” has been replaced with the number 0.

Email phishing works because attackers create convincing messages that mimic trusted brands and organisations.

Spear phishing

A targeted form of phishing.

Instead of sending generic emails to thousands of people, attackers research specific individuals or organisations.

Claire works in a company’s finance team. She receives an email that appears to be from her manager, referencing a real project and asking her to urgently pay an invoice to a new supplier account.

Because the message seems legitimate, she processes the payment. In reality, the email was sent by a cyber criminal who had researched the company online.

Spear phishing is dangerous because messages are highly personalised and designed to feel authentic.

Voice phishing (vishing)

Voice phishing, or vishing, happens over the phone.

Ethan receives a call from someone claiming to be from his bank, saying his account has been compromised. He is asked to share his PIN to verify his identity.

The caller is actually a cyber criminal who then gains access to his account.

In another case, Ada receives a call that sounds like her grandfather asking for urgent financial help. The voice is a deepfake created using generative AI.

Because the interaction happens in real time, victims often feel pressured to act quickly.

Smishing

Smishing is phishing carried out through SMS messages.

Jake receives a text saying his bank account has been locked due to suspicious activity. The message includes a link asking him to verify his identity.

The link leads to a fake banking website designed to steal his login details.

Smishing can be effective because SMS messages often lack the warning signs we look for in emails, making scams harder to spot.

Risks to organisations and individuals

Phishing attacks can have serious consequences.

For individuals, successful phishing may lead to:

  • Financial fraud
  • Identity theft
  • Account compromise
  • Loss of personal data

For organisations, the impact can be even greater.

Phishing is often the first step in larger cyber attacks. Once attackers gain access to login credentials or internal systems, they may:

  • Deploy ransomware
  • Steal sensitive data
  • Conduct corporate espionage
  • Disrupt operations

Real-world incidents show how damaging phishing attacks can be.

Phishing has also played a role in major infrastructure attacks. The 2021 Colonial Pipeline incident involved attackers gaining access to company systems before deploying ransomware. It is believed to be the largest successful cyber-attack on an oil company in US history (Politico, 2021). It forced the company to shut down operations temporarily, which disrupted fuel supply across the U.S. East Coast.

Financial organisations have suffered major losses as well. In Belgium, Crelan Bank was targeted by a business email compromise attack in which criminals impersonated the CEO and convinced employees to transfer funds. The incident reportedly resulted in losses exceeding £57 million (BCS, 2022).

These examples show why phishing is considered one of the most dangerous entry points for cyber criminals.

Modern phishing campaigns are also becoming more sophisticated. The World Economic Forum reports 'exposure of personal data through genAI' and 'advancement of adversarial capabilities' as the top two primary concerns for CEOs in 2026. (Source: WEF).

Similarly, threat intelligence reports show that AI tools are helping attackers move from initial access to impact faster than ever before. In fact, figures show that AI-enabled adversaries increased attacks by 89% year-over-year in 2025 (Source: CrowdStrike, 2026).

This evolving threat landscape is one reason phishing remains a major focus for cyber security professionals.

How to prevent phishing attacks

Defending against phishing requires a combination of technology, education, and security processes.

Cyber security teams use several key strategies.

Security awareness training

Cyber-aware employees are every organisation's first line of defence.

Companies should deliver regular training to employees to ensure that they recognise suspicious emails, links, and requests. Some cyber security teams perform phishing simulation tests, where fake, controlled phishing emails are sent to employees. They can then track and analyse how many employees report these emails and identify individuals who may need additional phishing awareness and training.

Simple habits - like checking sender addresses or avoiding unexpected attachments - can stop many attacks before they succeed.

Email filtering and threat detection

Modern security systems analyse incoming emails to detect malicious links, suspicious attachments, and impersonation attempts.

Artificial intelligence is increasingly used for phishing detection. In fact, 52% of organisations who are using AI in cybersecurity apply it specifically to improve phishing detection (Source: WEF, 2026).

Rolling out multi-factor authentication (MFA)

Even if attackers steal passwords through phishing, MFA can prevent them from accessing accounts.

MFA, such as 2FA (two-factor authentication), adds an extra verification step to confirm that the access attempt is being carried out by the legitimate account holder. Prompts could involve being asked to acknowledge a notification sent to the account holder's phone, doing a fingerprint scan, or entering a security code.

However, as the NCSC points out in this blog post, different MFA types vary a lot in terms of the level of security they offer. It has now published official guidance that helps organisations choose the strongest type of MFA authentication that is practical to implement.

Monitoring and incident response

Cyber security teams monitor networks for suspicious activity. If a phishing attack is detected, they can quickly block accounts, isolate affected systems, and investigate the breach.

How the King’s MSc in Advanced Cyber Security covers phishing and social engineering

Understanding phishing isn’t just about recognising suspicious emails. It involves studying the psychology, technology, and defensive strategies behind social engineering attacks.

In our Advanced Cyber Security MSc, students explore areas such as:

  • Network security
  • Security testing
  • Digital forensics
  • Threat detection and incident response
  • Risk and security management

These topics help you understand how attackers exploit human behaviour, and how organisations can defend against those threats.

By analysing real-world cyber incidents and attack techniques, you'll gain the skills needed to identify, investigate, and prevent phishing attacks

Learn to prevent phishing attacks with the King's Advanced Cyber Security MSc

Phishing is one of the most common cyber attacks because it exploits human behaviour rather than technical systems.

From fraudulent emails to voice impersonation scams, phishing continues to evolve as attackers adopt new technologies. AI-enabled social engineering is making these attacks more convincing and scalable.

For cyber security professionals, protecting individuals and organisations from phishing is a critical priority.

If you’re interested in learning how to analyse, detect, and defend against threats like phishing, visit the Advanced Cyber Security MSc programme page. There, you can learn about module content, career outcomes, and how we'll help you protect organisations against phishing attacks.

See programme details