
What Is Phishing? How Modern Phishing Scams Work
Ask around, and the standard answer to what phishing is hasn't moved much since about 2010: bad spelling, a stranded prince, a link nobody sensible would click.
That description still fits a certain kind of junk mail, but it has little to do with the messages that are now costing people money. Those arrive from companies you already deal with, at moments when the request makes sense, and they usually ask for something small.
The scale is easy to underestimate, because the individual amounts are usually trivial. Reported payment fraud across the European Economic Area reached €4.2 billion in 2024, up from €3.5 billion a year earlier, according to the joint EBA–ECB report on payment fraud.
A second figure, further in the same report, says more about how it happens: for credit transfers, payment service users bore around 85% of the losses, largely because they had been persuaded to make the payments themselves.
What is phishing in simple terms? It is impersonation with a request attached. Someone poses as a company you trust and asks you to do something you'd do without hesitating if the request were real: sign in, confirm a code, update a payment detail, or settle a small fee.
Nothing has to be broken into, because you are the one operating the controls.
The name is older than most people assume. It dates to the mid-1990s, when the attackers were teenagers posing as America Online staff in chat rooms. The “ph” comes from “phreaking”, the 1970s craft of hacking telephone systems, and hijacked AOL accounts were themselves called “phish” and traded between hackers like a currency.
So what information do phishers steal? Passwords first, then card numbers, and increasingly the session token your device is handed once you've logged in and cleared the security check. That token has become the more valuable prize, because it grants access without any further checks and survives a password change.
How a Phishing Attack Is Put Together
Take the branding away, and how phishing works is a short sequence, built from the same parts every time:
- A pretext, and a reason to hurry. A held parcel, an expiring document, and an unpaid toll, plus a deadline, a fee, or a threatened suspension.
- A channel. Email, SMS, WhatsApp, a call, a printed QR code, or a reply inside a real thread from a compromised account.
- A landing page, wired to a relay. A copy of a sign-in screen on a throwaway domain, backed by software that passes whatever you type to the real service in real time.
The relay is what surprises people. On a well-built phishing page, your password is forwarded to the genuine system the instant you submit it. That system checks it and sends a genuine one-time code. You enter the code on the fake page, it's passed on, and the login succeeds. The attacker keeps the session token that comes back.
Picture a courier who carries your passport into a government office and returns with your visitor badge. The badge is real, issued by the real office against your real documents, and it is not the only copy.
That is why “I've got two-factor authentication turned on” is no longer the end of the conversation, and why access can outlive a password reset unless active sessions are revoked.
Phishing as a Service Made the Messages Better
The old advice about watching for bad grammar and clumsy layouts assumed that whoever targeted you had built the page themselves, and more often than not they haven't.
Phishing-as-a-service means someone else builds the machinery, and criminals rent it by the week. For most of 2025, a striking share of the phishing reaching European inboxes came from one product: Tycoon 2FA, a subscription platform advertised on Telegram and run like a software business.
| Tycoon 2FA | Detail |
|---|---|
| What it was | A subscription phishing platform, live from August 2023, sold on Telegram and Signal |
| Price | From $120 for ten days of panel access; $350 for a month |
| Customers | Roughly 2,000 subscribers |
| Reach | Messages reaching over 500,000 organisations a month worldwide |
| Disrupted | 4 March 2026 — 330 domains seized, police action in six countries |
| Aftermath | Volumes fell sharply that day, then returned to normal within days |
Table: how a commercial phishing-as-a-service platform was packaged and sold. Source: Microsoft Threat Intelligence, 2026, with Europol.
How does phishing as a service work from the buyer's side? You pay, log in to a panel, pick which company to impersonate from a menu (e.g., Microsoft 365, Outlook, Google, or DocuSign), and choose whether the lure arrives as a PDF, a QR code, or an HTML attachment. Captured logins are posted to a Telegram feed.
One design choice explains the rest. Before showing the fake sign-in screen, the kit served victims a CAPTCHA. Technically, that kept scanners out; in practice, it made the page feel more official, because that is where real services put them.
Microsoft's analysts describe it as a gate that legitimised the process and nudged the target onwards. Sophisticated phishing scams now focus on choreography rather than wording, which is why proofreading a message is no longer much of a test.
Europol's takedown on 4 March 2026, coordinated with Microsoft and eleven private partners, put the operation offline for roughly a day. Volumes returned to normal within the week as customers switched to rival kits. At $120 for ten days, rebuilding costs less than losing one.
The Main Types of Phishing Attacks
The types of phishing attacks are grouped by how the message reaches you, because that decides which warning signs exist at all:
- Email phishing. Mass-sent, impersonating a brand. Highest volume, best filtered.
- Spear phishing. Written for you, from social media, a breach or a real thread. Rarer, far more effective.
- Smishing. By SMS or messaging app, where links are shortened by default and cannot be inspected.
- Vishing. A call, often after an SMS, so it feels expected, with a script and a reason to need your code.
- Quishing. A QR code, printed or attached. Nobody can read one with their eyes, which is the appeal.
- Adversary-in-the-middle. Any of the above, relaying live, so one-time codes are captured as they're used.
Quishing defeats a habit rather than a control. In September 2025, The Hague pulled around 70 fraudulent QR stickers off parking meters, and the same stickers turned up in Amsterdam, Rotterdam and Maastricht.
They led to a spoofed version of a well-known parking app. What made the case awkward is that The Hague doesn't use QR codes for parking at all, so nobody had been trained to distrust them. A sticker on a meter simply looks like part of the meter.
Why Careful People Still Fall for Phishing
Can anyone fall for phishing? Yes, and the research on why people fall for phishing points at attention rather than intelligence.
A 2025 study in the European Journal of Information Systems found detection dropped sharply when working memory was loaded by multitasking. Someone switching between a document, a call and a message thread is not really evaluating an email so much as clearing it off the screen.
Missing one is closer to missing your motorway exit on a familiar route than to failing a test: the knowledge is there, it just isn't consulted.
Social engineering phishing keeps it that way, using four levers:
- Urgency: A countdown, a suspension, a fee that grows if ignored.
- Authority: A tax office, a courier, a payment provider, your manager.
- Familiarity: Correct branding, your real name, something genuinely happening.
- Plausibility: A request that fits. Nobody questions a delivery fee the week they're expecting a delivery.
Why are phishing emails convincing in 2026 in a way they weren't in 2016? The templates are commercially produced, the timing is better, and the people were trained to spot the cheapest part to fix.
Tomás, a video editor in Porto, was caught by a version of this last spring. A client he'd invoiced two weeks earlier replied to the original thread, apologised for the delay, and asked him to confirm the new account details before they released the €3,480.
The email came from the client's real address, because that mailbox had been compromised a fortnight earlier. At no point was Tomás asked to do anything reckless; he was asked to be helpful about an invoice he was already chasing.
How to Recognise Phishing and What to Do If You've Clicked
Recognising phishing has less to do with inspecting the message than with noticing the shape of the request. If you're wondering how I can identify a phishing message, three questions do most of the work: was I expecting this, does it want me to authenticate or pay through its own link, and would waiting an hour cost me anything?
Real organisations can wait an hour, and most phishing email examples fall apart if you give them one, because the pressure is the whole mechanism.
Then reach the company through a route you already have the app, a bookmark, or the number on your card, and treat any request for a one-time code as a red flag.
So what should I do after clicking a phishing link? Work down this list, in order:
If you only loaded the page, the risk is low; close it and move on.
If you entered a password, change it, then sign out of all devices. Changing the password alone can leave a stolen session running.
- If you entered card details, block the card in your app and order a replacement.
- Tell your provider, through a channel you already trust, what was entered and when.
- Check for changes you didn't make: new payees, email forwarding rules, and a second authenticator.
- Report the message so it gets taken down.
So, how do I report phishing to my bank, card issuer, or payment provider? It depends on where you are. In the UK, suspicious emails go to report@phishing.gov.uk and texts to 7726, both run by the UK's National Cyber Security Centre; across the EU, most national police forces and CERTs run an equivalent route. Either way, tell your provider directly.
Phishing Protection in the Blackcat App
Controls are far easier to use if you set them up before anything goes wrong. Some of Blackcat's fraud protection runs in the background: transactions are monitored for unusual activity, and a payment that looks wrong can be declined or held for review.
Every Blackcat payment card is enrolled in 3D Secure, which adds a verification step to online purchases and makes a card number lifted from a phishing page considerably less useful.
The rest is yours to set, and the steps are in the Blackcat help centre:
- Block a card instantly. Open the app, select the card, and tap Block card. It takes effect immediately, and you can unblock it later if the alarm turns out to be false.
- Replace a card that was compromised. Block it in the app first, then contact support via chat or email; a replacement will be issued and sent to your registered address.
- Turn on 2-step verification and set card limits. Daily and monthly limits on each card set a ceiling for a stolen number.
- Keep codes and credentials to yourself. Nobody from Blackcat will ask for your PIN, your password or a one-time code through any channel.
One version of this targets Blackcat users directly: clone sites imitating Blackcat have been appearing online, built to collect exactly the details above.
There is one official address, blackcat.app, and it is worth reading in the address bar before you type anything into a page that looks familiar. Our security team works to get fraudulent sites taken down, and reports help; flag anything that looks off in the app or at support@blackcat.app.
How the wider setup fits together, from phishing protection to card controls, is on the Blackcat security page.
FAQ:
What is phishing in simple terms?
Someone impersonates a company or person you trust and asks you to hand over something: a password, a card number, a code, or a payment. It works by persuasion rather than hacking, which is why software alone can't remove the risk.
How does phishing-as-a-service work?
Criminals rent a ready-made kit instead of building one. It supplies sign-in templates, hosting, rotating domains and a victim dashboard. Tycoon 2FA, disrupted by Europol in March 2026, started at $120 for ten days.
Why can anyone fall for a phishing attack?
Because it targets attention, not knowledge. Research published in 2025 found that people spot phishing far less reliably while multitasking, and a message designed to arrive mid-task is meant to be processed, not examined.
Why are modern phishing messages so convincing?
The templates are commercially produced and reused across thousands of campaigns, so typos and broken layouts are a thing of the past. Attackers also reply inside genuine threads from accounts they've compromised.
What information are phishing attacks designed to steal?
Login details, card numbers and one-time codes, but increasingly the session token is issued after login. It grants access without further authentication and persists after a password change unless active sessions are revoked.
How can I recognise a phishing message?
Ask whether you were expecting it, whether it wants you to log in or pay via its own link, and whether anything would break if you waited an hour.
What should I do after clicking a phishing link?
Loading the page alone is usually low risk. If you entered a password, change it and sign out of all sessions; if you entered card details, block the card and order a replacement; then tell your provider. Protections are set out on the Blackcat security page.