Phishing
/ˈfɪʃ.ɪŋ/ · Noun · Verb · Security & Infosec · Origin: 1995
Definitions
Phishing is a social engineering attack where an attacker impersonates a trusted entity through email, text messages, phone calls, or fraudulent websites to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data. The term is a deliberate misspelling of fishing, referring to the practice of casting bait and waiting for victims to bite. Spear phishing targets specific individuals or organizations with personalized messages, making them more convincing. Whaling targets high-profile executives. Phishing emails often create urgency (your account will be locked) or curiosity (see this document) to bypass rational judgment. Technical indicators include mismatched URLs, misspelled domain names, generic greetings, and suspicious attachments. Defenses include email filtering, multi-factor authentication, URL scanning, security awareness training, and DMARC/SPF/DKIM email authentication standards. Phishing remains the most common initial attack vector in data breaches worldwide.
In plain English: Fake emails or messages pretending to be from someone you trust, trying to trick you into giving away your password or clicking a dangerous link.
Example: "That email from 'IT Support' asking you to verify your password? Classic phish."
Etymology
- 1995
- AOL hackers coin 'phishing' — fishing for passwords with a 'ph' nod to phone phreaking
- 2003
- First major phishing attacks against banks go mainstream
- 2016
- Spear-phishing of John Podesta's Gmail becomes geopolitical news
Origin Story
From phone phreaking to your inbox
The term 'phishing' emerged in the mid-1990s, coined by hackers who were using fraudulent emails and websites to 'fish' for America Online (AOL) passwords and credit card numbers. The 'ph' spelling was a nod to 'phreaking' — the earlier tradition of phone system hacking that used the same 'ph' for 'f' substitution.
Early phishing attacks were crude: mass emails claiming your AOL account would be suspended unless you replied with your password. But the technique evolved rapidly. By the 2000s, phishing emails convincingly mimicked banks, government agencies, and major websites.
Spear phishing (targeted attacks on specific individuals) and whaling (targeting executives) emerged as sophisticated variants. Today, phishing remains the number one initial attack vector in data breaches — not because the technique is clever, but because humans remain predictably susceptible to urgency, authority, and fear.
Context: AOL hacking community, mid-1990s
Fun fact: The 'ph' in phishing continues the tradition started by phone phreakers in the 1970s, who spelled 'freak' as 'phreak' — itself inspired by the 2600 Hz tone used to hack phone systems.