Skip to content
IT

Phishing: what it really is, where it reaches you, and why careful people still fall for it

It is not a virus and not a matter of gullibility: it is a staged scene built to arrive at the right moment. How it works, what the lures look like, and what actually holds.

Andrea Bissi · · 7 min read

Cyber for Humans
Level
beginner
Time
15 minutes
What you need
Nothing

Say “phishing” and most people picture a badly written email promising a Nigerian inheritance. That still exists, but it is the bottom of the barrel. The phishing that works today is a different animal: a short message, in correct language, about a plausible piece of business, arriving at the moment that business actually concerns you.

And above all: it is not a virus. Nothing installs itself and nothing breaks. It is a staged scene, and the only part that has to work is you, typing something into a box.

In plain words

Phishing (from "fishing": you cast a line and wait): a message pretending to come from someone you trust, to make you hand over data or money. Credentials: username and password, plus the codes that confirm a sign-in. Lure: the message's pretext, the story it tells you. Phishing page: the copy of the real site where you end up typing those details.

The mechanism, in three moves

Underneath every scam of this kind sits the same structure, and recognising it is worth more than any list of warning signs.

First, the lure. A message giving you a reason to act now: a parcel held up, a fine to pay, a refund owed to you, a suspicious sign-in on your account. It does not need to be true. It needs to be possible.

Second, the diversion. A link, a button, a QR code, a number to call. It moves you from the message to a place the scammer controls, one that looks a great deal like the real place.

Third, immediate use. What you type there is not filed away for later: it is used at that moment, often by an automated program, while you are still on the page. That detail changes everything, and we come back to it shortly.

Where it arrives, beyond email

There are five channels now, and it is worth knowing all of them, because your guard drops precisely on the unexpected ones.

Email is still the main channel: the highest volume, and where the best-crafted campaigns land.

Text messages, which when used for phishing are called smishing. Lower volume than email, but with an advantage for the scammer: on a phone a web address is half visible and your guard is lower. I cover it in detail in how to spot a scam text.

Certified email, which is an Italian peculiarity worth knowing about because it shows the pattern. In Italy, certified mail (PEC) carries near-automatic trust, since it is the channel for serious business. Attackers noticed: the national CERT counted 103 campaigns over that channel in 2025, up around 80 per cent on the year before. Small numbers in absolute terms, but the fastest-growing channel, and a fake message there is opened with far less suspicion. Wherever you live, the lesson transfers: the channel people trust most is the one worth attacking.

The telephone, which in spoken form is called vishing. Here the lure is not written, a person tells it to you, and it works much better because it can adapt to your answers.

QR codes, or quishing. The code hides the address, so you cannot see where it leads before going there, and it moves you onto a phone. The clearest recent case: in May 2026 the municipal parking operator in Pesaro, Italy, reported and filed a complaint over fraudulent QR codes stuck on top of the genuine ones on parking meters, leading to pages asking for card details. Victims handed over the card and were left without paid parking too. The check that costs two seconds: run a finger over the code and feel whether there is a sticker on it.

What the lures are about

This is the part that ages, but the current picture is useful because it shows how lures are chosen.

In 2025 the single most used theme in Italy was the public payment platform PagoPA, with 328 campaigns, nearly all of them fake traffic fines. In recent weekly bulletins the top spots go to tax refunds and again fines, followed by banks and couriers.

The criterion is plain: these are things that could concern anyone, and that involve money moving, in or out. They do not ask you to be greedy. They ask you to be someone who owns a car, pays taxes and receives parcels.

Why careful people still fall for it

Something rarely said out loud: falling for it is not a measure of gullibility. Modern campaigns pull three levers that have nothing to do with how sharp you are.

Context. If the fake delivery notice arrives on the day you are genuinely expecting a parcel, the message is not convincing you of anything: it is confirming something already in your head. Whoever sends a million messages knows that for a few thousand people, that day is the right day.

Haste. Every lure contains a clock: within 24 hours, today, or the parcel goes back. It exists to prevent the one step that would dismantle the whole thing, which is stopping to check somewhere else.

Authority. The message arrives with the name of your bank, the tax office, the post office. And, as we will see, it can now arrive with the right phone number, because that can be faked.

What changed: the one-time code is no longer enough

For years the advice was: turn on two-step verification and you are safe, because even with your password they lack the code.

That no longer holds, and people who write about security should say so plainly. Organised groups now use tools that do not build a copy of the bank’s site: they sit in the middle. You talk to their server, and their server talks in real time to the real bank. What you see is the genuine page, because it is the genuine page, relayed.

So everything passes through, live: the password, the code the bank really does send to your phone, the notification you approve. At the end of the sign-in the bank issues a session pass, and that gets copied. From then on the scammer is inside without needing either the password or the code again, which is why changing the password afterwards is not enough on its own: the session has to be revoked.

One thing genuinely holds against this attack, and it is the passkey, or a security key. They work because they are bound to the site’s exact address: faced with a lookalike page, the device simply produces no signature at all, so there is nothing to relay and nothing to steal. I cover them in what passkeys are and in the comparison of the methods.

Until your bank offers them, one practical rule holds the rest up: never type a code into a page you reached from a link.

Relax:

Opening the message does no harm, and neither does opening the page: in the great majority of cases the damage starts when you type something. If you only looked and closed it, almost certainly nothing happened. The risk rises if your phone is badly behind on updates, or if you then installed something.

When it combines with spoofing

The two pieces lock together, and that is why these scams work better than they did ten years ago.

Phishing is the staged scene. Spoofing is faking the sender: making the number, the name or the address of someone you trust appear on your screen. The first needs the second to be believable.

The typical fake-bank-officer sequence runs like this: a text message slips into the genuine thread from your bank, then your phone rings and the branch’s number is on the display, and a polite voice tells you it is blocking a suspicious payment and walks you to a page to “secure your account”. Every single element you would use to verify has been faked in advance.

How to take it apart is in spoofing: why the sender proves nothing.

The verdict

You cannot spot phishing by its spelling any more, because the spelling is fine. One habit dismantles it: when a message asks you to do something now, do not do it from there. Close it, and reach the bank, the site or the office by the route you know, the app or the address you type yourself. It costs thirty seconds and takes the ground out from under the entire category, whatever channel they used.

If it has already happened

No need for embarrassment, and above all no need to wait: the first two hours matter more than everything after. The steps in order, including what to tell the bank, are in I clicked a scam link: what to do now.

And to check whether a campaign is already known, the weekly bulletins listed in where to check are the place to look.

Sources

More in Cyber for Humans