Phishing Defined in Plain Terms
Phishing is a fraud in which an attacker sends a message that looks like it comes from someone you trust such as your bank, a supplier or your own IT department, to trick you into handing over a password, approving a payment or opening a file that installs malware. The message can arrive by email, text or phone call.
The FBI’s Internet Crime Complaint Center defines it in much the same way. Phishing and spoofing are unsolicited emails, text messages and telephone calls that purport to come from a legitimate company and ask for personal, financial or login credentials. In Swedish the word is nätfiske.
A thirty-year-old trick deserves a guide because it is still how most attackers get in. ENISA, the EU’s cybersecurity agency, analysed 4,875 incidents across Europe between July 2024 and June 2025 for its Threat Landscape 2025 report. Phishing was the primary initial intrusion vector in about 60 percent of them. Vulnerability exploitation, which is where most security budgets point, came second at 21.3 percent.
Your firewall is not the front door. Your people’s inboxes are.
How a Phishing Attack Works
Every phishing attack follows roughly the same five steps. Knowing them matters because you can break the chain at more than one point.
- Research: the attacker reads your website, your team’s LinkedIn profiles and any data that has already leaked. That shows them who approves payments and who resets passwords.
- The lure: a message that borrows a real reason to act. An unpaid invoice, an expiring password, a shared document, a delivery, a request from the chief executive.
- The handover: you type a password into a page that looks right, approve a login prompt, read out a code or open an attachment.
- The access: the attacker signs in as you or the malware runs on your machine.
- The payoff: money moves, mail is quietly forwarded to an outside address or the access is sold on to a ransomware crew.
What has changed is the cost of running that chain. ENISA describes phishing-as-a-service platforms that have turned phishing into a subscription product, letting operators with no skill run campaigns that once needed a team. One platform it names, Darcula, impersonated hundreds of organisations.
Then there is AI. ENISA reports that by early 2025 AI-supported phishing made up more than 80 percent of the social engineering activity observed worldwide and that more than 80 percent of the phishing emails identified between September 2024 and February 2025 used AI to some degree.
The FBI is seeing the same thing in its complaint data. In 2025 it logged 22,364 AI-related fraud complaints carrying 893 million dollars of losses, the first year it counted them. It describes chat tools writing emails that copy a chief executive’s writing style. It describes cloned voices making the phone call that confirms the transfer.
So the advice your staff were given a decade ago is now actively misleading. The phishing meaning most people carry around, a badly spelled email from a fake bank, is a decade out of date. Bad spelling and a generic greeting are no longer reliable tells. The message that lands in your inbox tomorrow will be well written, correctly branded and about something real.
Types of Phishing Attacks
These are channels and targeting styles rather than separate crimes. Every phishing scam below runs the same trick and only the delivery changes.
- Email phishing: sent indiscriminately to thousands of inboxes, fishing for whoever bites. Cheap, noisy and still effective.
- Spear phishing: aimed at a named person built from real detail about their work. The UK’s National Cyber Security Centre notes that these are significantly harder to detect than mass campaigns. In Swedish, riktat nätfiske.
- Whaling: spear phishing pointed at a senior figure, typically a board member or an executive with access to valuable systems and money.
- Business email compromise: the payments version. The FBI defines it as a scam against businesses that work with suppliers or make wire transfers, where attackers compromise email accounts and other channels through social engineering or intrusion, then redirect funds.
- Smishing: phishing by SMS where a short link and a small screen hide where you are actually going.
- Vishing: phishing by phone. In Sweden this now dominates. Of the 33,516 reports of attempted fraud registered by the police in 2025, 25,199 were attempted vishing, which is 75.2 percent of every attempt reported.
- Quishing: a QR code instead of a link. The code is an image so filters that read text see nothing. Scanning it also moves the victim onto a personal phone that your controls may not cover.
- Help desk impersonation: the attacker phones your service desk, plays a locked-out colleague and talks an agent into resetting a password or a multi-factor authentication device.
- MFA-bypass phishing: a fake login page that relays your code to the real site in real time or a flood of push prompts until someone taps approve. CISA is explicit that not all multi-factor authentication is equally secure and that some forms are vulnerable to phishing, push bombing, SS7 exploitation and SIM swapping.
A defence that only inspects email leaves the phone, the QR code and the service desk wide open.
The Business Impact of Phishing
Phishing costs money in four ways. Only the first one is obvious.
Money Sent to the Wrong Account
Business email compromise is where the losses concentrate. Victims reported more than 3 billion dollars of business email compromise losses to the FBI in 2025, across 24,768 complaints. No malware is involved in most of that. A finance team simply pays an invoice that looks normal.
Attacks That Do More Damage Each Time
Phishing and spoofing is the FBI’s most reported crime type with 191,561 complaints in 2025, more than double the next category. Volume was flat against 2024, which had 193,407. The losses tell a different story. Reported phishing losses rose from about 70 million dollars in 2024 to 215.8 million dollars in 2025, more than tripling in a year.
Read those two numbers together and the trend is clear. The same quantity of phishing is now landing much harder because the targeting is better and the follow-through is faster.
The Way In for Something Worse
CERT-SE, Sweden’s national CERT, describes nätfiske as one of the most effective methods attackers have for gaining unauthorised access to systems and sensitive information and a common entry vector for ransomware. The phishing email is usually the first hour of a much longer incident.
Downtime, Regulators and the Next Wave
A successful phish stops trading, triggers reporting duties and hands attackers the raw material for the next campaign. When the Swedish HR systems supplier Miljödata was breached in August 2025, personal data on around 1.5 million people ended up published on the dark web and IMY opened its GDPR investigations that November. Every one of those records is now fuel for a more convincing phishing message.
The Swedish numbers underneath all this are a floor. Brå recorded 232,862 fraud offences in Sweden in 2025 and notes that fraud through social manipulation is rising even as reported identity fraud falls. Brå also found that more than half of the Swedish companies hit by crime never report it and that the least likely to report are the ones dealing with fraud and computer intrusion.
Real-World Phishing Cases
Four attacks, four different failures and four controls that would have changed the outcome.
The Fake Supplier That Billed Two Tech Giants
Between 2013 and 2015 Evaldas Rimasauskas registered a company in Latvia carrying the same name as an Asian computer hardware manufacturer that two large US internet companies bought from regularly. His crew sent phishing emails that appeared to come from that manufacturer with forged invoices, contracts and letters to back them up, redirecting the payments to accounts he controlled.
The victims wired more than 120 million dollars. The US Department of Justice sentenced him to five years in prison in December 2019 and ordered him to forfeit 49.7 million dollars. The two companies, later reported as Facebook and Google, said they recovered all or most of the money.
The FBI’s account of the investigation is the part worth keeping. For two years the crew rang the victims’ customer service lines to collect names and job titles and phished their way into the email systems to learn how payments were approved. Only then did someone call to ask for the bank details to be updated.
What would have stopped it costs nothing. A change to a supplier’s bank details gets confirmed by calling a number you already hold, never a number supplied in the request itself.
Norsk Hydro and the Attachment From a Trusted Customer
On 18 March 2019 LockerGoga ransomware locked roughly 22,000 computers across 170 sites in 40 countries at the Norwegian aluminium producer Norsk Hydro. The company refused to pay, ran its smelters manually and rebuilt from backups. It put the financial impact at 300 to 350 million Norwegian kroner in the first quarter of 2019 alone.
The entry point, by Hydro’s own account of the incident, was an email attachment that arrived in December 2018 from a customer whose account had been compromised, inside a legitimate ongoing conversation. The attackers held a foothold for three months before the ransomware ran. Some analysts questioned the vector at the time, so treat the detail as Hydro’s own telling of it.
Two lessons sit in that timeline. A genuine sender is no guarantee of a safe attachment. And those three quiet months are precisely the window that monitoring exists to close.
Marks and Spencer and a Phone Call to the Help Desk
On 8 July 2025 the chairman of Marks and Spencer, Archie Norman, told a UK parliamentary committee that the retailer’s attackers got in on 17 April 2025 through social engineering, which he called “a euphemism for impersonation”. Someone posed convincingly as an employee, complete with that person’s details and got the account’s credentials reset. A third party was involved at the point of entry.
Marks and Spencer disclosed the incident to the London Stock Exchange on 22 April, stopped taking online orders on 25 April and confirmed on 13 May that customer data had been stolen. It estimated the damage at around 300 million pounds of operating profit.
No malware was needed to open that door. A convincing voice and a password reset were enough.
Treat the help desk as an identity checkpoint. Anyone who can reset a credential including staff at a supplier you outsource to, needs a verification step that refuses to accept confidence as proof of identity.
The Co-op and the Same Attack With a Different Ending
Days later the same technique was turned on the Co-op. Its chief digital and information officer, Rob Elsey, told the same committee that the attackers impersonated a colleague and answered enough security questions to get that account reset.
This time it ended differently. The Co-op spotted the intrusion and pulled systems offline quickly and the disruption its customers saw stayed comparatively small.
Same attackers, same trick, two very different quarters. The difference came down to how fast the Co-op noticed and how willing it was to take systems down while that still cost something. Assume the phish will land and measure yourself on the minutes after it does.
Phishing and Compliance
In Sweden, protecting people against phishing stopped being good practice and became a legal duty. Here is what each regime actually asks for.
Cybersäkerhetslagen and NIS2
Cybersäkerhetslagen (SFS 2025:1506) came into force on 15 January 2026 and transposes the EU’s NIS2 directive into Swedish law. Article 21.2g of NIS2 lists security awareness training among the security measures in-scope organisations must have. That moves awareness training out of the training budget and into the compliance register.
Article 20 puts it on the board. The management body must approve and oversee the security measures, and supervisory authorities can hold board members personally accountable. Fines reach 10 million euros or 2 percent of global turnover for essential entities and 7 million euros or 1.4 percent for important entities. Our NIS2 compliance in Sweden guide sets out the full obligations.
The Reporting Cascade
A significant incident is reported to MCF (formerly MSB) and to your sector authority on a fixed clock. An early warning within 24 hours. A full notification within 72 hours. A final report within one month. A phished mailbox that is used to move money or reach other systems will usually meet that bar, so the clock starts at detection rather than at the end of your enquiry.
GDPR
A phished mailbox holding personal data is a personal data breach. Article 33 of the GDPR gives you 72 hours to notify IMY. This is the duty most organisations forget because a stolen password does not feel like a data breach until you work out what the mailbox contained. See our GDPR compliance in Sweden guide.
DORA
Financial entities have a parallel regime. Article 17 of DORA sets the requirements for ICT incident management, supervised by Finansinspektionen. Read our DORA compliance guide for the detail.
One number puts the regulatory exposure in context. In ENISA’s European dataset for 2024 and 2025, entities classed as essential under NIS2 accounted for 53.7 percent of all incidents, and public administration was the most-targeted sector at 38.2 percent. The organisations with the heaviest duties are the ones being hit.
How to Spot a Phishing Attempt
The tells worth teaching are about behaviour rather than appearance. Look at what the message wants you to do and how fast it wants you to do it.
- Urgency, a deadline or a threat. Act now, or the account closes.
- Secrecy. A deal, an acquisition or a bonus you must not discuss with anyone.
- A request that skips the normal process or that comes from the right person through the wrong channel.
- Any change to bank details, payment routes or payroll destinations.
- A link that asks you to log in. Check the domain itself because the display name and the logo prove nothing.
- An attachment you were not expecting, even from someone you know well.
- A QR code in an email which moves you onto a phone your organisation may not protect.
- A caller who resists being called back on a number you already hold.
- A login page where your password manager refuses to autofill. It has compared the page against the real domain and they do not match.
Now the caveat and it matters more than the list above. The UK’s National Cyber Security Centre says plainly that no training package, phishing simulations included, can teach people to catch every attempt. Asking staff to forensically examine every email is unrealistic because opening mail and clicking links is the job.
The NCSC goes further. It warns that punishing people for clicking a simulated phish starts to look like entrapment and worse, teaches them not to report. Track your reporting rate with at least as much care as your click rate.
Teach the tells anyway. They catch the cheap attacks and they build the reflex to report. Just do not mistake them for a defence.
How to Defend Against Phishing
The NCSC recommends building phishing defences in four layers on the assumption that some attempts will always get through. Each layer buys you another chance to catch the same attack.
Make It Hard to Reach Your People
- Publish DMARC, SPF and DKIM and set your DMARC policy to reject. CISA, the NSA, the FBI and MS-ISAC all put this first in their joint phishing guidance because it stops criminals sending mail that appears to come from your domain.
- Filter and block at the mail server, not only on the device.
- Trim the digital footprint that makes spear phishing easy to write. Ask what a visitor genuinely needs to know about your org chart.
Make Reporting Easy and Safe
- Put a report button in the mail client, so reporting takes one click.
- Tell people what happened to the thing they reported. Silence kills the habit.
- Mark external email clearly which CERT-SE recommends, so a spoofed internal address stands out.
- Never punish a click. You need the report more than you need to be right.
Assume Some Phishing Lands
- Move to phishing-resistant multi-factor authentication. CISA calls FIDO2, WebAuthn and PKI the gold standard, because the key is bound to the real domain and a fake login page cannot use it. Start with administrators and with anyone who can move money or reset a credential.
- Give the help desk a scripted identity check that does not accept a confident voice as proof.
- Use a password manager. It will not autofill your credentials into a lookalike domain which makes it a detection control as well as a convenience.
- Keep devices patched and keep administrator rights rare.
- Verify every payment change and every unusual request through a channel you established before the request arrived.
Be Ready to Respond
- Log and monitor. The dangerous phish is the one nobody reported. Our managed detection and response service exists for exactly that window.
- Rehearse. Know who forces the password reset, who kills the active sessions and who cleans the machine.
- On a fraudulent payment, call the bank immediately. In 2025 the FBI’s Recovery Asset Team took 3,900 actions against 1.16 billion dollars of attempted theft and froze 679 million, a success rate of 58 percent. Freezing works far more often than people expect and it works within hours rather than days.
Why the Layers Beat Vigilance
The NCSC publishes a case study that shows the arithmetic. A financial firm with around 4,000 staff was hit with 1,800 emails carrying the Dridex malware, disguised as an invoice needing urgent attention and written in clean, correct English.
- Filtering stopped 1,750 of them.
- 50 reached an inbox.
- 36 were ignored or reported, with 25 reports in total, some of them after the click.
- 14 were clicked and launched the malware.
- 13 of those failed because the devices were up to date.
- 1 installed, and its call home to the attacker was detected and blocked.
One laptop was seized, cleaned and back in use within hours. No single layer caught everything. Filtering did the heavy lifting, patching absorbed most of what got through and monitoring closed out the last one. Build that stack, then train the habit that sits on top of it.



