Threats & attacks

What is Phishing?

What phishing is, why it still works and the layered defence that holds when spotting the email does not.

What is Phishing
Key takeaways
  • Phishing is a fraud that uses a trusted-looking message to steal a password, trigger a payment or install malware. It arrives by email, SMS, phone call or QR code.
  • It is still the main way attackers get in. ENISA found phishing was the initial intrusion vector in about 60 percent of the 4,875 European incidents it analysed for 2024 and 2025 ahead of vulnerability exploitation at 21.3 percent.
  • It was the most reported crime type to the FBI in 2025 with 191,561 complaints.
  • The same volume of attacks now does far more damage. Reported phishing losses to the FBI rose from about 70 million dollars in 2024 to 215.8 million dollars in 2025 more than tripling, while complaint numbers stayed flat.
  • Business email compromise, the version that targets payments, cost reported victims more than 3 billion dollars in 2025.
  • Phishing is no longer an email problem. Of 33,516 attempted frauds reported to the Swedish police in 2025, 25,199 were attempted vishing, which is three quarters of every attempt.
  • AI has removed the old tells. ENISA reports that AI-supported phishing made up more than 80 percent of the social engineering activity observed worldwide by early 2025.
  • Spotting phishing is the weakest layer. The UK’s NCSC says no training package can teach people to catch every attempt and warns against punishing those who click.
  • Ordinary multi-factor authentication is not enough. CISA warns that SMS codes and push prompts can be phished or bombarded and calls FIDO2, WebAuthn and PKI the gold standard.
  • Awareness training is now a legal duty. NIS2 Article 21.2g requires it and Cybersäkerhetslagen has applied it in Sweden since 15 January 2026 with boards personally accountable.

Phishing Defined in Plain Terms

Phishing is a fraud in which an attacker sends a message that looks like it comes from someone you trust such as your bank, a supplier or your own IT department, to trick you into handing over a password, approving a payment or opening a file that installs malware. The message can arrive by email, text or phone call.

The FBI’s Internet Crime Complaint Center defines it in much the same way. Phishing and spoofing are unsolicited emails, text messages and telephone calls that purport to come from a legitimate company and ask for personal, financial or login credentials. In Swedish the word is nätfiske.

A thirty-year-old trick deserves a guide because it is still how most attackers get in. ENISA, the EU’s cybersecurity agency, analysed 4,875 incidents across Europe between July 2024 and June 2025 for its Threat Landscape 2025 report. Phishing was the primary initial intrusion vector in about 60 percent of them. Vulnerability exploitation, which is where most security budgets point, came second at 21.3 percent.

Your firewall is not the front door. Your people’s inboxes are.

How a Phishing Attack Works

Every phishing attack follows roughly the same five steps. Knowing them matters because you can break the chain at more than one point.

  • Research: the attacker reads your website, your team’s LinkedIn profiles and any data that has already leaked. That shows them who approves payments and who resets passwords.
  • The lure: a message that borrows a real reason to act. An unpaid invoice, an expiring password, a shared document, a delivery, a request from the chief executive.
  • The handover: you type a password into a page that looks right, approve a login prompt, read out a code or open an attachment.
  • The access: the attacker signs in as you or the malware runs on your machine.
  • The payoff: money moves, mail is quietly forwarded to an outside address or the access is sold on to a ransomware crew.

What has changed is the cost of running that chain. ENISA describes phishing-as-a-service platforms that have turned phishing into a subscription product, letting operators with no skill run campaigns that once needed a team. One platform it names, Darcula, impersonated hundreds of organisations.

Then there is AI. ENISA reports that by early 2025 AI-supported phishing made up more than 80 percent of the social engineering activity observed worldwide and that more than 80 percent of the phishing emails identified between September 2024 and February 2025 used AI to some degree.

The FBI is seeing the same thing in its complaint data. In 2025 it logged 22,364 AI-related fraud complaints carrying 893 million dollars of losses, the first year it counted them. It describes chat tools writing emails that copy a chief executive’s writing style. It describes cloned voices making the phone call that confirms the transfer.

So the advice your staff were given a decade ago is now actively misleading. The phishing meaning most people carry around, a badly spelled email from a fake bank, is a decade out of date. Bad spelling and a generic greeting are no longer reliable tells. The message that lands in your inbox tomorrow will be well written, correctly branded and about something real.

Types of Phishing Attacks

These are channels and targeting styles rather than separate crimes. Every phishing scam below runs the same trick and only the delivery changes.

  • Email phishing: sent indiscriminately to thousands of inboxes, fishing for whoever bites. Cheap, noisy and still effective.
  • Spear phishing: aimed at a named person built from real detail about their work. The UK’s National Cyber Security Centre notes that these are significantly harder to detect than mass campaigns. In Swedish, riktat nätfiske.
  • Whaling: spear phishing pointed at a senior figure, typically a board member or an executive with access to valuable systems and money.
  • Business email compromise: the payments version. The FBI defines it as a scam against businesses that work with suppliers or make wire transfers, where attackers compromise email accounts and other channels through social engineering or intrusion, then redirect funds.
  • Smishing: phishing by SMS where a short link and a small screen hide where you are actually going.
  • Vishing: phishing by phone. In Sweden this now dominates. Of the 33,516 reports of attempted fraud registered by the police in 2025, 25,199 were attempted vishing, which is 75.2 percent of every attempt reported.
  • Quishing: a QR code instead of a link. The code is an image so filters that read text see nothing. Scanning it also moves the victim onto a personal phone that your controls may not cover.
  • Help desk impersonation: the attacker phones your service desk, plays a locked-out colleague and talks an agent into resetting a password or a multi-factor authentication device.
  • MFA-bypass phishing: a fake login page that relays your code to the real site in real time or a flood of push prompts until someone taps approve. CISA is explicit that not all multi-factor authentication is equally secure and that some forms are vulnerable to phishing, push bombing, SS7 exploitation and SIM swapping.

A defence that only inspects email leaves the phone, the QR code and the service desk wide open.

The Business Impact of Phishing

Phishing costs money in four ways. Only the first one is obvious.

Money Sent to the Wrong Account

Business email compromise is where the losses concentrate. Victims reported more than 3 billion dollars of business email compromise losses to the FBI in 2025, across 24,768 complaints. No malware is involved in most of that. A finance team simply pays an invoice that looks normal.

Attacks That Do More Damage Each Time

Phishing and spoofing is the FBI’s most reported crime type with 191,561 complaints in 2025, more than double the next category. Volume was flat against 2024, which had 193,407. The losses tell a different story. Reported phishing losses rose from about 70 million dollars in 2024 to 215.8 million dollars in 2025, more than tripling in a year.

Read those two numbers together and the trend is clear. The same quantity of phishing is now landing much harder because the targeting is better and the follow-through is faster.

The Way In for Something Worse

CERT-SE, Sweden’s national CERT, describes nätfiske as one of the most effective methods attackers have for gaining unauthorised access to systems and sensitive information and a common entry vector for ransomware. The phishing email is usually the first hour of a much longer incident.

Downtime, Regulators and the Next Wave

A successful phish stops trading, triggers reporting duties and hands attackers the raw material for the next campaign. When the Swedish HR systems supplier Miljödata was breached in August 2025, personal data on around 1.5 million people ended up published on the dark web and IMY opened its GDPR investigations that November. Every one of those records is now fuel for a more convincing phishing message.

The Swedish numbers underneath all this are a floor. Brå recorded 232,862 fraud offences in Sweden in 2025 and notes that fraud through social manipulation is rising even as reported identity fraud falls. Brå also found that more than half of the Swedish companies hit by crime never report it and that the least likely to report are the ones dealing with fraud and computer intrusion.

Real-World Phishing Cases

Four attacks, four different failures and four controls that would have changed the outcome.

The Fake Supplier That Billed Two Tech Giants

Between 2013 and 2015 Evaldas Rimasauskas registered a company in Latvia carrying the same name as an Asian computer hardware manufacturer that two large US internet companies bought from regularly. His crew sent phishing emails that appeared to come from that manufacturer with forged invoices, contracts and letters to back them up, redirecting the payments to accounts he controlled.

The victims wired more than 120 million dollars. The US Department of Justice sentenced him to five years in prison in December 2019 and ordered him to forfeit 49.7 million dollars. The two companies, later reported as Facebook and Google, said they recovered all or most of the money.

The FBI’s account of the investigation is the part worth keeping. For two years the crew rang the victims’ customer service lines to collect names and job titles and phished their way into the email systems to learn how payments were approved. Only then did someone call to ask for the bank details to be updated.

What would have stopped it costs nothing. A change to a supplier’s bank details gets confirmed by calling a number you already hold, never a number supplied in the request itself.

Norsk Hydro and the Attachment From a Trusted Customer

On 18 March 2019 LockerGoga ransomware locked roughly 22,000 computers across 170 sites in 40 countries at the Norwegian aluminium producer Norsk Hydro. The company refused to pay, ran its smelters manually and rebuilt from backups. It put the financial impact at 300 to 350 million Norwegian kroner in the first quarter of 2019 alone.

The entry point, by Hydro’s own account of the incident, was an email attachment that arrived in December 2018 from a customer whose account had been compromised, inside a legitimate ongoing conversation. The attackers held a foothold for three months before the ransomware ran. Some analysts questioned the vector at the time, so treat the detail as Hydro’s own telling of it.

Two lessons sit in that timeline. A genuine sender is no guarantee of a safe attachment. And those three quiet months are precisely the window that monitoring exists to close.

Marks and Spencer and a Phone Call to the Help Desk

On 8 July 2025 the chairman of Marks and Spencer, Archie Norman, told a UK parliamentary committee that the retailer’s attackers got in on 17 April 2025 through social engineering, which he called “a euphemism for impersonation”. Someone posed convincingly as an employee, complete with that person’s details and got the account’s credentials reset. A third party was involved at the point of entry.

Marks and Spencer disclosed the incident to the London Stock Exchange on 22 April, stopped taking online orders on 25 April and confirmed on 13 May that customer data had been stolen. It estimated the damage at around 300 million pounds of operating profit.

No malware was needed to open that door. A convincing voice and a password reset were enough.

Treat the help desk as an identity checkpoint. Anyone who can reset a credential including staff at a supplier you outsource to, needs a verification step that refuses to accept confidence as proof of identity.

The Co-op and the Same Attack With a Different Ending

Days later the same technique was turned on the Co-op. Its chief digital and information officer, Rob Elsey, told the same committee that the attackers impersonated a colleague and answered enough security questions to get that account reset.

This time it ended differently. The Co-op spotted the intrusion and pulled systems offline quickly and the disruption its customers saw stayed comparatively small.

Same attackers, same trick, two very different quarters. The difference came down to how fast the Co-op noticed and how willing it was to take systems down while that still cost something. Assume the phish will land and measure yourself on the minutes after it does.

Phishing and Compliance

In Sweden, protecting people against phishing stopped being good practice and became a legal duty. Here is what each regime actually asks for.

Cybersäkerhetslagen and NIS2

Cybersäkerhetslagen (SFS 2025:1506) came into force on 15 January 2026 and transposes the EU’s NIS2 directive into Swedish law. Article 21.2g of NIS2 lists security awareness training among the security measures in-scope organisations must have. That moves awareness training out of the training budget and into the compliance register.

Article 20 puts it on the board. The management body must approve and oversee the security measures, and supervisory authorities can hold board members personally accountable. Fines reach 10 million euros or 2 percent of global turnover for essential entities and 7 million euros or 1.4 percent for important entities. Our NIS2 compliance in Sweden guide sets out the full obligations.

The Reporting Cascade

A significant incident is reported to MCF (formerly MSB) and to your sector authority on a fixed clock. An early warning within 24 hours. A full notification within 72 hours. A final report within one month. A phished mailbox that is used to move money or reach other systems will usually meet that bar, so the clock starts at detection rather than at the end of your enquiry.

GDPR

A phished mailbox holding personal data is a personal data breach. Article 33 of the GDPR gives you 72 hours to notify IMY. This is the duty most organisations forget because a stolen password does not feel like a data breach until you work out what the mailbox contained. See our GDPR compliance in Sweden guide.

DORA

Financial entities have a parallel regime. Article 17 of DORA sets the requirements for ICT incident management, supervised by Finansinspektionen. Read our DORA compliance guide for the detail.

One number puts the regulatory exposure in context. In ENISA’s European dataset for 2024 and 2025, entities classed as essential under NIS2 accounted for 53.7 percent of all incidents, and public administration was the most-targeted sector at 38.2 percent. The organisations with the heaviest duties are the ones being hit.

How to Spot a Phishing Attempt

The tells worth teaching are about behaviour rather than appearance. Look at what the message wants you to do and how fast it wants you to do it.

  • Urgency, a deadline or a threat. Act now, or the account closes.
  • Secrecy. A deal, an acquisition or a bonus you must not discuss with anyone.
  • A request that skips the normal process or that comes from the right person through the wrong channel.
  • Any change to bank details, payment routes or payroll destinations.
  • A link that asks you to log in. Check the domain itself because the display name and the logo prove nothing.
  • An attachment you were not expecting, even from someone you know well.
  • A QR code in an email which moves you onto a phone your organisation may not protect.
  • A caller who resists being called back on a number you already hold.
  • A login page where your password manager refuses to autofill. It has compared the page against the real domain and they do not match.

Now the caveat and it matters more than the list above. The UK’s National Cyber Security Centre says plainly that no training package, phishing simulations included, can teach people to catch every attempt. Asking staff to forensically examine every email is unrealistic because opening mail and clicking links is the job.

The NCSC goes further. It warns that punishing people for clicking a simulated phish starts to look like entrapment and worse, teaches them not to report. Track your reporting rate with at least as much care as your click rate.

Teach the tells anyway. They catch the cheap attacks and they build the reflex to report. Just do not mistake them for a defence.

How to Defend Against Phishing

The NCSC recommends building phishing defences in four layers on the assumption that some attempts will always get through. Each layer buys you another chance to catch the same attack.

Make It Hard to Reach Your People

  • Publish DMARC, SPF and DKIM and set your DMARC policy to reject. CISA, the NSA, the FBI and MS-ISAC all put this first in their joint phishing guidance because it stops criminals sending mail that appears to come from your domain.
  • Filter and block at the mail server, not only on the device.
  • Trim the digital footprint that makes spear phishing easy to write. Ask what a visitor genuinely needs to know about your org chart.

Make Reporting Easy and Safe

  • Put a report button in the mail client, so reporting takes one click.
  • Tell people what happened to the thing they reported. Silence kills the habit.
  • Mark external email clearly which CERT-SE recommends, so a spoofed internal address stands out.
  • Never punish a click. You need the report more than you need to be right.

Assume Some Phishing Lands

  • Move to phishing-resistant multi-factor authentication. CISA calls FIDO2, WebAuthn and PKI the gold standard, because the key is bound to the real domain and a fake login page cannot use it. Start with administrators and with anyone who can move money or reset a credential.
  • Give the help desk a scripted identity check that does not accept a confident voice as proof.
  • Use a password manager. It will not autofill your credentials into a lookalike domain which makes it a detection control as well as a convenience.
  • Keep devices patched and keep administrator rights rare.
  • Verify every payment change and every unusual request through a channel you established before the request arrived.

Be Ready to Respond

  • Log and monitor. The dangerous phish is the one nobody reported. Our managed detection and response service exists for exactly that window.
  • Rehearse. Know who forces the password reset, who kills the active sessions and who cleans the machine.
  • On a fraudulent payment, call the bank immediately. In 2025 the FBI’s Recovery Asset Team took 3,900 actions against 1.16 billion dollars of attempted theft and froze 679 million, a success rate of 58 percent. Freezing works far more often than people expect and it works within hours rather than days.

Why the Layers Beat Vigilance

The NCSC publishes a case study that shows the arithmetic. A financial firm with around 4,000 staff was hit with 1,800 emails carrying the Dridex malware, disguised as an invoice needing urgent attention and written in clean, correct English.

  • Filtering stopped 1,750 of them.
  • 50 reached an inbox.
  • 36 were ignored or reported, with 25 reports in total, some of them after the click.
  • 14 were clicked and launched the malware.
  • 13 of those failed because the devices were up to date.
  • 1 installed, and its call home to the attacker was detected and blocked.

One laptop was seized, cleaned and back in use within hours. No single layer caught everything. Filtering did the heavy lifting, patching absorbed most of what got through and monitoring closed out the last one. Build that stack, then train the habit that sits on top of it.

Myths & Facts

Myth

You can spot a phishing email if you look closely enough.

We have multi-factor authentication so phishing cannot hurt us.

Phishing is an email problem.

Phishing is a consumer scam, not a business threat.

A phishing message will obviously come from a stranger.

Punishing people who click will make them more careful.

Fact

The UK's NCSC says that no training package, phishing simulations included, can teach people to catch every attempt and that targeted messages are harder again. AI has already removed the spelling mistakes staff were taught to look for.

CISA warns that SMS codes, one-time passwords and push prompts can be relayed, intercepted or bombarded until somebody approves. Only phishing-resistant MFA, meaning FIDO2, WebAuthn or PKI, is bound to the real domain.

Of the 33,516 attempted frauds reported to the Swedish police in 2025, 25,199 were attempted vishing made by phone. QR codes, SMS messages and help desk calls carry exactly the same attack.

Business email compromise alone cost reported victims more than 3 billion dollars in 2025 and ENISA found phishing was the initial intrusion vector in roughly 60 percent of European incidents.

Norsk Hydro's own account of its 2019 ransomware attack is that the attachment arrived from a real customer's compromised account, inside a conversation that was already under way.

The NCSC warns that punishing staff for clicking a simulated phish resembles entrapment and teaches them not to report. Reports are your early warning, so measure how many people report, not just how many click.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. A supplier you pay every month emails to say their bank details have changed. The invoice is due today and the email thread looks completely normal.

    What do you do?

    • Pay it, since the thread is genuine
    • Reply to the email and ask them to confirm
    • Call the supplier on the number you already hold and confirm
    • Forward it to a colleague to approve
  2. Someone calls, says they are from IT and needs to reset your multi-factor authentication because of a sync problem. They know your name, your manager and your office.

    What do you do?

    • Read out the code, since they clearly work here
    • Hang up and call IT back on the internal number you already have
    • Approve the push prompt they say they are sending
    • Give the code only after they confirm your employee number
  3. An attachment arrives from a customer you have been emailing all week. The message sits at the bottom of a real thread but nobody mentioned sending a file.

    What do you do?

    • Open it, because the sender is genuine
    • Open it in the browser preview instead, which is safer
    • Check with the customer through another channel before opening it
    • Forward it to a colleague to open first
  4. You clicked a link, typed your password into a login page and only then noticed the domain was wrong.

    What do you do?

    • Change the password quietly and say nothing
    • Report it straight away, then change the password
    • Wait and see whether anything happens
    • Run an antivirus scan and carry on

Knowledge Test

  1. In ENISA's Threat Landscape 2025, phishing was the initial intrusion vector in roughly what share of observed incidents?

    • About 20 percent
    • About 40 percent
    • About 60 percent
    • About 90 percent

    ENISA put phishing at about 60 percent of observed initial intrusions with vulnerability exploitation second at 21.3 percent.

  2. What happened to reported phishing losses at the FBI between 2024 and 2025?

    • They fell by half
    • They stayed flat
    • They more than tripled, from about 70 million to 215.8 million dollars
    • They rose slightly, in line with the number of complaints

    Complaint volume was flat, but reported losses went from about 70 million dollars to 215.8 million dollars, so each attack did far more damage.

  3. Which form of multi-factor authentication does CISA class as phishing-resistant?

    • SMS one-time codes
    • Push notifications with number matching
    • FIDO2 or WebAuthn keys and passkeys
    • One-time codes sent by email

    Only FIDO2, WebAuthn and PKI bind the key to the real domain so a fake login page cannot use them.

  4. In Sweden in 2025, roughly what share of reported attempted fraud was attempted vishing?

    • Almost none
    • About a quarter
    • About half
    • About three quarters

    The Swedish police recorded 25,199 attempted vishing reports out of 33,516 attempted frauds which is 75.2 percent.

  5. What does Article 21.2g of NIS2 require?

    • Annual penetration testing
    • Security awareness training
    • Cyber insurance
    • A 24-hour security operations centre

    Security awareness training is one of the required measures and Sweden applies it through Cybersäkerhetslagen.

  6. In the NCSC's phishing case study, how many of the 1,800 malicious emails were stopped by filtering before they reached an inbox?

    • None
    • 50
    • 1,750
    • 14

    Filtering caught 1,750. Patched devices, reporting and monitoring dealt with the rest, leaving one machine to clean.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Phishing works on people, so people have to be part of the answer. That does not mean drilling staff to spot every fake because the NCSC is clear that nobody can. It means building two habits that still hold when the fake is perfect.

The first is verification. Any unusual request gets confirmed through a second channel you already trust and so does any request that moves money or changes a payment detail. Not a reply to the thread and not the number printed in the message.

The second is reporting speed. People report quickly when reporting takes one click and when nothing bad happens to them for doing it. A report that arrives in minutes lets you end the session before the attacker uses it.

eBuilder Security runs security awareness training for organisations in Sweden, built around those two habits rather than around click rates. Article 21.2g of NIS2 makes awareness training a requirement and Cybersäkerhetslagen has applied it in Sweden since 15 January 2026.

Frequently Asked Questions

What is phishing?

Phishing is a fraud in which an attacker sends a message that appears to come from someone you trust, in order to steal a password, trigger a payment or install malware. It arrives by email, SMS, phone call or QR code. The FBI logged 191,561 phishing and spoofing complaints in 2025, its most reported crime type.

What is the difference between phishing and spear phishing?

Spear phishing is phishing aimed at a named person or organisation using researched detail, while ordinary phishing is sent indiscriminately to many inboxes. The UK's NCSC notes spear phishing is significantly harder to detect, because it references real colleagues and real deadlines. Whaling is spear phishing aimed at a senior executive.

Is phishing still the most common cyber attack?

Phishing remains the leading way attackers gain their first foothold. ENISA's Threat Landscape 2025 analysed 4,875 European incidents and found phishing was the primary initial intrusion vector in about 60 percent of cases, ahead of vulnerability exploitation at 21.3 percent. Volume is steady, but the financial damage is rising sharply.

Can multi-factor authentication stop phishing?

Multi-factor authentication helps, but not every form of it resists phishing. CISA warns that SMS codes, one-time passwords and push prompts can be intercepted, relayed through a fake login page or bombarded until someone approves. Phishing-resistant MFA, meaning FIDO2, WebAuthn or PKI, is cryptographically bound to the real domain.

What should I do if I clicked a phishing link?

Report it immediately, before you do anything else. Then change the password for the account involved and for any account that shares it. Tell your security team even if you entered nothing, because they can check sign-in logs and end active sessions. If money was sent, call the bank at once and ask for a recall.

How do I report phishing in Sweden?

Report it internally first, so your security team can act within minutes. Suspected fraud and phishing can be reported to the Swedish police on 114 14, and organisations can contact CERT-SE for support. Entities in scope of Cybersäkerhetslagen must also send an early warning to MCF (formerly MSB) within 24 hours.

Does phishing training actually work?

Training works, but not in the way most people assume. The UK's NCSC has said no training package, phishing simulations included, will teach staff to catch every attempt. Where training pays off is in faster reporting and in verification habits. The heavy lifting belongs to technical layers such as phishing-resistant MFA.

What is business email compromise?

Business email compromise is targeted phishing aimed at payments. The FBI defines it as a scam against businesses that work with suppliers or make wire transfers, where criminals compromise email accounts and other channels through social engineering or intrusion. It cost reported victims more than 3 billion dollars in 2025.

Does NIS2 require phishing training?

NIS2 requires security awareness training, listing it among the mandatory security measures in Article 21.2g. Sweden applies this through Cybersäkerhetslagen, in force since 15 January 2026. Article 20 also makes the management body responsible for approving and overseeing those measures, with board members personally accountable.

How can I tell if an email is phishing?

Look at the behaviour the message wants, not the spelling. Urgency, secrecy, a changed payment detail, a request that skips the usual process and a link that asks for your password are the reliable signals. If your password manager refuses to autofill the login page, the domain is not the real one.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.