← All articles

Phishing: how the scam works and why it still claims so many victims

GottaPhish Team · April 18, 2025

Ever received an email that looks exactly like one from your bank or a service like Google, urging you to "secure your account"? There's a good chance it's a phishing attempt.

Phishing is now one of the most widespread cyberattack techniques, and also one of the most effective. Why? Because it doesn't target a technical flaw, but a human one: trust.

In this article, we explain in concrete terms how these attacks work, which methods cybercriminals use, and how to protect yourself effectively. And as a bonus, we explain how GottaPhish tackles this problem head-on.

What exactly is phishing?

Phishing is a form of online scam that involves impersonating a trusted third party (a bank, a government agency, a company, a web platform, and so on) in order to extract sensitive personal or professional information.

This data can then be used to:

The methods most used by cybercriminals

1. The fake login page

The most classic method: a link takes you to a copy of an official site (such as Dropbox, Google, or Outlook). You enter your credentials without suspecting a thing... but they are sent straight to the attacker.

This method works even better when it's personalized or targeted: this is what we call targeted phishing, or spear phishing.

2. Real-time interception (Man-in-the-Middle attack)

This is a far more advanced version. Here, the attacker places a malicious proxy between you and the legitimate site, allowing them to intercept everything you type — including the temporary codes sent for two-factor authentication (2FA).

This grants access to your accounts, even when they are well protected.

3. SMS phishing (smishing)

The same principle as a booby-trapped email... but over SMS. The message often mimics a delivery notice, a banking alert, or a customer service message. People tend to trust their phones more, which makes this method highly effective.

The tools used to carry out these attacks

There are now open-source tools (and therefore accessible to anyone) that make it possible to automate these attacks and make them more convincing than ever.

Among the best known:

A concrete example: compromising a Dropbox account

In a technical demonstration, the company Vaadata showed how a Dropbox account could be compromised in three different ways:

  1. With a fake login page created using Gophish

  2. With a MitM interception via Evilginx, capturing even the 2FA code

  3. With a booby-trapped SMS, combined with a cloned page and a MitM attack

Each time, access to the account was complete... without the victim ever noticing.

How can you protect yourself?

Fortunately, there are several ways to defend yourself:

For individuals:

For businesses:

So where does GottaPhish fit in?

At GottaPhish, we tackle the problem at its source: awareness.

We develop educational, interactive tools to help companies spot the warning signs of a phishing attempt, test their employees' vigilance, and sharpen their cyber-reflexes against these increasingly convincing attacks.

Our approach is simple: the user is the first line of defense. And the more they train, the less likely they are to get caught.

Whether it's to test your own security or train your teams to respond to realistic attacks, GottaPhish supports you with tailor-made solutions suited to your specific challenges.

Conclusion

Phishing is not a distant threat: it's a daily risk, for individuals and businesses alike. Understanding how it works is already a first step toward protecting yourself.

And if you want to go further, train your teams, and test your posture against these attacks, GottaPhish is here to help you take action.