Phishing: how the scam works and why it still claims so many victims
Ever received an email that looks exactly like one from your bank or a service like Google, urging you to "secure your account"? There's a good chance it's a phishing attempt.
Phishing is now one of the most widespread cyberattack techniques, and also one of the most effective. Why? Because it doesn't target a technical flaw, but a human one: trust.
In this article, we explain in concrete terms how these attacks work, which methods cybercriminals use, and how to protect yourself effectively. And as a bonus, we explain how GottaPhish tackles this problem head-on.
What exactly is phishing?
Phishing is a form of online scam that involves impersonating a trusted third party (a bank, a government agency, a company, a web platform, and so on) in order to extract sensitive personal or professional information.
This data can then be used to:
-
hack into your accounts,
-
steal money,
-
access confidential information,
-
or spread further attacks across your organization.
The methods most used by cybercriminals
1. The fake login page
The most classic method: a link takes you to a copy of an official site (such as Dropbox, Google, or Outlook). You enter your credentials without suspecting a thing... but they are sent straight to the attacker.
This method works even better when it's personalized or targeted: this is what we call targeted phishing, or spear phishing.
2. Real-time interception (Man-in-the-Middle attack)
This is a far more advanced version. Here, the attacker places a malicious proxy between you and the legitimate site, allowing them to intercept everything you type — including the temporary codes sent for two-factor authentication (2FA).
This grants access to your accounts, even when they are well protected.
3. SMS phishing (smishing)
The same principle as a booby-trapped email... but over SMS. The message often mimics a delivery notice, a banking alert, or a customer service message. People tend to trust their phones more, which makes this method highly effective.
The tools used to carry out these attacks
There are now open-source tools (and therefore accessible to anyone) that make it possible to automate these attacks and make them more convincing than ever.
Among the best known:
-
Gophish: to create and manage test phishing campaigns.
-
Evilginx: to intercept sessions and bypass 2FA.
-
EvilGophish: a combination that enables realistic attacks with built-in statistics.
A concrete example: compromising a Dropbox account
In a technical demonstration, the company Vaadata showed how a Dropbox account could be compromised in three different ways:
-
With a fake login page created using Gophish
-
With a MitM interception via Evilginx, capturing even the 2FA code
-
With a booby-trapped SMS, combined with a cloned page and a MitM attack
Each time, access to the account was complete... without the victim ever noticing.
How can you protect yourself?
Fortunately, there are several ways to defend yourself:
For individuals:
-
Always check the web address before entering your credentials
-
Never click on a suspicious link received by email or SMS
-
Enable two-factor authentication (2FA), even though it isn't foolproof
-
Be wary of messages that are overly urgent or alarming
For businesses:
-
Train your teams regularly
-
Run internal phishing simulation campaigns
-
Put technical protections in place (SPF, DKIM, DMARC)
-
Monitor for unusual behavior
So where does GottaPhish fit in?
At GottaPhish, we tackle the problem at its source: awareness.
We develop educational, interactive tools to help companies spot the warning signs of a phishing attempt, test their employees' vigilance, and sharpen their cyber-reflexes against these increasingly convincing attacks.
Our approach is simple: the user is the first line of defense. And the more they train, the less likely they are to get caught.
Whether it's to test your own security or train your teams to respond to realistic attacks, GottaPhish supports you with tailor-made solutions suited to your specific challenges.
Conclusion
Phishing is not a distant threat: it's a daily risk, for individuals and businesses alike. Understanding how it works is already a first step toward protecting yourself.
And if you want to go further, train your teams, and test your posture against these attacks, GottaPhish is here to help you take action.
