Phishing is the use of fraudulent messages, most often email, that impersonate a trusted party to trick recipients into revealing credentials, paying money, granting access or installing malware. It remains the most common starting point of successful breaches, and generative AI has removed its classic tells.
Key facts
- Phishing is a family, not a single attack. Mass phishing, spear phishing, whaling, BEC, quishing, smishing and consent phishing differ in channel and targeting but share the same psychology.
- The costliest variants often contain no link or attachment at all, which defeats filters that only scan payloads.
- AI-written phishing is fluent in every language; grammar-based "spot the phish" advice is obsolete.
The phishing family tree
| Variant | Channel | Targeting | Typical goal |
|---|---|---|---|
| Mass phishing | Everyone | Credentials, malware | |
| Spear phishing | One researched person | Credentials, access, payments | |
| Whaling | Senior executives | Wire transfers, sensitive data | |
| Business email compromise | Email, usually no payload | Finance, HR, executives | Fraudulent payments, payroll diversion |
| Consent phishing | OAuth prompt | Any user | Persistent mailbox and file access |
| Quishing | QR code in email or print | Mobile users | Credentials, bypass of link scanning |
| Smishing | SMS | Phone numbers | Credentials, payments |
| Vishing | Voice call | Help desks, finance | MFA resets, payments |
How a modern phishing attack lands
The pattern is consistent across variants: a credible sender (spoofed, lookalike or genuinely compromised), a pretext that justifies the ask, pressure (urgency, authority, confidentiality), and an action that looks routine: click, reply, scan, approve. Increasingly the first message is clean smalltalk to build trust before anything malicious appears, and the attack may hop channels (email to SMS to voice) to escape email security entirely.
Defense that survives 2026
Three layers, in order of leverage: behavioral email security that judges sender, relationship and intent rather than just payloads; verification procedures for money, credentials and data requests through a second known channel; and training focused on social engineering levers rather than yesterday's scam formats. MFA everywhere, with the caveat that consent phishing bypasses passwords and MFA by stealing permissions instead.
How Sentaro stops phishing
Vord, Sentaro’s engine, evaluates every message across Message, App and Behavioral Defense vectors: intent in the text and the infrastructure behind the sender, OAuth permission requests, and deviation from each relationship's normal. Built AI-native for the payload-free, AI-written era of phishing, on Google Workspace and Microsoft 365.