Know
What is Phishing?
Phishing impersonates a trusted person, company, service, or situation. It may arrive through email, text, social media, collaboration tools, search results, QR codes, phone calls, or other channels. The attacker’s goal is usually to obtain credentials, money, sensitive information, malware execution, or access to a trusted environment.
Why it matters
Phishing targets human decision-making and can bypass technical controls by convincing a legitimate user to perform the attacker’s action for them.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Fake IT-support contacts use Teams to obtain user-approved remote access
Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.
This is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.
TerminalFix uses a fake verification prompt to establish a reverse tunnel
Microsoft's TerminalFix analysis describes a fake CAPTCHA prompt that persuades a user to execute a command, followed by a multistage intrusion and a reverse tunnel.
The case connects a human verification pretext with malware execution and network access. Microsoft distinguishes observed activity from possible downstream actions; it did not observe the suggested ransomware or data-theft outcomes in this analyzed chain.
Invisible Unicode characters appear in phishing keyword evasion
Microsoft describes invisible Unicode characters inserted into phishing text to obstruct keyword parsing. Signature activity increased from February 9 and remained elevated on weekdays for roughly three months. Layered protections flagged most of the messages.
This illustrates the difference between visible text and machine-processed content. It is newly published analysis of older activity, not evidence that all email protections are defeated or that every invisible character is malicious.
Counterfeit vendor pages deliver changing malicious installers
Microsoft describes look-alike software download pages distributing malicious installers whose contents change between downloads. Observed affected devices were predominantly associated with China-based operations and Chinese-speaking users across several industries.
The campaign illustrates brand impersonation leading to malware delivery. Impersonating a vendor's download page does not establish compromise of its official distribution. The observed geography is not a measured global scope.
Phishing and spoofing remained among the most frequently reported internet crimes
The FBI's 2025 Internet Crime Report recorded more than one million complaints overall and identified phishing/spoofing among the most frequently reported complaint categories.
This is large-scale victim reporting evidence that phishing is not a theoretical training scenario; it remains a common real-world attack and fraud mechanism.
Businesses reported hundreds of millions of dollars in BEC losses
The FBI's 2025 IC3 report lists reported Business Email Compromise losses above $568 million and separately documents AI-assisted BEC tactics including official-sounding executive impersonation and voice cloning.
BEC can produce major financial loss without exploiting a software vulnerability; the attacker exploits trust, business process, and identity verification.
Scattered Spider targeted enterprise help desks and identity controls
A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.
The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.
Understand the mechanics
How it works
- 1
The attacker selects a target or broad audience.
- 2
A believable pretext is created, often using urgency, authority, fear, curiosity, or opportunity.
- 3
The target is directed to click, scan, reply, call, open a file, authenticate, pay, or disclose information.
- 4
If successful, the attacker uses the resulting access or information for fraud, compromise, persistence, or further attacks.
Practice
What to watch for
- Unexpected request for credentials or money
- Urgency or secrecy
- Sender/domain mismatch
- Unexpected login page
- Link destination does not match its label
- Unusual attachment or QR code
Perform
What to do
- 1
Do not use the message’s link, attachment, number, or QR code.
- 2
Verify through a known independent channel.
- 3
Report the message using the approved security process.
- 4
If credentials were entered, change them from a trusted device and report immediately.
How to reduce the risk
- Phishing-resistant MFA
- Email authentication and filtering
- User reporting workflows
- Role-based simulations
- Browser and DNS protections
- Clear payment and identity-verification procedures
Business impact
- Account takeover
- Fraud
- Malware or ransomware
- Data loss
- Business email compromise
- Downstream partner or customer compromise
What different roles should do
Employee
- Pause when a request creates urgency
- Verify using a known channel
- Report suspicious messages
Security
- Triage the message
- Identify recipients and clicks
- Contain compromised identities or endpoints
Framework & standards context
- MITRE ATT&CK T1566 — Phishing
Source transparency
Authoritative sources
Last reviewed: 2026-09-02