A phishing email doesn't persuade - it rushes you
A phishing message is built around one action. Not "read and think," but "click here now." Everything else is wrapping: a logo, a signature, a sender address that looks real. The wrapping exists for one reason: so you don't stop in the first second.
They use something that could already be true: your package is delayed, your subscription wasn't renewed, or someone logged into your account from another city. The last one works best - it explains both why you need to hurry and why you'll be asked for your password now. Anxiety narrows your attention: instead of checking the page address, you check whether your account is okay.
According to Verizon reports, for people who fell for it, less than a minute most often passed between opening the email and entering their details. It's not about carelessness. In a minute, doubt simply doesn't have time to appear - it comes later, when the page has already sent the data on.
Build a list. They get addresses from leaks and public profiles. The more precisely they know which services you use, the more believable the pretext will be.
Copy the login page. They copy the real site's layout in full and change only the address - often to a similar one, with an extra letter or a different ending.
Send a pretext. An email or SMS with one link and a deadline: confirm within a day, or access will be closed.
Pass it on instantly. Modern kits work as proxies: your password and SMS code go straight to the real site while they're still valid. That's why a one-time code alone doesn't save you.
Dig in. Inside the account, they change the recovery method or set up email forwarding so they can return even if you change your password.
Why the same services get spoofed
An attacker needs a brand you're sure to have an account with and a pretext that needs no explanation. That's why the list of spoofed brands is short and barely changes. According to APWG reports, the shares are roughly as follows - leaders switch places from quarter to quarter, but the set stays the same:
The rest is delivery services, government services, and stores: they're used seasonally, when the pretext is believable on its own. It also follows that spotting phishing by clunky design is a bad strategy. The copy is built from the real site, and the text is increasingly written without a single mistake.
What's the safest way to check an alarming account message?
Why doesn't a one-time SMS code always stop phishing?
Sources
- Based on APWG Phishing Activity Trends reports and the Verizon Data Breach Investigations Report
Next in the “Cybercrime” series
2 articles in full on the site, 3 more in the app
