Meaning and Nature
Phishing is a form of cyber fraud in which an attacker impersonates a trusted person, institution or digital service to trick users into revealing sensitive information or performing a harmful action.
Attackers commonly target:
- passwords;
- banking credentials;
- one-time passwords;
- credit or debit card details;
- personal identity information;
- login tokens;
- confidential organisational data.
Phishing usually relies more on social engineering than on technically breaking into a system.
Major Forms
Email Phishing
Fraudulent emails imitate banks, government departments, companies or online platforms and contain malicious links or attachments.
Spear Phishing
Highly targeted messages are customised using personal or professional information about a specific individual or organisation.
Smishing
Phishing conducted through SMS or messaging applications.
Vishing
Fraudulent voice calls are used to obtain confidential information or persuade victims to transfer money.
Clone Phishing
A genuine email is copied and modified by replacing legitimate links or attachments with malicious ones.
Business Email Compromise
Attackers impersonate senior executives, suppliers or employees to manipulate financial transactions or obtain confidential information.
How Phishing Works
A typical phishing attack follows this sequence:
Impersonation → Urgency or fear → Malicious link or request → Theft of credentials or money
Attackers may create fake websites that closely resemble genuine banking, e-commerce or government portals.
Common warning signs include:
- suspicious or misspelled web addresses;
- urgent requests for money or passwords;
- unexpected attachments;
- messages claiming account suspension;
- requests for OTPs or banking PINs;
- unusual grammar or sender addresses.
More sophisticated attacks may use artificial intelligence to generate convincing messages, imitate writing styles or produce realistic voice and video content.
Impact and Indian Context
Phishing can result in:
- financial fraud;
- identity theft;
- unauthorised access to accounts;
- corporate data breaches;
- installation of malware;
- theft of government or defence information;
- reputational damage.
In India, phishing frequently targets users through fake banking links, digital-payment messages, fraudulent KYC updates, parcel scams and impersonation of government officials.
Relevant legal provisions may arise under:
- Information Technology Act, 2000;
- Bharatiya Nyaya Sanhita, 2023;
- banking and data-protection regulations.
Institutions such as CERT-In, banks, telecom providers and law-enforcement agencies play important roles in cyber-fraud prevention and response.
Prevention and Response
Important precautions include:
- never sharing OTPs, passwords or PINs;
- verifying the sender independently;
- avoiding links received through suspicious messages;
- typing official website addresses directly;
- using multi-factor authentication;
- keeping software and browsers updated;
- checking website domains before entering credentials;
- enabling transaction alerts;
- reporting suspicious messages.
Organisations should also implement:
- employee awareness training;
- email authentication standards;
- spam and malware filtering;
- restricted access privileges;
- incident-response mechanisms;
- regular phishing simulations.
If credentials are compromised, the user should immediately change passwords, contact the relevant bank or service provider and report financial fraud through official cybercrime channels.
Conclusion
Phishing is one of the most common forms of cybercrime because it exploits human trust rather than only technical weaknesses. Effective prevention depends on user awareness, secure authentication, rapid reporting and strong organisational cyber-hygiene.

