Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Phishing Attempt

← Back to Glossary
By NHI Mgmt Group Updated September 17, 2026 Domain: Threats, Abuse & Incident Response

A phishing attempt is a deceptive message or interaction designed to trick someone into revealing credentials, financial details, or other sensitive information. It often impersonates a trusted organisation or person and uses urgency, fear, or familiarity to prompt action before the recipient verifies the request.

How phishing attempts work

Phishing attempts usually succeed by compressing the victim’s decision time. The sender imitates a trusted brand, person, or process and adds urgency, curiosity, or fear so the recipient acts before checking the request independently.

That social-engineering pattern matters because the message is rarely the actual objective. The real goal is usually to obtain credentials and API keys through social engineering, capture a session token, or push the target toward a fraudulent payment or form submission.

Phishing also evolves across channels. Email remains common, but text messages, collaboration tools, social platforms, and voice calls can all carry the same deceptive structure, with the delivery channel chosen to match the target’s normal working habits.

Common phishing patterns

Most phishing attempts fall into a few familiar patterns: a fake login page, a counterfeit invoice or document, a message asking the user to reset a password, or a request to approve a login, transfer, or shared file. The details change, but the core tactic is always to exploit trust and routine.

Some campaigns are broad and noisy, while others are highly targeted. Spear phishing uses better personalisation, such as job role, internal language, or a real relationship, to make the message feel legitimate. Business email compromise often adds impersonation and payment redirection, turning the attack into a financial fraud path rather than a simple credential-harvesting page.

A useful practical distinction is between the lure and the payload. The lure is the persuasive message; the payload may be a malicious link, attachment, callback number, or request for secrets. Even when no malware is delivered, the attack can still succeed if the recipient discloses enough information to enable account takeover.

Why phishing is effective

Phishing works because it targets human judgment under pressure. Attackers rely on urgency, authority, familiarity, and distraction, which are all normal conditions in busy organisations. The attack does not need to break encryption or exploit a software flaw if it can persuade a person to hand over access directly.

It is also effective because a single successful message can bypass multiple layers of technical control. If a user reveals a password, approves a fraudulent prompt, or enters data into a convincing fake site, the attacker may gain a foothold that looks legitimate from the outside. Phishing-resistant authentication helps reduce that payoff, which is why NIST SP 800-63 Digital Identity Guidelines place strong emphasis on authenticators that resist replay and real-time interception.

The risk grows when phishing reaches accounts with broad permissions, shared access, or valuable business workflows. A compromised inbox, finance account, or admin console can quickly become a platform for impersonation, lateral abuse, and downstream fraud.

How to recognise and respond

The safest response is to verify the request through a separate trusted channel before clicking, approving, paying, or sharing anything. Users should treat unexpected urgency, mismatched domains, unusual attachments, and requests to bypass normal process as warning signs rather than proof of legitimacy.

Organisations reduce exposure when they pair user awareness with controls that limit the value of a stolen credential. Phishing-resistant MFA, strong email filtering, explicit payment verification, and least-privilege access all help contain the blast radius when a message gets through. That approach aligns well with the general security-control logic in NIST Cybersecurity Framework 2.0 and with practical implementation guidance in OWASP Cheat Sheet Series.

Common misunderstanding: phishing is not only a user-training problem. Training helps, but resilient organisations also design processes so that a single convincing message cannot easily turn into credential theft, payment diversion, or account compromise.

Risk and Threat Considerations

Phishing attempts are risky because they convert trust into a direct attack surface. A successful message can lead to credential theft, payment fraud, session hijacking, or the disclosure of secrets and sensitive business data, often before defenders have any signal beyond a user report or unusual login activity.

Failure mechanism: the attacker exploits urgency, authority, or familiarity to get the target to authenticate on a fake page, approve a malicious request, or reveal information that enables further abuse.

Impact: the resulting compromise can extend beyond the first account, creating unauthorised access, financial loss, impersonation, and broader incident response effort if the attacker uses the foothold for follow-on activity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Phishing-Resistant Authentication — Phishing-Resistant AuthenticationAddresses authenticators that resist real-time phishing interception and replay.
Recommendation — Prefer phishing-resistant authenticators to reduce the value of stolen credentials.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlPhishing often succeeds by abusing authentication and access decisions.
DE.CM — Continuous MonitoringPhishing is often detected through anomalous login, mail, or payment activity.
Recommendation — Strengthen authentication and access controls to limit the damage from stolen credentials. Monitor for suspicious authentication and communication patterns that indicate phishing activity.
CIS Controls v85 — Account ManagementPhishing frequently targets account compromise and misuse of valid accounts.
6 — Access Control ManagementLeast privilege limits what a phished account can do after compromise.
Recommendation — Harden account lifecycle controls to reduce the impact of credential theft. Restrict access rights so a phished account cannot reach high-value assets broadly.
OWASP Agentic AI Top 10A1 — Prompt Injection and Instruction HijackingPhishing-style deception can target agent prompts and tool-use decisions.
Recommendation — Treat deceptive instructions as hostile input when agents can act on external messages.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org