Glossary: Phishing
Launch library · evergreen read

Phishing describes a deliberate attempt to trick someone into revealing sensitive information, passwords, financial details, personal data, typically through a message or page carefully designed to closely imitate a trusted, legitimate source that the target already recognises and would not normally think twice about trusting or questioning.
The term itself plays on the older word 'fishing', casting a wide net of messages out and waiting patiently for a portion of recipients to take the bait offered. More targeted versions, aimed specifically at just one person using personal details gathered beforehand, are sometimes called spear phishing for exactly this same reason.
Recognising phishing usually comes down to checking the actual sender address and link destination carefully rather than the visible name or design shown on screen, since both of those surface elements are trivially easy for anyone with only basic tools to imitate convincingly at a passing glance from an unsuspecting reader.