Back to blog
Guide 7 min readMay 9, 2026

How Phishing Attacks Work: A Step-by-Step Breakdown (With Real Examples)

How a phishing attack actually works — the attacker's $50 setup, the three psychological triggers baked into every phishing email, how credentials are stolen silently, and why the average organisation doesn't detect it for 197 days. With real email examples.

Most employees have completed a security awareness training module that says "phishing is when attackers send fake emails." But understanding how a phishing attack actually works — from the attacker's preparation to the moment your credentials are stolen — makes you significantly better at spotting one.

This is a complete walkthrough of a phishing attack from start to finish, written for anyone who wants to understand it properly.

Phase 1: The attacker's setup (before you ever see the email)

A targeted phishing attack doesn't start with an email. It starts with infrastructure that looks legitimate. The attacker:

  • Registers a lookalike domain — something like microsoft-helpdesk.com, payslip-portal.in, or a Unicode lookalike where the "o" in your company name is actually the Cyrillic letter "о". These domains cost $10–12 and take 5 minutes to register.
  • Configures email authentication records — they set up SPF, DKIM, and DMARC on the fake domain so the email passes spam filters. The same records a legitimate company uses.
  • Stands up a fake login page — a near-perfect copy of Microsoft 365, Google Workspace, or your company's internal portal. Tools like HTTrack can clone a website in under a minute. The fake page captures anything typed into the username/password fields and sends it to the attacker.
  • Sets up a sending server — usually a cheap VPS ($5–6/month) configured to send the phishing emails.

Total cost for a targeted attack on a company: under $50. Setup time for a reasonably skilled attacker: 2–3 hours.

Phase 2: Crafting the lure

The email itself is designed around three psychological triggers that bypass rational thinking:

  • Authority — the sender appears to be IT, HR, the CEO, Microsoft, a bank, or a government agency. Humans are wired to comply with authority figures without questioning.
  • Urgency — "Your account will be locked in 24 hours", "Mandatory action required before Friday", "Your salary payment is on hold". Urgency short-circuits deliberate thinking.
  • Plausibility — the email looks exactly like one the target would normally receive. The logo is correct, the footer has the right legal text, the sender name is familiar.

What the most effective phishing emails look like

The highest click-rate templates in phishing simulations are consistently:

  • IT password reset — "Your Microsoft 365 password expires in 24 hours. Click here to reset it." Simple, common, urgent.
  • Payroll notification — "Your payslip for April is available. Please verify your bank account details to ensure correct payment." Targets financial anxiety.
  • Shared document — "Priya Sharma has shared a file with you: Q1 Board Report.pdf." Social proof from a known colleague name.
  • Two-factor authentication prompt — "Unusual sign-in detected on your account. Verify your identity to keep your account secure." Exploits security awareness paradoxically.
  • CEO request — an email from a spoofed CEO address asking for an urgent wire transfer approval or gift card purchase. Known as Business Email Compromise (BEC) — costs companies billions annually.

Phase 3: Delivery and inbox placement

The email is sent. A few things happen at this stage:

If the attacker has properly configured SPF, DKIM, and DMARC, the email passes authentication checks at Gmail, Microsoft, and most corporate gateways. It doesn't look like spam. It arrives in the primary inbox.

In corporate environments, email security gateways (Proofpoint, Mimecast, Zscaler) automatically click every link in every email to check for malware. These "safe link" systems are why attackers sometimes use delayed redirects — the link points to a benign page at delivery time, then switches to the phishing page after a few hours once the automated scanners have moved on.

Phase 4: The click and the fake landing page

The target clicks the link. They land on a page that looks identical to Microsoft 365, Google Workspace, or whatever system was spoofed. The URL in the browser bar looks almost right — microsofft.com/login, accounts.google-security.com, or similar.

The target types their username and password.

Two things happen simultaneously:

  1. The credentials are silently sent to the attacker's server
  2. The target is redirected to the real Microsoft 365 or Google login page, which says "Incorrect password" or just logs them in normally. The target assumes they mistyped, enters their password again on the real page, and logs in successfully. They have no idea anything happened.

If the target has multi-factor authentication enabled, more sophisticated attacks use real-time relay — the fake page proxies the login to the real Microsoft server in real time, passing the MFA prompt through to the victim and capturing the session token before the victim realises what happened. Tools like Evilginx2 automate this entirely.

Phase 5: What happens with stolen credentials

Once credentials are captured, the attacker has several options:

  • Email forwarding rules — log into the target's mailbox, set up a forwarding rule to redirect all incoming email to an attacker-controlled address. Invisible to the victim, persistent even if the password is later changed.
  • Business Email Compromise — use the compromised account to send payment diversion emails to Finance, or to request gift cards from colleagues who trust the sender.
  • Lateral movement — use the stolen credentials to access internal systems, VPNs, cloud storage, or HR platforms. One compromised account often unlocks many others if passwords are reused.
  • Data exfiltration — access and download sensitive files, customer data, or intellectual property before the account is locked.

The average time between credential theft and detection in a real attack is 197 days.

Why phishing simulations work

A phishing simulation replicates exactly this process — domain registration, lookalike sending address, realistic template, fake landing page — but in a controlled, authorised environment. When an employee clicks and sees a training page instead of a credential-harvesting form, the lesson is immediate and visceral.

Employees who experience a simulated phish and are immediately shown what they missed — the suspicious URL, the unusual sender, the urgency trigger — are far less likely to fall for a real one. Research shows that organisations running quarterly simulations reduce click rates by 60–80% over 12 months.

The difference between a simulated phish and a real one is: in a simulation, the landing page educates instead of stealing. Everything else is identical.

How to see your organisation's real click rate

The only way to know how vulnerable your team is to phishing is to test them. PhishSpark is free for up to 500 targets — create an account, verify your domain, pick a template, and send your first campaign in under 30 minutes. No credit card required.

The results may surprise you. Industry average click rate on a first simulation: 28%.

how phishing worksphishing attack explainedphishing exampleswhat is phishing

Run your first phishing simulation today

Free for up to 500 targets. No credit card, no DevOps, no setup headache.

Get started free