8 September 2022 • Phishing
What exactly does phishing mean?
Phishing is a form of digital fraud in which cybercriminals impersonate a trusted authority — such as a bank, government agency, or well-known company — and send you an urgent message. Through an email, phone call, WhatsApp message, or SMS, you are asked to click a link, open an attachment, or provide sensitive information. Before you realize it, the scammer has gained access to your bank details, login credentials, or personal documents.
The term ‘phishing’ is derived from the word ‘fishing.’ Just as a fisherman casts a line hoping something will bite, cybercriminals cast out deceptive messages hoping their victims will take the bait. And unfortunately, it works — phishing remains one of the most common and effective cyberattack methods worldwide.
Phishing in the Netherlands
According to figures from the Central Bureau of Statistics (CBS), no fewer than 2.5 million Dutch people fell victim to phishing in 2021 alone. This form of cybercrime is growing rapidly because fraudulent messages are becoming increasingly difficult to recognize. Fake emails now look remarkably professional, often replicating the exact layout, logos, and tone of legitimate organizations. Even digitally savvy individuals struggle to tell the difference between a genuine message and a carefully crafted fake.
For businesses, the risk is even greater. A single employee clicking the wrong link can expose an entire organization to data breaches, financial loss, and reputational damage.
Common types of phishing attacks
Phishing is not a one-size-fits-all attack. Cybercriminals use a range of techniques, each tailored to exploit different communication channels and targets.
Email phishing is the most widespread form. Attackers send mass emails that appear to come from legitimate organizations, urging recipients to click a malicious link or download an infected attachment. These emails often mimic banks, delivery services, or software providers.
Smishing (SMS phishing) uses text messages to trick victims. You might receive an SMS claiming your package is being held or that your bank account has been compromised, with a link that leads to a fake website designed to steal your credentials.
Vishing (voice phishing) involves phone calls from scammers posing as bank employees, IT support, or government officials. They use pressure and urgency to convince you to hand over personal information or grant remote access to your device.
Spear phishing is a targeted form of phishing in which the attacker researches a specific individual or organization before crafting a highly personalized message. Because these emails reference real names, roles, or recent activities, they are far more convincing — and far more dangerous — than generic phishing attempts.
Whaling takes spear phishing a step further by targeting senior executives and decision-makers. These attacks often involve fake invoices, urgent wire transfer requests, or impersonation of board members, and can result in significant financial losses.
Different forms of phishing
There are many different forms of phishing. An example is spear phishing. There is also clone phishing, where the cybercriminal copies an e-mail from a legitimate company. Then the original links are replaced by malicious links. Phone phishing is also possible, where the criminal pretends to be a staff member of, for example, a bank.
How can you spot fake messages?
Recognizing phishing messages can be tricky. Below we share some examples and tips on how to recognize a fake message.
First, check the sender’s e-mail address. You can often spot from the email that it is not a real email from the company. For example, the real email address of a webshop is [email protected] but the email address in the phishing email is [email protected].
The same goes for links in the e-mail. A tip is to hover over the link, so you can see the real URL of the link. You will often see that the link does not refer to the real website. So always check this before clicking on a link.
Another way to recognize a fake message is by the text itself. Many phishing messages have spelling errors, which is an indication that it is not a real email.
Finally, be cautious when a message creates a sense of urgency. Phrases like “your account will be closed within 24 hours” or “immediate action required” are designed to make you act before you think. Legitimate organizations rarely pressure you into taking immediate action.
Phishing via social media
Phishing is also done via social media. Cybercriminals create a fake login portal. For example, you see a login portal of Facebook. However, the portal is created by cybercriminals. If someone logs in via this portal, the login credentials are sent to the creator of the portal.
LinkedIn is another common target. Attackers send fake connection requests or job offers containing malicious links, exploiting the professional trust users place in the platform. On Instagram and WhatsApp, scammers often impersonate friends or brands, sending messages with links to fake giveaways or “account verification” pages. Because social media messages feel more personal than email, victims are often less cautious — making these attacks particularly effective.
QR code phishing (quishing)
QR codes are used to quickly and easily access websites from your phone. However, you have to be careful with this. When scanning a QR code, you do not see in advance which website you will be directed to. So you may enter your login details for your bank account on a website created by criminals.
This type of attack, known as quishing, is growing rapidly. Fake QR codes appear on parking meters, restaurant menus, and even in physical mail. Always check the URL that appears after scanning before entering any personal information, and avoid scanning QR codes from unknown or suspicious sources.
What if you clicked on a phishing email?
If you suspect you have fallen for a phishing attack, act quickly to limit the damage:
Change your passwords immediately — starting with the account that was compromised, and any other accounts where you use the same password. Use strong, unique passwords for each service.
Contact your bank if you have shared financial information or noticed suspicious transactions. Most banks can freeze your account or reverse unauthorized payments if you act fast enough.
Report the incident. In the Netherlands, you can report phishing to the Fraud Helpdesk (fraudehelpdesk.nl). If you are an employee, inform your IT department right away so they can assess whether company systems have been affected.
Run a malware scan on your device. If you clicked a suspicious link or downloaded an attachment, there is a chance that malware was installed. Use up-to-date antivirus software to check and remove any threats.
How to protect your organization against phishing
Technical measures like spam filters and firewalls are important, but they cannot catch every phishing attempt. The most effective defense is making sure the people in your organization know how to recognize and respond to threats.
Security awareness training teaches employees to identify phishing emails, suspicious links, and social engineering tactics. Regular training ensures that knowledge stays fresh and that your team is prepared for the latest attack methods.
Phishing simulations take this a step further by sending realistic but harmless fake phishing emails to your employees. This allows you to measure how your organization responds in practice and identify who needs additional support.
With Guardey, you can combine gamified security awareness training with automated phishing simulations — helping your team build real skills, not just check a box. Start a free 14-day trial and see the results for yourself.