Current Threat
68% of data breaches involve a human factor.
No patch, no firewall protects if an employee clicks under time pressure. This page explains how phishing works - and how to protect yourself.
- 68%
- of data breaches involve a human factor (Verizon DBIR 2024)
- $4.5 M
- Average cost per incident
- 72%
- Click-rate reduction with training
- 3 sec.
- Decision time under pressure
Basics
What is Phishing?
Phishing is a social engineering attack in which attackers impersonate legitimate organisations or individuals to trick victims into revealing sensitive data, clicking malicious links or performing actions. The term derives from "fishing" - with humans as the catch.
What makes phishing so dangerous: it attacks people, not technology. No patch, no firewall and no antivirus fully protects if an employee under stress or time pressure clicks a link. This is why security awareness is just as important as technical countermeasures.
Phishing Types Overview
Email Phishing
Spear Phishing
Whaling
Smishing
Vishing
QR Code Phishing (Quishing)
Threat Intelligence
Current Phishing Methods 2025/2026
AI-powered attacks, deepfakes and new delivery channels are rapidly transforming the phishing landscape. What was a recognition indicator yesterday no longer works today.
AI-Generated Phishing Content
Critical · 2025/2026Deepfake Voice & Video
High · 2025/2026Adversary-in-the-Middle (AiTM)
Critical · 2024-2026QR Code Phishing in Documents
Medium · 2024-2026Microsoft Teams / Slack Phishing
High · 2023-2026Sources: Verizon DBIR 2024, Proofpoint State of the Phish 2025, IBM Cost of a Data Breach Report 2024, FBI IC3 Annual Report 2024, KnowBe4 Phishing Benchmark 2024.
Protection
Recognising Phishing: Checklist
Phishing emails are becoming increasingly convincing. This checklist helps identify suspicious messages - even when they appear legitimate at first glance.
The 3-Second Rule
Attackers rely on time pressure. If an email demands immediate action - stop for 3 seconds and ask: Would this organisation contact me this way? Does this request make sense in my context? This brief pause prevents the majority of phishing clicks.
Check the sender address carefully
Check link destination before clicking
Question urgent calls to action
Never open unexpected attachments
HTTPS is not a security indicator
Restrict form input to known domains
Call back on known numbers to verify
Practical Example
Anatomy of a Phishing Email
This realistic reconstruction shows the typical warning signs of a phishing email. Watch how the 5 most common red flags are revealed step by step.
Dringende Sicherheitswarnung: Ihr Konto wurde eingeschränkt
im Rahmen unserer routinemäßigen Sicherheitsüberprüfung haben wir ungewöhnliche Aktivitäten in Ihrem Online-Banking-Konto festgestellt. Zum Schutz Ihrer Daten haben wir den Zugang zu Ihrem Konto vorübergehend eingeschränkt.
Mit freundlichen Grüßen
Thomas Weber
Abteilung Kontosicherheit
Deutsche Kredit Bank AG
Diese E-Mail wurde automatisch generiert. Bitte antworten Sie nicht auf diese Nachricht.
Deutsche Kredit Bank AG | Taunusanlage 12 | 60325 Frankfurt am Main
Spot the 5 warning signs
The display name says "Deutsche Kredit Bank AG", but the actual address is service@dk-bank-sicherheit.com: a foreign domain with no relation to the bank.
Your real bank knows your name. "Sehr geehrter Kunde" ("Dear customer") signals a mass phishing campaign sent to thousands of recipients.
"Within 24 hours" plus an account-suspension threat: a classic panic tactic. Legitimate companies never set deadlines this short via email.
The button promises the official site, but the real URL is dk-bank-sicherheit.com/verify: a phishing domain. Always check the link target!
No legitimate company asks you to enter passwords, TANs or credit card details via email. Never log in through email links.
Click or hover the numbered warning signs in the email.
Technology
Technical Countermeasures
Technical controls significantly reduce the attack surface. No single protection is sufficient - defence in depth is the right approach.
DMARC (p=reject)
Highest PrioritySPF & DKIM
Highest PriorityEmail Gateway with Sandboxing
High PriorityPhishing-Resistant MFA (FIDO2)
High PriorityDNS Filtering
Medium PriorityEndpoint Detection & Response (EDR)
Medium PriorityThe Human Defence Factor
Security Awareness as the Key
Technical measures alone are not enough. People remain the last safety net - and with the right training also the strongest line of defence.
Security awareness programmes relying solely on classroom instruction fade away ineffectively. Sustainable behaviour change comes from repeated, realistic exercises - exactly what continuous phishing simulation provides.
According to the KnowBe4 Phishing Benchmark Report 2024, the average click rate in companies without training is 34.3%. After 12 months of consistent simulation and accompanying training, it drops to 4.6%.
Effectiveness Comparison
Source: KnowBe4 Phishing by Industry Benchmark Report 2024
Average click-rate reduction
Our Service
AWARE7 Phishing Simulation - Managed Service
Fully automated monthly phishing campaigns with realistic scenarios, real-time dashboard and individual training module for every click.
Monthly Campaigns
Real-Time Dashboard
Instant Training
Legally Compliant Setup
How the Onboarding Process Works
Phishing Simulation for Which Organisations?
- SMEs from 25 employees
Cost-efficient managed service option without own platform licence.
- Organisations under NIS-2 requirements
Phishing simulation as evidence for security training under NIS-2 Art. 21.
- Financial and healthcare sector
Industry-specific scenarios (SWIFT emails, patient data, banking portals).
- Organisations after a security incident
Targeted re-training of affected departments after a phishing incident.
FAQ
FAQ: Phishing & Phishing Simulation
What is the difference between phishing and spear phishing?
Does two-factor authentication (2FA/MFA) protect against phishing?
What does a phishing attack cost a company on average?
What is a phishing simulation and how does it work?
How often should phishing simulations be conducted?
Which technical measures are most effective against phishing?
What should I do if I have fallen for a phishing email?
Can companies conduct phishing simulations without employee consent?
Aus dem Blog
Weiterführende Artikel
Phishing erkennen: Checkliste für Mitarbeiter (2026)
Phishing erkennen: Checkliste mit Erkennungsmerkmalen für E-Mail-Phishing, Smishing und Vishing - mit Sofortmaßnahmen nach dem Klick.
Security Awareness messen: Klickraten, Wissenstests und Metriken
Security Awareness messen: Phishing-Klickraten richtig interpretieren, Verhaltensmetriken, Wissenstests und ROI-Argumente für den Vorstand.
Was kostet ein Live Hacking? Preise und Pakete im Überblick
Ein Live Hacking ist eine gute Möglichkeit, Mitarbeiter zu sensibilisieren - doch was kostet ein Live Hacking?
Start a Phishing Simulation
Find out how well your team is equipped against phishing - with a realistic, anonymised baseline campaign. No shaming, just genuine learning.
Free · 30 minutes · No obligation