What Is Phishing?
Updated 13 September 2026
Jump to section
Phishing is an attempt to steal sensitive information, such as usernames, passwords, or bank details, by posing as a trusted source. The attacker sends a fake email, text, or call that looks genuine and pushes you to click a link or hand over data. In Malaysia, online financial scams cost victims RM1.58 billion in 2024, according to police figures. Strong passwords help, but two-factor authentication is the real defense.
How does a phishing attack work?
A phishing attack works by impersonating someone you trust and creating a reason to act fast. Cloudflare describes it as masquerading "as a reputable source with an enticing request" to lure a victim, the way bait catches a fish.
The message points you to a fake login page or a harmful attachment. You enter your password on the fake page, and the attacker captures it in real time. Urgency is the common thread, because a rushed reader checks less.
Once they have one password, they try it on your email, bank, and other accounts, since many people reuse the same one everywhere.
What are the common types of phishing?
The common types of phishing differ by target and by channel. By target, spear phishing aims at a specific person, and whaling goes after executives or business owners with the most access.
By channel, phishing spreads well beyond email. Smishing arrives by SMS, vishing comes as a phone call, and quishing hides the trap inside a QR code. Clone phishing copies a real message you have seen before and swaps in a bad link.
| Type | How it targets you |
|---|---|
| Spear phishing | A researched message aimed at one person |
| Whaling | Goes after executives or business owners |
| Clone phishing | Copies a real message, swaps in a bad link |
| Smishing | Phishing sent by SMS |
| Vishing | Phishing over a phone call |
| Quishing | The trap hidden inside a QR code |
The tactic is the same across all of them: a trusted disguise plus a reason to act now.
How can you spot a phishing message?
You can spot most phishing messages by checking a few signals before you click. No single sign is proof, but several together are a strong warning.
- A sender address or link domain that does not match the real company.
- Urgent or threatening language, such as an account about to be closed.
- A request for a password, OTP, or card number, which real companies rarely ask for by message.
- A generic greeting, odd grammar, or an attachment you did not expect.
Google's Safe Browsing flags this behavior as social engineering, which it defines as tricking users into "performing an action that they normally would not". If a message fails these checks, go to the site directly instead of using its link.
How do you protect your business from phishing?
You protect your business from phishing with a mix of technology and habits, because the attack targets people, not just systems. The single strongest control is two-factor authentication on every important account, so a stolen password alone is not enough.
In our experience, the most common way a Malaysian SME account gets compromised is not a dramatic website hack but a convincing email that quietly harvests a login.
Train your team to slow down and verify, keep software updated, and use proper email security. If your own domain is ever cloned to phish your customers, a malware blacklist and a report to the host are the fastest ways to shut it down.
Frequently asked questions
What should I do if I clicked a phishing link?
Act quickly. Change the password for that account right away, and change it anywhere you reused it. Turn on two-factor authentication if it is not already active, then review recent account activity and logins. If you entered payment details, contact your bank. Fast action often limits the damage before the attacker can use what they took.
Is phishing only an email problem?
No. Phishing now spreads by SMS (smishing), phone calls (vishing), and QR codes (quishing) as well as email. The channel changes, but the goal is the same: a trusted disguise that gets you to reveal something or click something. Treat an urgent text or call asking for a code with the same caution as a suspicious email.
How is spear phishing different from ordinary phishing?
Spear phishing is targeted, while ordinary phishing is a mass mailing. A spear-phishing message is researched and personalized, often naming your company, your role, or a real colleague to seem credible. That makes it harder to spot and more dangerous, which is why executives and finance staff are common targets.
Can my website be used for phishing?
Yes. Attackers clone real business sites or hack legitimate ones to host fake login pages. If that happens, browsers may show a warning and blacklist the site, which cuts your traffic until it is cleaned. A trustworthy, well-maintained site and prompt cleanup both reduce the risk.
Does two-factor authentication stop phishing?
It helps a great deal, and the method matters. Passkeys and hardware keys resist phishing, because they check the real web address before responding. Texted or app codes can still be phished if you type them into a fake page, so they are weaker but still far better than a password alone. For key accounts, prefer a passkey or hardware key.
How common are online scams in Malaysia?
They are a serious and growing problem. Police recorded 35,368 online financial scam cases in 2024, with losses of RM1.58 billion, according to figures released by the Ministry of Digital in August 2025. Phishing is one of the main tactics behind those numbers. That scale is why simple defenses like 2FA and staff awareness matter for every business.
Keeping your business off the hook
Storming Solutions builds and maintains websites for Malaysian businesses from Kuala Lumpur, and part of that job is making a site both trustworthy and hard to abuse. We help clients lock down logins, keep software current, and act fast when a domain is cloned or a login is phished. We would rather prevent a compromise than clean up after one.
Worried an email or a lookalike site is targeting your business or your customers? Message us about web development and maintenance, and we will help you shore up the weak points.