How Do Phishing Attacks Actually Work?
A phishing attack does not break a system; it borrows a relationship. The message arrives looking like one the recipient already expects — a delivery notice, a payment alert, a password reset — and asks for one action that seems small: click a link, confirm a code, approve a prompt. Everything else is timing and familiarity.
The technical part is only a convincing copy of a login page. That is why awareness material built around spelling mistakes and suspicious-looking addresses no longer helps. Modern attempts are well written, correctly branded, and often sent at the moment the recipient is genuinely expecting that message. An explanation that still teaches "look for bad grammar" gives people false confidence in a test they will pass while being defrauded. What belongs in the file rather than the frames is a live example of a working phishing page or a real malicious link, even blurred, because published material gets reused.
This template covers the mechanism in seven scenes: two on how a convincing message is assembled, two on the pressure tactics that shorten the recipient's decision, one on the checks that still work, one on the single action to take instead of clicking, and one on how to report an attempt to your organisation.

