What phishing is
Phishing is a form of attack that targets people rather than systems. Instead of breaking through technical defences, the attacker tricks a person into doing something harmful: entering their password on a fake page, clicking a malicious link, or opening an attachment that installs malware. It works because it exploits trust and habit, not software flaws.
Phishing comes in several forms. The classic is a fraudulent email that appears to come from a trusted source. There is also smishing, which uses text messages, and voice-based approaches by phone. Increasingly, attackers use convincing fake login pages that look identical to the real service. The common thread is deception aimed at a human being.
How phishing steals credentials
The most common goal of phishing is to steal credentials, and the mechanism is usually straightforward. The victim receives a message that looks legitimate, perhaps a warning that their account needs attention, and follows a link to a page that looks exactly like the real login screen. They enter their username and password, and those details go straight to the attacker.
Other phishing steals credentials through malware. The victim opens an attachment or clicks a link that installs software designed to capture what they type or harvest stored passwords. Either way, the outcome is the same: the attacker ends up holding valid credentials for the victim’s accounts, without ever breaking a single technical control.
What happens to stolen credentials next
Stolen credentials rarely stay with the attacker who took them. They enter a marketplace. Credentials are collected, packaged and sold on the dark web across Tor forums and marketplaces, Telegram channels and, to a lesser degree, I2P sites. A set of credentials phished today can be for sale within days, bought by someone else entirely, and used in an attack against the victim’s employer weeks later.
This is why phishing matters far beyond the individual victim. A single employee tricked into revealing their password can become the entry point for an attack on the whole organisation, once those credentials are traded and reach someone looking for a way in.
Why phishing remains so effective
Despite years of awareness efforts, phishing remains one of the most effective attack methods, for a simple reason: it targets people, and people are fallible. A well-crafted phishing message can fool even careful, security-aware individuals, especially when it is timely, personalised and convincing. Attackers have refined their techniques, and the fake pages and messages are often indistinguishable from the real thing.
Because it works, and because it is cheap and scalable, phishing continues to be a primary way attackers get in. It is not a solved problem, and treating it as one is a mistake.
How to defend against it
Defending against phishing takes more than a single measure. Awareness helps people recognise and report suspicious messages, and a culture where reporting is encouraged rather than punished makes that far more effective. Multi-factor authentication is one of the strongest defences, because it means a stolen password alone is often not enough to access an account. And technical controls can filter many phishing attempts before they reach people.
But no defence is perfect, and some credentials will always be stolen. That is why the final layer matters: knowing when your credentials have been exposed, so you can act before they are used.
How dark web monitoring shortens the window
Because stolen credentials are traded on the dark web before they are used, monitoring for them provides early warning. If an employee’s credentials appear for sale, detecting that quickly means you can reset the password and close the door before an attacker walks through it.
DarkThreatX monitors Tor, Telegram and I2P around the clock, tracking more than 100 billion records and indexing over a million new stealer logs each week, with alerts in under five minutes when exposed credentials appear and tuning for zero false positives. No single source has full coverage of the dark web, and DarkThreatX maintains broad Telegram monitoring across these networks. The aim is to catch a stolen credential in the window between it being traded and being used.
To watch for exposed credentials tied to your organisation, explore employee credential monitoring, or for individuals, personal dark web monitoring.
For guidance on recognising phishing, see cyber.gov.au.
Frequently asked questions
What is phishing?
Phishing is an attack that tricks people rather than systems, using fake emails, messages or websites to get victims to hand over credentials or install malware. It exploits trust and habit rather than software flaws, which is why it remains so effective.
How does phishing steal credentials?
Usually through fake login pages that capture what victims enter, or through malware that captures keystrokes or harvests stored passwords. Either way the attacker ends up with valid credentials without breaking any technical control.
What happens to stolen credentials?
They are collected, packaged and sold on the dark web across Tor, Telegram and I2P, along with forums and marketplaces. Credentials phished today can be for sale within days and used in an attack against the victim’s organisation later.
How do you defend against phishing?
Combine awareness so people recognise and report suspicious messages, multi-factor authentication so a stolen password alone is not enough, and technical filtering. Because some credentials will always be stolen, monitoring for exposed credentials provides the final layer of defence.