In this article
- Phishing is an industry, not a hobby
- The roles involved
- Why modern phishing pages are convincing
- How campaigns avoid being caught
- Which signals actually survive
- The defences that are not judgement-based
- If you entered details
Phishing is an industry, not a hobby
The mental image most people carry is of an individual writing dodgy emails. The reality is a supply chain with specialised roles, in which the person who sends you a message may have built none of the infrastructure they are using and may not understand how it works.
This matters for two reasons. It explains why the quality is so much higher than it used to be, since the people producing the templates are specialists. And it explains why volume is so high, since the marginal cost of one more target is effectively zero.
The roles involved
Kit builders produce the fake pages and the systems behind them, and sell or rent them. Their customers want convincing appearance, reliable capture, and evasion of detection.
Infrastructure providers supply domains, hosting and sending capability, often abusing legitimate services because traffic to a well-known platform attracts less suspicion than traffic to an unknown one.
Operators run campaigns. Frequently they are the least skilled part of the chain, working from instructions.
Cashers convert access into money, which is where most of the risk to the criminals sits and where money mules are recruited — often people who genuinely believe they have found a job. Our job scam guide covers how that recruitment looks from the inside.
Why modern phishing pages are convincing
You are not being asked to spot a crude copy. A current fake login page is typically an accurate reproduction of the real one, served over an encrypted connection with a valid certificate, from a domain chosen to survive a glance. It may check whether the email address you entered exists before continuing, and it may relay your details to the real service in real time so the login actually succeeds and nothing appears to have gone wrong.
That last point is worth sitting with. In a well-executed attack, the victim's experience is that they logged in successfully. There is no error, no redirect to a broken page, and nothing that feels off. The only signal available before that point was the address in the address bar.
How campaigns avoid being caught
Operations invest heavily in making sure security researchers and automated scanners see something different from what the target sees. Traffic from data centre networks, security vendors and automated crawlers is often shown a harmless page, while traffic that looks like an ordinary person on an ordinary connection is shown the attack. Links frequently expire after a short window or after a single use.
The practical consequence for you: the fact that a link checker or a security product did not flag something is weaker evidence than it appears. It may simply have been shown the other page.
Which signals actually survive
Very few of the classic signals still hold. Spelling, grammar, certificates, page design and personalisation have all been neutralised. What remains:
- The domain. Read the two labels immediately before the first single slash. Everything else in the address can say anything.
- Whether you initiated it. A message you were not expecting is the common factor in essentially every successful attack.
- The nature of the request. Passwords, one-time codes, payment details, remote access and moving money are never legitimate requests by email or phone.
- Whether verification is possible independently. If the only way to check is to ask the sender, that is not verification.
The defences that are not judgement-based
Because the signals are thin, the strongest defences do not rely on you spotting anything at all.
Passkeys are cryptographically bound to the real site's address and will not respond to a copy, which defeats real-time relaying completely. Where they are offered, they are the single most effective step available.
Password manager autofill matches on the exact domain. On a lookalike page it silently declines to fill, which is a free warning you did not have to earn.
Reaching sites your own way — bookmarks, typed addresses, official apps — removes the delivery mechanism entirely. An attack that cannot get you onto its page has failed regardless of how good the page is.
A verification habit for money. Any change of payment details confirmed by phoning a number you already had. This one rule prevents most business losses and costs nothing to adopt.
If you entered details
Change that password immediately from a device you trust, and everywhere else you used it. Sign out of all sessions on the account, because a relayed login may still be active. Turn on two-factor authentication, ideally passkeys. Check the account's settings for forwarding rules, recovery addresses or connected apps you did not add. If payment details were involved, call your bank now. Our first 24 hours checklist sets out the full order.
Frequently asked questions
Can I still spot phishing by the writing quality?
Rarely. Modern phishing pages and messages are accurate reproductions written fluently. Judge the domain, whether you initiated the contact, and whether the request is one a legitimate organisation would ever make.
Does a padlock or valid certificate mean a login page is genuine?
No. Certificates are free and automated, so most phishing pages have one. It confirms the connection is encrypted, not that the site is who it claims to be.
Why did the login appear to work?
Some attacks relay your details to the real service in real time, so you are genuinely signed in while the attacker captures the session. Nothing appears to go wrong, which is what makes it effective.
Why do passkeys help so much?
A passkey is bound to the real website's address and simply will not respond to a lookalike. There is nothing typed for a fake page to capture and nothing to relay.
My security tool did not flag the link. Is it safe?
Not necessarily. Campaigns routinely show harmless content to scanners and security vendors while showing the attack to ordinary visitors, and links often expire after one use.