Phishing sends deceptive messages — most often email — that impersonate a trusted sender to lure you into revealing credentials, clicking a malicious link, or running malware. A message arrives appearing to come from a party you trust — a bank, your IT department, a shipping company, a colleague — presenting a plausible reason to act now and a single convenient path to comply: a login page, an attachment, a request for a code or payment. The trusted appearance borrows credibility the attacker never earned; the manufactured urgency compresses the window in which you might otherwise pause and verify.
Mass (“bulk”) phishing casts a wide, generic net, relying on the fraction who bank with that institution and act reflexively. It differs from spear phishing, which tailors the lure to a specific person, and from business email compromise, a pure-text impersonation to redirect payment. The channel names the siblings: by phone it is vishing, by SMS smishing, by QR code quishing. The common engine is identical — substitute borrowed trust and time pressure for the verification that would expose the deception.
What has changed is the tooling, not the psychology. Phishing-as-a-service kits and, most consequentially, adversary-in-the-middle proxies now relay a victim’s login and the resulting session token in real time — defeating many one-time-code second factors. That is why the defensive frontier has moved from “spot the typo” to phishing-resistant authentication and out-of-band verification.