Phishing: How a Phishing Operation Works, From Domain to Cash-Out

What phishing is, how criminals build fake emails and websites to steal credentials and card details, and the signs that give a fraudulent message away.

Madhurendra SachanBy Madhurendra Sachan
March 15, 2021
7 min read
Updated October 5, 2026
Phishing: How a Phishing Operation Works, From Domain to Cash-Out

Phishing is a fraud in which criminals pose as a trusted bank, brand, employer or government office to trick people into handing over passwords, card details, OTPs or money. Behind every fake message sits a small supply chain: a lookalike domain, hosting, a copied login page, a lure, a way to deliver it and a way to turn stolen data into cash.

This page follows that supply chain link by link, because each link is a place where a campaign can be broken. If you want the basics first, read what phishing is and how to prevent it. For the different forms it takes, see 10 types of phishing attacks.

The volume is large and still rising. The Anti-Phishing Working Group (APWG) counted 1,069,681 phishing attacks in the second quarter of 2026, up 10.1% on the first quarter, and 425,808 in June alone, its highest monthly total since April 2023, according to its Phishing Activity Trends Report for Q2 2026. In the US, the FBI’s Internet Crime Complaint Center received 191,561 phishing and spoofing complaints in 2025, more than any other crime type, in its 2025 Internet Crime Report.

1. The domain

Most phishing starts with a web address that looks close enough to the real one. Common patterns:

  • a misspelling or swapped letter, such as a digit 1 in place of a letter l
  • an extra word, such as “secure”, “login” or “verify” added to the brand name
  • a different ending, such as .co or .info in place of .com or .in
  • a subdomain trick, where the real brand name sits on the left of someone else’s domain

Registering one takes minutes. APWG member Fortra found that the business email compromise (BEC) domains it saw in Q2 2026 were most often registered through Namecheap (16%), NameSilo (12%) and Dynadot (11%). Some campaigns skip registration entirely and abuse free form builders, file sharing links and website builders, which borrow the reputation of a well known platform.

2. The hosting

The fake site needs somewhere to live. In APWG’s Q2 2026 data, Cloudflare was the most common provider behind phishing sites at 34%, followed by RouterHosting at 12% and Amazon at 11%. A proxy or CDN hides the server behind it, so a takedown usually means contacting several parties at once: the registrar, the host and the proxy.

3. The phishing kit

Attackers rarely build pages by hand. A phishing kit is a ready made bundle that copies a brand’s login page, records whatever the victim types and forwards it to the attacker, often by email or through a Telegram bot. Newer kits sit between the victim and the real website and relay the session live, so they capture the one-time code or session cookie as well as the password. That is how some phishing gets past SMS and app based two-step verification.

Kits are reused and adapted endlessly. APWG saw 941 different brands attacked in Q2 2026, and half of them were hit five times or fewer, a sign that kits are being built for regional and lesser known targets as well as household names.

4. The lure

The lure is the story that earns the click: a failed delivery, a locked account, an unpaid fine, a KYC update, a job offer, an invoice. Lures follow the news and the calendar, and we track the current ones in phishing lures in 2026.

Some lures carry no link at all. In BEC the email simply asks for a payment or a change of bank details. Fortra reported that the average wire transfer requested in BEC attacks in Q2 2026 was $61,732, up 45% on the previous quarter. It also saw more “two-step” phishing, where the first email is a harmless looking business inquiry and the link only arrives after the victim replies.

5. The delivery

Email is still the main route, but one campaign often runs across SMS, WhatsApp, voice calls, social media and paid ads at the same time. APWG’s contributors saw smishing rise 40% and vishing 20% from Q1 to Q2 2026, and ZeroFox recorded a 571% jump in threat activity on Meta ads over the same period. Senders and domains rotate quickly, so blocklists are always a step behind.

6. Collection and cash-out

Stolen data is used straight away, sold or combined with other leaks. Card details and bank logins become fraudulent payments. A captured mailbox becomes a base for BEC against the victim’s contacts. In BEC, Fortra found gift cards were the most common way to cash out in Q2 2026, at more than half of attempts, ahead of wire transfers at 17%. Money then moves through mule accounts, which is why speed matters: the FBI’s IC3 recorded about $3.05 billion in reported BEC losses in 2025.

Where the chain breaks: what to do

For individuals

  • Reach a website by typing the address or opening the official app. Don’t log in through a link in a message.
  • Read the whole domain. The brand name must sit directly before the .com, .in or other ending, not anywhere else in the address.
  • Never share an OTP, PIN or password because a message or a caller asked for it.
  • Use passkeys or an authenticator app where you can. Passkeys are tied to the real site, so a lookalike page can’t use them.
  • In India, report money lost to fraud at once on the 1930 helpline or at cybercrime.gov.in. Quick reports give banks a chance to freeze funds.

For organisations

  • Watch new domain registrations that resemble your brand, so you find the kit before your customers do.
  • Publish SPF and DKIM records and a DMARC policy at enforcement, so nobody can send mail as your exact domain.
  • Verify any change of bank details by calling a number you already hold, never one in the email.
  • Have a takedown process ready: evidence, abuse contacts at the registrar, host and proxy, and follow up until the page is gone. TIKAJ’s takedown service runs this end to end, and TIKAJ and Hunto handle more than 100,000 takedowns a year for over 150 enterprise customers.

Banks and other regulated entities in India can map these controls with our RBI cyber security framework checklist.

FAQ

What is phishing in simple words?

Phishing is when a criminal pretends to be someone you trust, such as your bank, a delivery company, your employer or a government office, to get you to reveal a password, card number or OTP, install malware or send money. It usually arrives as an email, text, call or social media message that pushes you to act quickly.

What is a phishing kit?

A phishing kit is a ready made package of web pages and scripts that copies a real login page and sends whatever the victim types to the attacker. Kits are sold and shared on criminal forums, so one person can launch convincing fake sites for many brands without any design or coding skill. Some kits also capture one-time codes in real time.

Who can take a phishing site down?

The domain registrar can suspend the domain, the hosting provider can remove the content, and a proxy or CDN provider can stop serving it. Browser blocklists such as Google Safe Browsing can warn visitors even before the site itself is removed. Brands usually report to all of them at once, with screenshots and the full URL as evidence, and keep checking until the page is offline.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch