Skip to main content
Essay Undergraduate 1,565 words

Phishing in Internet Security: History, Risks & Prevention

~8 min read 5 sections Technology · Internet Security
Abstract

This paper examines phishing as a persistent internet security threat, tracing its origins from early America Online scams in the mid-1990s to increasingly sophisticated modern cyberattacks. The paper explains how phishing works — through deceptive emails, fake websites, malware, and social media lures — and documents the sharp rise in attack frequency between 2010 and 2012. It also outlines practical countermeasures individuals and organizations can employ, including verifying URLs, using HTTPS-secured sites, avoiding suspicious email attachments, and confirming communications directly with financial institutions before submitting any personal information.

Key Takeaways
  • Introduction to Phishing: Defines phishing and common online security threats
  • History of Phishing: Origins of phishing from AOL to payment systems
  • Results and Impact of Phishing Attacks: Rising attack statistics and organized cybercrime
  • How to Avoid Phishing: Practical strategies to detect and prevent phishing
  • Conclusion: Call for stronger individual and organizational security
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • The paper moves logically from definition and historical context to documented impact and then actionable prevention advice, giving readers a complete picture of the threat.
  • It grounds abstract security concepts in concrete examples — the AOL phishing case, the 2001 E-gold attack, and PayPal domain spoofing — making the discussion accessible to general readers.
  • Statistical evidence (attack counts from 2010–2012) is used to demonstrate the escalating scale of the problem, adding empirical weight to the argument.

Key academic technique demonstrated

The paper effectively uses a problem–evidence–solution structure: it establishes what phishing is, supports the claim that it is worsening with cited statistics, and then provides a systematic set of user-level countermeasures. This pattern is a reliable framework for applied security and technology essays at the undergraduate level.

Structure breakdown

The paper contains five sections. The introduction defines phishing and its social context. The history section traces the term's coinage and early attacks. The results section documents escalating attack numbers and the shift toward organized cybercrime. The prevention section offers specific, practical detection and avoidance strategies. The conclusion synthesizes the threat landscape and calls for stronger protective measures at both individual and organizational levels.

Essay 1,565 words

Introduction to Phishing

The number of people browsing the internet across the world is increasing with each passing day. There are numerous new internet users daily, and many of these users are unaware of the challenges and security risks the internet presents. Any online user is vulnerable to numerous security threats such as viruses, worms, Trojan horses, hackers, phishing, and pharming. All of these are well-documented risks that continue to evolve. The viruses users encountered in the past are very different from those circulating today. Scammers have developed a variety of methods to gain access to sensitive user information, primarily targeting financial, banking, credit card, and personal data.

Phishing is a method of obtaining personal information from a user by masquerading as a trustworthy entity (Marforio, Masti, Soriente, Kostiainen, & Capkun, 2015). This is typically accomplished by forging or faking an entity — such as a bank or credit card processing company — that collects personal or sensitive information. Scammers send a person an email informing them that they need to update their account, or that their online account has been compromised and they need to act quickly. The email contains a link to a fake website that closely resembles the genuine one. When the user enters their information, the scammer gains access to it and can defraud the victim, steal their identity, or make online purchases using the user's credentials.

History of Phishing

The term phishing was first used in 1996. It was coined from the word fishing, with the letter "f" replaced by "ph" because phishing was associated with underground hackers known as phreaks (Rader & Rahman, 2013). Since these hackers were fishing for passwords and financial data, their methods became known as phishing. The term illustrates the way they lure unsuspecting users — much as a fisherman lures fish with bait. The first recorded phishing fraud involved America Online (AOL). Because AOL provided internet access to millions of people at the time, it was a natural target. The service was popular, most users had never encountered online scammers, and people were consequently vulnerable and easily fell prey to these schemes.

Phishing remains an active internet security concern today. Hackers have devised various methods of capturing user information and credit card data, including posting on social media sites and using images tailored to a person's interests to attract victims. When a user clicks on such a link, they are directed to a website designed to capture their information. Hackers also continue to use email to instruct users to submit their credentials in order to "verify" or "update" their accounts.

While phishing scams may have become somewhat less prevalent than in their early days, the underlying methodologies remain the same. Awareness has improved — users are now taught to check the URL bar and verify a website before entering personal information. The first direct attack on a payment system using phishing was carried out in 2001 against E-gold. Although the attack was ultimately unsuccessful, it demonstrated the feasibility of targeting payment systems. By late 2003, phishers had registered numerous domains closely resembling legitimate ones — such as those mimicking eBay and PayPal (Levin, Richardson, Warner, & Kerley, 2012) — making it difficult for users to identify fraudulent sites, since most people do not read a full domain name carefully.

Results and Impact of Phishing Attacks

Phishing has resulted in widespread fraudulent activity, particularly for users who do not recognize a scam in time. Hackers have sold collected information to others who use it for identity theft or other malicious purposes. When AOL first introduced online accounts, it did not use credit card verification, which allowed hackers to create multiple fraudulent accounts and sell them to others. This practice was curtailed once AOL began using banks to verify credit cards. Hackers then shifted to email scams, encouraging users to enter their information on fake websites by claiming their accounts had been compromised or were missing required information. Users, trusting the messages, would willingly provide their personal data without first confirming the authenticity of the website.

Today, hackers have formed organized groups that target not only individuals but also senior government officials in countries around the world — a phenomenon now referred to as cyberattacks. The scale of these attacks has grown dramatically: there were 186,203 attacks in 2010, rising to 258,432 in 2011 and 445,004 in 2012 (Hong, 2012). These figures demonstrate that attacks have been increasing in parallel with technological advancement. Hackers are continuously refining their methods, and users must remain vigilant about their online activity and avoid websites they do not trust. Increasingly, phishing attacks are being combined with other techniques such as malware or Trojan horses.

1 Section Hidden · 390 words
How to Avoid Phishing390 words
Given that phishing attacks increase each year and hackers are continually developing more sophisticated methods, users must understand the tactics employed and accept that the internet carries real risks. Most phishing attacks make use of popup windows, emails, worms, or…

Conclusion

People should understand that the internet is full of malicious and dangerous individuals. The same caution people exercise in protecting their homes and physical bank cards should be applied to their online activity. Online security is not solely an individual concern — companies must also ensure their systems are protected against attacks in order to safeguard customer information. Phishing remains the preferred method for obtaining user data, with most hackers using email to flood a user's inbox with messages containing malicious links disguised as legitimate ones.

To reduce the frequency and impact of these attacks, stronger protective measures are needed. Online forms have proven to be a vulnerable point of entry, and many users continue to fall prey to hackers who exploit the basic requirement to input information in order to trick them into disclosing personal data. Hackers have further strengthened their attacks by incorporating malware that can compromise a user's computer and make it susceptible to additional exploitation. Awareness, caution, and good online habits remain the most accessible and effective defenses available to everyday users.

References

Goodman, J. T., Rehfuss, P. S., Rounthwaite, R. L., Mishra, M., Hulten, G. J., Richards, K. G., . . . Deyo, R. C. (2012). Phishing detection, prevention, and notification. Google Patents.

Hong, J. (2012). The state of phishing attacks. Communications of the ACM, 55(1), 74–81.

Levin, R., Richardson, J., Warner, G., & Kerley, K. (2012). Explaining cybercrime through the lens of differential association theory, Hadidi44-2.php PayPal case study. Paper presented at the eCrime Researchers Summit (eCrime), 2012.

Marforio, C., Masti, R. J., Soriente, C., Kostiainen, K., & Capkun, S. (2015). Personalized security indicators to detect application phishing attacks in mobile platforms. arXiv preprint arXiv:1502.06824.

Rader, M. A., & Rahman, S. S. M. (2013). Exploring historical and emerging phishing techniques and mitigating the associated security risks. International Journal of Network Security & Its Applications, 5(4).

Key Concepts in This Paper
Phishing Attacks Social Engineering Identity Theft Email Fraud HTTPS Security Cyberattacks Domain Spoofing Malware Online Fraud Internet Security
Cite This Paper
PaperDue. (2026). Phishing in Internet Security: History, Risks & Prevention. PaperDue. https://www.paperdue.com/study-guide/phishing-internet-security-history-prevention-2150180

Always verify citation format against your institution’s current style guide requirements.