Skip to main content

CNiC Solutions

Vintage CRT, laptop, and smartphone on a desk symbolizing the history and evolution of phishing attacks

Phishing is now the most reported cybercrime in the United States, but it started as a prank aimed at stealing free hours of dial-up internet. In just under three decades it has grown from clumsy AOL chat messages into AI-generated video calls that drain millions from corporate accounts in a single afternoon. Understanding how the attack evolved is the fastest way to see where it is heading, and what your business needs to defend against next.

 

 

Timeline infographic of phishing milestones from the 1996 AOL era to the 2024 deepfake scam era
Key milestones in the evolution of phishing from 1996 to 2024. Sources: FBI IC3, Gartner, APWG.

 

 

Key Takeaways

  • Phishing is old, but never static. The word first appeared in 1996, yet the tactic has reinvented itself for every new platform, from email to text messages to video calls.
  • The target moved from consumers to companies. Early scams chased individual AOL passwords. Today’s most damaging variant, business email compromise, targets finance teams and wire transfers.
  • Speed is the new weapon. Verizon found the median time to click a malicious link after opening a phishing email is just 21 seconds, and only 28 more seconds to hand over data.
  • Volume keeps breaking records. The Anti-Phishing Working Group counted nearly five million phishing attacks in 2023, the worst year on record.
  • AI erased the old warning signs. Typos and broken grammar no longer reliably flag a scam, because generative tools produce flawless, personalized messages, voices, and faces.
  • People, not firewalls, are the front line. Every era of phishing has exploited human trust, which is why training and layered defenses matter more than any single tool.

What’s in This Guide

The AOL Era: Where Phishing Began (1995 to 2000)

Phishing was born on America Online, the walled-garden internet that millions of households used in the mid-1990s. Before attackers went after money, they went after access: free AOL accounts and the credentials of other users.

1994 to 1995: AOHell arrives. A teenager using the handle “Da Chronic” released AOHell, a toolkit that automated harassment and account theft on AOL. One of its features let a scammer pose as an AOL employee in a chat window and ask a victim to “verify your account” or “confirm your password.” It packaged social engineering into a point-and-click tool, which is why it spread so fast.

January 2, 1996: the word “phishing” is first recorded. The term appeared in a Usenet newsgroup dedicated to AOL. The metaphor is simple: dangle a convincing lure and wait for someone to bite. The “ph” was borrowed from “phreaking,” the earlier practice of hacking phone systems, tying the new scam to established hacker culture.

1996 to 2000: impersonation becomes routine. Attackers refined the AOL playbook, sending instant messages and emails that impersonated billing departments and warned of account problems. AOL began attaching notices to its communications reminding members that staff would never ask for a password, an early version of the warnings we still see today.

1996
First recorded use of the word “phishing,” in an AOL Usenet newsgroup

The AOL era established the template every later attack would reuse: impersonate a trusted authority, invent a reason for urgency, and ask the victim to reveal a secret. The platform would change many times, but that formula never did. As dial-up gave way to broadband and online banking, the same trick found a far more profitable target.

Source: Anti-Phishing Working Group

Going Pro: Phishing Becomes an Industry (2001 to 2007)

Once people started moving real money online, phishing followed it. The early 2000s turned a nuisance into organized crime, complete with toolkits, fake bank sites, and dedicated criminal crews.

2001 to 2003: the money follows the internet. Attackers shifted from AOL passwords to online payment systems and banks, standing up fake login pages for services like e-gold, eBay, and PayPal. Victims received emails warning of a “suspended account” with a link to a counterfeit site that captured their credentials.

2003: the Anti-Phishing Working Group forms. As bank-targeted scams multiplied, industry and law enforcement created the Anti-Phishing Working Group to track incidents and share intelligence. Its quarterly trends reports have measured the problem ever since, giving the industry a common yardstick.

2004 to 2005: phishing becomes a billion-dollar problem. The research firm Gartner estimated that roughly 1.2 million U.S. computer users suffered phishing-related losses valued at about $929 million between May 2004 and May 2005. Prewritten “phishing kits” appeared for sale, letting low-skill criminals clone a bank’s website in minutes.

$929M
Estimated U.S. phishing losses, May 2004 to May 2005 (Gartner)

By 2007, phishing had a supply chain. Crews such as the group behind the “Rock Phish” kit industrialized the process, hosting many fake sites at once and reusing infrastructure across campaigns. Phishing was no longer a hobby, it was a service that anyone could rent. The next leap was not about scale, it was about precision.

Source: Federal Trade Commission consumer guidance

Explore Data Backup & Recovery

Getting Personal: Spear Phishing and the Corporate Breach (2008 to 2015)

Mass phishing works on averages: send enough messages and someone clicks. Spear phishing flips that logic. Instead of a million strangers, the attacker studies one person and writes a message built to fool that individual. This era proved a single tailored email could open the door to an entire company.

2011: spear phishing breaches a security giant. The security company RSA was compromised after employees received emails carrying a spreadsheet titled “2011 Recruitment Plan.” One person opened it, the attached file exploited a software flaw, and intruders gained a foothold that ultimately threatened the SecurID tokens used by thousands of organizations. It was a stark lesson that even security firms fall to a well-aimed email.

2013: the Target breach starts with a vendor. Attackers stole payment details for roughly 40 million cards from the retailer Target, and the intrusion has been widely traced to a phishing email sent to a third-party heating and air-conditioning contractor. Stolen vendor credentials became the path into Target’s network, showing that your suppliers’ inboxes are part of your attack surface.

2014 to 2015: high-profile intrusions multiply. Spear phishing featured in a wave of major breaches, and “business email compromise,” in which criminals impersonate an executive or vendor to trigger fraudulent wire transfers, began to emerge as its own costly category tracked by the FBI.

~40M
Payment cards exposed in the 2013 Target breach, linked to a phishing entry point

The message of these years was uncomfortable: technical defenses could be bypassed by targeting the people who operate them. Firewalls do not open attachments, employees do. That realization set the stage for the moment phishing stepped onto the world stage.

Source: CISA guidance on social engineering and phishing attacks

Explore Managed IT Services

Elections, Worms, and Wire Fraud (2016 to 2020)

By the late 2010s phishing was no longer just a fraud story, it was a national-security story and a boardroom budget line. The same basic email trick influenced elections, spread across the cloud, and quietly moved billions of dollars.

2016: a phishing email enters the political arena. During the U.S. election cycle, a spear-phishing email disguised as a Google security alert helped attackers access the inbox of a senior political campaign official. It was one of the most consequential demonstrations that a single click can have effects far beyond one account.

2017: phishing goes self-propagating. A fake “Google Docs” message spread rapidly by abusing legitimate account permissions, tricking users into granting access and then mailing itself to their contacts. It previewed a modern tactic: instead of stealing a password, trick the user into approving access directly.

2019 to 2020: business email compromise becomes the costliest scam. The FBI’s Internet Crime Complaint Center reported that BEC losses reached about $1.8 billion in 2020, making it the most damaging cybercrime category it tracked. Pandemic-era remote work, with its flood of urgent digital requests, gave attackers ideal cover.

$1.8B
Reported U.S. business email compromise losses in 2020 (FBI IC3)

These years cemented phishing as the entry point for the biggest cyber incidents, from ransomware to fraud to espionage. What made the next chapter different was not a new delivery method, but a new author. Artificial intelligence would soon write the messages.

Source: FBI Internet Crime Complaint Center

 

CNiC Solutions — Cybersecurity

 

The AI Era: Deepfakes and Flawless Fakes (2021 to Present)

For 25 years, one piece of security advice held up well: watch for bad spelling, odd grammar, and generic greetings. Generative AI broke that rule. Attackers can now produce fluent, personalized, error-free messages at scale, and clone the voices and faces of people you trust.

2021 to 2022: the channels multiply. Phishing expanded well beyond email into text messages (“smishing”), phone calls (“vishing”), and malicious QR codes (“quishing”). Attackers also learned to defeat basic multi-factor authentication by bombarding users with login prompts until someone approved one out of fatigue.

2023: a record year for volume. The Anti-Phishing Working Group recorded nearly five million phishing attacks across the year, the most it had ever counted, with more than one million in the fourth quarter alone. Cheap, capable AI writing tools were a major reason campaigns could scale so quickly.

2024: the deepfake heist. In one of the clearest signs of the new era, the global engineering firm Arup lost about $25.6 million after an employee in Hong Kong was invited to a video call. The “CFO” and “colleagues” on the call were AI-generated deepfakes built from public footage. It began, as so many attacks do, with a suspicious email that the fake meeting was designed to make believable.

$25.6M
Lost by engineering firm Arup to a 2024 deepfake video-call scam

Myth: “I can always spot a phishing email by the typos.”

This was once decent advice. It is now dangerous. Generative AI writes clean, natural messages in any language and can mimic a specific person’s tone. Verizon’s investigators found the median time from opening a phishing email to clicking its link is 21 seconds, far too fast for careful proofreading to save you. Modern detection has to rely on verifying requests through a second channel and on technical controls, not on spotting a spelling mistake.

Source: APWG Phishing Activity Trends Reports | Verizon Data Breach Investigations Report

Where We Are Now

Phishing today is high-volume, low-cost, and disturbingly effective. It is the leading way attackers get their first foot inside an organization, and the numbers behind it are no longer subtle.

298,878
Phishing and spoofing complaints in 2023, the most reported U.S. cybercrime (FBI IC3)
21 sec
Median time to click a phishing link after opening the email (Verizon 2024 DBIR)
$2.9B
Reported U.S. business email compromise losses in 2023 (FBI IC3)

The trend in fraud losses tells the clearest story. Business email compromise, the targeted descendant of those 1990s AOL scams, has climbed steadily as attackers refined their impersonation of executives and vendors.

Reported U.S. Business Email Compromise Losses, 2020 to 2023 (FBI IC3)

2020
$1.8B

2021
$2.4B

2022
$2.7B

2023
$2.9B

 

 

Infographic showing phishing branching from email into smishing, vishing, QR codes, BEC, and deepfakes
The same social-engineering trick has spread from email into texts, calls, QR codes, and AI deepfakes.

 

 

The takeaway is not that any single number is catastrophic, it is the direction. More attacks, faster compromises, larger losses, and fewer reliable warning signs. The defenses that worked against 2010-era phishing are no longer enough on their own.

Source: FBI IC3 2023 Internet Crime Report

What This Means for Your Business

Every era of phishing has exploited the same weakness: a person’s willingness to trust a familiar-looking request. That is good news, because it means the defense has stayed consistent even as the attacks changed. You reduce risk by making trust harder to abuse and by catching the messages that slip through.

No business builds all of that overnight, and most small and midsize teams do not have the in-house staff to run it. That is where a managed security partner earns its keep, combining the tools, monitoring, and training into one program that keeps pace as the attacks evolve. If you are not sure where your gaps are, a security assessment is the fastest way to find out. CNiC Solutions helps Texas and national businesses map their exposure and close it before an attacker finds it first.

Talk to CNiC About a Security Audit

Backups and a recovery plan turn a breach into a bad day instead of a disaster, which is why they belong in every phishing defense. A virtual CIO can turn scattered security tools into a coherent strategy rather than a pile of disconnected products. For a data-driven look at local risk, our Houston-area cyber threat data shows how these national trends land on regional businesses, and our guide to why network security matters for modern businesses covers the foundations phishing tries to bypass.

Phishing Milestone Reference Table

Year Event Impact Source
1994 to 1995 AOHell toolkit released Automated AOL account theft and impersonation; packaged social engineering for anyone to use APWG
Jan 1996 Word “phishing” first recorded Named the tactic; appeared in an AOL Usenet newsgroup APWG
1996 to 2000 AOL impersonation scams peak Established the “trusted authority + urgency + secret request” template APWG
2001 to 2003 Fake bank and payment sites appear Phishing pivots from stealing access to stealing money FTC
2003 Anti-Phishing Working Group formed Created a shared system to track and measure phishing globally APWG
2004 to 2005 Losses hit an estimated $929M Roughly 1.2M U.S. users affected; phishing becomes a criminal industry Gartner
2007 Phishing kits industrialized “Rock Phish” and similar crews turn phishing into a rentable service APWG
2011 RSA breached via spear phishing A single “Recruitment Plan” attachment threatens SecurID tokens worldwide CISA
2013 Target breach (~40M cards) Traced to a phishing email at a third-party vendor; suppliers become an attack surface Major reporting
2014 to 2015 BEC emerges as a category Executive and vendor impersonation drives fraudulent wire transfers FBI IC3
2016 Election-related spear phishing A fake security alert compromises a senior campaign inbox Major reporting
2017 “Google Docs” OAuth worm Self-spreading phishing abuses permissions instead of stealing passwords Major reporting
2020 BEC losses reach ~$1.8B Remote work fuels urgent-request fraud; BEC is the costliest tracked cybercrime FBI IC3
2021 to 2022 Smishing, vishing, quishing, MFA fatigue Phishing expands across texts, calls, QR codes, and push-prompt spam CISA
2023 Record ~5M phishing attacks Most on record (APWG); 298,878 IC3 complaints; BEC losses $2.9B APWG / FBI IC3
2024 Arup deepfake video-call scam ~$25.6M lost to AI-cloned executives; generative-AI phishing goes mainstream CNN

Frequently Asked Questions

When did phishing start?

The first recorded use of the word phishing dates to January 2, 1996, in an America Online (AOL) Usenet newsgroup. Attackers used a toolkit called AOHell to impersonate AOL staff and trick users into handing over passwords and billing details. The “ph” spelling traces back to “phreaking,” the 1970s practice of hacking telephone systems.

Why is it spelled phishing instead of fishing?

The concept is the same as fishing: cast a lure and wait for a bite. The unusual “ph” spelling was borrowed from “phreaking,” the underground hobby of manipulating phone networks to make free calls. Early internet attackers adopted the style to signal a link to that hacker culture.

What is the difference between phishing and spear phishing?

Standard phishing casts a wide net, sending the same generic message to thousands of people and hoping a small percentage respond. Spear phishing is targeted: the attacker researches a specific person or company and crafts a tailored message, often impersonating a known colleague, vendor, or executive to make the request believable.

How much does phishing cost businesses today?

According to the FBI’s Internet Crime Complaint Center, business email compromise, a targeted form of phishing, caused more than $2.9 billion in reported U.S. losses in 2023 across 21,489 complaints. Phishing and spoofing were also the single most reported cybercrime that year, with 298,878 complaints.

Can AI make phishing harder to detect?

Yes. Generative AI removes the spelling and grammar errors that once gave scams away, writes fluent messages in any language, and can clone voices and faces. In early 2024 the engineering firm Arup lost $25.6 million after an employee joined a video call with deepfake versions of the company’s CFO and colleagues.

Methodology & Sources

This history draws on primary cybercrime data and established reporting. Loss and complaint figures come from the FBI’s Internet Crime Complaint Center (IC3) annual reports. Attack-volume figures come from the Anti-Phishing Working Group’s quarterly Phishing Activity Trends Reports. Time-to-compromise data comes from Verizon’s Data Breach Investigations Report. Early-market loss estimates are attributed to Gartner. Historical milestones are corroborated with agency guidance from CISA and the FTC and with major news reporting where a primary agency source is not the origin of the event. Figures are reported as published and rounded where noted; where a range of years is given, the entry reflects the period over which the trend developed rather than a single date.

Primary sources:
FBI IC3 2023 Internet Crime Report |
APWG Phishing Activity Trends Reports |
Verizon Data Breach Investigations Report |
CISA: Avoiding Social Engineering and Phishing Attacks |
FTC: How to Recognize and Avoid Phishing Scams |
CNN: Arup deepfake scam

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog