Phishing is now the most reported cybercrime in the United States, but it started as a prank aimed at stealing free hours of dial-up internet. In just under three decades it has grown from clumsy AOL chat messages into AI-generated video calls that drain millions from corporate accounts in a single afternoon. Understanding how the attack evolved is the fastest way to see where it is heading, and what your business needs to defend against next.

Phishing was born on America Online, the walled-garden internet that millions of households used in the mid-1990s. Before attackers went after money, they went after access: free AOL accounts and the credentials of other users.
1994 to 1995: AOHell arrives. A teenager using the handle “Da Chronic” released AOHell, a toolkit that automated harassment and account theft on AOL. One of its features let a scammer pose as an AOL employee in a chat window and ask a victim to “verify your account” or “confirm your password.” It packaged social engineering into a point-and-click tool, which is why it spread so fast.
January 2, 1996: the word “phishing” is first recorded. The term appeared in a Usenet newsgroup dedicated to AOL. The metaphor is simple: dangle a convincing lure and wait for someone to bite. The “ph” was borrowed from “phreaking,” the earlier practice of hacking phone systems, tying the new scam to established hacker culture.
1996 to 2000: impersonation becomes routine. Attackers refined the AOL playbook, sending instant messages and emails that impersonated billing departments and warned of account problems. AOL began attaching notices to its communications reminding members that staff would never ask for a password, an early version of the warnings we still see today.
The AOL era established the template every later attack would reuse: impersonate a trusted authority, invent a reason for urgency, and ask the victim to reveal a secret. The platform would change many times, but that formula never did. As dial-up gave way to broadband and online banking, the same trick found a far more profitable target.
Source: Anti-Phishing Working Group
Once people started moving real money online, phishing followed it. The early 2000s turned a nuisance into organized crime, complete with toolkits, fake bank sites, and dedicated criminal crews.
2001 to 2003: the money follows the internet. Attackers shifted from AOL passwords to online payment systems and banks, standing up fake login pages for services like e-gold, eBay, and PayPal. Victims received emails warning of a “suspended account” with a link to a counterfeit site that captured their credentials.
2003: the Anti-Phishing Working Group forms. As bank-targeted scams multiplied, industry and law enforcement created the Anti-Phishing Working Group to track incidents and share intelligence. Its quarterly trends reports have measured the problem ever since, giving the industry a common yardstick.
2004 to 2005: phishing becomes a billion-dollar problem. The research firm Gartner estimated that roughly 1.2 million U.S. computer users suffered phishing-related losses valued at about $929 million between May 2004 and May 2005. Prewritten “phishing kits” appeared for sale, letting low-skill criminals clone a bank’s website in minutes.
By 2007, phishing had a supply chain. Crews such as the group behind the “Rock Phish” kit industrialized the process, hosting many fake sites at once and reusing infrastructure across campaigns. Phishing was no longer a hobby, it was a service that anyone could rent. The next leap was not about scale, it was about precision.
Source: Federal Trade Commission consumer guidance
Explore Data Backup & Recovery
Mass phishing works on averages: send enough messages and someone clicks. Spear phishing flips that logic. Instead of a million strangers, the attacker studies one person and writes a message built to fool that individual. This era proved a single tailored email could open the door to an entire company.
2011: spear phishing breaches a security giant. The security company RSA was compromised after employees received emails carrying a spreadsheet titled “2011 Recruitment Plan.” One person opened it, the attached file exploited a software flaw, and intruders gained a foothold that ultimately threatened the SecurID tokens used by thousands of organizations. It was a stark lesson that even security firms fall to a well-aimed email.
2013: the Target breach starts with a vendor. Attackers stole payment details for roughly 40 million cards from the retailer Target, and the intrusion has been widely traced to a phishing email sent to a third-party heating and air-conditioning contractor. Stolen vendor credentials became the path into Target’s network, showing that your suppliers’ inboxes are part of your attack surface.
2014 to 2015: high-profile intrusions multiply. Spear phishing featured in a wave of major breaches, and “business email compromise,” in which criminals impersonate an executive or vendor to trigger fraudulent wire transfers, began to emerge as its own costly category tracked by the FBI.
The message of these years was uncomfortable: technical defenses could be bypassed by targeting the people who operate them. Firewalls do not open attachments, employees do. That realization set the stage for the moment phishing stepped onto the world stage.
Source: CISA guidance on social engineering and phishing attacks
By the late 2010s phishing was no longer just a fraud story, it was a national-security story and a boardroom budget line. The same basic email trick influenced elections, spread across the cloud, and quietly moved billions of dollars.
2016: a phishing email enters the political arena. During the U.S. election cycle, a spear-phishing email disguised as a Google security alert helped attackers access the inbox of a senior political campaign official. It was one of the most consequential demonstrations that a single click can have effects far beyond one account.
2017: phishing goes self-propagating. A fake “Google Docs” message spread rapidly by abusing legitimate account permissions, tricking users into granting access and then mailing itself to their contacts. It previewed a modern tactic: instead of stealing a password, trick the user into approving access directly.
2019 to 2020: business email compromise becomes the costliest scam. The FBI’s Internet Crime Complaint Center reported that BEC losses reached about $1.8 billion in 2020, making it the most damaging cybercrime category it tracked. Pandemic-era remote work, with its flood of urgent digital requests, gave attackers ideal cover.
These years cemented phishing as the entry point for the biggest cyber incidents, from ransomware to fraud to espionage. What made the next chapter different was not a new delivery method, but a new author. Artificial intelligence would soon write the messages.
Source: FBI Internet Crime Complaint Center
For 25 years, one piece of security advice held up well: watch for bad spelling, odd grammar, and generic greetings. Generative AI broke that rule. Attackers can now produce fluent, personalized, error-free messages at scale, and clone the voices and faces of people you trust.
2021 to 2022: the channels multiply. Phishing expanded well beyond email into text messages (“smishing”), phone calls (“vishing”), and malicious QR codes (“quishing”). Attackers also learned to defeat basic multi-factor authentication by bombarding users with login prompts until someone approved one out of fatigue.
2023: a record year for volume. The Anti-Phishing Working Group recorded nearly five million phishing attacks across the year, the most it had ever counted, with more than one million in the fourth quarter alone. Cheap, capable AI writing tools were a major reason campaigns could scale so quickly.
2024: the deepfake heist. In one of the clearest signs of the new era, the global engineering firm Arup lost about $25.6 million after an employee in Hong Kong was invited to a video call. The “CFO” and “colleagues” on the call were AI-generated deepfakes built from public footage. It began, as so many attacks do, with a suspicious email that the fake meeting was designed to make believable.
This was once decent advice. It is now dangerous. Generative AI writes clean, natural messages in any language and can mimic a specific person’s tone. Verizon’s investigators found the median time from opening a phishing email to clicking its link is 21 seconds, far too fast for careful proofreading to save you. Modern detection has to rely on verifying requests through a second channel and on technical controls, not on spotting a spelling mistake.
Source: APWG Phishing Activity Trends Reports | Verizon Data Breach Investigations Report
Phishing today is high-volume, low-cost, and disturbingly effective. It is the leading way attackers get their first foot inside an organization, and the numbers behind it are no longer subtle.
The trend in fraud losses tells the clearest story. Business email compromise, the targeted descendant of those 1990s AOL scams, has climbed steadily as attackers refined their impersonation of executives and vendors.
Reported U.S. Business Email Compromise Losses, 2020 to 2023 (FBI IC3)

The takeaway is not that any single number is catastrophic, it is the direction. More attacks, faster compromises, larger losses, and fewer reliable warning signs. The defenses that worked against 2010-era phishing are no longer enough on their own.
Source: FBI IC3 2023 Internet Crime Report
Every era of phishing has exploited the same weakness: a person’s willingness to trust a familiar-looking request. That is good news, because it means the defense has stayed consistent even as the attacks changed. You reduce risk by making trust harder to abuse and by catching the messages that slip through.
No business builds all of that overnight, and most small and midsize teams do not have the in-house staff to run it. That is where a managed security partner earns its keep, combining the tools, monitoring, and training into one program that keeps pace as the attacks evolve. If you are not sure where your gaps are, a security assessment is the fastest way to find out. CNiC Solutions helps Texas and national businesses map their exposure and close it before an attacker finds it first.
Talk to CNiC About a Security Audit
Backups and a recovery plan turn a breach into a bad day instead of a disaster, which is why they belong in every phishing defense. A virtual CIO can turn scattered security tools into a coherent strategy rather than a pile of disconnected products. For a data-driven look at local risk, our Houston-area cyber threat data shows how these national trends land on regional businesses, and our guide to why network security matters for modern businesses covers the foundations phishing tries to bypass.
| Year | Event | Impact | Source |
|---|---|---|---|
| 1994 to 1995 | AOHell toolkit released | Automated AOL account theft and impersonation; packaged social engineering for anyone to use | APWG |
| Jan 1996 | Word “phishing” first recorded | Named the tactic; appeared in an AOL Usenet newsgroup | APWG |
| 1996 to 2000 | AOL impersonation scams peak | Established the “trusted authority + urgency + secret request” template | APWG |
| 2001 to 2003 | Fake bank and payment sites appear | Phishing pivots from stealing access to stealing money | FTC |
| 2003 | Anti-Phishing Working Group formed | Created a shared system to track and measure phishing globally | APWG |
| 2004 to 2005 | Losses hit an estimated $929M | Roughly 1.2M U.S. users affected; phishing becomes a criminal industry | Gartner |
| 2007 | Phishing kits industrialized | “Rock Phish” and similar crews turn phishing into a rentable service | APWG |
| 2011 | RSA breached via spear phishing | A single “Recruitment Plan” attachment threatens SecurID tokens worldwide | CISA |
| 2013 | Target breach (~40M cards) | Traced to a phishing email at a third-party vendor; suppliers become an attack surface | Major reporting |
| 2014 to 2015 | BEC emerges as a category | Executive and vendor impersonation drives fraudulent wire transfers | FBI IC3 |
| 2016 | Election-related spear phishing | A fake security alert compromises a senior campaign inbox | Major reporting |
| 2017 | “Google Docs” OAuth worm | Self-spreading phishing abuses permissions instead of stealing passwords | Major reporting |
| 2020 | BEC losses reach ~$1.8B | Remote work fuels urgent-request fraud; BEC is the costliest tracked cybercrime | FBI IC3 |
| 2021 to 2022 | Smishing, vishing, quishing, MFA fatigue | Phishing expands across texts, calls, QR codes, and push-prompt spam | CISA |
| 2023 | Record ~5M phishing attacks | Most on record (APWG); 298,878 IC3 complaints; BEC losses $2.9B | APWG / FBI IC3 |
| 2024 | Arup deepfake video-call scam | ~$25.6M lost to AI-cloned executives; generative-AI phishing goes mainstream | CNN |
This history draws on primary cybercrime data and established reporting. Loss and complaint figures come from the FBI’s Internet Crime Complaint Center (IC3) annual reports. Attack-volume figures come from the Anti-Phishing Working Group’s quarterly Phishing Activity Trends Reports. Time-to-compromise data comes from Verizon’s Data Breach Investigations Report. Early-market loss estimates are attributed to Gartner. Historical milestones are corroborated with agency guidance from CISA and the FTC and with major news reporting where a primary agency source is not the origin of the event. Figures are reported as published and rounded where noted; where a range of years is given, the entry reflects the period over which the trend developed rather than a single date.
Primary sources:
FBI IC3 2023 Internet Crime Report |
APWG Phishing Activity Trends Reports |
Verizon Data Breach Investigations Report |
CISA: Avoiding Social Engineering and Phishing Attacks |
FTC: How to Recognize and Avoid Phishing Scams |
CNN: Arup deepfake scam
A firmware update is a manufacturer-issued revision to the low-level software built into a device, such…
A human firewall is the group of employees who, through security awareness and good habits, act…
A distributed system is a collection of independent computers, called nodes, that are connected over a…
A firewall is a network security device or software that monitors incoming and outgoing traffic and…