By Nur Dalila Wahida Binti Mohamad Ghazali and Dr. Mohd Istajib Bin Mokhtar
The internet has become a necessary component of everyday life in today’s digital world, which allows e-commerce, digital banking, and online communication. This simplicity has also contributed to numerous cyber risks, especially phishing. Phishing is a type of cybercrime in which perpetrators imitate reputable businesses to deceive individuals into disclosing personal information, including passwords, credit card numbers, and banking credentials.
Phishing attacks are experiencing a significant increase in popularity on a global scale, impacting governments, enterprises, and individuals. A study published in the journal Cybersecurity revealed that phishing is among the most prevalent techniques employed by cybercriminals to obtain unauthorised access to personal data. Similarly, researchers from the University of Maryland reported that cyber-attacks occur every few seconds, highlighting the scale and urgency of the issue. As reliance on digital platforms continues to grow, so does the sophistication of cybercriminal tactics.
Issues and controversies
Phishing attacks have grown from simple fraudulent emails to highly sophisticated schemes that involve phoney websites, SMS scams (smishing), and phone calls (vishing). Cybercriminals frequently impersonate as reputable organisations like banks, governments, or well-known businesses, making it is harder for users to discern between malicious and legitimate messages.
According to a research by the Anti-Phishing Working Group, millions of phishing attacks are discovered every year, indicating a notable increase in phishing websites worldwide. These findings demonstrate that phishing is not only increasing in frequency but also becoming more advanced and targeted. In Malaysia, phishing has become a serious concern, particularly through SMS scams and fraudulent banking messages. According to Bank Negara Malaysia, online financial scams have resulted in substantial financial losses among Malaysians, with phishing identified as a major contributor. Meanwhile, the Royal Malaysia Police has issued repeated warnings about scam syndicates that exploit phishing techniques to deceive victims.
One of the most controversial aspects of phishing is the use of social engineering. Cybercriminals manipulate emotions such as fear, urgency, and trust to influence victims’ decisions. For example, individuals may receive messages claiming their bank accounts have been compromised, prompting immediate action without verification. This manipulation highlights that phishing is not only a technological issue but also a psychological one.
Legal and ethical perspectives
From an international and regional legal perspective, phishing poses major challenges due to gaps in existing regulations. A study by Purwadi et al. highlights the exploitation of psychological manipulation in social engineering-based phishing, which current cybercrime laws often fail to address. While most legal frameworks focus on technical hacking, phishing relies on deception and human vulnerability, making it harder to prosecute. Additionally, research in Cybercrime: A New Challenge of Criminality in the Digital Age notes that, although phishing is classified under fraud and cybercrime offenses, enforcement is difficult due to its cross-border nature and the anonymity of perpetrators.
Phishing is not only against the law, but it also takes advantage of people’s feelings of trust, anxiety, and urgency. Victims often unknowingly disclose personal information, showing how cybercriminals manipulate human weaknesses rather than technical systems. This raises serious moral concerns, especially as phishing frequently targets vulnerable groups like the elderly and those with low digital literacy. Overall, it violates key values such as honesty, integrity, and privacy, making ethical considerations just as important as legal enforcement.
Recommendations
Addressing the growing threat of phishing requires a multi-level approach involving individuals, organizations, and governments.
First, public awareness must be strengthened. Research published in Brilliance: Research of Artificial Intelligence by Fauzan Prasetyo Eka Putra and colleagues emphasizes that user education is crucial, as informed individuals are better equipped to identify suspicious links and messages.
Second, organizations should enhance cybersecurity measures. According to research on phishing prevention strategies by FNU Jimmy, combining technological solutions—such as multi-factor authentication and advanced email filtering—with user awareness is the most effective defense against phishing attacks.
Finally, governments must improve legal frameworks and international cooperation. Since phishing often involves cross-border activities, stronger collaboration between countries is essential. Establishing mechanisms for information sharing and joint investigations can significantly improve efforts to combat cybercrime.
Conclusion
Phishing attacks are becoming a more serious worldwide threat, and their impact and complexity are constantly changing. As cybercriminals develop more sophisticated techniques, individuals and organizations must remain vigilant and proactive in addressing these risks.
While legal frameworks and technological advancements provide some level of protection, they are not sufficient on their own, as they often fail to address the human element of security, which is crucial in preventing phishing attacks. Combating phishing requires a combination of awareness, strong policies, ethical responsibility, and international cooperation. In a world where a single click can have serious consequences, understanding and preventing phishing is more important than ever.


The authors are from the Department of Science and Technology Studies, Faculty of Science, Universiti Malaya
