February 10, 2026
Multi-stage phishing: hook, bait, and switch
If you haven’t already read our post on what phishing is, we suggest reading that one first.
Now that you’re caught up, let’s look at how attackers might use those phished credentials in an attack known as multi-stage phishing or multi-step phishing.
But how’s it different?
Multi-stage phishing is basically a “slow burn” scam. It’s generally not one of those obvious pop-ups that say “CONGRATS YOU WON $1,000,000!!! (which is super suspicious and easy to spot). It’s much more sneaky.
Setup: preparing the hook
First, the attacker needs to get your attention. They don’t just spam you; instead, they try to look like someone you know or something you care about.
This manifests itself as one of many phishing email types. It could be a “friend” asking for a favor, a “school admin” telling you your grades or ready, or a “recruiter” for a job you applied for.
Bait: building trust
This is the “multi-stage” part. Attackers don’t ask for your password directly. That would be too obvious. Instead, they build a fake relationship.
If they’re pretending to be school administrators or ITS, they might ask you to verify your account. Or, if they’re pretending to be a recruiter, they might tell you that they want to hire you.
Switch: the big ask
Once they have you hooked and you’ve demonstrated a willingness to give up some information, they strike.
They might ask you to then provide your password to complete the account verification. Or, they might ask for your Social Security number for “hiring tax purposes.” Using this information, they can steal your accounts or commit fraud in your name.
Why is it dangerous?
Because it feels normal. It feels like a conversation.
Classic scams were just one step: “hey, send me money.” A multi-stage scam is “hey, how are you? Do you like pizza? By the way, send me your credit card info.”