The user is tricked into believing they are interacting with a legitimate site while data is sent to an attacker