Phishing attacks succeed when they entice or manipulate users into performing actions they wouldn't normally do - clicking malicious links, entering credentials, downloading malware, or making payments. The attack exploits human psychology rather than technical vulnerabilities. Option A refers to unpatched servers (not phishing). Option C refers to user patching (relevant but not phishing success). Option D is unrelated.