While this is fairly straightforward, I feel obligated to explain how most phishing works and why it applies to his story.
Phishing is normally done with two methods, fake site, fake email. In a fake site, the phisherman (note: probably not an actual term) gives you a link to his site...