Types of Phishing Attacks
Phishing is a fraudulent attempt to obtain sensitive information by impersonating a trusted source, and it splits into distinct types defined by the channel it uses and the target it picks. The types of phishing attacks include email phishing, spear phishing, whaling, business email compromise, smishing, vishing, clone phishing, angler phishing, pharming, and quishing.
What Is Phishing?
Phishing is a fraudulent attempt to obtain sensitive information, such as credentials or financial data, by impersonating a trusted source. It delivers a deceptive message that prompts a victim to reveal information, click a malicious link, or open a harmful attachment. The defining traits are:
- Impersonation: the attacker poses as a trusted person, company, or institution.
- A fraudulent message: delivered by email, text, voice, social media, or a QR code.
- An objective: steal credentials, steal money, or deliver malware.
- A lure: urgency, fear, authority, or reward to push the victim to act fast.
Phishing is the most common form of social engineering, attacking a person rather than a technical flaw. The fundamentals are introduced in the explanation of what phishing is.
What Are the Main Types of Phishing Attacks?
The main types are email phishing, spear phishing, whaling, BEC, smishing, vishing, clone phishing, angler phishing, pharming, and quishing. Each one keeps the same trick (impersonate a trusted source) but changes the channel or the target:
Email phishing
Spear phishing
Whaling
BEC
Smishing
Vishing
Clone phishing
Angler phishing
Pharming
Quishing
Email phishing is the broadest type and the foundation the targeted variants grew from, per the APWG. The rest of this article defines each, the channel it uses, the target it picks, and its warning signs.
What Is Email Phishing?
Email phishing is a mass attack that sends fraudulent emails impersonating a trusted source to a large number of recipients. It casts a wide net, relying on a small percentage of recipients to respond. Its traits are:
- Mass distribution: the same message goes to many recipients at once.
- Generic impersonation: it mimics a well-known bank, retailer, or service provider.
- A malicious link or attachment: it leads to a fake login page or delivers malware.
- A general lure: it claims an account problem or a pending reward.
Best spotted by: a generic greeting, a mismatched sender address, and a link that does not resolve to the official domain.
What Is Spear Phishing?
Spear phishing is a targeted attack that uses personal details about a specific individual to make a fraudulent message more convincing. It researches the victim and tailors the message to the person’s role, contacts, or activities. Its traits are:

- A specific target: one individual or a small group, not a mass audience.
- Personalized content: it references the victim’s name, role, employer, or recent activity.
- Research: it draws on public profiles, social media, and prior breaches for credibility.
- A tailored lure: it aligns with the victim’s responsibilities to lower suspicion.
Best spotted by: a personalized but unexpected request, especially one bypassing normal process. AI now writes these at scale – one figure puts AI-generated phishing at a ~54% success rate against humans, versus ~12% for human-written. It is a frequent initial-access method in a larger cyberattack.
What Is Whaling?
Whaling is a form of spear phishing that targets senior executives and other high-value individuals. It pursues people with authority over money or sensitive data, where a single success yields a large gain. Its traits are:
- A high-value target: a chief executive, finance officer, or other senior leader.
- Business context: it references contracts, payments, legal matters, or executive duties.
- A high-stakes lure: it requests a wire transfer, confidential data, or an urgent approval.
- Careful research: it studies the executive’s role and communication style for credibility.
Best spotted by: an unexpected high-value request, pressure for secrecy, and a deviation from normal approval procedures. Whaling overlaps heavily with BEC, the next type.
What Is Business Email Compromise (BEC)?
Business email compromise spoofs or hijacks a corporate mailbox to redirect a legitimate payment to the attacker. It is the costliest email scam by losses and often carries no malicious link or attachment, so filters miss it. Its traits are:
- Impersonation of trust: it poses as an executive, a vendor, or a known partner.
- A payment pivot: it asks finance to change bank details or send an urgent wire.
- A clean message: no link or attachment, only convincing text – so it bypasses link scanners.
- Speed: 86% of BEC losses move by wire or ACH, often gone before fraud is detected.
What Are Smishing and Vishing?
Smishing is phishing delivered by SMS text message, and vishing is phishing delivered by voice call. Both move the attack off email to a channel the victim may trust more. Their traits are:
- Smishing: a fraudulent text with a malicious link or a number to call.
- Vishing: a phone call impersonating a bank, government agency, or support line.
- Caller ID and sender spoofing: the displayed number is falsified to look legitimate.
- An urgent script: it pressures the victim to act before verifying the caller.
Best spotted by: any request for credentials or payment over the phone or by text. Vishing surged ~442% in 2025 as attackers added AI voice cloning, making deepfake “executive” calls a real BEC vector. A request to act fast over the phone is a classic social engineering trigger.
What Is Clone Phishing?
Clone phishing copies a legitimate message the victim has received and replaces its links or attachments with malicious versions. It reuses a familiar, trusted message to lower suspicion. Its traits are:
- A copied message: it duplicates a genuine email the victim previously received.
- Replaced content: it swaps the original link or attachment for a malicious one.
- A plausible reason: it claims the message is a resend, update, or correction.
- A spoofed sender: it mimics the original sender’s address to appear authentic.
Best spotted by: an unexpected resend, a slightly altered sender address, and a link that differs from the one in the original.
What Are Angler Phishing and Pharming?
Angler phishing uses fake social media accounts to intercept customer complaints, and pharming redirects users from a legitimate website to a fraudulent one. Both push phishing beyond direct messages. Their traits are:
- Angler phishing: a fake support account replies to complaints to harvest credentials.
- Pharming: it corrupts DNS or a hosts file to send a user to a fake site even when the correct address is typed.
- A fake destination: both end on a replica login page that captures entered credentials.
- No obvious lure in pharming: the redirect happens without the user clicking a bad link.
Best spotted by: a “support” reply from an unverified handle, or the wrong site despite a correct address. Pharming relates to the DNS attacks in the guide to common network attacks; checking the certificate and address bar defends against the fake destination both rely on.
What Is Quishing (QR Code Phishing)?
Quishing hides a malicious URL inside a QR code, so the victim scans it on a phone and lands on a fake site. It is potent because the payload is an image: email filters read text, not the link encoded in the QR. Its traits are:
- An image payload: the URL is inside the QR code, not in scannable email text.
- A mobile landing: the scan opens on a phone, outside corporate email defenses.
- A physical or attached vector: a sticker over a real code, or a QR inside a PDF or flyer.
- A trusted pretext: a parking meter, restaurant menu, delivery notice, or a DocuSign-style document.
Best spotted by: any QR code that asks you to log in or pay. Quishing rose to roughly 12% of all phishing in 2025 (from 0.8% in 2021); Unit 42 documented a 2025 campaign hiding the entire payload in a QR-coded URL inside a macro-free DocuSign-style PDF. Preview the decoded URL before opening it.
How Do You Avoid Phishing Attacks?
Phishing attacks are avoided by verifying senders, inspecting links, enabling multi-factor authentication, and reporting suspicious messages. Defense lowers the chance of acting on a fraudulent message. The core defenses are:
- Verify the sender by checking the full address and confirming through a separate trusted channel.
- Inspect links by hovering (or previewing a decoded QR) before clicking.
- Enable multi-factor authentication so a stolen password alone does not grant access.
- Avoid attachments from unexpected or unverified messages.
- Confirm payments out-of-band, calling a known number before any wire or bank-detail change.
- Report suspicious messages to the email provider or security team.
CISA recommends verification, multi-factor authentication, and reporting as the core defenses against every phishing type. Recognizing fraudulent email in detail is the focus of the guide to spotting a phishing email.
Phishing Attack Types Comparison Table
The table compares each phishing type across the channel it uses, the target it picks, and its clearest warning sign:

| Type | Channel | Target | Key Warning Sign |
|---|---|---|---|
| Email phishing | Mass audience | Generic greeting, mismatched sender | |
| Spear phishing | Specific individual | Personalized but unexpected request | |
| Whaling | Senior executive | High-value request, secrecy pressure | |
| Smishing | SMS text | Mobile user | Unexpected link in a text |
| Vishing | Voice call | Phone user | Caller requesting credentials or payment |
| Clone phishing | Prior recipient | Resend with altered link | |
| Angler phishing | Social media | Customer with a complaint | Fake support account reply |
| Pharming | Web / DNS | Website visitor | Wrong site despite correct address |
What Happens After a Successful Phishing Attack?
After a successful phishing attack, the attacker uses the stolen credentials or installed malware to access accounts, move through systems, and steal data or money. One deceived user can lead to broad harm. The consequences are:
- Account takeover: the stolen credentials open email, banking, or business systems.
- Lateral movement: the attacker expands from the first account toward more systems and data.
- Data theft: confidential information is copied for fraud, extortion, or resale.
- Financial loss: fraudulent transfers, ransomware, or further fraud follow.
A single successful phishing attack often becomes the initial access for a larger cyberattack or leads directly to identity theft. Multi-factor authentication limits account takeover, since a stolen password alone does not grant access.
How Do Phishing Attacks Use Social Engineering?
Phishing attacks use social engineering by applying psychological triggers such as urgency, authority, and fear to prompt a victim to act. Phishing is the delivery of social engineering through a message. The connection is:
- Urgency pressures the victim to click or respond before verifying the message.
- Authority impersonates a bank, employer, or government agency to compel compliance.
- Fear warns of account suspension, fraud, or penalties to force a quick response.
- Trust mimics a familiar brand or contact to lower the victim’s suspicion.
Every phishing type applies these triggers, which is why phishing is the most common form of social engineering. Recognizing the trigger behind a message is a core skill in the guide to spotting a phishing email.
Last Thoughts on Types of Phishing Attacks
Phishing keeps one trick – impersonate a trusted source – and varies the channel and the target. Email phishing is the untargeted baseline; spear phishing, whaling, and BEC target named people and redirect money; smishing, vishing, angler phishing, and quishing change the channel to text, voice, social media, or a QR code; and pharming needs no click at all. In 2026 nearly all of these are AI-assisted, so the defense has shifted from spotting typos to verifying identity out-of-band, enabling multi-factor authentication, and reporting. Continue with the explanation of what phishing is, the overview of social engineering, the guide to spotting a phishing email, or the introduction to cybersecurity.
Key Takeaways:
- Phishing is a fraudulent attempt to obtain sensitive information by impersonating a trusted source.
- Email phishing targets a mass audience, while spear phishing and whaling target specific people.
- Smishing and vishing deliver phishing through SMS and voice calls.
- Clone phishing copies a real message and replaces its links with malicious ones.
- Angler phishing and pharming use fake social accounts and redirected websites.
- Defenses include verifying senders, inspecting links, multi-factor authentication, and reporting.
Frequently Asked Questions (FAQs)
What are the main types of phishing attacks?
The main types are email phishing, spear phishing, whaling, smishing, vishing, clone phishing, angler phishing, and pharming. They differ by channel and target but all impersonate a trusted source.
What is the difference between phishing and spear phishing?
Email phishing sends the same message to many recipients, while spear phishing targets a specific individual with personalized details drawn from research, making the message more convincing and harder to detect.
What is whaling in phishing?
Whaling is a form of spear phishing that targets senior executives and other high-value individuals. It requests wire transfers, confidential data, or urgent approvals where a single success yields a large gain.
What are smishing and vishing?
Smishing is phishing delivered by SMS text message, and vishing is phishing delivered by voice call. Both move the attack off email and often use spoofed sender numbers or caller IDs.
What is clone phishing?
Clone phishing copies a legitimate message the victim already received and replaces its links or attachments with malicious versions, claiming the message is a resend, update, or correction.
How can you avoid phishing attacks?
Avoid phishing by verifying senders through a separate channel, inspecting links before clicking, enabling multi-factor authentication, avoiding unexpected attachments, and reporting suspicious messages.


