Computer Security

Types of Phishing Attacks

Phishing is a fraudulent attempt to obtain sensitive information by impersonating a trusted source, and it splits into distinct types defined by the channel it uses and the target it picks. The types of phishing attacks include email phishing, spear phishing, whaling, business email compromise, smishing, vishing, clone phishing, angler phishing, pharming, and quishing.

In shortPhishing types differ by channel (email, SMS, voice, social media, QR, DNS) and target (a mass audience versus one named person or executive). Email phishing is the untargeted baseline; spear phishing, whaling, and BEC are targeted; smishing, vishing, angler phishing, and quishing change the channel; pharming needs no click at all. In 2026 most of these are AI-assisted, which removes the old grammar tells.
$20.9B
FBI IC3 2025 cybercrime losses
$3.04B
BEC losses in 2025
~54%
AI-phishing success rate
+442%
Vishing surge in 2025

What Is Phishing?

Phishing is a fraudulent attempt to obtain sensitive information, such as credentials or financial data, by impersonating a trusted source. It delivers a deceptive message that prompts a victim to reveal information, click a malicious link, or open a harmful attachment. The defining traits are:

  • Impersonation: the attacker poses as a trusted person, company, or institution.
  • A fraudulent message: delivered by email, text, voice, social media, or a QR code.
  • An objective: steal credentials, steal money, or deliver malware.
  • A lure: urgency, fear, authority, or reward to push the victim to act fast.

Phishing is the most common form of social engineering, attacking a person rather than a technical flaw. The fundamentals are introduced in the explanation of what phishing is.

What Are the Main Types of Phishing Attacks?

The main types are email phishing, spear phishing, whaling, BEC, smishing, vishing, clone phishing, angler phishing, pharming, and quishing. Each one keeps the same trick (impersonate a trusted source) but changes the channel or the target:

Email phishing

Mass, untargeted email spoofing a known brand. Relies on volume; a generic greeting and mismatched sender address are the tells.

Spear phishing

One named victim, message tailored from researched details (role, contacts, projects). Harder to question than bulk email.

Whaling

Spear phishing aimed at C-suite and other high-authority targets. One success buys a large wire transfer or sensitive data.

BEC

Business email compromise: a spoofed or hijacked corporate mailbox redirects a payment. Often no link or attachment – pure impersonation.

Smishing

Phishing by SMS text. The link is tapped on a phone, outside most email defenses (fake delivery or bank alerts).

Vishing

Phishing by voice call, now frequently AI voice-cloned. Pretexts a bank, agency, or a cloned executive to extract an OTP or payment.

Clone phishing

A near-identical copy of a real prior email, with links or attachments swapped for malicious ones and a resend pretext.

Angler phishing

A fake brand-support account on social media that replies to public complaints with a credential-stealing help link.

Pharming

Poisons DNS or the hosts file so the correct address silently resolves to a fake site. No click required.

Quishing

A malicious URL hidden in a QR code. Scanned on mobile, it evades URL scanners that read email text.

Email phishing is the broadest type and the foundation the targeted variants grew from, per the APWG. The rest of this article defines each, the channel it uses, the target it picks, and its warning signs.

What Is Email Phishing?

Email phishing is a mass attack that sends fraudulent emails impersonating a trusted source to a large number of recipients. It casts a wide net, relying on a small percentage of recipients to respond. Its traits are:

  • Mass distribution: the same message goes to many recipients at once.
  • Generic impersonation: it mimics a well-known bank, retailer, or service provider.
  • A malicious link or attachment: it leads to a fake login page or delivers malware.
  • A general lure: it claims an account problem or a pending reward.

Best spotted by: a generic greeting, a mismatched sender address, and a link that does not resolve to the official domain.

What Is Spear Phishing?

Spear phishing is a targeted attack that uses personal details about a specific individual to make a fraudulent message more convincing. It researches the victim and tailors the message to the person’s role, contacts, or activities. Its traits are:

What Is Spear Phishing? - Types of Phishing Attacks
  • A specific target: one individual or a small group, not a mass audience.
  • Personalized content: it references the victim’s name, role, employer, or recent activity.
  • Research: it draws on public profiles, social media, and prior breaches for credibility.
  • A tailored lure: it aligns with the victim’s responsibilities to lower suspicion.

Best spotted by: a personalized but unexpected request, especially one bypassing normal process. AI now writes these at scale – one figure puts AI-generated phishing at a ~54% success rate against humans, versus ~12% for human-written. It is a frequent initial-access method in a larger cyberattack.

Related Articles

What Is Whaling?

Whaling is a form of spear phishing that targets senior executives and other high-value individuals. It pursues people with authority over money or sensitive data, where a single success yields a large gain. Its traits are:

  • A high-value target: a chief executive, finance officer, or other senior leader.
  • Business context: it references contracts, payments, legal matters, or executive duties.
  • A high-stakes lure: it requests a wire transfer, confidential data, or an urgent approval.
  • Careful research: it studies the executive’s role and communication style for credibility.

Best spotted by: an unexpected high-value request, pressure for secrecy, and a deviation from normal approval procedures. Whaling overlaps heavily with BEC, the next type.

What Is Business Email Compromise (BEC)?

Business email compromise spoofs or hijacks a corporate mailbox to redirect a legitimate payment to the attacker. It is the costliest email scam by losses and often carries no malicious link or attachment, so filters miss it. Its traits are:

  • Impersonation of trust: it poses as an executive, a vendor, or a known partner.
  • A payment pivot: it asks finance to change bank details or send an urgent wire.
  • A clean message: no link or attachment, only convincing text – so it bypasses link scanners.
  • Speed: 86% of BEC losses move by wire or ACH, often gone before fraud is detected.
Red flags (verify out-of-band)The FBI IC3 puts 2025 BEC losses at $3.04 billion, the #2 cybercrime by loss. Treat any change of bank details, any “urgent and confidential” wire, and any payment request that skips normal approval as suspect – confirm by a phone call to a known number, never by replying to the email.

What Are Smishing and Vishing?

Smishing is phishing delivered by SMS text message, and vishing is phishing delivered by voice call. Both move the attack off email to a channel the victim may trust more. Their traits are:

  • Smishing: a fraudulent text with a malicious link or a number to call.
  • Vishing: a phone call impersonating a bank, government agency, or support line.
  • Caller ID and sender spoofing: the displayed number is falsified to look legitimate.
  • An urgent script: it pressures the victim to act before verifying the caller.

Best spotted by: any request for credentials or payment over the phone or by text. Vishing surged ~442% in 2025 as attackers added AI voice cloning, making deepfake “executive” calls a real BEC vector. A request to act fast over the phone is a classic social engineering trigger.

What Is Clone Phishing?

Clone phishing copies a legitimate message the victim has received and replaces its links or attachments with malicious versions. It reuses a familiar, trusted message to lower suspicion. Its traits are:

  • A copied message: it duplicates a genuine email the victim previously received.
  • Replaced content: it swaps the original link or attachment for a malicious one.
  • A plausible reason: it claims the message is a resend, update, or correction.
  • A spoofed sender: it mimics the original sender’s address to appear authentic.

Best spotted by: an unexpected resend, a slightly altered sender address, and a link that differs from the one in the original.

What Are Angler Phishing and Pharming?

Angler phishing uses fake social media accounts to intercept customer complaints, and pharming redirects users from a legitimate website to a fraudulent one. Both push phishing beyond direct messages. Their traits are:

  • Angler phishing: a fake support account replies to complaints to harvest credentials.
  • Pharming: it corrupts DNS or a hosts file to send a user to a fake site even when the correct address is typed.
  • A fake destination: both end on a replica login page that captures entered credentials.
  • No obvious lure in pharming: the redirect happens without the user clicking a bad link.

Best spotted by: a “support” reply from an unverified handle, or the wrong site despite a correct address. Pharming relates to the DNS attacks in the guide to common network attacks; checking the certificate and address bar defends against the fake destination both rely on.

What Is Quishing (QR Code Phishing)?

Quishing hides a malicious URL inside a QR code, so the victim scans it on a phone and lands on a fake site. It is potent because the payload is an image: email filters read text, not the link encoded in the QR. Its traits are:

  • An image payload: the URL is inside the QR code, not in scannable email text.
  • A mobile landing: the scan opens on a phone, outside corporate email defenses.
  • A physical or attached vector: a sticker over a real code, or a QR inside a PDF or flyer.
  • A trusted pretext: a parking meter, restaurant menu, delivery notice, or a DocuSign-style document.

Best spotted by: any QR code that asks you to log in or pay. Quishing rose to roughly 12% of all phishing in 2025 (from 0.8% in 2021); Unit 42 documented a 2025 campaign hiding the entire payload in a QR-coded URL inside a macro-free DocuSign-style PDF. Preview the decoded URL before opening it.

How Do You Avoid Phishing Attacks?

Phishing attacks are avoided by verifying senders, inspecting links, enabling multi-factor authentication, and reporting suspicious messages. Defense lowers the chance of acting on a fraudulent message. The core defenses are:

  • Verify the sender by checking the full address and confirming through a separate trusted channel.
  • Inspect links by hovering (or previewing a decoded QR) before clicking.
  • Enable multi-factor authentication so a stolen password alone does not grant access.
  • Avoid attachments from unexpected or unverified messages.
  • Confirm payments out-of-band, calling a known number before any wire or bank-detail change.
  • Report suspicious messages to the email provider or security team.

CISA recommends verification, multi-factor authentication, and reporting as the core defenses against every phishing type. Recognizing fraudulent email in detail is the focus of the guide to spotting a phishing email.

Phishing Link InspectorPaste a suspicious link to check the address for common phishing red flags. The tool reads the link text only and never opens it.

Phishing Attack Types Comparison Table

The table compares each phishing type across the channel it uses, the target it picks, and its clearest warning sign:

Phishing Attack Types Comparison Table - Types of Phishing Attacks
TypeChannelTargetKey Warning Sign
Email phishingEmailMass audienceGeneric greeting, mismatched sender
Spear phishingEmailSpecific individualPersonalized but unexpected request
WhalingEmailSenior executiveHigh-value request, secrecy pressure
SmishingSMS textMobile userUnexpected link in a text
VishingVoice callPhone userCaller requesting credentials or payment
Clone phishingEmailPrior recipientResend with altered link
Angler phishingSocial mediaCustomer with a complaintFake support account reply
PharmingWeb / DNSWebsite visitorWrong site despite correct address
Quick ruleIf a message creates urgency and asks you to log in, pay, or change bank details, slow down and verify through a separate channel – that single habit defeats every type in the table.

What Happens After a Successful Phishing Attack?

After a successful phishing attack, the attacker uses the stolen credentials or installed malware to access accounts, move through systems, and steal data or money. One deceived user can lead to broad harm. The consequences are:

  • Account takeover: the stolen credentials open email, banking, or business systems.
  • Lateral movement: the attacker expands from the first account toward more systems and data.
  • Data theft: confidential information is copied for fraud, extortion, or resale.
  • Financial loss: fraudulent transfers, ransomware, or further fraud follow.

A single successful phishing attack often becomes the initial access for a larger cyberattack or leads directly to identity theft. Multi-factor authentication limits account takeover, since a stolen password alone does not grant access.

How Do Phishing Attacks Use Social Engineering?

Phishing attacks use social engineering by applying psychological triggers such as urgency, authority, and fear to prompt a victim to act. Phishing is the delivery of social engineering through a message. The connection is:

  • Urgency pressures the victim to click or respond before verifying the message.
  • Authority impersonates a bank, employer, or government agency to compel compliance.
  • Fear warns of account suspension, fraud, or penalties to force a quick response.
  • Trust mimics a familiar brand or contact to lower the victim’s suspicion.

Every phishing type applies these triggers, which is why phishing is the most common form of social engineering. Recognizing the trigger behind a message is a core skill in the guide to spotting a phishing email.

Punycode and Look-alike Domain DecoderPaste a domain or an xn-- punycode string to reveal the real Unicode it represents and spot phishing look-alikes
Scam Text CheckerPick the kind of text you received to see if it matches a known smishing scam, the red flags, and what to do

Last Thoughts on Types of Phishing Attacks

Phishing keeps one trick – impersonate a trusted source – and varies the channel and the target. Email phishing is the untargeted baseline; spear phishing, whaling, and BEC target named people and redirect money; smishing, vishing, angler phishing, and quishing change the channel to text, voice, social media, or a QR code; and pharming needs no click at all. In 2026 nearly all of these are AI-assisted, so the defense has shifted from spotting typos to verifying identity out-of-band, enabling multi-factor authentication, and reporting. Continue with the explanation of what phishing is, the overview of social engineering, the guide to spotting a phishing email, or the introduction to cybersecurity.

Key Takeaways:

  • Phishing is a fraudulent attempt to obtain sensitive information by impersonating a trusted source.
  • Email phishing targets a mass audience, while spear phishing and whaling target specific people.
  • Smishing and vishing deliver phishing through SMS and voice calls.
  • Clone phishing copies a real message and replaces its links with malicious ones.
  • Angler phishing and pharming use fake social accounts and redirected websites.
  • Defenses include verifying senders, inspecting links, multi-factor authentication, and reporting.

Frequently Asked Questions (FAQs)

What are the main types of phishing attacks?

The main types are email phishing, spear phishing, whaling, smishing, vishing, clone phishing, angler phishing, and pharming. They differ by channel and target but all impersonate a trusted source.

What is the difference between phishing and spear phishing?

Email phishing sends the same message to many recipients, while spear phishing targets a specific individual with personalized details drawn from research, making the message more convincing and harder to detect.

What is whaling in phishing?

Whaling is a form of spear phishing that targets senior executives and other high-value individuals. It requests wire transfers, confidential data, or urgent approvals where a single success yields a large gain.

What are smishing and vishing?

Smishing is phishing delivered by SMS text message, and vishing is phishing delivered by voice call. Both move the attack off email and often use spoofed sender numbers or caller IDs.

What is clone phishing?

Clone phishing copies a legitimate message the victim already received and replaces its links or attachments with malicious versions, claiming the message is a resend, update, or correction.

How can you avoid phishing attacks?

Avoid phishing by verifying senders through a separate channel, inspecting links before clicking, enabling multi-factor authentication, avoiding unexpected attachments, and reporting suspicious messages.

Nizam Ud Deen

Muhammad Nizam Ud Deen Usman is the founder of theCoreiTech and the author of The Local SEO Cosmos. Nizam works as an SEO consultant and content strategy expert with more than a decade of experience in digital marketing and IT, and he also founded ORM Digital Solutions, a digital agency serving medium and large businesses. He holds a degree from the University of Education, Lahore (Multan Campus), and was listed among the top 20 SEO experts in Pakistan in 2024. Nizam started theCoreiTech in 2012 to make computers easier to understand and use for everyone. Connect with Nizam on LinkedIn (seoobserver), X (@SEO_Observer), or at nizamuddeen.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button