Email Security 101 — a 4-part series. ← Part 1: Remove Yourself From Data Brokers · Part 2: What to Do After an Email Data Breach. You’re on Part 3. Part 4 (what BIMI is) is coming next.
The short version
- Phishing isn’t one attack — it’s a family. Email phishing, spear phishing, whaling, BEC, clone phishing, smishing, vishing, quishing, angler phishing and pharming all trick you into handing over data or money, each through a different channel or lure.
- The tells are shared: unexpected urgency, a request to click/log in/pay, a sender you can’t verify, and a link or number that doesn’t match the real organisation.
- Defence is layered: slow down and verify, use 2FA and a password manager, and shrink your exposure with per-site aliases so a leaked address can’t be used to target you as easily.
Phishing is the most common way people get hacked, and it works because it targets you, not your software. But “phishing” is an umbrella term — the types of phishing attacks vary widely in how they reach you and who they target, from mass emails blasted to millions to a single, painstakingly researched message aimed at one finance manager. Knowing the categories is what lets you spot the next one, because once you recognise the shape of the trick, the specific disguise stops mattering. This is Part 3 of our Email Security 101 series, and it picks up where Part 2 on surviving a data breach left off — because a breach is exactly what feeds the targeted phishing below.
What Phishing Is — and Why the Type Matters
Phishing is social engineering: an attacker impersonates someone you trust — your bank, a courier, your boss, a colleague — to trick you into revealing credentials, transferring money, or installing malware. The genius of it is that it bypasses your technical defences entirely and goes after your judgement, usually by manufacturing urgency so you act before you think.
Why bother categorising it? Because the type tells you what to watch for. A mass email phishing blast is caught by a healthy scepticism of “your account is suspended” messages. A spear-phishing email that names your actual project and manager needs a different reflex — verifying through a second channel. A text message (smishing) or phone call (vishing) sidesteps your email filters completely. If you only know “phishing = suspicious email,” you’ll miss the half of it that doesn’t arrive by email at all. So here are the main types of phishing attacks, each with the lure it uses and the tell that gives it away.
The Main Types of Phishing Attacks
1. Email phishing (deceptive phishing)
The classic: a mass email impersonating a well-known brand — a bank, PayPal, a delivery company — sent to millions in the hope that a fraction click. It claims there’s a problem (“unusual activity,” “package held,” “payment failed”) and links to a fake login page that harvests your credentials. It’s low-effort and high-volume, so the tells are usually obvious once you look: generic greetings, slightly-off sender domains, and links that don’t go where they claim.
2. Spear phishing
Targeted phishing aimed at a specific person or organisation, using real details to be convincing — your name, employer, role, a recent purchase, a colleague’s name. Attackers gather this from data breaches, social media, and data brokers (the exact reason Part 1 of this series matters). Because it’s personalised, spear phishing defeats the “it’s obviously generic” instinct — the message knows things about you, so it feels legitimate.
3. Whaling
Spear phishing aimed at “big fish” — executives, finance chiefs, founders. The lure is tailored to someone with authority and access: a fake legal notice, an urgent board matter, a wire-transfer request. Whaling messages are often well-written and business-like, with no typos or clumsy formatting, because the payoff justifies the effort. A single successful whaling or wire-transfer fraud can net six or seven figures, which is why attackers happily spend weeks researching one target’s calendar, contacts, and writing style before sending a word.
4. Business email compromise (BEC) / CEO fraud
Business email compromise is one of the costliest attacks in existence. The attacker impersonates (or actually takes over) an executive’s or vendor’s email account and instructs an employee to make an urgent payment or change bank details. There’s often no malicious link at all — just a plausible, authority-driven request — which is why it slips past filters that look for bad URLs. The defence is procedural: verify any payment or bank-detail change through a second, known channel.
5. Clone phishing
The attacker takes a real, legitimate email you’ve received — a genuine invoice, a shipping notice — clones it exactly, and re-sends it with the links or attachments swapped for malicious ones, often claiming it’s a “resend” or “updated version.” Because the template is authentic, clone phishing is unusually convincing; the tell is the unexpected re-send and a sender address that’s subtly wrong. If you get a “here’s the corrected version” of a message you weren’t expecting to be corrected, slow down and check the sender before opening anything.
6. Smishing (SMS phishing)
Smishing is phishing by text message — “your parcel couldn’t be delivered, confirm here,” “your bank card is locked.” Texts feel more urgent and personal than email and bypass email security entirely, which is why smishing has exploded. Legitimate companies rarely ask you to log in or pay via a texted link; treat any that does as suspect and go to the app or website directly.
7. Vishing (voice phishing)
Vishing is phishing by phone call — a “bank fraud department,” “tech support,” or “tax office” caller pressuring you to confirm details, move money, or grant remote access. AI voice cloning has made this dramatically more convincing, even mimicking a family member’s or executive’s voice. The rule: hang up and call back on a number you look up yourself, never one the caller gives you. Real institutions are happy for you to call back on the number printed on your card or their official site; a scammer will pressure you to stay on the line precisely because hanging up breaks the spell.
8. Quishing (QR-code phishing)
A newer type: the malicious link is hidden in a QR code — on a poster, a parking meter, a fake “verify your account” email, or a sticker placed over a real one. Because your eye can’t read a QR code, you can’t spot a bad URL before scanning, and phones open the link immediately. Be wary of QR codes that lead to a login or payment page, especially unsolicited ones.
9. Angler phishing (social media)
Attackers pose as a brand’s customer-support account on social media, watching for people complaining to a company and swooping in with a “support” reply that links to a fake help page or asks for account details. If you tweet at your bank about a problem, be sceptical of the “official support” account that DMs you — check the handle carefully — a real support account is usually verified and long-established, while the impostor is freshly created with a near-identical name and a hair-trigger willingness to take your conversation into private messages.
10. Pharming
Rather than luring you to a fake site, pharming poisons the path so that even typing the correct address lands you on the attacker’s copy — via malware on your device or a compromised DNS server. It’s rarer and more technical, but it’s why HTTPS and watching for certificate warnings matter: the address bar can look right while the destination is fake. Because there’s no obvious lure to second-guess, the defence is technical hygiene — keep your device malware-free, use a trusted DNS resolver, and never dismiss a browser certificate warning as a nuisance.

The Types of Phishing Attacks at a Glance
Here’s the field guide condensed — the channel each uses, who it targets, and the single biggest tell.
| Type | Channel | Target | The tell |
|---|---|---|---|
| Email phishing | Email (mass) | Anyone | Generic greeting, off-domain sender |
| Spear phishing | Email (targeted) | A specific person | Knows real details, still asks you to act now |
| Whaling | Email (targeted) | Executives | Authority + urgency (legal, wire transfer) |
| BEC / CEO fraud | Email (often no link) | Finance/staff | Urgent payment or bank-detail change |
| Clone phishing | Anyone | Unexpected “resend” of a real message | |
| Smishing | Text message | Anyone | Texted link to log in or pay |
| Vishing | Phone call | Anyone | Pressure to act; number they gave you |
| Quishing | QR code | Anyone | Unsolicited QR to a login/payment page |
| Angler phishing | Social media | Complainers | “Support” account that DMs you first |
| Pharming | DNS/malware | Anyone | Right address, wrong site; cert warnings |
Why These Attacks Keep Getting More Effective
Phishing isn’t just persisting — it’s getting harder to spot, for three reinforcing reasons worth understanding, because they explain why old advice (“look for bad spelling”) no longer protects you.
First, breach data fuels personalisation. Every corporate breach dumps millions of names, emails, and purchase histories into criminal markets. Attackers stitch these together — often via the same breach data indexed by services like Have I Been Pwned — into dossiers that turn a generic blast into a convincing spear-phishing message that knows your name, your bank, and what you bought last week. The more breaches pile up, the sharper the lures get. This is why Parts 1 and 2 of this series — shrinking your exposure and responding to breaches — are the foundation the anti-phishing advice here sits on.
Second, AI has removed the old tells. The clumsy grammar and awkward phrasing that used to give phishing away are gone: large language models write flawless, on-brand messages in any language, and voice cloning reproduces a boss’s or family member’s voice from seconds of audio. A “your CEO is calling about an urgent transfer” vishing attack that would once have been caught by a wrong accent now sounds exactly right.
Third, the channels keep multiplying. As email filters improve, attackers move to the gaps — text, phone, QR codes, social DMs — where there’s little filtering and more implicit trust. Each new channel resets the arms race in the attacker’s favour. The takeaway isn’t despair; it’s that you can’t rely on spotting bad craftsmanship anymore. You have to rely on the process — verify through a channel you chose — because that defeats even a flawless, personalised, perfectly-voiced attack.
How to Spot Any of These Types of Phishing Attacks
You don’t need to memorise ten categories in the moment — nearly every phishing attempt, whatever the type, trips at least one of these wires:
- Unexpected urgency or threat. “Act now or lose access,” “your account will be closed,” “the payment is overdue.” Urgency is engineered to stop you thinking. Legitimate organisations give you time.
- A request to click, log in, pay, or share a code. The whole point of phishing is to get you to do something. Any unsolicited message steering you to a login page, a payment, or a one-time code deserves suspicion.
- A sender or number you can’t verify. Display names are trivial to fake — our explainer on email spoofing shows how the “from” line lies. Check the actual address, and never trust a phone number or link the message itself provides.
- A link or destination that doesn’t match. Hover a link before clicking (on desktop) to see the real URL; a “PayPal” email pointing to a random domain is a phish. On mobile, go to the app or type the address yourself.
- Something slightly off. A greeting that isn’t your name, a domain with an extra word or swapped letter, a tone that’s not quite how that person writes. Trust the itch.
The universal move that defeats almost all of it: stop and verify through a channel you chose. Don’t reply, don’t click, don’t call the number in the message — independently look up the organisation or person and reach them yourself. Ninety seconds of verification beats every disguise.
Phishing in the Real World
Categories are easier to remember when you can picture them. Here’s how the common types actually land:
- The delivery text (smishing). “Your parcel is held — a £1.45 customs fee is due, pay here.” You are expecting a parcel, so the timing feels right; the link leads to a convincing courier page that harvests your card. The tell: real couriers don’t collect fees by SMS link.
- The invoice swap (BEC + clone). A supplier you actually use emails an updated invoice with “new bank details for payment.” The email address is a look-alike, or the supplier’s account was compromised. Paying it wires money straight to the attacker. The tell: any bank-detail change must be confirmed by phone on a known number.
- The account alert (email phishing). “Unusual sign-in to your account — secure it now.” The panic of a possible hack pushes you to click and “log in,” handing your password to a fake page. The tell: go to the service directly, never via the email’s button.
- The boss’s urgent ask (whaling/BEC). “I’m in a meeting, can you buy £500 of gift cards for a client and send me the codes? Will reimburse.” It exploits the desire to be responsive to authority. The tell: gift-card requests are almost always fraud; verify in person or by call.
- The QR at the restaurant/parking meter (quishing). A sticker over the real code sends you to a fake payment page. The tell: be wary when a QR leads to a login or payment, and check for tampering.
Notice the pattern across all five: a plausible context, a manufactured reason to hurry, and a request to pay, log in, or share something. Recognise that pattern and the specific channel becomes irrelevant.
How to Protect Yourself From Phishing
Spotting attacks is half of it; the other half is arranging things so that even a successful phish does limited damage:
- Turn on two-factor authentication (2FA) everywhere, ideally with an authenticator app or hardware key. If a phish captures your password, 2FA is the wall that still stands — and phishing-resistant methods like passkeys defeat even real-time credential theft.
- Use a password manager. Beyond unique passwords, a manager won’t autofill your credentials on a look-alike domain — so it quietly catches phishing sites your eye might miss.
- Never act on an inbound request without verifying. Especially payments, bank-detail changes, gift cards, or one-time codes — call the person or company back on a number you already trust.
- Keep devices and browsers updated, and heed certificate/security warnings — your first line against pharming and malware payloads.
- Report and delete. Report phishing to your provider and, in the US, follow the FTC’s phishing guidance; then delete the message. Reporting improves the filters that protect everyone.
On the technical side, email authentication — SPF, DKIM, and especially DMARC — helps stop attackers spoofing a domain outright. It’s not a complete cure (it can’t stop a look-alike domain), but it raises the bar, and it’s the groundwork for BIMI, which we cover in Part 4.
Where Email Aliases Fit
Per-site email aliases don’t stop a phisher from sending you a message — but they change the economics of phishing in three quiet, useful ways, which is why they belong in any anti-phishing setup.
- They shrink what attackers can learn about you. Spear phishing runs on personal data harvested from breaches and brokers. When every service knows you by a different alias, a breach at one leaks a dead-end address that can’t be cross-referenced into a rich profile — so the personalised lures that make spear phishing work are harder to build.
- They make a phish easier to spot. If you gave your bank a single-purpose alias and a “bank security alert” arrives at a different address, you know instantly it’s fake — the mismatch is the tell. Purpose-scoped addresses turn “is this real?” into a quick check.
- They let you cut off a compromised channel. When an alias starts attracting phishing after a service is breached — the exact breach-to-phishing pipeline from Part 2 — you disable that one alias and the attack surface closes, without touching your real inbox.
To be clear, aliases are a containment and detection layer, not a phishing cure — you still need the human vigilance and 2FA above. But by starving attackers of the data that powers targeted phishing and giving you a fast “this doesn’t add up” signal, they meaningfully reduce your risk. Our take on whether to use your real email online goes deeper on that trade.
Final Thoughts
The types of phishing attacks keep multiplying — quishing barely existed a few years ago, and AI voice cloning has supercharged vishing — but the underlying trick never changes: impersonate trust, manufacture urgency, get you to act before you verify. Learn the shape of that move and you’re protected against types that haven’t been invented yet. Slow down on anything urgent, verify through a channel you chose, lean on 2FA and a password manager, and shrink your exposure so attackers have less to work with. Do that and phishing goes from your biggest risk to a manageable annoyance. Next in Email Security 101: what BIMI is, how it builds on DMARC to put a verified logo on legitimate mail, and whether you actually need it.
Frequently Asked Questions
What are the most common types of phishing attacks?
The most common is email phishing — mass, generic emails impersonating a bank, courier, or payment service. Beyond that, the main types are spear phishing (targeted, using your real details), whaling (aimed at executives), business email compromise or CEO fraud (urgent payment/bank-change requests), clone phishing (a real email re-sent with malicious links), and the non-email channels: smishing (text), vishing (phone call), quishing (QR code), and angler phishing (fake support on social media). Pharming, which redirects you to a fake site even when you type the correct address, is rarer and more technical.
What is the difference between phishing and spear phishing?
Phishing (specifically mass or deceptive phishing) is a wide net — the same generic message sent to millions, hoping a small fraction click. Spear phishing is a targeted spear thrown at one person or organisation, using real details about you (name, employer, role, recent activity) gathered from breaches, social media, and data brokers. Spear phishing is far more convincing precisely because it’s personalised, so it defeats the instinct that a message is ‘obviously generic spam.’
What are smishing and vishing?
They’re phishing through non-email channels. Smishing is phishing by SMS text message — for example, a fake ‘your parcel is held, confirm here’ text with a malicious link. Vishing is phishing by phone call — a caller pretending to be your bank’s fraud team, tech support, or the tax office, pressuring you to confirm details, move money, or grant remote access. Both bypass your email filters, and AI voice cloning has made vishing especially convincing. The defence is the same: don’t act on the message; independently look up the organisation and contact it yourself.
What is quishing (QR code phishing)?
Quishing hides the malicious link inside a QR code instead of visible text — on a poster, a parking meter, an email, or a sticker placed over a legitimate code. Because you can’t read a QR code with your eyes, you can’t spot a bad URL before scanning, and phones open the link immediately. Be cautious with any unsolicited QR code that leads to a login or payment page, and prefer typing the address or using the official app.
How can I tell if an email is a phishing attempt?
Look for the shared tells: unexpected urgency or a threat (‘act now or lose access’), a request to click a link, log in, pay, or share a one-time code, a sender address you can’t verify (display names are easily faked), and a link whose real destination doesn’t match the supposed organisation. Anything slightly off — a generic greeting, a domain with an extra word or swapped letter — is a red flag. When in doubt, don’t click; go to the company’s website or app directly.
What should I do if I clicked a phishing link?
Act quickly. If you entered a password, change it immediately on that account and anywhere you reused it, and turn on two-factor authentication. If you entered card or bank details, contact your bank and watch for fraudulent charges. If it was a work account, tell your IT/security team right away. Run a malware scan if you downloaded anything. Then report the phishing to your email provider and, in the US, at the FTC — reporting helps protect others.
Does two-factor authentication stop phishing?
It stops most of the damage. If a phish captures your password, 2FA means the attacker still can’t log in without your second factor — a wall that still stands. Standard 2FA (codes via app or SMS) can occasionally be defeated by real-time phishing that relays your code, but phishing-resistant methods like passkeys and hardware security keys defeat even that. 2FA doesn’t stop you receiving a phish, but it dramatically limits what a successful one achieves, which is why it’s the single highest-value protection to enable.
Do email aliases protect against phishing?
Aliases don’t block phishing messages, but they reduce your risk in three ways. They starve spear phishing of the personal data it relies on — a breach of an alias leaks a dead-end address that can’t be built into a rich profile. They make a phish easier to spot: a ‘bank alert’ arriving at an address you never gave your bank is obviously fake. And they let you disable a compromised alias to cut off attacks after a service is breached. Treat aliases as a containment and detection layer on top of vigilance and 2FA, not a replacement for them.
