{"id":386,"date":"2026-09-19T04:42:48","date_gmt":"2026-09-18T23:12:48","guid":{"rendered":"https:\/\/emailalias.io\/blog\/?p=386"},"modified":"2026-09-19T04:42:51","modified_gmt":"2026-09-18T23:12:51","slug":"types-of-phishing-attacks","status":"publish","type":"post","link":"https:\/\/emailalias.io\/blog\/types-of-phishing-attacks\/","title":{"rendered":"Email Security 101 (Part 3): Types of Phishing Attacks and How to Spot Them"},"content":{"rendered":"<p class=\"series-nav\"><em>Email Security 101 \u2014 a 4-part series. \u2190 Part 1: <a href=\"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/\">Remove Yourself From Data Brokers<\/a> \u00b7 Part 2: <a href=\"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/\">What to Do After an Email Data Breach<\/a>. You&#8217;re on Part 3. Part 4 (what BIMI is) is coming next.<\/em><\/p>\n\n<div class=\"post-tldr\">\n  <p class=\"post-tldr__title\">The short version<\/p>\n  <ul>\n    <li><strong>Phishing isn&#8217;t one attack \u2014 it&#8217;s a family.<\/strong> Email phishing, spear phishing, whaling, BEC, clone phishing, smishing, vishing, quishing, angler phishing and pharming all trick you into handing over data or money, each through a different channel or lure.<\/li>\n    <li><strong>The tells are shared:<\/strong> unexpected urgency, a request to click\/log in\/pay, a sender you can&#8217;t verify, and a link or number that doesn&#8217;t match the real organisation.<\/li>\n    <li><strong>Defence is layered:<\/strong> slow down and verify, use 2FA and a password manager, and shrink your exposure with per-site aliases so a leaked address can&#8217;t be used to target you as easily.<\/li>\n  <\/ul>\n<\/div>\n\n<p>Phishing is the most common way people get hacked, and it works because it targets you, not your software. But &#8220;phishing&#8221; is an umbrella term \u2014 the types of phishing attacks vary widely in how they reach you and who they target, from mass emails blasted to millions to a single, painstakingly researched message aimed at one finance manager. Knowing the categories is what lets you spot the next one, because once you recognise the shape of the trick, the specific disguise stops mattering. This is Part 3 of our Email Security 101 series, and it picks up where <a href=\"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/\" rel=\"noopener\" target=\"_blank\">Part 2 on surviving a data breach<\/a> left off \u2014 because a breach is exactly what feeds the targeted phishing below.<\/p>\n\n<nav class=\"post-toc\" aria-label=\"Table of contents\">\n  <h2 class=\"post-toc__title\">Table of contents<\/h2>\n  <ol class=\"post-toc__list\">\n    <li><a href=\"#what-is\">What phishing is \u2014 and why the type matters<\/a><\/li>\n    <li><a href=\"#the-types\">The main types of phishing attacks<\/a><\/li>\n    <li><a href=\"#compared\">The types of phishing attacks at a glance<\/a><\/li>\n    <li><a href=\"#why-worse\">Why these attacks keep getting more effective<\/a><\/li>\n    <li><a href=\"#spot\">How to spot any of these types of phishing attacks<\/a><\/li>\n    <li><a href=\"#scenarios\">Phishing in the real world<\/a><\/li>\n    <li><a href=\"#protect\">How to protect yourself<\/a><\/li>\n    <li><a href=\"#aliases\">Where email aliases fit<\/a><\/li>\n    <li><a href=\"#final-thoughts\">Final thoughts<\/a><\/li>\n    <li><a href=\"#faq\">Frequently asked questions<\/a><\/li>\n  <\/ol>\n<\/nav>\n\n<h2 id=\"what-is\">What Phishing Is \u2014 and Why the Type Matters<\/h2>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Phishing\" rel=\"noopener\" target=\"_blank\">Phishing<\/a> is social engineering: an attacker impersonates someone you trust \u2014 your bank, a courier, your boss, a colleague \u2014 to trick you into revealing credentials, transferring money, or installing malware. The genius of it is that it bypasses your technical defences entirely and goes after your judgement, usually by manufacturing urgency so you act before you think.<\/p>\n<p>Why bother categorising it? Because the type tells you what to watch for. A mass email phishing blast is caught by a healthy scepticism of &#8220;your account is suspended&#8221; messages. A spear-phishing email that names your actual project and manager needs a different reflex \u2014 verifying through a second channel. A text message (smishing) or phone call (vishing) sidesteps your email filters completely. If you only know &#8220;phishing = suspicious email,&#8221; you&#8217;ll miss the half of it that doesn&#8217;t arrive by email at all. So here are the main types of phishing attacks, each with the lure it uses and the tell that gives it away.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Phishing attacks your judgement, not your software, by manufacturing urgency. Knowing the type matters because the channel and lure differ \u2014 and &#8220;suspicious email&#8221; alone misses the attacks that arrive by text, call, or QR code.<\/aside>\n\n<h2 id=\"the-types\">The Main Types of Phishing Attacks<\/h2>\n\n<h3>1. Email phishing (deceptive phishing)<\/h3>\n<p>The classic: a mass email impersonating a well-known brand \u2014 a bank, PayPal, a delivery company \u2014 sent to millions in the hope that a fraction click. It claims there&#8217;s a problem (&#8220;unusual activity,&#8221; &#8220;package held,&#8221; &#8220;payment failed&#8221;) and links to a fake login page that harvests your credentials. It&#8217;s low-effort and high-volume, so the tells are usually obvious once you look: generic greetings, slightly-off sender domains, and links that don&#8217;t go where they claim.<\/p>\n\n<h3>2. Spear phishing<\/h3>\n<p>Targeted phishing aimed at a specific person or organisation, using real details to be convincing \u2014 your name, employer, role, a recent purchase, a colleague&#8217;s name. Attackers gather this from data breaches, social media, and <a href=\"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/\" rel=\"noopener\" target=\"_blank\">data brokers<\/a> (the exact reason Part 1 of this series matters). Because it&#8217;s personalised, spear phishing defeats the &#8220;it&#8217;s obviously generic&#8221; instinct \u2014 the message knows things about you, so it feels legitimate.<\/p>\n\n<h3>3. Whaling<\/h3>\n<p>Spear phishing aimed at &#8220;big fish&#8221; \u2014 executives, finance chiefs, founders. The lure is tailored to someone with authority and access: a fake legal notice, an urgent board matter, a wire-transfer request. Whaling messages are often well-written and business-like, with no typos or clumsy formatting, because the payoff justifies the effort. A single successful whaling or wire-transfer fraud can net six or seven figures, which is why attackers happily spend weeks researching one target&#8217;s calendar, contacts, and writing style before sending a word.<\/p>\n\n<h3>4. Business email compromise (BEC) \/ CEO fraud<\/h3>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Business_email_compromise\" rel=\"noopener\" target=\"_blank\">Business email compromise<\/a> is one of the costliest attacks in existence. The attacker impersonates (or actually takes over) an executive&#8217;s or vendor&#8217;s email account and instructs an employee to make an urgent payment or change bank details. There&#8217;s often no malicious link at all \u2014 just a plausible, authority-driven request \u2014 which is why it slips past filters that look for bad URLs. The defence is procedural: verify any payment or bank-detail change through a second, known channel.<\/p>\n\n<h3>5. Clone phishing<\/h3>\n<p>The attacker takes a real, legitimate email you&#8217;ve received \u2014 a genuine invoice, a shipping notice \u2014 clones it exactly, and re-sends it with the links or attachments swapped for malicious ones, often claiming it&#8217;s a &#8220;resend&#8221; or &#8220;updated version.&#8221; Because the template is authentic, clone phishing is unusually convincing; the tell is the unexpected re-send and a sender address that&#8217;s subtly wrong. If you get a &ldquo;here&#8217;s the corrected version&rdquo; of a message you weren&#8217;t expecting to be corrected, slow down and check the sender before opening anything.<\/p>\n\n<h3>6. Smishing (SMS phishing)<\/h3>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/SMS_phishing\" rel=\"noopener\" target=\"_blank\">Smishing<\/a> is phishing by text message \u2014 &#8220;your parcel couldn&#8217;t be delivered, confirm here,&#8221; &#8220;your bank card is locked.&#8221; Texts feel more urgent and personal than email and bypass email security entirely, which is why smishing has exploded. Legitimate companies rarely ask you to log in or pay via a texted link; treat any that does as suspect and go to the app or website directly.<\/p>\n\n<h3>7. Vishing (voice phishing)<\/h3>\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Voice_phishing\" rel=\"noopener\" target=\"_blank\">Vishing<\/a> is phishing by phone call \u2014 a &#8220;bank fraud department,&#8221; &#8220;tech support,&#8221; or &#8220;tax office&#8221; caller pressuring you to confirm details, move money, or grant remote access. AI voice cloning has made this dramatically more convincing, even mimicking a family member&#8217;s or executive&#8217;s voice. The rule: hang up and call back on a number you look up yourself, never one the caller gives you. Real institutions are happy for you to call back on the number printed on your card or their official site; a scammer will pressure you to stay on the line precisely because hanging up breaks the spell.<\/p>\n\n<h3>8. Quishing (QR-code phishing)<\/h3>\n<p>A newer type: the malicious link is hidden in a QR code \u2014 on a poster, a parking meter, a fake &#8220;verify your account&#8221; email, or a sticker placed over a real one. Because your eye can&#8217;t read a QR code, you can&#8217;t spot a bad URL before scanning, and phones open the link immediately. Be wary of QR codes that lead to a login or payment page, especially unsolicited ones.<\/p>\n\n<h3>9. Angler phishing (social media)<\/h3>\n<p>Attackers pose as a brand&#8217;s customer-support account on social media, watching for people complaining to a company and swooping in with a &#8220;support&#8221; reply that links to a fake help page or asks for account details. If you tweet at your bank about a problem, be sceptical of the &#8220;official support&#8221; account that DMs you \u2014 check the handle carefully \u2014 a real support account is usually verified and long-established, while the impostor is freshly created with a near-identical name and a hair-trigger willingness to take your conversation into private messages.<\/p>\n\n<h3>10. Pharming<\/h3>\n<p>Rather than luring you to a fake site, pharming poisons the path so that even typing the correct address lands you on the attacker&#8217;s copy \u2014 via malware on your device or a compromised DNS server. It&#8217;s rarer and more technical, but it&#8217;s why HTTPS and watching for certificate warnings matter: the address bar can look right while the destination is fake. Because there&#8217;s no obvious lure to second-guess, the defence is technical hygiene \u2014 keep your device malware-free, use a trusted DNS resolver, and never dismiss a browser certificate warning as a nuisance.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The families to know: mass email phishing, targeted spear phishing and whaling, payment-focused BEC, template-stealing clone phishing, and the non-email channels \u2014 smishing (text), vishing (call), quishing (QR), and angler phishing (social). Pharming poisons the path itself.<\/aside>\n\n<figure class=\"wp-block-image size-large\">\n  <img data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks-example.jpg?resize=1080%2C608&#038;ssl=1\"\n       alt=\"types of phishing attacks: one hooked envelope hidden among genuine letters, showing how a phish blends in\"\n       width=\"1080\" height=\"608\" loading=\"lazy\" decoding=\"async\" \/>\n  <figcaption>Every type of phishing attack is the same move in a different disguise \u2014 a baited hook mixed in with mail you trust.<\/figcaption>\n<\/figure>\n\n<h2 id=\"compared\">The Types of Phishing Attacks at a Glance<\/h2>\n<p>Here&#8217;s the field guide condensed \u2014 the channel each uses, who it targets, and the single biggest tell.<\/p>\n\n<figure class=\"wp-block-table\"><table><caption>Types of phishing attacks: channel, target, and the tell for each<\/caption>\n  <thead>\n    <tr><th>Type<\/th><th>Channel<\/th><th>Target<\/th><th>The tell<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Email phishing<\/td><td>Email (mass)<\/td><td>Anyone<\/td><td>Generic greeting, off-domain sender<\/td><\/tr>\n    <tr><td>Spear phishing<\/td><td>Email (targeted)<\/td><td>A specific person<\/td><td>Knows real details, still asks you to act now<\/td><\/tr>\n    <tr><td>Whaling<\/td><td>Email (targeted)<\/td><td>Executives<\/td><td>Authority + urgency (legal, wire transfer)<\/td><\/tr>\n    <tr><td>BEC \/ CEO fraud<\/td><td>Email (often no link)<\/td><td>Finance\/staff<\/td><td>Urgent payment or bank-detail change<\/td><\/tr>\n    <tr><td>Clone phishing<\/td><td>Email<\/td><td>Anyone<\/td><td>Unexpected &#8220;resend&#8221; of a real message<\/td><\/tr>\n    <tr><td>Smishing<\/td><td>Text message<\/td><td>Anyone<\/td><td>Texted link to log in or pay<\/td><\/tr>\n    <tr><td>Vishing<\/td><td>Phone call<\/td><td>Anyone<\/td><td>Pressure to act; number they gave you<\/td><\/tr>\n    <tr><td>Quishing<\/td><td>QR code<\/td><td>Anyone<\/td><td>Unsolicited QR to a login\/payment page<\/td><\/tr>\n    <tr><td>Angler phishing<\/td><td>Social media<\/td><td>Complainers<\/td><td>&#8220;Support&#8221; account that DMs you first<\/td><\/tr>\n    <tr><td>Pharming<\/td><td>DNS\/malware<\/td><td>Anyone<\/td><td>Right address, wrong site; cert warnings<\/td><\/tr>\n  <\/tbody>\n<\/table><\/figure>\n\n<h2 id=\"why-worse\">Why These Attacks Keep Getting More Effective<\/h2>\n<p>Phishing isn&#8217;t just persisting \u2014 it&#8217;s getting harder to spot, for three reinforcing reasons worth understanding, because they explain why old advice (&#8220;look for bad spelling&#8221;) no longer protects you.<\/p>\n<p>First, <strong>breach data fuels personalisation.<\/strong> Every corporate breach dumps millions of names, emails, and purchase histories into criminal markets. Attackers stitch these together \u2014 often via the same <a href=\"https:\/\/haveibeenpwned.com\/\" rel=\"noopener\" target=\"_blank\">breach data indexed by services like Have I Been Pwned<\/a> \u2014 into dossiers that turn a generic blast into a convincing spear-phishing message that knows your name, your bank, and what you bought last week. The more breaches pile up, the sharper the lures get. This is why Parts 1 and 2 of this series \u2014 shrinking your exposure and responding to breaches \u2014 are the foundation the anti-phishing advice here sits on.<\/p>\n<p>Second, <strong>AI has removed the old tells.<\/strong> The clumsy grammar and awkward phrasing that used to give phishing away are gone: large language models write flawless, on-brand messages in any language, and voice cloning reproduces a boss&#8217;s or family member&#8217;s voice from seconds of audio. A &#8220;your CEO is calling about an urgent transfer&#8221; vishing attack that would once have been caught by a wrong accent now sounds exactly right.<\/p>\n<p>Third, <strong>the channels keep multiplying.<\/strong> As email filters improve, attackers move to the gaps \u2014 text, phone, QR codes, social DMs \u2014 where there&#8217;s little filtering and more implicit trust. Each new channel resets the arms race in the attacker&#8217;s favour. The takeaway isn&#8217;t despair; it&#8217;s that you can&#8217;t rely on spotting bad craftsmanship anymore. You have to rely on the process \u2014 verify through a channel you chose \u2014 because that defeats even a flawless, personalised, perfectly-voiced attack.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Breach data makes lures personal, AI removes the grammar-and-accent tells, and new channels dodge email filters. &#8220;Spot the typo&#8221; no longer works \u2014 only a verify-through-your-own-channel habit defeats a polished, personalised attack.<\/aside>\n\n<h2 id=\"spot\">How to Spot Any of These Types of Phishing Attacks<\/h2>\n<p>You don&#8217;t need to memorise ten categories in the moment \u2014 nearly every phishing attempt, whatever the type, trips at least one of these wires:<\/p>\n<ul>\n  <li><strong>Unexpected urgency or threat.<\/strong> &#8220;Act now or lose access,&#8221; &#8220;your account will be closed,&#8221; &#8220;the payment is overdue.&#8221; Urgency is engineered to stop you thinking. Legitimate organisations give you time.<\/li>\n  <li><strong>A request to click, log in, pay, or share a code.<\/strong> The whole point of phishing is to get you to <em>do<\/em> something. Any unsolicited message steering you to a login page, a payment, or a one-time code deserves suspicion.<\/li>\n  <li><strong>A sender or number you can&#8217;t verify.<\/strong> Display names are trivial to fake \u2014 our explainer on <a href=\"https:\/\/emailalias.io\/blog\/what-is-email-spoofing\/\" rel=\"noopener\" target=\"_blank\">email spoofing<\/a> shows how the &#8220;from&#8221; line lies. Check the actual address, and never trust a phone number or link the message itself provides.<\/li>\n  <li><strong>A link or destination that doesn&#8217;t match.<\/strong> Hover a link before clicking (on desktop) to see the real URL; a &#8220;PayPal&#8221; email pointing to a random domain is a phish. On mobile, go to the app or type the address yourself.<\/li>\n  <li><strong>Something slightly off.<\/strong> A greeting that isn&#8217;t your name, a domain with an extra word or swapped letter, a tone that&#8217;s not quite how that person writes. Trust the itch.<\/li>\n<\/ul>\n<p>The universal move that defeats almost all of it: <strong>stop and verify through a channel you chose.<\/strong> Don&#8217;t reply, don&#8217;t click, don&#8217;t call the number in the message \u2014 independently look up the organisation or person and reach them yourself. Ninety seconds of verification beats every disguise.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Whatever the type, phishing trips the same wires \u2014 manufactured urgency, a request to act, an unverifiable sender, a mismatched link. The universal defence is to stop and verify through a channel you chose yourself, not one the message handed you.<\/aside>\n\n<h2 id=\"scenarios\">Phishing in the Real World<\/h2>\n<p>Categories are easier to remember when you can picture them. Here&#8217;s how the common types actually land:<\/p>\n<ul>\n  <li><strong>The delivery text (smishing).<\/strong> &#8220;Your parcel is held \u2014 a \u00a31.45 customs fee is due, pay here.&#8221; You are expecting a parcel, so the timing feels right; the link leads to a convincing courier page that harvests your card. The tell: real couriers don&#8217;t collect fees by SMS link.<\/li>\n  <li><strong>The invoice swap (BEC + clone).<\/strong> A supplier you actually use emails an updated invoice with &#8220;new bank details for payment.&#8221; The email address is a look-alike, or the supplier&#8217;s account was compromised. Paying it wires money straight to the attacker. The tell: any bank-detail change must be confirmed by phone on a known number.<\/li>\n  <li><strong>The account alert (email phishing).<\/strong> &#8220;Unusual sign-in to your account \u2014 secure it now.&#8221; The panic of a possible hack pushes you to click and &#8220;log in,&#8221; handing your password to a fake page. The tell: go to the service directly, never via the email&#8217;s button.<\/li>\n  <li><strong>The boss&#8217;s urgent ask (whaling\/BEC).<\/strong> &#8220;I&#8217;m in a meeting, can you buy \u00a3500 of gift cards for a client and send me the codes? Will reimburse.&#8221; It exploits the desire to be responsive to authority. The tell: gift-card requests are almost always fraud; verify in person or by call.<\/li>\n  <li><strong>The QR at the restaurant\/parking meter (quishing).<\/strong> A sticker over the real code sends you to a fake payment page. The tell: be wary when a QR leads to a login or payment, and check for tampering.<\/li>\n<\/ul>\n<p>Notice the pattern across all five: a plausible context, a manufactured reason to hurry, and a request to pay, log in, or share something. Recognise that pattern and the specific channel becomes irrelevant.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> The delivery-fee text, the swapped-invoice payment, the &#8220;secure your account&#8221; login, the boss&#8217;s gift-card ask, and the tampered QR are the phishing you&#8217;ll actually meet \u2014 same pattern (plausible context + hurry + a request) in five disguises.<\/aside>\n\n<h2 id=\"protect\">How to Protect Yourself From Phishing<\/h2>\n<p>Spotting attacks is half of it; the other half is arranging things so that even a successful phish does limited damage:<\/p>\n<ul>\n  <li><strong>Turn on two-factor authentication (2FA)<\/strong> everywhere, ideally with an authenticator app or hardware key. If a phish captures your password, 2FA is the wall that still stands \u2014 and phishing-resistant methods like passkeys defeat even real-time credential theft.<\/li>\n  <li><strong>Use a password manager.<\/strong> Beyond unique passwords, a manager <em>won&#8217;t autofill<\/em> your credentials on a look-alike domain \u2014 so it quietly catches phishing sites your eye might miss.<\/li>\n  <li><strong>Never act on an inbound request without verifying.<\/strong> Especially payments, bank-detail changes, gift cards, or one-time codes \u2014 call the person or company back on a number you already trust.<\/li>\n  <li><strong>Keep devices and browsers updated,<\/strong> and heed certificate\/security warnings \u2014 your first line against pharming and malware payloads.<\/li>\n  <li><strong>Report and delete.<\/strong> Report phishing to your provider and, in the US, follow the <a href=\"https:\/\/consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams\" rel=\"noopener\" target=\"_blank\">FTC&#8217;s phishing guidance<\/a>; then delete the message. Reporting improves the filters that protect everyone.<\/li>\n<\/ul>\n<p>On the technical side, email authentication \u2014 SPF, DKIM, and especially <a href=\"https:\/\/emailalias.io\/blog\/what-is-dmarc\/\" rel=\"noopener\" target=\"_blank\">DMARC<\/a> \u2014 helps stop attackers spoofing a domain outright. It&#8217;s not a complete cure (it can&#8217;t stop a look-alike domain), but it raises the bar, and it&#8217;s the groundwork for BIMI, which we cover in Part 4.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Arrange your defences so a successful phish does little: 2FA (ideally passkeys), a password manager that won&#8217;t autofill on fake domains, a verify-before-you-act rule for money and codes, and updated devices. Report phishing to improve everyone&#8217;s filters.<\/aside>\n\n<h2 id=\"aliases\">Where Email Aliases Fit<\/h2>\n<p>Per-site email aliases don&#8217;t stop a phisher from sending you a message \u2014 but they change the economics of phishing in three quiet, useful ways, which is why they belong in any anti-phishing setup.<\/p>\n<ul>\n  <li><strong>They shrink what attackers can learn about you.<\/strong> Spear phishing runs on personal data harvested from breaches and brokers. When every service knows you by a different <a href=\"https:\/\/emailalias.io\/blog\/what-is-an-email-alias\/\" rel=\"noopener\" target=\"_blank\">alias<\/a>, a breach at one leaks a dead-end address that can&#8217;t be cross-referenced into a rich profile \u2014 so the personalised lures that make spear phishing work are harder to build.<\/li>\n  <li><strong>They make a phish easier to spot.<\/strong> If you gave your bank a single-purpose alias and a &#8220;bank security alert&#8221; arrives at a <em>different<\/em> address, you know instantly it&#8217;s fake \u2014 the mismatch is the tell. Purpose-scoped addresses turn &#8220;is this real?&#8221; into a quick check.<\/li>\n  <li><strong>They let you cut off a compromised channel.<\/strong> When an alias starts attracting phishing after a service is breached \u2014 the exact breach-to-phishing pipeline from <a href=\"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/\" rel=\"noopener\" target=\"_blank\">Part 2<\/a> \u2014 you disable that one alias and the attack surface closes, without touching your real inbox.<\/li>\n<\/ul>\n<p>To be clear, aliases are a containment and detection layer, not a phishing cure \u2014 you still need the human vigilance and 2FA above. But by starving attackers of the data that powers targeted phishing and giving you a fast &#8220;this doesn&#8217;t add up&#8221; signal, they meaningfully reduce your risk. Our take on <a href=\"https:\/\/emailalias.io\/blog\/should-you-use-your-real-email\/\" rel=\"noopener\" target=\"_blank\">whether to use your real email online<\/a> goes deeper on that trade.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Aliases don&#8217;t block phishing, but they starve spear-phishing of the personal data it needs, turn a wrong-address message into an obvious fake, and let you cut off a compromised channel \u2014 a real containment layer on top of vigilance and 2FA.<\/aside>\n\n<h2 id=\"final-thoughts\">Final Thoughts<\/h2>\n<p>The types of phishing attacks keep multiplying \u2014 quishing barely existed a few years ago, and AI voice cloning has supercharged vishing \u2014 but the underlying trick never changes: impersonate trust, manufacture urgency, get you to act before you verify. Learn the shape of that move and you&#8217;re protected against types that haven&#8217;t been invented yet. Slow down on anything urgent, verify through a channel you chose, lean on 2FA and a password manager, and shrink your exposure so attackers have less to work with. Do that and phishing goes from your biggest risk to a manageable annoyance. Next in Email Security 101: what BIMI is, how it builds on DMARC to put a verified logo on legitimate mail, and whether you actually need it.<\/p>\n\n<h2 id=\"faq\">Frequently Asked Questions<\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-q-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What are the most common types of phishing attacks?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>The most common is email phishing \u2014 mass, generic emails impersonating a bank, courier, or payment service. Beyond that, the main types are spear phishing (targeted, using your real details), whaling (aimed at executives), business email compromise or CEO fraud (urgent payment\/bank-change requests), clone phishing (a real email re-sent with malicious links), and the non-email channels: smishing (text), vishing (phone call), quishing (QR code), and angler phishing (fake support on social media). Pharming, which redirects you to a fake site even when you type the correct address, is rarer and more technical.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is the difference between phishing and spear phishing?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Phishing (specifically mass or deceptive phishing) is a wide net \u2014 the same generic message sent to millions, hoping a small fraction click. Spear phishing is a targeted spear thrown at one person or organisation, using real details about you (name, employer, role, recent activity) gathered from breaches, social media, and data brokers. Spear phishing is far more convincing precisely because it&#8217;s personalised, so it defeats the instinct that a message is &#8216;obviously generic spam.&#8217;<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What are smishing and vishing?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>They&#8217;re phishing through non-email channels. Smishing is phishing by SMS text message \u2014 for example, a fake &#8216;your parcel is held, confirm here&#8217; text with a malicious link. Vishing is phishing by phone call \u2014 a caller pretending to be your bank&#8217;s fraud team, tech support, or the tax office, pressuring you to confirm details, move money, or grant remote access. Both bypass your email filters, and AI voice cloning has made vishing especially convincing. The defence is the same: don&#8217;t act on the message; independently look up the organisation and contact it yourself.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is quishing (QR code phishing)?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Quishing hides the malicious link inside a QR code instead of visible text \u2014 on a poster, a parking meter, an email, or a sticker placed over a legitimate code. Because you can&#8217;t read a QR code with your eyes, you can&#8217;t spot a bad URL before scanning, and phones open the link immediately. Be cautious with any unsolicited QR code that leads to a login or payment page, and prefer typing the address or using the official app.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How can I tell if an email is a phishing attempt?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Look for the shared tells: unexpected urgency or a threat (&#8216;act now or lose access&#8217;), a request to click a link, log in, pay, or share a one-time code, a sender address you can&#8217;t verify (display names are easily faked), and a link whose real destination doesn&#8217;t match the supposed organisation. Anything slightly off \u2014 a generic greeting, a domain with an extra word or swapped letter \u2014 is a red flag. When in doubt, don&#8217;t click; go to the company&#8217;s website or app directly.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What should I do if I clicked a phishing link?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Act quickly. If you entered a password, change it immediately on that account and anywhere you reused it, and turn on two-factor authentication. If you entered card or bank details, contact your bank and watch for fraudulent charges. If it was a work account, tell your IT\/security team right away. Run a malware scan if you downloaded anything. Then report the phishing to your email provider and, in the US, at the FTC \u2014 reporting helps protect others.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Does two-factor authentication stop phishing?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>It stops most of the damage. If a phish captures your password, 2FA means the attacker still can&#8217;t log in without your second factor \u2014 a wall that still stands. Standard 2FA (codes via app or SMS) can occasionally be defeated by real-time phishing that relays your code, but phishing-resistant methods like passkeys and hardware security keys defeat even that. 2FA doesn&#8217;t stop you receiving a phish, but it dramatically limits what a successful one achieves, which is why it&#8217;s the single highest-value protection to enable.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Do email aliases protect against phishing?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Aliases don&#8217;t block phishing messages, but they reduce your risk in three ways. They starve spear phishing of the personal data it relies on \u2014 a breach of an alias leaks a dead-end address that can&#8217;t be built into a rich profile. They make a phish easier to spot: a &#8216;bank alert&#8217; arriving at an address you never gave your bank is obviously fake. And they let you disable a compromised alias to cut off attacks after a service is breached. Treat aliases as a containment and detection layer on top of vigilance and 2FA, not a replacement for them.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Email Security 101 \u2014 a 4-part series. \u2190 Part 1: Remove Yourself From Data Brokers \u00b7 Part 2: What to Do After an Email Data Breach. You&#8217;re on Part 3&#8230;.<\/p>\n","protected":false},"author":3,"featured_media":384,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"rank_math_focus_keyword":"types of phishing attacks","rank_math_title":"Types of Phishing Attacks: 10 to Know and How to Spot Them","rank_math_description":"A field guide to the main types of phishing attacks \u2014 email, spear, whaling, BEC, smishing, vishing, quishing \u2014 with the tell for each and how to stay safe.","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[5],"tags":[],"class_list":{"0":"post-386","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security"},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":369,"url":"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/","url_meta":{"origin":386,"position":0},"title":"Email Security 101 (Part 2): What to Do After an Email Data Breach","author":"Troy Hunt","date":"September 15, 2026","format":false,"excerpt":"Email Security 101 \u2014 a 4-part series. \u2190 Part 1: How to Remove Yourself From Data Brokers. You're on Part 2. Part 3: Types of Phishing Attacks is now live. The short version Move fast, in order: confirm the breach, change the password on the breached account, then change that\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"what to do after an email data breach, shown as a forced-open mailbox with mail spilling out and a broken padlock","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":185,"url":"https:\/\/emailalias.io\/blog\/how-to-protect-crypto-wallet\/","url_meta":{"origin":386,"position":1},"title":"How to Protect Your Crypto Wallet from Phishing and Theft","author":"Troy Hunt","date":"June 18, 2026","format":false,"excerpt":"If you hold any meaningful amount of cryptocurrency, knowing how to protect your crypto wallet is no longer optional \u2014 it's the single highest-leverage skill in the space. The FBI's 2024 Internet Crime Report logged $9.3 billion in crypto-related fraud losses, a 66% jump over 2023, and that's just what\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-how-to-protect-crypto-wallet.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-how-to-protect-crypto-wallet.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-how-to-protect-crypto-wallet.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-how-to-protect-crypto-wallet.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-how-to-protect-crypto-wallet.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":190,"url":"https:\/\/emailalias.io\/blog\/travel-safety-guide-2026\/","url_meta":{"origin":386,"position":2},"title":"Travel Safety Guide 2026: Digital and Physical Risks","author":"Troy Hunt","date":"June 19, 2026","format":false,"excerpt":"A complete travel safety guide for 2026 has to cover both halves of the modern threat surface: the physical risks tourists have always faced (pickpocketing, hotel theft, transportation scams) and the digital ones that have exploded in the past two years (Booking.com phishing, airline data breaches, public Wi-Fi attacks). Both\u2026","rel":"","context":"In &quot;Privacy&quot;","block_context":{"text":"Privacy","link":"https:\/\/emailalias.io\/blog\/category\/privacy\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-travel-safety-guide-2026.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-travel-safety-guide-2026.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-travel-safety-guide-2026.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-travel-safety-guide-2026.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-travel-safety-guide-2026.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":305,"url":"https:\/\/emailalias.io\/blog\/email-alias-for-gaming\/","url_meta":{"origin":386,"position":3},"title":"Email Alias for Gaming Accounts","author":"Troy Hunt","date":"August 20, 2026","format":false,"excerpt":"Your gaming accounts are worth more than you think. Between purchased games, in-game currency, rare skins, years of progress, and a rank you actually earned, a single account can represent hundreds of dollars and hundreds of hours \u2014 and the only thing standing between it and a stranger is often\u2026","rel":"","context":"In &quot;Use Cases&quot;","block_context":{"text":"Use Cases","link":"https:\/\/emailalias.io\/blog\/category\/use-cases\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-email-alias-for-gaming.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-email-alias-for-gaming.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-email-alias-for-gaming.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-email-alias-for-gaming.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-email-alias-for-gaming.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":141,"url":"https:\/\/emailalias.io\/blog\/email-alias-for-traveller\/","url_meta":{"origin":386,"position":4},"title":"Email Alias for Traveller: Bookings, Wi-Fi, Loyalty","author":"Troy Hunt","date":"June 8, 2026","format":false,"excerpt":"An email alias for traveller use is a permanent forwarding address you hand to booking sites, airline loyalty programs, hotel chains, and public Wi-Fi captive portals \u2014 one that delivers inbound mail to your real inbox without ever exposing the inbox itself. A single international trip can hand your address\u2026","rel":"","context":"In &quot;Use Cases&quot;","block_context":{"text":"Use Cases","link":"https:\/\/emailalias.io\/blog\/category\/use-cases\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-alias-for-traveller.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-alias-for-traveller.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-alias-for-traveller.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-alias-for-traveller.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-email-alias-for-traveller.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":291,"url":"https:\/\/emailalias.io\/blog\/what-is-email-spoofing\/","url_meta":{"origin":386,"position":5},"title":"What Is Email Spoofing?","author":"Troy Hunt","date":"August 17, 2026","format":false,"excerpt":"You get an email that looks like it came from your bank, your boss, or a service you use every day. The sender name is right, the address looks right, and it wants you to click a link or approve a payment. But the message never came from where it\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-what-is-email-spoofing.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-what-is-email-spoofing.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-what-is-email-spoofing.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-what-is-email-spoofing.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/08\/og-what-is-email-spoofing.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/comments?post=386"}],"version-history":[{"count":1,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/386\/revisions"}],"predecessor-version":[{"id":387,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/386\/revisions\/387"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media\/384"}],"wp:attachment":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media?parent=386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/categories?post=386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/tags?post=386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}