Home Technology Phishing: 9 Types and How to Spot Them Before You Click

Phishing: 9 Types and How to Spot Them Before You Click

12
0
An open envelope with a small metal fishing hook snagged on its edge, illustrating phishing

Phishing is a fraudulent attempt to obtain credentials, financial details or system access by impersonating a trusted entity. It is the dominant initial attack vector in cyber incidents, and it works not by breaking encryption or exploiting software, but by exploiting a person under time pressure.

That is why it has not been solved. Technical controls have improved enormously for twenty years, and phishing has simply moved to the weakest component in every system — the human who approves the request.

Anatomy of a phishing message

Almost every successful phish follows the same sequence:

  1. Impersonation — a brand, colleague, supplier or authority figure you have reason to trust
  2. Pretext — a plausible reason for contact: an invoice, a delivery, a password expiry, a document to review
  3. Urgency or consequence — act now, account closes, late fee, disciplinary action
  4. A call to action — link, attachment, phone number, or QR code
  5. Exfiltration — you land on a credential-harvesting page, or the attachment runs, or you reply with the information requested

The urgency is load-bearing. Without a deadline, people verify. With one, they comply.

9 types of phishing

1. Email phishing

Bulk messages sent to millions, impersonating banks, delivery companies, tax authorities and software vendors. Low sophistication, high volume — it works on statistics alone.

2. Spear phishing

Targeted at a specific individual using researched details: your job title, a recent project, a real colleague’s name. The personalisation is what defeats the “this looks generic” filter.

3. Whaling

Spear phishing aimed at executives, because they authorise large payments and rarely question requests. Often requests a wire transfer with minimal correspondence.

4. Smishing (SMS phishing)

Text messages exploiting delivery notifications, bank alerts or toll charges. Short messages discourage careful reading, and the small screen makes checking the sender and hovering links harder.

5. Vishing (voice phishing)

Phone calls from spoofed numbers. The caller may already know partial card details to establish credibility, then asks you to “confirm” the rest — or to read a one-time code, which is the actual objective.

6. Quishing (QR code phishing)

A QR code in an email, printed flyer or parking meter that resolves to a malicious destination. The user sees an image rather than a URL, so the link check they would normally perform never happens. Increasingly common because it also moves the click from a monitored corporate device to an unmonitored personal phone.

7. Clone phishing

A genuine message you previously received is re-sent with the legitimate link replaced by a malicious one and the sender address altered. Because the wording is authentic, it is unusually convincing.

8. Business email compromise

Not always malware at all — often a plain email requesting a change of bank details for a supplier, or an executive instructing a payment. The FBI’s Internet Crime Complaint Center consistently reports this category among the highest in annual losses, at billions of dollars. No attachment needed, nothing for antivirus to detect.

9. Malvertising and typosquatting

Paid adverts that imitate official login pages above the real result, and domains that differ from the genuine one by a character or a lookalike glyph. Search-engine ads have become one of the more reliable routes to credential theft because people trust the top result.

The red flags worth memorising

  • Urgency or threat with a deadline — the single most consistent marker
  • An unexpected action — a password reset you did not request, an invoice you do not recognise
  • The sender address does not match the display name — check the actual address, not “PayPal”
  • Links that do not go where the text claims — hover, or long-press on mobile
  • A domain that is subtly wrong — extra characters, wrong top-level domain, an unexpected subdomain
  • Requests for credentials, codes, or gift cards — no legitimate organisation needs your one-time code
  • Pressure to bypass process — “don’t tell anyone”, “use my personal address”, “just this once”
  • Unsolicited attachments — particularly archives and documents asking you to enable content

One correction to common advice: poor grammar is no longer a reliable signal. Language models produce flawless copy, and translated phishing is now indistinguishable from professional writing. Treat typos as a hint, never as a clearance.

And: a padlock in the address bar is not trust. It means the connection is encrypted to the domain shown — and free, automated certificates are available to phishing sites. It tells you nothing about who is on the other end. Our website safety checks guide covers the checks that do carry signal.

How to verify properly

  1. Never use the contact details in the message. If your bank emailed you, open the app or call the number printed on your card — not the number in the email
  2. Navigate directly. Type the address or use a bookmark rather than clicking through
  3. Confirm out of band. For payment or detail changes, verify by a channel you initiated — a known phone number, not a reply
  4. Check the full URL before entering anything, including the protocol and exact domain
  5. Treat one-time codes as passwords. Anyone asking for one is committing fraud, whoever they claim to be

MFA is not a complete answer

Multi-factor authentication blocks the majority of account takeover, and you should have it enabled. But it has known weaknesses:

  • MFA fatigue — flooding a target with push notifications until they approve one to make it stop. Mitigated by number matching, which requires entering a displayed digit
  • Real-time relay — proxy sites that forward your credentials and code to the genuine service as you type, capturing a valid session
  • Social engineering the fallback — convincing support to reset MFA entirely

Passkeys and FIDO2 hardware tokens are the current answer to relay attacks, because they are bound to the domain — a spoofed site simply cannot complete the authentication. If a service offers passkeys, they are worth adopting.

You clicked. Now what?

The first ten minutes matter more than anything else. Do not panic, and do not close the tab and hope.

  1. If you entered a password, change it — from a different, known-clean device, not the one you just used
  2. If you entered a one-time code, assume the account is compromised and change the password immediately; the attacker has the session
  3. Check for new recovery methods — added email addresses, phone numbers, forwarding rules, delegated access
  4. Check mail rules — attackers commonly create rules that move or hide reply messages so you never see the conversation they are conducting in your name
  5. Review active sessions and revoke anything unfamiliar
  6. Contact your bank if financial details were entered — fraud departments can reverse card transactions far more easily than bank transfers
  7. Report it — to your IT team at work (report, do not just delete; they may need to hunt for other recipients), and to the impersonated organisation
  8. Scan the device if you opened an attachment

If it was business email compromise or an executed transfer, tell someone senior immediately. Recovery rates drop sharply with each hour of delay, and some payment systems can still reverse a transaction if caught fast enough.

For organisations

  • Simulated phishing with training attached to failure — effective, though it should build competence rather than punish
  • Out-of-band verification for payments, enforced by policy rather than discretion
  • DMARC, DKIM and SPF on your own domain so nobody can send mail as you
  • Conditional access — device trust, impossible-travel detection, phishing-resistant MFA
  • Least privilege so a single compromised account cannot reach everything

Frequently asked questions

Can antivirus or spam filters stop phishing?

They stop a lot of it. Modern filters quarantine the vast majority of bulk campaigns before delivery. What gets through is targeted, freshly sent or convincingly legitimate — which is precisely the part that reaches a person rather than a filter. Assume some will arrive.

I only click links on my phone. Am I safer?

No — you are arguably less safe. The display is smaller, the URL is truncated, hover does not exist, and personal devices often lack corporate protections. Smishing and quishing target phones exactly because of this.

Why do they want gift cards or cryptocurrency?

Because both are effectively irreversible. A card payment can be charged back; a gift card code, once redeemed, and a crypto transfer, once confirmed, are gone. Reversibility is the property attackers design around.

Is a VPN useful against phishing?

Only incidentally. A VPN encrypts your connection and hides traffic from the local network — useful on public Wi-Fi — but it does nothing about entering your credentials on a convincing fake site. The connection is secure; the destination is wrong. These solve different problems.

Are older people simply more vulnerable?

Age is a weak predictor on its own. What predicts susceptibility is unfamiliarity with the specific platform being imitated, and cognitive load — people rushing, distracted, or multitasking. A targeted business email compromise aimed at a finance officer is usually more sophisticated than consumer scams, and succeeds at comparable rates.

This article explains general technology concepts and is not a substitute for advice from your IT or security team.

LEAVE A REPLY

Please enter your comment!
Please enter your name here