Threats, Incidents and Claims
Types of Phishing Attacks: Examples and How to Spot Them
Understanding the types of phishing attacks is the single most useful thing a small business can do to cut its cyber risk, because phishing is still the way most breaches start. The National Cyber Security Centre continues to name it as a leading cause of ransomware, account takeover and data theft across the UK, and the tactics have spread well beyond the dodgy email into text messages, phone calls and even QR codes.
This guide breaks down each type, shows what a real attempt looks like, and lists the red flags your staff can learn to spot. It also explains why phishing sits at the heart of nearly every cyber insurance proposal form.
What phishing actually is
Phishing is an attempt to trick someone into handing over information, money or access by pretending to be a person or organisation they trust. The classic version is a fake email from a bank or supplier, but the underlying con is the same across every channel: create urgency, impersonate authority, and push the target to act before they think.
What makes phishing so effective is that it targets people, not software. A firewall cannot stop an employee who chooses to type their password into a convincing fake login page. That is why insurers and Cyber Essentials both focus so heavily on staff training and multi-factor authentication.
Email phishing (the broad-net attack)
This is the original and still the most common form. Attackers send the same message to thousands of addresses, impersonating a familiar brand such as a bank, a delivery firm, Microsoft or HMRC. The goal is a small percentage of clicks on a link that leads to a fake login page or a malware download.
Red flags to teach:
- A generic greeting such as “Dear Customer” rather than your name.
- A sense of urgency: an account will be closed, a payment has failed, a parcel is held.
- A sender address that does not quite match the real domain (microsofft-support.com).
- Links that, on hover, point somewhere unrelated to the brand.
Spear phishing (the targeted attack)
Spear phishing narrows the net to one person or a small team, using details that make the message believable: your name, your job title, a colleague’s name, a real project. The research often comes from LinkedIn or a company website. Because it is personalised, it slips past the “this is obviously spam” instinct.
A typical example: a message that appears to come from a named supplier you actually use, referencing a real invoice number and asking you to confirm updated bank details.
Whaling (going after the big fish)
Whaling is spear phishing aimed at senior leaders: directors, finance heads, business owners. The reward is higher because these people can authorise payments and access sensitive data. A whaling email might imitate a solicitor mid-acquisition or a regulator, and it is written in a calm, corporate tone rather than with obvious panic.
Business email compromise and invoice fraud
Business email compromise (BEC) is the costliest phishing type of all, and it often carries no malware at all, which is why antivirus never catches it. The attacker either spoofs or actually takes over a legitimate email account, then inserts themselves into a real conversation about money. The classic UK version is the redirected invoice: a genuine-looking email asks your accounts team to pay a real supplier into a new account, which belongs to the criminal.
Because BEC relies on a plausible email rather than a malicious file, the defence is procedural: verify any change of bank details by phone using a number you already hold, never a number in the email.
Smishing (phishing by text message)
Smishing arrives by SMS or messaging app, and it is growing fast because people trust and act on texts more quickly than emails. Common UK lures impersonate Royal Mail, DPD, your bank, or a “missed delivery” needing a small fee. The link leads to a fake page that harvests card details or login credentials.
Because texts are short and mobile screens hide full web addresses, the usual email checks are harder, so the rule is simple: banks and couriers do not ask for passwords or payment via a text link.
Vishing (phishing by phone call)
Vishing is voice phishing. A caller pretends to be your bank’s fraud team, a software vendor, or even your own IT department, and talks the target into moving money or granting remote access. Attackers spoof legitimate phone numbers so the caller ID looks right, and the rise of AI voice cloning means a familiar voice is no longer proof of identity.
The defence is to hang up and call back on a number you have independently verified. No legitimate bank will object to that.
Quishing (phishing by QR code)
Quishing hides a malicious link inside a QR code, printed on a poster, stuck over a real code on a parking meter, or embedded in a PDF attachment. Because the payload is an image rather than a clickable link, it sails past many email filters, and the victim scans it on a phone that may have weaker protection than a work laptop. Treat an unexpected QR code with the same suspicion as an unexpected link.
Clone and angler phishing
Two more worth naming. Clone phishing copies a genuine email you have already received, swaps the link or attachment for a malicious one, and resends it as a “resend” or “updated version”. Angler phishing uses fake social media support accounts to intercept customers complaining to a brand, then “helps” them straight into a scam.
How to spot any phishing attempt
Across every type, the same instincts protect people:
- Pause on urgency. Pressure to act immediately is the attacker’s main tool.
- Check the sender, not the display name. Look at the real address or number.
- Never enter credentials from a link. Navigate to the site yourself instead.
- Verify money and access requests out of band. Phone a known number to confirm.
- Report it. Forward suspicious emails to the NCSC and warn colleagues.
For the wider picture of what UK firms face, see our guide to the cyber threats UK small businesses face and the deeper dive into phishing, BEC and invoice fraud. If a message did get through, our ransomware response plan and data breach reporting steps cover what to do next. Staff training that satisfies insurers is covered in our page on security awareness training requirements.
You can report scams and read the official advice through the NCSC guidance on phishing, and forward suspicious emails to report@phishing.gov.uk.
Frequently asked questions
What are the main types of phishing attacks? The main types are broad email phishing, spear phishing (targeted at an individual), whaling (aimed at senior leaders), business email compromise, smishing (by text), vishing (by phone call) and quishing (by QR code). Clone phishing and angler phishing on social media are further variants.
What is the difference between phishing and spear phishing? Ordinary phishing sends the same generic message to large numbers of people and relies on a few taking the bait. Spear phishing targets one person or a small team using specific personal or company details, which makes it far more convincing and harder to spot.
Which type of phishing is most dangerous for a business? Business email compromise usually causes the biggest financial losses, because it redirects genuine payments to a criminal’s account and carries no malware for antivirus to detect. The best defence is to verify any change of bank details by phone using a number you already hold.
How can staff spot a phishing attack? Look for urgency, generic greetings, sender addresses that do not match the real domain, and requests for passwords or payments. Never enter login details from a link, and verify money or access requests through a separately confirmed phone number.
Does cyber insurance cover phishing losses? Many cyber policies cover the fallout from phishing, such as a resulting data breach or ransomware, but pure financial loss from invoice fraud or BEC is often only covered by a specific social engineering endorsement. Check your policy wording, because this is one of the most common gaps.
Where should I report a phishing email in the UK? Forward suspicious emails to report@phishing.gov.uk, the NCSC’s Suspicious Email Reporting Service, and report suspicious texts by forwarding them to 7726. If money has been lost, also report it to Action Fraud.