Our last blog took a look at what is phishing and some ways to prevent phishing attacks. But in order to accurately identify such attacks, one needs to know the different forms such hacks can take. There are several variations of phishing attacks that are utilised by attackers. It is crucial to understand the differences between these variations and how to combat them. This article will aim to shed light on this.
Below are six main types of phishing attacks utilised by cyber criminals, with an explanation of how they work:
Business Email Compromise (BEC) or CEO Fraud
This type of Phishing attack involves attackers targeting key employees in key departments in an organisation, for instance managers in the finance and accounting department of an organisation. During Business Email Compromise or CEO Fraud an attacker impersonates a CEO or finance officer in an organisation and sends an email on their behalf to a subordinate asking them to initiate a transfer of funds into a fake account owned by the attacker.
In Australia, BEC remains one of the most common cybercrimes reported by businesses. In 2024–25, BEC fraud resulting in financial loss made up 15% of cybercrime reports from businesses to the Australian Signals Directorate (ASD), second only to email compromise that caused no financial loss (19%).
How it works - Attackers often compromise the account of an authoritative figure in an organisation like a senior executive by exploiting an existing infection planted in the system, for example, through a spear phishing attack; others simply spoof a lookalike email address. The attacker then studies the email activity to decipher the procedures and processes surrounding communication in the organisation. Once the attacker has a good idea of the communication habits of the compromised account, he or she sends a fake email to a regular recipient. The fake email will usually urge the recipient to make an unauthorised transfer of funds to an external account in control of the attacker.
Vishing
Vishing stands for ‘voice phishing’ and refers to phishing attacks over the phone. Attackers may utilise Interactive Voice Response (IVR) technology that is commonly used by financial institutions, or simply call victims directly, to trick victims into divulging sensitive information. Scamwatch data in the National Anti-Scam Centre’s Targeting scams report shows Australians reported losing $72.5 million to scams that began with a phone call in 2025.
How it works - A message sent by the attacker will request recipients to call a number and enter their account information or PIN number for verification or security purposes. The source of these malicious messages is typically disguised as coming from a bank or government institution, essentially an entity that is trustworthy. But in reality when victims dial the number provided it puts them in touch with the attacker using IVR technology.
Smishing
Smishing, similar to Vishing, is a portmanteau of the term ‘Phishing’ and ‘SMS’ and refers to phishing attacks carried out via the text message function of mobile phones. The reason why attackers have started to target victims via text message is that people are often quicker to open and read messages on their phone than a message received via email.
How it works - Attackers send their victims messages on their mobile phones masquerading as a trusted person or organisation. These messages are designed to trick victims to provide attackers with exploitable information or access to their mobile devices. Cyber criminals also target mobile phones because individuals often secure their mobile devices less carefully than their personal computers or laptops.
Clone Phishing
Clone Phishing is a type of phishing where the attacker creates a replica of a legitimate message the victim has already received, such as one sent between an employer and employee, in the hopes of tricking the victim into thinking it’s real. The email address that the message is being sent from resembles the address of the legitimate sender along with the body of text which matches a prior message in terms of style and substance. The main difference between the legitimate message and the illegitimate one from the attacker is a link, file or attachment that carries an infection.
How it works: The idea behind this type of phishing attack is that the victim is supposed to think that the original message is simply being re-sent to them, so there is no reason to doubt its legitimacy. This makes it more likely that they will fall for the attacker’s trap and click on the malicious attachment or download a file that has malware embedded code in it.
Spear Phishing
While Phishing involves cyber criminals fishing for random victims by using spoofed email as bait, Spear Phishing consists of attackers picking their targets. Instead of targeting 1,000 victims’ login credentials, attackers who utilise a spear phishing method target a single organisation or handful of businesses. An example of where spear phishing is used is between nations: a government agent from one nation may target another country for sensitive intel via fraudulent emails.
How it works - Unlike regular Phishing, attackers spend time researching their victims and crafting messages specific to the recipient. For example, messages may refer to a recent event the target attended or the message may be spoofed to resemble a communication from the organisation the victim is employed by.
Whaling
This is a social engineering tactic used by cyber criminals to ensnare senior or other important individuals in an organisation by acting like another senior player, in the hopes of gaining access to their computer systems or stealing money or sensitive data. Whaling has an added element of social engineering compared to phishing as staff are more likely to carry out actions or divulge information without giving it a second thought when the request is coming from someone who is a ‘big fish’ or ‘whale’ in the organisation, like the CEO or Finance Manager.
How it works - This social engineering tactic is very similar to phishing as it also uses email and website spoofing to trick individuals. The key difference is that phishing tends to target non-specific individuals, while whaling involves targeting key individuals or ‘whales’ of the company like the CEO or Finance Manager while masquerading as another influential or senior individual in the organisation.
In conclusion
Organisations need to realise that their employees are the weakest link when it comes to information security, and training and awareness need to be prioritised if they want to avoid succumbing to cyber criminals. By studying the different types of phishing attacks utilised by attackers, you and your organisation can prevent the consequences of falling for a cyber attack. By understanding how popular phishing attacks work you and your employees will have an easier time identifying red flags in fraudulent emails.
StickmanCyber's team is equipped to help your employees recognise such attempts, and prevent social engineering attacks.
Take your first step by speaking to an expert at StickmanCyber.
