Blog

Types of Phishing Scams: How Cybercriminals Trick Their Victims

3.4 billion phishing emails go out every day. Once someone opens one, it takes a median of 21 seconds before they click the bad link. Not much time to think twice. That’s the whole problem with phishing, really. It doesn’t need to be clever, it just needs to catch someone at the wrong moment.

This blog walks you through the most common types of phishing attacks, how they show up in real life, and what current numbers say about how often they land.

Why Phishing Still Works So Well

Phishing goes after trust, not code. An email that looks like it’s from a bank or a coworker doesn’t need to break through a firewall, it just needs one person to click, reply, or type something they shouldn’t. Verizon’s 2025 Data Breach Investigations Report puts phishing at the center of 36% of confirmed data breaches. And it’s gotten sharper lately. Another study found that 82.6% of phishing emails are now AI-generated.

Common Types of Phishing Attacks

Email phishing is the classic version, still the most common by volume. A message shows up looking like it’s from a trusted company, asking someone to verify account details, reset a password, or review an invoice. A shipping notice claiming a package couldn’t be delivered, with a link to “reschedule,” is a familiar one. Click it, and the fake page is often built to look exactly like the real company’s site, right down to the fonts.

Spear phishing is the targeted version. Rather than blasting the same email to thousands of inboxes, the attacker researches one person specifically, pulling from LinkedIn, a company site, whatever’s public, and builds something that feels personal. It’s a small slice of total phishing volume by count, but a disproportionately large one when it comes to actual successful breaches, some studies put its share of successful attacks as high as 65%. An email addressed to a specific project manager, referencing a real project by name, asking them to open an “updated contract” that’s actually loaded with malware; that’s spear phishing doing what it does.

Then there’s whaling, which goes straight for the top: CEOs, CFOs, board members, people with the authority to move large sums of money. One case involved a $25 million loss after attackers used an AI-generated deepfake video call to impersonate a company’s CFO in a live meeting, convincing staff to authorize the transfer. Text-based scams feel almost quaint next to that.

Business Email Compromise, or BEC, skips the malware entirely a lot of the time. It’s just a convincing, well-timed request, either from a hijacked real account or a close copy of one. The FBI tied $2.77 billion in losses to BEC across more than 21,000 complaints in a single year. The scenario that comes up again and again: an accounts payable employee gets an email from what looks like a regular vendor, asking that future payments go to a “new” account. The invoice number’s right. The tone’s right. Nothing about it feels unusual until the money’s already gone.

Text messages have their own version: smishing. A fake delivery notice, a fake billing alert, a fake toll payment reminder, all pointing to a link that grabs card details. Smishing now makes up around 35% of phishing activity, and U.S. consumers reported $470 million in losses to text scams in one year alone. People generally trust texts more than email, and reading one on a small screen while distracted doesn’t help either, which is part of why smishing tends to outperform email phishing on click-through rate.

Vishing does the same thing over the phone. A spoofed caller ID pretending to be a bank or an internal help desk. What used to be fairly obvious has gotten harder to catch. Vishing attempts jumped 442% between the first and second half of a recent year. Voice cloning tools now need just a few seconds of someone’s real voice to produce something convincing enough to fool a help desk employee into resetting a password over the phone.

QR codes get their own category too: quishing. A fake code on a parking meter, or one buried in an email disguised as something that “requires scanning to view.” This one jumped roughly 400% in a recent stretch, mostly because it slides right past email filters built to catch links and attachments, not images.

There’s also angler phishing, which lives on social media. Fake customer support accounts that swoop into public complaints offering to “help,” then steer the person toward a link asking for login details. It works because someone venting about a bad experience is usually impatient and not thinking about verification.

Clone phishing copies a real email the target has already received and resends it with the link swapped out for something malicious. Since it looks nearly identical to something already trusted, it tends to slide past the usual skepticism.

And pharming is the odd one out, it redirects someone to a fake site even when they type the correct address themselves, usually by tampering with domain settings or exploiting a network flaw. No link to click, no message to fall for, which makes it genuinely hard to catch through awareness alone. Updated browsers and solid network security do most of the heavy lifting here.

Who Gets Targeted Most

Financial institutions took the brunt of it, targeted in roughly 31% of phishing attacks globally, up 22% year over year. Finance and accounting staff specifically are reportedly three times more likely to be targeted by spear phishing than employees elsewhere in a company, for the obvious reason that they’re the ones with access to payment systems.

What Actually Helps

Training works, and the data backs that up. Well-run programs have brought susceptibility down from around 33% to under 5%. Beyond training, a few habits matter: confirming unexpected payment requests through a separate channel instead of just replying, checking where a link actually goes before clicking it, turning on multi-factor authentication, and reporting anything suspicious right away instead of just deleting it. Passkeys and modern email filtering help too, especially against the AI-written stuff that no longer reads like a scam.

Conclusion

Phishing isn’t the clumsy, typo-ridden email a lot of people still picture. It spans email, text, phone calls, QR codes, and video calls now, and the different types of phishing attacks keep multiplying as attackers find new channels to abuse. Knowing the types of phishing scams covered here and understanding why the phishing scams succeed as often as they do gives people a genuine edge. Staying alert, double-checking anything that feels slightly off, and building a few habits into daily communication go a long way toward staying ahead of it.

Need Help

Talk to us

Get Started

Protect your online assets from cyber threats with Paramount

Comprehensive cyber security solutions for individuals and businesses

Significantly reduce the risk of cyber threats and ensure a safer digital environment.

Paramount-Whatsapp