
Types of phishing attacks that could cost Businesses over £100M
Different types of phishing
The types of phishing businesses face can be grouped according to the communication channel or technique being used.
Email based
Email-based phishing includes mass phishing emails, spear phishing, whaling, clone phishing and business email compromise. Attackers may impersonate a supplier, manager, bank, delivery company or cloud service.
Some emails contain malicious attachments, while others direct the recipient to a fake login page. More advanced messages may refer to real colleagues, projects or previous conversations.
Phone based
Phone-based attacks are often known as vishing. The caller may impersonate a bank, senior manager, IT technician, police officer or trusted supplier.
They may ask for security codes, payment information or remote access to a device. Voice cloning can also make a fraudulent call sound as though it came from someone the victim knows.
Text and app based
Smishing uses text messages to deliver fake delivery alerts, unpaid invoice warnings, account notifications or security messages.
Similar attacks can appear through WhatsApp, social media, Microsoft Teams, Slack and other messaging platforms. Because the message appears inside a familiar app, the recipient may trust it more quickly.
Website based
Website-based phishing uses fake websites designed to copy legitimate login pages, payment portals or document-sharing services.
Some attackers also use search advertisements, compromised websites and manipulated search results to place fraudulent pages in front of potential victims.
Workplace methods
Workplace phishing is designed around someone’s responsibilities. Finance employees may receive fake supplier requests, HR teams may receive malicious CVs and managers may receive urgent payment instructions.
To stay updated about different workplace attack scenarios, follow the Optimise Cyber Solutions LinkedIn page , where we share practical examples of how scams can appear during an ordinary working day.
Compare similar phishing attacks
Many types of phishing attacks overlap, but understanding their differences can help employees recognise what is happening.
Spear phishing vs whaling
Spear phishing targets a particular person or small group using personalised information.
Whaling is a form of spear phishing aimed at senior leaders or other high-value individuals, such as directors, executives and financial decision-makers.
Smishing vs vishing
Smishing happens through text messages or messaging apps.
Vishing happens through voice calls. In both cases, the attacker commonly creates urgency and asks the target to share information, call a number or complete an immediate action.
Clone phishing vs email spoofing
Clone phishing copies a real email and replaces its original link or attachment with a malicious one.
Email spoofing makes a message appear to come from another email address. A spoofed message may not be a copy of a genuine email, but it imitates a trusted sender.
Business email compromise vs ordinary phishing
Ordinary phishing is often sent to many recipients and may attempt to steal login credentials.
Business email compromise is usually more targeted. The attacker may impersonate or compromise a real business account to request payments, payroll changes or confidential information.
Pharming vs fake login pages
A fake login page depends on persuading someone to visit a fraudulent website.
Pharming redirects users to a malicious website, sometimes even when they entered the correct address. This can involve compromised systems, devices or network settings.
MFA phishing vs password phishing
Password phishing focuses on collecting usernames and passwords.
MFA phishing also attempts to capture authentication codes, approval notifications or session information. Some attacks relay the victim’s details to the real website in real time.
Are you recruiting a new employee? Fully funded cyber security and AI training across Yorkshire can help train new recruits or upskill your existing team.
What attackers are actually trying to steal
Different types of phishing target different information, access levels and business processes.
Login credentials
Stolen usernames and passwords can provide access to email accounts, cloud platforms, customer records and internal systems.
MFA codes
An attacker may request a one-time code or repeatedly send authentication prompts until the user approves one.
Session cookies
Session cookies can allow an attacker to enter an account after the legitimate user has already completed the login and authentication process.
Payment details
Fake invoices, payment portals and refund pages may be used to collect card numbers or banking information.
Personal information
Names, dates of birth, addresses, identification details and security answers can be used for fraud or further impersonation.
Confidential documents
Attackers may target contracts, client information, pricing documents, business plans, employee records and intellectual property.
Payroll changes
A message may impersonate an employee and ask HR or payroll to replace their existing bank details.
Gift-card purchases
Attackers often impersonate senior managers and ask employees to purchase gift cards urgently.
Remote access to device
Fake support staff may persuade an employee to install remote-access software or begin a support session.
Malware or ransomware access
Malicious attachments, downloads and remote tools can provide attackers with the access needed to deploy malware or ransomware.
Psychological techniques used
Many types of phishing work because they influence emotions and decision-making rather than defeating technical security controls.
1. Urgency
Urgency pressures someone to act before checking the request. The message may claim an account will be closed or a payment must be completed immediately.
2. Authority
The attacker impersonates someone powerful, such as a director, bank representative, police officer or IT administrator.
3. Fear
Warnings about legal action, lost access, suspicious activity or financial penalties can prevent rational decision-making.
4. Curiosity
Unexpected documents, photographs, complaints or confidential updates may tempt someone to click.
5. Familiarity
The attacker may mention a real colleague, supplier, workplace system or current project.
6. Helpfulness
Fake IT support and customer-service scams succeed because the attacker appears to be solving a problem.
7. Secrecy
The target may be instructed not to discuss the request with colleagues, which prevents independent verification.
8. Financial pressure
Fake invoices, refunds and payment warnings are designed to create concern about losing money.
9. Scarcity
Limited-time offers, expiring documents and restricted access can pressure someone into acting quickly.
10. Trust in recognised platforms
Messages delivered through Microsoft Teams, cloud services, trusted apps or genuine accounts may feel safer than ordinary email.
How phishing has changed
Modern types of phishing attacks increasingly use artificial intelligence, workplace technology and legitimate online platforms.
AI-written phishing emails
AI can help attackers create convincing messages with natural language, accurate spelling and personalised information.
Deepfake voice calls
Artificially generated voices may imitate managers, family members or trusted business contacts.
QR-code phishing
QR codes can hide the destination of a malicious link and encourage employees to continue the process on a personal phone.
Microsoft Teams and Slack impersonation
Attackers may create external accounts, compromise genuine accounts or impersonate colleagues inside workplace platforms.
Fake IT support calls
Someone claiming to be from IT may ask the employee to share their screen, approve a login or install remote-access software.
OAuth consent phishing
Instead of asking for a password, the attacker asks the user to approve permissions for a malicious application.
Session-cookie theft
Some advanced types of phishing attacks capture session cookies, which may allow an attacker to access an account without repeatedly entering a password or MFA code.
Phishing through legitimate apps and notification systems
Attackers may abuse genuine platforms to send fraudulent notifications, invoices or callback requests.
Role-based scams targeting finance, HR or senior managers
Role-based attacks are adapted to the target’s responsibilities. Finance teams handle payments, HR teams handle personal information and senior managers have authority to approve important decisions.
Follow the Optimise Cyber Solutions LinkedIn page to see examples of different workplace attacks and the warning signs employees should recognise.
Common warning signs of phishing attacks
Although the types of phishing vary, certain warning signs appear repeatedly.
1. Unexpected request
Be cautious when a request arrives without context, especially if it involves money, credentials or confidential information.
2. Unusual urgency
A genuine request should normally allow enough time for appropriate checks.
3. New payment details
Changes to supplier or employee bank details should always be verified through a trusted contact method.
4. Pressure to keep the request secret
Secrecy may be used to prevent the employee from asking a colleague for advice.
5. Login link sent through an unusual channel
A login request sent through a text message, social media account or unexpected chat should be treated carefully.
6. Request to install remote-access software
Employees should only install approved tools through the organisation’s established IT process.
7. Sender name looks correct but the address does not
Display names can be copied easily. Always check the complete email address.
8. Request bypasses the normal company process
A request to ignore approval procedures, payment checks or security controls is a serious warning sign.
Explain why some phishing attacks look legitimate
The most convincing types of phishin attacks contain enough truthful information to make the fraudulent part seem believable.
Compromised real accounts
A message sent from a genuine account may pass basic checks and appear inside an existing contact history.
Previous email conversations
Attackers may reply to a real email thread after gaining access to an account.
Real company names
Public websites, social media and leaked information can help attackers identify genuine organisations and suppliers.
Correct employee job titles
Job titles can help criminals decide who manages payments, recruitment, systems or confidential records.
Information from LinkedIn
LinkedIn can reveal employee names, responsibilities, promotions, business relationships and workplace activities.
Genuine cloud services
Attackers may host malicious files or forms through familiar cloud platforms.
Trusted apps
Messages delivered through a recognised app may receive less scrutiny than messages from unknown senders.
Lookalike domains
A domain may contain a minor spelling change, additional character or different extension that is difficult to notice quickly.
Stolen email signature
Copied logos, contact details and disclaimers can make a fraudulent message look professional.
Understanding the types of phishing attacks is valuable, but employees also need confidence to pause, verify unusual requests and report concerns quickly.
Fully Funded Cybersecurity Training
At Optimise Cyber Solutions, we help businesses and organisations stay safe and one step ahead of attackers through practical, workplace-focused training.
Optimise Cyber is ready to help businesses and organisations of any size. Cybersecurity training helps employees recognise the types of phishing attacks they may encounter through email, phone calls, workplace platforms and everyday business processes.
The strongest defence is not simply knowing the names of different attacks. It is building a workplace culture where people question unusual requests, follow verification procedures and feel comfortable reporting mistakes before they become serious incidents.
More from the blog

Cyber Security Training for Businesses: 3 Hidden Risks
Cyber security training for businesses: help employees spot fake security checks, risky AI permissions and phishing attacks through practical workplace examples.

7 Essential Ways to Prevent Business Account Take Over Risks
Protect your UK company from business account take over with practical tips on MFA, phishing, password security, monitoring, recovery, and BEC prevention today.

7 Proven Ways to Prevent Business Email Compromise in the UK
Learn how Business Email Compromise targets UK firms, spot warning signs, prevent fraud with MFA and payment checks, and respond fast after an attack right now.