Back to blog
Types of phishing attacks that could cost Businesses over £100M

Types of phishing attacks that could cost Businesses over £100M

3 August 2026

Different types of phishing

The types of phishing businesses face can be grouped according to the communication channel or technique being used.

Email based

Email-based phishing includes mass phishing emails, spear phishing, whaling, clone phishing and business email compromise. Attackers may impersonate a supplier, manager, bank, delivery company or cloud service.

Some emails contain malicious attachments, while others direct the recipient to a fake login page. More advanced messages may refer to real colleagues, projects or previous conversations.

Phone based

Phone-based attacks are often known as vishing. The caller may impersonate a bank, senior manager, IT technician, police officer or trusted supplier.

They may ask for security codes, payment information or remote access to a device. Voice cloning can also make a fraudulent call sound as though it came from someone the victim knows.

Text and app based

Smishing uses text messages to deliver fake delivery alerts, unpaid invoice warnings, account notifications or security messages.

Similar attacks can appear through WhatsApp, social media, Microsoft Teams, Slack and other messaging platforms. Because the message appears inside a familiar app, the recipient may trust it more quickly.

Website based

Website-based phishing uses fake websites designed to copy legitimate login pages, payment portals or document-sharing services.

Some attackers also use search advertisements, compromised websites and manipulated search results to place fraudulent pages in front of potential victims.

Workplace methods

Workplace phishing is designed around someone’s responsibilities. Finance employees may receive fake supplier requests, HR teams may receive malicious CVs and managers may receive urgent payment instructions.

To stay updated about different workplace attack scenarios, follow the Optimise Cyber Solutions LinkedIn page , where we share practical examples of how scams can appear during an ordinary working day.

Compare similar phishing attacks

Many types of phishing attacks overlap, but understanding their differences can help employees recognise what is happening.

Spear phishing vs whaling

Spear phishing targets a particular person or small group using personalised information.

Whaling is a form of spear phishing aimed at senior leaders or other high-value individuals, such as directors, executives and financial decision-makers.

Smishing vs vishing

Smishing happens through text messages or messaging apps.

Vishing happens through voice calls. In both cases, the attacker commonly creates urgency and asks the target to share information, call a number or complete an immediate action.

Clone phishing vs email spoofing

Clone phishing copies a real email and replaces its original link or attachment with a malicious one.

Email spoofing makes a message appear to come from another email address. A spoofed message may not be a copy of a genuine email, but it imitates a trusted sender.

Business email compromise vs ordinary phishing

Ordinary phishing is often sent to many recipients and may attempt to steal login credentials.

Business email compromise is usually more targeted. The attacker may impersonate or compromise a real business account to request payments, payroll changes or confidential information.

Pharming vs fake login pages

A fake login page depends on persuading someone to visit a fraudulent website.

Pharming redirects users to a malicious website, sometimes even when they entered the correct address. This can involve compromised systems, devices or network settings.

MFA phishing vs password phishing

Password phishing focuses on collecting usernames and passwords.

MFA phishing also attempts to capture authentication codes, approval notifications or session information. Some attacks relay the victim’s details to the real website in real time.

Are you recruiting a new employee? Fully funded cyber security and AI training across Yorkshire can help train new recruits or upskill your existing team.

What attackers are actually trying to steal

Different types of phishing target different information, access levels and business processes.

Login credentials

Stolen usernames and passwords can provide access to email accounts, cloud platforms, customer records and internal systems.

MFA codes

An attacker may request a one-time code or repeatedly send authentication prompts until the user approves one.

Session cookies

Session cookies can allow an attacker to enter an account after the legitimate user has already completed the login and authentication process.

Payment details

Fake invoices, payment portals and refund pages may be used to collect card numbers or banking information.

Personal information

Names, dates of birth, addresses, identification details and security answers can be used for fraud or further impersonation.

Confidential documents

Attackers may target contracts, client information, pricing documents, business plans, employee records and intellectual property.

Payroll changes

A message may impersonate an employee and ask HR or payroll to replace their existing bank details.

Gift-card purchases

Attackers often impersonate senior managers and ask employees to purchase gift cards urgently.

Remote access to device

Fake support staff may persuade an employee to install remote-access software or begin a support session.

Malware or ransomware access

Malicious attachments, downloads and remote tools can provide attackers with the access needed to deploy malware or ransomware.

Psychological techniques used

Many types of phishing work because they influence emotions and decision-making rather than defeating technical security controls.

1. Urgency

Urgency pressures someone to act before checking the request. The message may claim an account will be closed or a payment must be completed immediately.

2. Authority

The attacker impersonates someone powerful, such as a director, bank representative, police officer or IT administrator.

3. Fear

Warnings about legal action, lost access, suspicious activity or financial penalties can prevent rational decision-making.

4. Curiosity

Unexpected documents, photographs, complaints or confidential updates may tempt someone to click.

5. Familiarity

The attacker may mention a real colleague, supplier, workplace system or current project.

6. Helpfulness

Fake IT support and customer-service scams succeed because the attacker appears to be solving a problem.

7. Secrecy

The target may be instructed not to discuss the request with colleagues, which prevents independent verification.

8. Financial pressure

Fake invoices, refunds and payment warnings are designed to create concern about losing money.

9. Scarcity

Limited-time offers, expiring documents and restricted access can pressure someone into acting quickly.

10. Trust in recognised platforms

Messages delivered through Microsoft Teams, cloud services, trusted apps or genuine accounts may feel safer than ordinary email.

How phishing has changed

Modern types of phishing attacks increasingly use artificial intelligence, workplace technology and legitimate online platforms.

AI-written phishing emails

AI can help attackers create convincing messages with natural language, accurate spelling and personalised information.

Deepfake voice calls

Artificially generated voices may imitate managers, family members or trusted business contacts.

QR-code phishing

QR codes can hide the destination of a malicious link and encourage employees to continue the process on a personal phone.

Microsoft Teams and Slack impersonation

Attackers may create external accounts, compromise genuine accounts or impersonate colleagues inside workplace platforms.

Fake IT support calls

Someone claiming to be from IT may ask the employee to share their screen, approve a login or install remote-access software.

Instead of asking for a password, the attacker asks the user to approve permissions for a malicious application.

Some advanced types of phishing attacks capture session cookies, which may allow an attacker to access an account without repeatedly entering a password or MFA code.

Phishing through legitimate apps and notification systems

Attackers may abuse genuine platforms to send fraudulent notifications, invoices or callback requests.

Role-based scams targeting finance, HR or senior managers

Role-based attacks are adapted to the target’s responsibilities. Finance teams handle payments, HR teams handle personal information and senior managers have authority to approve important decisions.

Follow the Optimise Cyber Solutions LinkedIn page  to see examples of different workplace attacks and the warning signs employees should recognise.

Common warning signs of phishing attacks

Although the types of phishing vary, certain warning signs appear repeatedly.

1. Unexpected request

Be cautious when a request arrives without context, especially if it involves money, credentials or confidential information.

2. Unusual urgency

A genuine request should normally allow enough time for appropriate checks.

3. New payment details

Changes to supplier or employee bank details should always be verified through a trusted contact method.

4. Pressure to keep the request secret

Secrecy may be used to prevent the employee from asking a colleague for advice.

A login request sent through a text message, social media account or unexpected chat should be treated carefully.

6. Request to install remote-access software

Employees should only install approved tools through the organisation’s established IT process.

7. Sender name looks correct but the address does not

Display names can be copied easily. Always check the complete email address.

8. Request bypasses the normal company process

A request to ignore approval procedures, payment checks or security controls is a serious warning sign.

Explain why some phishing attacks look legitimate

The most convincing types of phishin attacks contain enough truthful information to make the fraudulent part seem believable.

Compromised real accounts

A message sent from a genuine account may pass basic checks and appear inside an existing contact history.

Previous email conversations

Attackers may reply to a real email thread after gaining access to an account.

Real company names

Public websites, social media and leaked information can help attackers identify genuine organisations and suppliers.

Correct employee job titles

Job titles can help criminals decide who manages payments, recruitment, systems or confidential records.

Information from LinkedIn

LinkedIn can reveal employee names, responsibilities, promotions, business relationships and workplace activities.

Genuine cloud services

Attackers may host malicious files or forms through familiar cloud platforms.

Trusted apps

Messages delivered through a recognised app may receive less scrutiny than messages from unknown senders.

Lookalike domains

A domain may contain a minor spelling change, additional character or different extension that is difficult to notice quickly.

Stolen email signature

Copied logos, contact details and disclaimers can make a fraudulent message look professional.

Understanding the types of phishing attacks is valuable, but employees also need confidence to pause, verify unusual requests and report concerns quickly.

Stay ahead of phishing attacks with cybersecurity training

At Optimise Cyber Solutions, we help businesses and organisations stay safe and one step ahead of attackers through practical, workplace-focused training.

Optimise Cyber is ready to help businesses and organisations of any size. Cybersecurity training helps employees recognise the types of phishing attacks they may encounter through email, phone calls, workplace platforms and everyday business processes.

The strongest defence is not simply knowing the names of different attacks. It is building a workplace culture where people question unusual requests, follow verification procedures and feel comfortable reporting mistakes before they become serious incidents.

More from the blog

Is Microsoft Teams Secure for Confidential Information? (+5 Security Tips)
Post

Is Microsoft Teams Secure for Confidential Information? (+5 Security Tips)

Is Microsoft Teams secure for confidential information? Learn how phishing, fake IT support, malicious links and role-based scams can put business data at risk.

28 July 2026Read more
How to Use AI Safely at Work: Practical Guide and +3 solutions
Post

How to Use AI Safely at Work: Practical Guide and +3 solutions

If you are unsure how to use AI safely, this guide will help you evaluate any AI service. It outlines what to check when using AI tools and what to do if you are at risk or experience a cyberattack.

13 July 2026Read more