Skip to content
Back to home
2025-08-12Security Fundamentals

Phishing Attacks — Meaning, Types and Mitigations

A breakdown of what phishing actually is, the many forms it takes beyond email, and the practical steps individuals and SOC teams use to catch it early.

Hey everyone — I can guess you may be bored to hear about phishing and think it isn't all that harmful. But the truth is: 3.4 billion phishing emails are received every single day, and many companies have been hit by phishing attacks that cost billions in data breaches. So it's important to talk about this and help everyone guard against it.

What is Phishing, actually?

Phishing is one of the best known Social Engineering attacks. While other types of attacks exploit system or network vulnerabilities, Social Engineering attacks exploit human vulnerability — lack of awareness, overconfidence, and emotional manipulation.

For example, an attacker might pretend to be someone the victim knows well and ask them to send a bank statement over email for some "urgent" situation.

So we should always be alert to these situations and double-check before sending important data.

Types of Phishing

Many people assume phishing only happens via email. But sadly, no — as technology evolves, attackers and their techniques evolve with it. Let's look at the most common types of phishing.

  • Email Phishing – This is the OG of online scams. You know those "Congratulations, you won a lottery!" emails — that's email phishing. It's been around forever because, sadly, people still fall for it.
  • Spear Phishing – Instead of targeting random strangers, the attacker studies you — your job, your hobbies, maybe your last LinkedIn post — and crafts an email just for you.
  • Whaling – This one targets people in high positions — CEOs, directors, or anyone with high-level access.
  • Smishing – Scammy messages sent via SMS. "Your bank account is locked. Click this link." The urgency makes people panic-tap before thinking.
  • Vishing – Voice + phishing = vishing. The caller pretends to be tech support, a bank rep, or even the police. They'll use authority and urgency to trick you into spilling sensitive info.
  • Clone Phishing – Imagine getting a legitimate email from your colleague, but it's actually a copy of the real one, sent with the link replaced by a malicious one.
  • Angler Phishing – Fake customer support on social media. You tweet at your bank about a problem, and a so-called "support account" DMs you with a fake link. Fast, friendly, but fraudulent.
  • Quishing – A newer method that isn't widely known yet. Scammers hide malicious links in QR codes — because nobody checks what's behind a QR code before scanning it.
  • AI-Generated Phishing – This is the most dangerous method. AI can write flawless, personalized messages with no broken English, no red flags — just perfectly convincing scams.

How to Avoid Phishing

The first and foremost step is creating awareness. Always watch for urgent language, unfamiliar sender addresses, bad grammar, mismatched links, the same email sent to many recipients, or suspicious attachments.

Some pro tips:

  • Always use Multi-Factor Authentication (MFA).
  • When in doubt, verify via a separate channel — call the sender back, don't just reply.
  • Hover over links to check their real destination.
  • Educate your team regularly with real examples and test drills.
  • Deploy email filters and security gateways.
  • In SOC environments, set up logs and rules to detect phishing patterns fast. A quick Splunk rule might catch bursts of "password reset" requests or mass suspicious links heading to the same domain.

Finally, phishing is too cheap and effective. With AI and personalization, even tech professionals can fall for it. As a SOC analyst, we don't just block emails — we're stopping breaches, cleaning up damage, and keeping the organization safe from the first click.