What is phishing? The main types, and what actually stops them
Phishing is fraud that works on people rather than software. The variants differ mainly in how well the attacker has researched you before making contact.
Phishing is an attempt to obtain something valuable — a password, a payment, access to a system — by sending a message that pretends to come from someone the recipient trusts. It is not a technical attack in the usual sense. It defeats no encryption and exploits no software flaw. It works on the person, which is why better software has not made it go away.
The main variants
Bulk phishing is the familiar form: an identical message sent to enormous numbers of people, impersonating a bank, a delivery company or a well-known service. Any individual recipient is unlikely to fall for it. At sufficient volume that does not matter.
Spear phishing reverses the economics. The attacker researches one person — their employer, their colleagues, a project they are working on, something they posted publicly — and writes a message that fits. It arrives at a plausible moment, references things only an insider might know, and carries none of the tells people are taught to look for.
Whaling is spear phishing aimed at senior executives, who can authorise payments and are often shielded by assistants in ways an attacker can exploit. A related pattern impersonates the executive rather than targeting them, instructing a finance team to make an urgent transfer.
Clone phishing takes a real message the target has already received and resends a near-identical copy with the attachment or link swapped. Because the original was genuine and expected, the duplicate inherits its credibility.
Smishing arrives by text message and vishing by voice call. Both strip away the cues people rely on in email — there is no sender address to inspect, no hovering over a link, and on a phone screen far less context. Voice attacks increasingly use synthesised speech, which removes the assumption that a familiar voice proves identity.
Phishing, spam and scams
These get used interchangeably and mean different things. Spam is unsolicited bulk messaging; most of it is merely unwanted advertising and is not trying to steal anything. Phishing specifically impersonates a trusted party to extract credentials, money or access. A scam is the broader category of fraud, of which phishing is one delivery method.
The distinction matters because the defences differ. Spam filters are tuned to volume and reputation, and are good at bulk phishing for that reason. A single well-written message from a compromised but legitimate account has none of the statistical signatures those filters look for, and routinely lands in the inbox.
What the messages have in common
Nearly all of them manufacture urgency. An account will be closed, a payment has failed, a delivery will be returned, a login was detected from another country. The purpose is to compress the time between reading and acting, because verification takes time and haste is what the attack needs.
They also route you somewhere. A link to a login page, an attachment to open, a phone number to call, a QR code to scan. And they ask you to break a normal procedure just this once — to bypass the usual approval, to keep it confidential, to use a different payment channel because the regular one is down.
Poor spelling and clumsy grammar remain common in bulk campaigns, but they are no longer a reliable signal. Targeted messages are generally well written, and treating fluency as evidence of legitimacy is now a liability rather than a defence.
What actually reduces the risk
The most effective single measure is not vigilance but architecture: phishing-resistant authentication. A passkey or hardware security key is bound to the genuine website’s address and will not respond to a counterfeit one, no matter how convincing the page or how convinced the user. That protection does not depend on anyone noticing anything.
Beyond that, the reliable habit is to verify through a channel the message did not supply. If a message appears to come from your bank, use the number on your card. If a colleague asks for an urgent transfer, call them on a number you already had. An attacker controls everything inside their message, including any contact details it offers, so verification is only meaningful when it happens somewhere they do not control.
Finally, report rather than merely delete. Most organisations have a route for it, and a report from the first recipient is often what stops the rest of a campaign from succeeding.

