Types of Phishing: A Guide to Social Engineering Attacks
One word covers a dozen different techniques. Each uses a different channel and a different psychological lever. We go through them one by one and show what gives each of them away.
CERT Polska logged 260,783 incidents in 2025, up 152% year on year. Nearly 78,000 of them were phishing. That scale has nothing to do with technical difficulty. It comes from the fact that the target is a person, and no firewall stops an employee who hands over their own password.
What is phishing?
Phishing is a social engineering attack. A criminal impersonates a trusted person or institution and persuades the victim to hand over data, click a link, or authorise a payment. The name comes from "fishing", because the mechanism is exactly that: cast bait and wait.
One thing separates it from a conventional intrusion. Phishing does not break controls, it goes around them by convincing an authorised user to open the door. From the system's point of view everything looks correct: right login, right password, right code. Which is why technology alone was never going to be enough.
What the numbers look like
CERT Polska's 2025 figures give a sense of the scale in Poland:
- 658,320 reports received by the team, more than 1,800 a day
- 260,783 registered incidents, a 152% increase year on year
- 78,391 incidents classified as phishing
- Around 250,000 domains added to the national Warning List, roughly 670 a day
- 140 million blocked attempts to reach those domains
One more number says more than all of those combined. According to the Verizon DBIR 2025, the median time from opening a phishing email to clicking it is 21 seconds. The median time to report it to security is 28 minutes. The entire attack fits inside that gap.
Anatomy of a phishing attack
Reconnaissance
The attacker collects information about the organisation: structure, names, email format, systems in use. Sources are professional networks, the company website, public registries and older breach data. This stage almost never requires a break-in.
Delivering the bait
The victim gets a message matched to their context: an invoice, a request from a manager, a delivery notice. Better reconnaissance makes it harder to tell apart from real correspondence.
Harvesting credentials
The click opens a fake login page or launches an attachment. Modern phishing kits work as a live proxy and capture the one-time code too, so SMS-based two-factor authentication stops protecting anything.
Exploiting access
The compromised account is used to move through the network, pull out data, or send the next round of messages. This time from a real internal address, which more or less guarantees a high hit rate.
Types of phishing
Techniques differ by channel, level of personalisation and chosen target. These are the variants we actually see in the field.
Mass email phishing
One message goes to thousands of recipients, impersonating a bank, a courier or a government body. There is barely any personalisation, but at that scale a fraction of a percent of clicks pays for the campaign. It is the most common variant and also the easiest to filter.
Spear phishing
An attack aimed at one person, built on reconnaissance. The message references real projects and real colleagues, so the classic warning signs stop working. We go deeper in our guide to spear phishing and whaling, and we test it in practice through Arsen social engineering simulations.
Whaling
Spear phishing aimed at the board. The stakes are higher because a CEO or CFO can approve a payment without a second signature. The FBI put losses from BEC attacks at $3.046 billion in 2025 alone.
Smishing (SMS)
Phishing over text. The short format works for the attacker: no full URL, no headers to inspect, and people read texts on the move. CERT Polska blocked roughly 1.88 million malicious texts in 2025. Details in our article on smishing and fake SMS messages.
Vishing (voice)
A phone call where the criminal poses as IT support, a bank or a manager. AI voice cloning means the "CEO" on the line now sounds convincing. We analyse it in our piece on vishing as the number one threat. We are the only company in Poland that tests organisations with voice cloning and deepfake video.
Quishing (QR codes)
A link hidden inside a QR code. The email filter sees an image, not a URL, and the user scans with a phone that is usually personal. By 2025 around 12% of all phishing messages carried a QR code. We break the vector down in our quishing guide.
Clone phishing
The attacker copies a real message the victim already received and swaps the link or attachment. The content looks familiar because it genuinely was. Scrutiny drops to almost nothing at that point.
How to recognise phishing
A single signal rarely means much. Risk climbs when several show up at once:
- Time pressure, usually some version of "your account will be suspended within 24 hours"
- A request for data no institution collects by email: password, full card number, one-time code
- A sender address one character or one suffix away from the official domain
- A link that goes somewhere other than its visible text suggests
- An unusual request from a known person, especially about money or a changed account number
- An unexpected attachment, particularly an archive, a macro-enabled file or HTML
- A channel that does not fit the matter, such as a work request arriving on a personal number
KEY TAKEAWAYS
- 1Defending against one variant does not cover the others, because each uses a different channel
- 2Language errors stopped being a warning sign once attackers started using generative AI
- 3Campaigns combine channels, so a training programme limited to email leaves a gap
- 4Median time to click is 21 seconds and median time to report is 28 minutes, which is the real problem
- 5Training alone is not enough, you need regular testing with a measurable result
How to protect your organisation
Technology stops most messages but not all of them, and one is enough. So the technical layer and the team's reflexes have to work together.
- Deploy phishing-resistant authentication, meaning hardware keys or passkeys instead of SMS codes
- Configure SPF, DKIM and DMARC to make impersonating your domain harder
- Run regular phishing simulations covering email, SMS and voice
- Require payment and account-number changes to be verified on a different channel than the one the request arrived on
- Give the team a simple way to report suspicious messages, and respond to every report
- Monitor the environment around the clock, for example through SOC-as-a-Service, to catch the fallout of a successful attack
- Rehearse the "someone clicked" scenario, because cutting those 28 minutes buys more than another training session
- Start from the data: our Social Engineering Report 2026 covers the scale and includes a team checklist
Conclusion
Phishing will not disappear, because it is not a technical problem. It is a trust problem, and you cannot switch off trust in an organisation that has to function. The sensible goal is not zero clicks. It is a team that spots an attack faster than 28 minutes, and processes that limit the damage from the one click that eventually lands.
Do not ask whether your people will click. Assume they will, and find out what happens next.
Find out which techniques work on your team
Arsen tests your organisation with every vector described above: email phishing, smishing, quishing and vishing with voice cloning. You get results per department, not a generic report.