// SOCIAL ENGINEERING

Phishing, spear phishing, vishing, and smishing: four forms of one attack

Phishing is a fraudulent message that poses as a trusted sender and asks you for data, money, or the opening of an attachment. Spear phishing is its targeted version, vishing arrives by phone, and smishing by text message. The difference isn’t in the technique but in the preparation and the channel: the narrower the target, the more work the attacker puts in and the harder it is to spot.

// 01

The four forms side by side

Form of attackChannel and targetHow it is preparedHow to spot it
PhishingEmail sent to thousands of addressesA bank or courier template; the attacker knows nothing about the recipientGeneric greeting, an unfamiliar domain, urgency in the subject line
Spear phishingEmail to a handful of people, often in finance or ITBuilt on a real project, supplier, or invoiceThe text fits, the sender address or the account number doesn’t
VishingA phone call to a specific personAn IT support or bank script, often following up on an emailPressure to act at once and a refusal to be called back
SmishingA text message or a message in a chat appA short text with a link: a parcel, a payment, a blocked accountA shortened link, an unfamiliar domain, no history of conversation

The only thing the same across all four is the intent: to get from a person something the technical protection wouldn’t hand over by itself. What differs is the cost of preparation and the channel, and with them how easily the attack is recognized.

// 02

Phishing: mass and cheap

Phishing is a mass send in which the attacker knows nothing about the recipient and relies on numbers. The template is usually bought or copied from the real sender: a bank, a courier, a shared document, a password expiry. The economics rest on volume: even a tiny success rate over enough messages gives the attacker a result, so the quality of the text doesn’t matter.

That is exactly why it is the easiest to spot. A generic greeting, a domain that differs by one character, and pressure to act immediately. The catalog of attacker techniques lists this one under the label T1566 and distinguishes four variants by what the message arrives as: an attachment, a link, an invitation to a service, and a voice call.

// 03

Spear phishing: targeted and prepared

Spear phishing is the targeted version, aimed at a handful of people and built on what is public about them. The attacker reads LinkedIn profiles, the annual report, and the format of company addresses, then writes a message that fits a project currently under way. Preparation is counted in hours instead of seconds, and the success rate matches. Where the attacker gets the names and roles is described in more detail elsewhere.

It most often aims at people who send money or hold access: finance, executive assistants, administrators. That this isn’t only a foreign phenomenon is documented by the NÚKIB recommendation on spear phishing (in Czech): among the Czech organizations hit it names hospitals, universities, and financial institutions, from which the attackers wanted credentials and money. The giveaway usually isn’t the text, which fits, but a detail around it: a different sender domain, a new account number, a request to keep it from colleagues.

// 04

Vishing and smishing: when the channel changes

The same fraud moved to the phone and to text messages. Vishing is a call in which the attacker poses as IT support, a bank, or a supplier and pushes for immediate action, because on a call there is no time to verify anything. Smishing is a short message with a link, most often about a parcel, a payment, or a blocked account.

Both channels get around most of the technical protection: a call doesn’t pass through the mail gateway, and a text message opens on a phone, outside the company filters and device management. The catalog of techniques lists the voice variant twice and splits it by what the attacker is after. When the call only pulls out information for a further attack, it is T1598.004 among the reconnaissance techniques. When the call is meant to open the way inside straight away, it is T1566.004 among the initial access techniques.

// 05

Why are they combined in practice?

Attackers combine channels because two channels together work better than one. The typical sequence is an email and then a call: the message announces an invoice or a change in a system, and an hour later a person calls, refers to it and walks the victim through to a payment or to entering a code. The second channel supplies credibility the message alone doesn’t have.

Phishing is combined with bypassing multi-factor authentication in the same way. The message pulls out the password, the call the one-time code, or instead of a password all that is asked for is approval of a login on the phone. The four boxes from the glossary are therefore useful for describing an attack, not for building a defense: the defense has to count on both arriving at once.

// 06

How do you spot it?

A fraudulent message isn’t recognized by mistakes in the language; those stopped being the rule long ago. Three things are more reliable: an unusual request (a change of account number, forwarding a code, installing a remote access tool), pressure on time, and a channel that doesn’t belong to that request. A change of bank details announced by text message is suspicious no matter how it is worded.

The second layer is technical: a sender domain one character off, a link pointing somewhere other than its label, an attachment in a format that doesn’t match the content. And one rule holds for all four forms. Verification goes back through a channel the recipient picks, not through the one the caller or the sender offered.

// 07

What can be exercised?

Email can be exercised without trouble, the phone with preparation, and text messages only rarely. An email campaign can be prepared and evaluated in numbers, so a campaign run against your own people is the basis. Vishing is exercised person by person and measures worse, because every call goes differently and the results don’t add up into one percentage. In the list of what can be tested, testing people is a separate type of test.

Scenarios that play out away from the screen belong to a physical test, because they need different authorization and different rules. Scenarios that end at the entrance are often combined with a fraudulent message: a call announces a technician, and then the technician is standing in the doorway.

A category of its own is quishing, a link hidden in a QR code that many mail gateways don’t read. We cover it in an article on what is currently getting through the filters.

// 08

Frequently asked questions

The number of recipients and the preparation. Phishing is a mass send to anyone; spear phishing aims at named people and builds on what the attacker found out about them from public sources. Technically it is the same attack, but the success rate of a targeted message is in a different league, and it can be spotted only by the details around the text, not by the text itself.

Vishing is phishing over the phone. The attacker calls, poses as IT support, a bank, or a supplier, and wants a code, a password, or the installation of a remote access tool. It works because on a call there is no time to verify anything, and refusing a person is socially harder than deleting a message. It often follows an email that arrived an hour earlier.

Smishing is phishing over text messages or a chat app. The text tends to be short, contains a shortened link and refers to a parcel, a payment, or a blocked account. What makes it unpleasant is mainly that the phone sits outside the company filters and nobody checks the address of a page on a small display, especially on a personal device.

Mass campaigns largely yes, targeted messages often not. A filter works with the reputation of the domain, the structure of the message, and the links, so on a freshly registered domain with two sentences of text and no attachment it has little to hold on to. Vishing and smishing don’t pass through the mail gateway at all, because it never sees them.

They can, but not by a lecture on how to recognize a fraud. What works is training built on messages people really received, and that tracks the share of reported messages rather than the share of clicks. Sooner or later everyone clicks; reporting is a habit and it can be trained.

The assessment belongs to the employer, who is the controller of the personal data, and to their data protection officer or lawyer. The vendor of a simulation can’t decide it for you and we don’t claim to. The legal basis for the processing, informing employees, and what we have approved in writing are covered in the answer on the phishing simulation page.

Related pages

Updated September 5, 2026.

// NEXT STEP

See what a phishing campaign that teaches people something looks like

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.