Phishing Attack Warning Signs and Types: How to Identify Spear Phishing, Whaling, Smishing, Vishing and QR-Code Phishing (Quishing)
Phishing is a social engineering attack in which a cybercriminal impersonates a trusted person, company, government department, bank, employer, service provi...
Phishing is a social engineering attack in which a cybercriminal impersonates a trusted person, company, government department, bank, employer, service provider, or online platform to manipulate a victim into taking an unsafe action.
The attacker may try to convince the victim to:
- Enter a username and password on a fake website
- Reveal an OTP or authentication code
- Approve an unexpected MFA request
- Open a malicious attachment
- Click a malicious link
- Scan a fraudulent QR code
- Install malware or remote-access software
- Transfer money
- Change banking or payment information
- Reveal confidential business information
- Provide credit card, banking, identity, or personal information
Traditional phishing commonly uses email, but modern phishing attacks can arrive through SMS, WhatsApp, messaging applications, telephone calls, social media, collaboration platforms and QR codes.
The delivery method may change, but the attacker's objective is usually the same: gain the victim's trust and persuade the victim to do something that benefits the attacker.
1. What Are the Common Warning Signs of a Phishing Email?
A phishing email does not always contain an obvious virus or suspicious attachment. Modern phishing campaigns can closely imitate legitimate communications.
Therefore, users should evaluate the sender, message, request, links, attachments and context together.
1.1 Suspicious Sender Address
One of the first things to examine is the actual sender's email address.
For example:
Expected:
billing@company.com
Suspicious:
billing@company-support.com
or
billing@cornpany.com
Attackers frequently register domains that visually resemble legitimate domains.
Common techniques include:
- Misspelled company names
- Additional words
- Extra hyphens
- Different domain extensions
- Character substitutions
- Lookalike Unicode characters
- Recently registered domains
Do not rely only on the sender's display name.
An email might display:
Microsoft Support
while the actual sender address belongs to an unrelated domain.
1.2 Unexpected Urgency
Phishing messages frequently attempt to create panic or urgency.
Examples include:
- "Your account will be suspended today."
- "Immediate verification required."
- "Your mailbox has exceeded its storage limit."
- "Payment failed. Update your details immediately."
- "Your password expires in 2 hours."
- "Unauthorized login detected."
- "Your parcel cannot be delivered."
Urgency reduces the amount of time a victim spends thinking about whether the request is legitimate.
A legitimate urgent request can certainly occur, but urgency combined with unusual links, payment requests or credential requests should be treated carefully.
1.3 Threatening Language
Some phishing campaigns use fear instead of urgency.
Examples include threats involving:
- Account suspension
- Tax penalties
- Legal action
- Banking restrictions
- Service termination
- Domain expiration
- Email deletion
- Security breaches
- Failed payments
Do not follow instructions simply because a message sounds serious.
Verify the issue independently.
1.4 Unexpected Requests for Passwords or Authentication Codes
A major warning sign is a request for:
- Passwords
- PINs
- OTPs
- MFA codes
- Recovery codes
- Security answers
- Credit card details
- Banking credentials
Legitimate organizations generally do not ask users to email or verbally disclose passwords.
An OTP or MFA code should normally be entered only into the legitimate service where the authentication process was initiated.
1.5 Suspicious Links
A hyperlink can display one address while directing the user somewhere completely different.
For example, visible text might say:
Microsoft 365 Login
but the underlying URL could point to an attacker-controlled domain.
On a desktop computer, hovering the mouse pointer over a link can often reveal its destination before clicking.
Check:
- Domain spelling
- Unexpected subdomains
- Strange URL parameters
- URL-shortening services
- Unusual domain extensions
- HTTP instead of HTTPS
- Lookalike domains
However, remember that HTTPS does not prove that a website is legitimate. Attackers can obtain TLS certificates for malicious websites too.
1.6 Unexpected Attachments
Unexpected attachments should be treated cautiously, particularly files such as:
.exe.msi.js.vbs.bat.cmd.scr.iso.img.lnk.zip.rar
Office documents and PDFs can also be used as part of phishing campaigns.
For example, a PDF might simply contain a button or QR code directing the victim to a credential-stealing website.
1.7 Generic Greetings
Traditional phishing campaigns frequently use greetings such as:
- Dear Customer
- Dear User
- Dear Account Holder
- Dear Employee
However, this indicator has become less reliable.
Modern attackers can obtain names and other information from social networks, breached databases, corporate websites and public records.
A personalized email can still be phishing.
1.8 Grammar and Spelling Problems
Poor grammar and spelling have historically been associated with phishing.
Examples include:
- Strange sentence structure
- Unusual capitalization
- Incorrect company terminology
- Formatting problems
- Unprofessional wording
But users should not depend on grammar as a phishing detector.
Modern attackers can create professionally written phishing messages using translation tools, templates and generative AI.
1.9 Requests to Bypass Normal Business Procedures
Business phishing attacks often attempt to convince employees to ignore established procedures.
For example:
"Do not call me because I am in a meeting. Purchase these gift cards immediately."
or
"Our bank account has changed. Please send today's payment to the new account."
Any unexpected change involving:
- Bank details
- Vendor payment information
- Payroll information
- Employee direct deposit
- Purchase orders
- Large transfers
should be independently verified through a previously known communication channel.
2. What Is Spear Phishing?
Spear phishing is a targeted phishing attack designed specifically for a particular individual, employee, department or organization.
Unlike mass phishing campaigns, spear phishing attackers typically research their intended victim.
They may collect information from:
- Corporate websites
- Social media
- Previous data breaches
- Public directories
- Press releases
- Employee profiles
- Conference information
- Supplier websites
The attacker then uses this information to make the message appear believable.
Example
Suppose an attacker discovers that:
- Raj works in accounts.
- His manager is Amit.
- The company regularly purchases from ABC Technologies.
The attacker might impersonate Amit and send:
"Raj, please process the attached ABC Technologies invoice today. The supplier needs confirmation before 4 PM."
Because the message contains familiar names and business context, the recipient may be more likely to trust it.
Why Is Spear Phishing Dangerous?
Spear phishing can be especially dangerous because it combines technical impersonation with personalized social engineering.
Potential objectives include:
- Credential theft
- Malware installation
- Financial fraud
- Business email compromise
- Intellectual property theft
- Network compromise
- Initial access for ransomware attacks
3. What Is Whaling in Cybersecurity?
Whaling is a specialized form of spear phishing targeting senior executives or other high-value individuals within an organization.
Typical targets include:
- CEO
- CFO
- Managing Director
- Directors
- Partners
- Senior managers
- Finance heads
- Legal executives
- System administrators
- People with payment authorization
The term "whaling" refers to targeting a particularly valuable target or "big fish."
Example of a Whaling Attack
An attacker may impersonate a lawyer and contact a CFO:
"This acquisition is confidential. Please transfer the attached amount to the escrow account immediately. Do not discuss this with other employees until the transaction is announced."
The attacker combines:
Authority + confidentiality + urgency
to discourage normal verification procedures.
Common Whaling Objectives
Whaling attacks frequently target:
- Wire transfers
- Sensitive corporate information
- Payroll information
- Tax records
- Intellectual property
- Employee information
- Login credentials
- Administrative access
Organizations should require independent verification for high-value financial transactions regardless of who appears to request them.
4. What Is Smishing or SMS Phishing?
Smishing is phishing conducted through SMS or text messages.
The word combines:
SMS + Phishing = Smishing
Attackers send fraudulent messages designed to persuade victims to click links, call numbers, disclose information or make payments.
Common Smishing Messages
Examples include:
Parcel Delivery Scam
"Your package could not be delivered. Pay ₹25 delivery charge here."
Bank Security Scam
"Your bank account has been temporarily blocked. Verify KYC immediately."
Toll or Traffic Scam
"Unpaid toll detected. Pay immediately to avoid additional charges."
Tax Scam
"Your tax refund is pending. Verify your banking information."
Account Security Scam
"Suspicious login detected. Secure your account now."
Why Smishing Is Effective
Mobile devices create several advantages for attackers.
Users may:
- Read messages quickly
- Have difficulty examining complete URLs
- Trust SMS notifications
- Be distracted while using their phone
- Assume a message is legitimate because it appears in an existing SMS conversation
Users should avoid opening suspicious SMS links and instead access the organization through its official application or manually entered website address.
5. What Is Vishing or Voice Phishing?
Vishing is phishing performed through telephone or voice communication.
The term combines:
Voice + Phishing = Vishing
The attacker attempts to manipulate the victim during a telephone conversation.
Attackers may impersonate:
- Bank employees
- Police officers
- Government officials
- Tax departments
- Technical support
- Microsoft support
- Internet providers
- Credit card companies
- Employers
- Vendors
Typical Vishing Attack
A victim receives a telephone call:
"This is your bank's fraud department. We detected an unauthorized transaction. Please provide the OTP that was just sent to your phone so we can cancel it."
In reality, the attacker may already be attempting a transaction and needs the OTP to complete it.
Caller ID Spoofing
Attackers can sometimes manipulate caller ID information so that an incoming call appears to originate from a trusted organization.
Therefore:
Caller ID alone should never be considered proof of identity.
If someone claims to represent a bank or other organization and requests sensitive information, end the call and contact the organization using its independently verified official number.
6. What Is QR-Code Phishing or Quishing?
Quishing is a phishing attack that uses a QR code to direct victims to a malicious website or fraudulent action.
The term commonly means:
QR Code + Phishing = Quishing
Instead of presenting a traditional clickable hyperlink, attackers provide a QR code.
The victim scans the code with a smartphone and is redirected to an attacker-controlled website.
How Quishing Works
A typical attack follows this sequence:
Phishing Email or Physical QR Code
↓
Victim Scans QR Code
↓
Mobile Browser Opens
↓
Fake Login Page Appears
↓
Victim Enters Credentials
↓
Credentials Are Captured by Attacker
The fake website may imitate:
- Microsoft 365
- Google Workspace
- Gmail
- Banking portals
- Payment services
- Cloud storage
- Corporate VPN portals
- Employee authentication systems
Why Are QR-Code Phishing Attacks Dangerous?
QR codes hide their destination from normal visual inspection.
A user cannot determine the destination simply by looking at the QR pattern.
Additionally, an email containing a QR code may contain no conventional clickable malicious URL.
This can make some traditional link-analysis mechanisms less effective, although modern email security platforms increasingly analyze QR codes and their destinations.
Another important problem is device switching.
A user might receive the phishing email on a protected corporate computer but scan the QR code using a personal smartphone.
The resulting malicious website therefore opens outside some of the organization's normal desktop security controls.
Physical QR-Code Phishing
Quishing is not limited to email.
Attackers may place malicious QR codes on:
- Parking meters
- Restaurant menus
- Posters
- Payment terminals
- Public notices
- Event advertisements
- Charging stations
- Product packaging
An attacker may even place a fraudulent QR-code sticker over a legitimate QR code.
Before completing a payment or entering credentials after scanning a public QR code, verify the destination carefully.
Comparing Major Phishing Types
| Attack Type | Primary Method | Typical Target | Main Risk |
|---|---|---|---|
| Phishing | Email/web | General users | Credential theft/malware |
| Spear Phishing | Personalized email/message | Specific person | Targeted compromise |
| Whaling | Targeted communication | Executives/high-value users | Financial/data theft |
| Smishing | SMS/text | Mobile users | Credential/payment fraud |
| Vishing | Phone/voice | Individuals/employees | Information/OTP theft |
| Quishing | QR codes | Mobile users/employees | Credential theft/fraud |
Phishing vs. Spear Phishing vs. Whaling
These terms are related but should not be confused.
Phishing is the broad category.
A campaign might send the same fake Microsoft password-expiration email to thousands of people.
Spear phishing is targeted.
The attacker researches a particular employee and creates a personalized message.
Whaling is an even more specialized targeted attack in which the intended victim is a senior executive or another high-value individual.
Therefore:
Phishing → Spear Phishing → Whaling
can be understood as increasingly targeted forms of social engineering.
Modern Phishing and Multi-Factor Authentication
Multi-factor authentication significantly improves account security, but it does not make phishing impossible.
Attackers may attempt techniques such as:
- OTP theft
- MFA push fatigue
- Fake MFA pages
- Session-cookie theft
- Adversary-in-the-middle phishing
- Social engineering of account recovery
For example, an attacker might create a fake Microsoft 365 login page that captures both the username/password and subsequent authentication information.
This is why organizations should consider phishing-resistant authentication, such as FIDO2/WebAuthn security keys and passkeys, where supported.
Business Email Compromise and Phishing
Business Email Compromise (BEC) is an important business-focused threat closely associated with phishing and impersonation.
Attackers may impersonate or compromise:
- Executives
- Vendors
- Accountants
- Customers
- HR departments
- Finance teams
The attacker may request:
- Payment to a different bank account
- Urgent wire transfer
- Payroll change
- Confidential documents
- Gift card purchases
Financial requests should therefore be verified using established procedures.
For example, if a supplier unexpectedly emails new bank details, contact the supplier using a previously verified telephone number, not a telephone number included in the suspicious email.
How to Protect Against Phishing Attacks
Organizations should use multiple layers of protection rather than depending entirely on employees identifying every phishing message.
Technical Controls
Consider implementing:
- Spam and phishing filtering
- Secure email gateways
- URL reputation filtering
- Attachment scanning
- Endpoint protection
- DNS/web filtering
- Multi-factor authentication
- Phishing-resistant authentication
- Conditional access policies
- Browser protection
- Endpoint Detection and Response (EDR)
- Security monitoring
SPF, DKIM and DMARC
Organizations operating their own email domains should properly configure:
SPF — Sender Policy Framework
SPF identifies which mail servers are authorized to send email for a domain.
DKIM — DomainKeys Identified Mail
DKIM adds a cryptographic signature that allows receiving systems to verify that an email was authorized by the signing domain and has not been improperly modified in transit.
DMARC — Domain-based Message Authentication, Reporting and Conformance
DMARC builds upon SPF and DKIM and allows domain owners to define policies for messages that fail authentication and receive reports about email authentication activity.
These technologies help reduce certain types of domain spoofing, although they cannot eliminate phishing entirely.
What Should You Do If You Receive a Suspicious Message?
If you suspect phishing:
- Do not click links.
- Do not scan unexpected QR codes.
- Do not open suspicious attachments.
- Do not reply to the sender.
- Do not provide passwords, OTPs or MFA codes.
- Verify the request independently.
- Report the message to your IT or security team.
- Use the email provider's phishing-reporting feature where appropriate.
- Delete the message after reporting it according to organizational procedures.
What If You Already Clicked a Phishing Link?
Clicking a phishing link does not automatically mean an account has been compromised, but the incident should be evaluated.
If you only opened the page and entered nothing, close it and report the incident.
If you entered credentials, take immediate action.
Consider:
- Change the compromised password using the legitimate website.
- Ensure the new password is unique.
- Enable or review MFA.
- Sign out active sessions where possible.
- Review account recovery information.
- Check for suspicious login activity.
- Notify your IT/security administrator.
- Check email forwarding and inbox rules.
- Review recently authorized applications.
- Monitor the account for unauthorized activity.
For corporate accounts, administrators may also need to revoke sessions or tokens and investigate authentication logs.
What If You Shared an OTP?
If you accidentally disclose an OTP or MFA code:
- Contact the relevant organization immediately.
- Change the account password.
- Review recent transactions.
- Terminate suspicious sessions.
- Check MFA configuration.
- Review registered devices.
- Monitor financial accounts if banking information was involved.
An OTP should be treated like a temporary password.
What If You Scanned a Suspicious QR Code?
Scanning a QR code by itself does not necessarily compromise the device.
Risk increases if you:
- Enter credentials
- Download an application
- Install a configuration profile
- Grant permissions
- Make a payment
- Provide personal information
If the QR code opened a suspicious website, close the page.
If credentials were entered, treat them as potentially compromised and follow your organization's incident-response procedures.
Important Rule: Verify Through a Separate Channel
One of the strongest defenses against social engineering is independent verification.
Suppose you receive an email apparently from your manager:
"Transfer ₹5 lakh immediately to this new supplier account."
Do not verify by simply replying:
"Is this really you?"
If the email account itself is compromised, the attacker can answer yes.
Instead, verify through a separate trusted channel:
- Call a known telephone number.
- Speak with the person directly.
- Use an established internal communication system.
- Follow your organization's payment approval procedure.
Phishing Security Checklist
Before trusting an unexpected email, SMS, call or QR code, ask:
Who sent it?
Is the sender genuinely who they claim to be?
Was I expecting it?
Unexpected communication deserves additional scrutiny.
What is being requested?
Credentials, money and confidential information require special caution.
Is there urgency or fear?
Attackers frequently manufacture urgency.
Where does the link lead?
Inspect the actual destination.
Why am I being asked to scan a QR code?
A QR code should not automatically be trusted because it appears in a professional-looking email.
Can I verify this another way?
Independent verification can prevent many social-engineering attacks.
Frequently Asked Questions (FAQ)
1. What is the most common warning sign of a phishing email?
There is no single indicator that identifies every phishing email. Common warning signs include suspicious sender addresses, unexpected requests, urgency, unusual links, attachments and requests for passwords or authentication information.
2. Can a phishing email come from a legitimate email address?
Yes. If a legitimate email account has been compromised, attackers may send phishing messages from the real account.
3. Is an email safe if SPF, DKIM and DMARC pass?
Not necessarily. Email authentication helps verify aspects of the sending domain, but a legitimate or compromised domain can still send malicious content.
4. What is spear phishing?
Spear phishing is a targeted phishing attack customized for a particular person, department or organization.
5. What is the difference between phishing and spear phishing?
Traditional phishing often targets many recipients with similar messages. Spear phishing is specifically personalized for selected targets.
6. What is whaling?
Whaling is a targeted phishing attack directed at executives or other high-value individuals.
7. Why are executives targeted by whaling attacks?
Executives often have access to sensitive information, financial authorization and privileged corporate resources.
8. What is smishing?
Smishing is phishing conducted through SMS or text messages.
9. Can WhatsApp messages be used for phishing?
Yes. Social engineering and phishing can occur through WhatsApp and other messaging platforms.
10. What is vishing?
Vishing is voice-based phishing conducted through telephone calls or other voice communication.
11. Can attackers fake caller ID?
Yes. Caller ID spoofing can make a fraudulent call appear to originate from another number.
12. Should I provide an OTP to a bank employee over the phone?
As a general security practice, do not disclose OTPs or authentication codes in response to unsolicited calls. If uncertain, end the call and contact the institution through its independently verified official channel.
13. What is quishing?
Quishing is phishing that uses QR codes to redirect victims to malicious websites or fraudulent transactions.
14. Can scanning a QR code infect my phone?
Simply scanning a QR code does not automatically mean the device is infected. However, the code can direct you to a malicious website or download, so you should inspect the destination and avoid installing unknown software.
15. Can QR codes steal passwords?
A QR code can direct a victim to a fake login page designed to capture usernames, passwords and other information.
16. Is HTTPS proof that a website is safe?
No. HTTPS encrypts communication between your browser and the website, but malicious websites can also use HTTPS.
17. Can phishing bypass MFA?
Some sophisticated phishing attacks can steal OTPs, manipulate MFA approval or capture authenticated sessions. Phishing-resistant authentication technologies provide stronger protection.
18. What should I do after entering my password on a phishing website?
Change the password immediately through the legitimate service, terminate suspicious sessions where possible, review MFA and recovery settings, and notify your IT/security administrator if it is a business account.
19. Should I reply to a suspicious email asking whether it is genuine?
Usually not. Verify the request through a separate trusted communication channel.
20. Can AI make phishing attacks more convincing?
Yes. Generative AI can help attackers create grammatically correct, personalized and multilingual messages, making grammar alone an unreliable phishing indicator.
21. Can antivirus software stop phishing?
Antivirus and endpoint security can help block malicious files and websites, but no security product can prevent every social-engineering attack.
22. Are shortened URLs dangerous?
Not automatically, but shortened URLs hide the final destination and therefore deserve additional scrutiny when received unexpectedly.
23. Can phishing emails contain only a QR code?
Yes. Some quishing campaigns use an image or QR code with very little conventional text or no clickable malicious hyperlink.
24. Why do phishing attackers create urgency?
Urgency encourages victims to react quickly rather than carefully examining or independently verifying the request.
25. What is the best defense against phishing?
The strongest approach combines user awareness, independent verification, secure email controls, MFA or phishing-resistant authentication, endpoint protection, monitoring and well-defined business procedures.
Conclusion
Phishing has evolved far beyond poorly written fraudulent emails. Today's attackers can use highly personalized emails, executive impersonation, SMS messages, telephone calls, QR codes and professionally designed fake websites.
The major forms discussed in this article are:
Phishing — broad social-engineering attacks commonly delivered through email.
Spear Phishing — personalized attacks targeting specific individuals or organizations.
Whaling — targeted phishing aimed at executives and other high-value individuals.
Smishing — phishing delivered through SMS or text messages.
Vishing — phishing conducted through telephone or voice communication.
Quishing — phishing that uses QR codes to redirect victims to fraudulent destinations.
The most important principle is simple:
Do not trust a communication merely because it looks professional, contains familiar information or appears to come from someone you know. Verify sensitive requests independently before providing credentials, approving authentication requests, transferring money or revealing confidential information.
#Tags
#Phishing #PhishingAttack #PhishingEmail #PhishingScam #PhishingAwareness #CyberSecurity #CyberSecurityAwareness #CyberSecurityTips #CyberThreats #CyberAttack #EmailSecurity #EmailPhishing #SpearPhishing #Whaling #WhalingAttack #Smishing #SMSPhishing #Vishing #VoicePhishing #Quishing #QRCodePhishing #QRCodeScam #SocialEngineering #SocialEngineeringAttack #CredentialTheft #PasswordSecurity #IdentityTheft #OnlineFraud #CyberFraud #EmailScam #BusinessEmailCompromise #BEC #EmailSpoofing #DomainSpoofing #MaliciousLinks #Malware #MFA #MultiFactorAuthentication #OTPScam #CallerIDSpoofing #MobileSecurity #InternetSecurity #InformationSecurity #SecurityAwareness #DataSecurity #Microsoft365Security #GoogleWorkspaceSecurity #AntiPhishing #PhishingPrevention #CyberSafety
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.