It’s no secret that in cybersecurity, many attacks begin with some form of “‑ishing.” But what exactly are these tactics and who’s behind them? From classic phishing emails to more advanced impersonation schemes using AI and social platforms, attackers continue to evolve their methods to exploit human behavior. Understanding the full spectrum of “‑ishing” techniques is critical for organizations looking to protect their people, data, and reputation.
In this blog, we explore the different types of “‑ishing” and their definitions. In future posts, we’ll take a deeper dive into specific attack vectors and how to defend against them.
Expanded “‑ishing” Attacks: What’s Out There?
Angler Phishing (Social Media Phishing)
Attackers create fake social media profiles that impersonate customer support or brand representatives. These fake accounts engage with users through public posts or direct messages, often prompting them to click malicious links or share login details.
Calendar Phishing
This technique leverages calendar invites (typically via email or mobile) to deliver malicious links or attachments. The invite looks legitimate, but clicking it leads to credential harvesting or malware installation.
Captcha Phishing
A newer tactic where attackers insert fake CAPTCHA challenges (like “I’m not a robot” checkboxes) on phishing sites. After the user completes the CAPTCHA, they’re redirected to a malicious form. This not only makes the page appear more legitimate but can also evade automated security scans.
Clone Phishing
In this method, attackers copy a legitimate, previously delivered email and resend it with altered links or attachments. Because the email appears familiar, the recipient is more likely to engage without suspicion.
Deepfake Phishing
A growing threat involving AI-generated voice or video content used to impersonate trusted figures, such as executives or business partners. Deepfake phishing can be used in vishing calls or video messages, making social engineering even more convincing.
Domain Spoofing (Lookalike Domains)
Cybercriminals register domains that closely mimic legitimate ones (e.g., paypa1.com vs. paypal.com). These domains are then used to send phishing emails or host fake websites, fooling users into entering sensitive data.
Email Phishing
The most common form of phishing: deceptive emails designed to look like they come from trusted sources. These emails often contain malicious links, infected attachments, or urgent messages that prompt users to act quickly without verifying the source.