What is phishing, and what variants exist beyond classic email phishing?
Phishing tricks people into handing over confidential data by impersonating a trusted party — and it now spans voice, QR codes, and more.
* Phishing beyond the inbox — voice, QR, SMS and targeted spear variants of the same bait. *
The word blends Password + fishing. Attackers pose as trustworthy institutions (e.g. your bank) and exploit people's trust and helpfulness to harvest credentials or account details.
Variants:
- Vishing — voice phishing (phone calls)
- QR-phishing (quishing) — malicious QR codes leading to fake login pages
- Smishing — via SMS
- Spear phishing — targeted at a specific person/role
Why it works: it attacks the human pillar, bypassing technical controls entirely — no exploit needed if the victim just types in their password.
Tip: Phishing is a form of social engineering — #3 on the ENISA threat list — and the most common initial-access method in real breaches.
Go deeper:
Phishing (Wikipedia) — dedicated sections on each channel variant the card names.
Phishing, vishing, smishing (Swiss NCSC) — the Swiss CERT view of the channel variants and how to spot them.
What is phishing? (Malwarebytes) — a spear/vishing/smishing/whaling walkthrough.