QLAN

Phishing: The Social Engineer's Weapon of Choice

Email phishing, spear phishing, whaling, vishing, and smishing: how each works, the tactics they share, and how a small business trains staff to resist them.

Abed Farah · Co-Founder & President · · 3 min read

Written by the team that has provided Managed IT Services to Orange County businesses since 1999.

Social engineering attacker composing a deceptive email

What is phishing and why does it work?

Phishing remains one of the most effective tools in a hacker’s arsenal for exploiting human psychology and tricking victims into divulging sensitive information. By understanding the various phishing techniques employed by cybercriminals, individuals and organizations can better protect themselves against these insidious attacks.

The scale is large. The FBI’s Internet Crime Complaint Center (IC3) logged 193,407 phishing and spoofing complaints in 2024, more than any other crime type, alongside 21,442 business email compromise complaints with $2.77 billion in reported losses, out of $16.6 billion in total reported cybercrime losses that year (FBI IC3 2024 Internet Crime Report).

How does email phishing work?

Email phishing is the most common and well-known form of phishing. Hackers craft convincing emails that appear to come from legitimate sources, often mimicking trusted brands or institutions. These emails typically contain:

  • Urgent requests for action
  • Threats of account closure or financial penalties
  • Promises of rewards or exclusive offers

The goal is to manipulate the recipient into clicking malicious links or downloading infected attachments. Hackers may use personalization tactics to increase credibility, referencing recent events or personal details gleaned from public sources.

What is spear phishing?

While traditional phishing casts a wide net, spear phishing takes a more targeted approach. Attackers research specific individuals or organizations to craft highly personalized messages. This method often targets high-value individuals like executives or those with access to sensitive data. Spear phishing emails may include:

  • References to colleagues or recent company events
  • Industry-specific jargon and terminology
  • Spoofed sender addresses from known contacts

The heightened level of personalization makes spear phishing particularly dangerous, as even savvy users can be fooled by the apparent legitimacy of the communication.

What is whaling?

Whaling is a subset of spear phishing that specifically targets high-level executives or other “big fish” within an organization. These attacks often involve:

  • Impersonation of C-suite executives or board members
  • Requests for urgent wire transfers or confidential data
  • Exploitation of the target’s authority to bypass normal security protocols

Whaling attacks can result in massive financial losses, as evidenced by the roughly $75.8 million (€70 million) stolen from Belgian bank Crelan in a 2016 CEO-impersonation scheme.

What is vishing?

Vishing, or voice phishing, takes the concepts of phishing and applies them to phone calls. Attackers may use:

  • Deliver malicious links disguised as package tracking updates or account notifications
  • Create a sense of urgency to prompt immediate action
  • Exploit the trust people often place in mobile communications

A high-profile example of vishing occurred in July 2020, when attackers phoned Twitter employees while posing as IT staff and tricked four of them into handing over credentials, which opened the internal account tools and led to the compromise of 130 high-profile accounts.

What is smishing?

As mobile devices become increasingly central to our digital lives, smishing (SMS phishing) has grown in prevalence. These attacks use text messages to:

  • Deliver malicious links disguised as package tracking updates or account notifications
  • Create a sense of urgency to prompt immediate action
  • Exploit the trust people often place in mobile communications

Conclusion

Phishing attacks continue to evolve, leveraging new technologies and exploiting human psychology in increasingly sophisticated ways. By staying informed about these tactics and maintaining a healthy skepticism towards unsolicited communications, individuals and organizations can better defend against social engineering attempts. Regular security awareness training and the implementation of robust email filtering systems are crucial steps in building a strong defense against phishing in all its forms.

QLAN’s cybersecurity services include email filtering, multi-factor authentication, and staff awareness training for small and mid-sized businesses in Orange County, and its Managed IT Services keep those defenses maintained. If your team has received a convincing attempt recently, schedule a security assessment.

Common questions

What is the difference between phishing and spear phishing? +

Phishing sends the same lure to many people and relies on volume. Spear phishing targets a specific person or company with details drawn from research, such as colleague names or current projects, which makes it far more convincing.

What is whaling? +

Spear phishing aimed at executives or people who can move money. Attackers impersonate the CEO or a board member and request urgent wire transfers or confidential data, counting on authority to bypass normal checks.

How can a small business defend against smishing and vishing? +

Treat texts and calls with the same suspicion as email: never act on a link or a request for credentials from an unexpected message, call back on a number you already have, and give staff a simple way to report attempts.

Next step

Find your security gaps before an attacker does.

A senior engineer reviews your environment, identifies exposure, and outlines practical fixes. No pressure, no obligation.