Types of corporate phishing: how to recognize them and protect your company
By the QuantumSec team
Phishing remains the number-one entry vector in corporate security breaches. Not because the attacks are highly sophisticated, but because they constantly adapt to context, exploit urgency, and take advantage of the trust inherent to email and digital communications. Knowing the types of phishing that exist is the first step to training your team to spot them.
Mass phishing (generic)
Mass phishing is the best known: emails sent to thousands of recipients impersonating trusted entities (banks, postal services, tax authorities, Microsoft, courier companies). The message usually creates urgency ("your account will be blocked", "package pending customs clearance") and directs the victim to a fake website to steal credentials or install malware. Although it's the least sophisticated, it's still effective through sheer volume.
Spear phishing: the targeted attack
Unlike mass phishing, spear phishing targets a specific person or company. The attacker researches the victim on LinkedIn, the corporate website and social media to build a credible email: mentioning real projects, colleagues' names, known suppliers. The success rate is much higher, and it's the most common type of phishing in targeted attacks against companies.
Whaling: when the target is the CEO
Whaling is spear phishing aimed at senior executives: CEO, CFO, chief operating officers. The goal is usually to authorize fraudulent wire transfers, access confidential company data, or compromise accounts with elevated privileges. A successful whaling attack can cost a company hundreds of thousands of euros in minutes.
Business Email Compromise (BEC)
BEC doesn't always involve phishing in the strict sense. The attacker compromises or impersonates the email account of an executive, supplier or trusted client to request urgent transfers, IBAN changes, or system access. It's one of the costliest types of fraud: the FBI estimates BEC has generated losses of over $50 billion worldwide since 2013.
Vishing and smishing
Vishing (voice phishing) uses phone calls: the attacker poses as Microsoft technical support, a bank, social security, or a service provider to obtain credentials, install remote access, or authorize transactions. Smishing uses SMS: package alerts, bank verifications, or HR messages with malicious links. Both are especially effective because the user doesn't expect an attack through these channels.
How to protect your company
Continuous training and realistic simulations: training works, but only if it uses realistic attacks and is repeated regularly. Multi-factor authentication (MFA): even if an employee hands over the password, MFA blocks access. Properly configured SPF, DKIM and DMARC drastically reduce corporate domain spoofing. Out-of-band verification for transfers or banking detail changes: a confirmation call can prevent a million-euro fraud.
FAQ
Does an internal phishing simulation harm team trust?
If managed well, no. The key is to inform management beforehand, frame the results in an educational (not punitive) way, and run an awareness session after the simulation. Most employees respond positively once they understand the goal.
Does DMARC fully protect against phishing?
DMARC protects against exact spoofing of your domain, but not against lookalike domains, compromised accounts, or supplier phishing. It's an important layer, but not sufficient on its own.