Phishing is no longer just a suspicious email asking someone to click a strange link. Attackers now use email, messaging platforms, phone calls, QR codes, and even AI-generated voice and video to make fraudulent requests look legitimate.
The underlying tactic remains the same: exploit trust and human decision-making to gain access to information, systems, or money. What has changed is how convincing, targeted, and scalable these attacks can be.
AI has made it easier for attackers to research targets, personalize messages, remove obvious language mistakes, and adapt their approach across different communication channels. As a result, traditional warning signs such as poor grammar or unfamiliar branding are no longer enough to identify every phishing attempt.
For organizations, effective phishing protection now requires more than employee awareness. Technical controls, phishing-resistant authentication, verification processes, and a tested incident response plan need to work together.
This guide explains what phishing attacks are, the main types organizations face in 2026, how AI is changing them, the warning signs to look for, and the controls organizations can use to reduce phishing risk.
Key takeaways
- Phishing has expanded beyond email. Attacks now target SMS, voice calls, QR codes, and collaboration platforms.
- AI is making phishing harder to recognize. Personalized messages can be created at greater scale with fewer obvious warning signs.
- Traditional red flags are no longer enough. Verification of context, sender identity, links, and unusual requests is increasingly important.
- MFA needs the right approach. Phishing-resistant methods such as FIDO2 and passkeys can provide stronger protection against credential and session theft.
- People and processes still matter. Verification procedures can stop high-impact attacks even when a phishing attempt bypasses technical controls.
- Phishing defense should be layered. Email security, authentication, awareness, process controls, and incident response need to work together.
- A phishing incident can create compliance obligations. Depending on the organization and jurisdiction, a successful attack may trigger breach notification or other regulatory requirements.
What is a phishing attack?
A phishing attack is a type of cyberattack that uses deception to make a person trust a fraudulent message, request, or interaction. Attackers typically impersonate a legitimate individual, organization, or service to persuade the target to reveal sensitive information, authorize a transaction, provide access to an account, or download malicious software.
The technique is simple at its core: instead of exploiting a technical vulnerability, attackers exploit trust and human behavior. A convincing request can be enough to make someone take an action they would normally question.
For example, a phishing attack may:
- Steal credentials: Direct an employee to a fake login page that captures their password.
- Trigger a fraudulent payment: Impersonate an executive or supplier and request an urgent wire transfer.
- Deliver malware: Use a malicious attachment or link to install malware on a device.
- Gain account access: Trick a user into approving a login or sharing a verification code.
- Collect sensitive information: Pose as a trusted service to obtain financial, personal, or business information.
Phishing has also expanded well beyond traditional email. Attackers now use text messages, phone calls, QR codes, video, and collaboration platforms to reach people through channels they already use for everyday business. AI is further changing the threat by making fraudulent messages easier to personalize and harder to distinguish from legitimate communication.
For organizations, this means phishing protection cannot rely on employees simply recognizing suspicious emails. Effective defense requires a combination of technical controls, secure authentication, verification processes, and incident response capabilities.
The 7 types of phishing attacks in 2026
Phishing is no longer limited to email. Attackers now use the same communication channels employees rely on every day, including text messages, phone calls, QR codes, and collaboration platforms.
Understanding these different forms of phishing helps organizations identify where their existing security controls may not provide coverage.
1. Email phishing
Email phishing uses fraudulent messages to impersonate a trusted organization, service, or individual. The goal is usually to make the recipient click a malicious link, open an attachment, or provide sensitive information.
Example: An employee receives an email appearing to come from a familiar service, asking them to verify their account through a link.
What to watch for: Unexpected login requests, suspicious links or attachments, unusual sender addresses, and urgent requests.
2. Spear phishing
Spear phishing is a more targeted form of phishing. Instead of sending the same message to thousands of people, attackers research a specific person or organization and tailor the message to make it more convincing.
Example: An attacker researches an employee’s role and current project, then sends a message that appears to come from a colleague asking them to review a project document.
What makes it different: The more relevant the message appears, the harder it can be to recognize as fraudulent.
3. Whaling
Whaling is spear phishing aimed at senior or high-value individuals, such as executives or finance leaders. These attacks often attempt to trigger high-impact actions, including financial transfers or access to sensitive information.
Example: An attacker impersonates a CEO and asks a finance employee to urgently transfer funds to a new account.
What to watch for: Requests involving money, sensitive information, or unusual approvals, especially when they ask employees to bypass normal procedures.
4. Vishing
Vishing, or voice phishing, uses phone calls or voice-based communication to impersonate a trusted person or organization. AI-generated voice cloning can make these attacks more convincing.
Example: An employee receives a call that appears to come from an executive asking them to urgently approve a payment.
What to watch for: Unexpected requests, unusual urgency, and instructions that bypass established verification procedures.
5. Smishing
Smishing is phishing delivered through SMS or messaging apps. Because these messages reach employees on their mobile devices, they may not pass through the same security controls used for corporate email.
Example: An employee receives a text claiming to be from a delivery service and is asked to click a link to confirm a delivery.
What to watch for: Unexpected links, requests for payment or personal information, and messages creating a sense of urgency.
6. Quishing
Quishing uses malicious QR codes to redirect users to fraudulent websites, often fake login or payment pages. The QR code may appear in an email, document, poster, or other physical or digital material.
Example: A QR code in an email appears to provide access to a company document but instead opens a fake Microsoft 365 login page.
What to watch for: Unexpected QR codes that request login credentials, payment information, or other sensitive data.
7. Collaboration platform phishing
Attackers are increasingly using collaboration platforms such as Microsoft Teams, Slack, SharePoint, and Google Workspace to reach employees. These channels can create a stronger sense of trust because they are already part of normal workplace communication.
Example: An employee receives a message from an unfamiliar external account on a collaboration platform. The sender claims to be from IT and asks the employee to join a call or open a document.
What to watch for: Unexpected messages from external users, unfamiliar accounts, suspicious links or files, and requests to move the conversation or bypass normal processes.
How AI has transformed phishing in 2026
AI is changing phishing at a more fundamental level than simply helping attackers write better emails. It is reducing the time and effort needed to research targets, create convincing messages, and adapt campaigns as they unfold.
1. More personalized attacks
Traditional phishing often relies on broad messages sent to large numbers of people. AI allows attackers to use information about a person, their role, organization, or current activities to create a message that feels relevant to the recipient.
For example, an attacker could use information about an employee’s department and current projects to create a request that appears to come from a colleague or business partner. The more closely the message matches a person’s real context, the harder it can be to dismiss.
2. Fewer obvious warning signs
Spelling mistakes, awkward wording, and generic messages have long been common indicators of phishing. AI can now produce polished, natural-sounding content that closely resembles legitimate business communication.
This does not make these warning signs irrelevant. It means organizations should not rely on language quality alone when assessing whether a message is legitimate.
3. More adaptable campaigns
Attackers can also generate different versions of the same phishing campaign for different targets. Messages can be adjusted based on the recipient, the situation, or how the target responds.
This makes it harder for security teams to rely only on known phishing patterns. Detection increasingly needs to consider sender behavior, identity, links, authentication activity, and unusual requests.
4. Attacks across multiple channels
Phishing is also moving beyond the inbox. The same campaign can span email, messaging platforms, phone calls, and other communication channels.
For example, an attacker may first send an email, then follow up via a messaging platform or by phone to make the request appear more legitimate. This creates a more convincing interaction than a single fraudulent message.
How to stop phishing attacks: a layered defense strategy
Phishing cannot be addressed effectively with a single security control. Email filtering can block many malicious messages, but it cannot stop a fraudulent request that arrives through a phone call or collaboration platform. Similarly, employee awareness can reduce risky behavior, but it cannot prevent every credential theft or account compromise.
A stronger approach combines technical controls, employee awareness, and clear verification processes. Each layer addresses a different part of the attack, so if one control fails, another can still limit the impact.
1. Strengthen email authentication
Email authentication helps prevent attackers from impersonating your organization through spoofed domains. Organizations should configure SPF, DKIM, and DMARC across their sending domains and use DMARC enforcement where appropriate.
These controls are particularly useful for reducing domain impersonation. However, they do not stop every form of phishing, especially attacks that use compromised accounts or external domains.
2. Use phishing-resistant MFA
MFA adds another layer of protection when credentials are stolen, but not all MFA methods provide the same level of phishing resistance. Adversary-in-the-Middle attacks can relay authentication sessions and capture credentials or session information even after a user completes certain types of MFA.
For higher-risk accounts, organizations should consider phishing-resistant authentication such as FIDO2 security keys or passkeys. These methods bind authentication to the legitimate website or service, making it much harder for attackers to relay the authentication process.
3. Improve email security
Email security gateways can reduce the number of phishing messages that reach employees in the first place. Effective controls can include URL scanning, attachment analysis, sandboxing, impersonation detection, and other behavioral detection capabilities.
However, email security should not be treated as the entire phishing defense. Attackers can move to other channels or use techniques that make individual messages harder to distinguish from legitimate communication.
4. Train employees for real-world scenarios
Security awareness training should reflect how phishing actually occurs in the workplace. Training that focuses only on suspicious emails may leave employees unprepared for vishing, smishing, QR-code phishing, or attacks through collaboration platforms.
Regular, role-specific training and phishing simulations can help employees practice recognizing suspicious requests. High-risk roles, such as finance and executives, may also require training focused on payment fraud, impersonation, and credential theft.
5. Build verification into business processes
Some phishing attacks are difficult to distinguish from legitimate communication, particularly when attackers successfully impersonate executives or business partners. In these situations, asking employees to “spot the phishing email” is not enough.
Organizations should establish clear verification procedures for high-impact actions. For example, financial transfers can require multiple approvals, while unexpected payment or credential requests can require verification through a separate trusted channel.
6. Prepare for phishing incidents
Even strong preventive controls cannot guarantee that every phishing attack will be stopped. Organizations need a clear response process for situations where an employee clicks a malicious link, submits credentials, or approves a fraudulent request.
A phishing incident response plan should define who needs to be notified, how compromised accounts are contained, how sessions or credentials are revoked, and when regulatory assessment or notification is required. Regular testing helps ensure these actions can happen quickly when an incident occurs.
Phishing and compliance: what a successful attack triggers
A phishing attack does not always end when an employee clicks a malicious link or shares their credentials. If the attack leads to unauthorized access to personal data, financial information, or regulated systems, the organization may also face legal and regulatory obligations.
The specific requirements depend on the organization, the information involved, and the jurisdiction. A single phishing incident can therefore require both incident response and compliance assessment.
1. GDPR: personal data breach notification
Under GDPR, a phishing incident that results in unauthorized access to personal data may constitute a personal data breach. When the breach is likely to pose a risk to individuals’ rights and freedoms, the organization must generally notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
If the breach is likely to result in a high risk to affected individuals, they may also need to be informed. This means the incident response process needs to assess not only how the attacker gained access, but also what personal data was exposed and the resulting risk.
2. DORA: reporting major ICT-related incidents
For financial entities covered by DORA, a phishing incident may become reportable when it meets the criteria for a major ICT-related incident. Major incidents require an initial notification without undue delay and no later than 4 hours after classification as major, followed by an intermediate report within 72 hours and a final report within one month.
This makes incident classification an important part of phishing response. Financial organizations need clear processes for determining whether an incident meets DORA’s reporting criteria and for coordinating the required notifications.
3. HIPAA: breaches involving protected health information
For US healthcare organizations subject to HIPAA, a phishing attack that results in a breach of protected health information (PHI) can trigger the HIPAA Breach Notification Rule. Covered entities generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery.
Additional notification requirements may apply to the U.S. Department of Health and Human Services and, for certain breaches affecting more than 500 residents of a state or jurisdiction, to prominent media outlets. Business associates also have notification obligations to the covered entity when they discover a breach.
4. SEC: material cybersecurity incidents
For US public companies subject to the SEC’s cybersecurity disclosure rules, a phishing incident may require disclosure if it is determined to be a material cybersecurity incident. The company must generally file Form 8-K Item 1.05 within four business days after determining that the incident is material.
Importantly, the reporting clock is tied to the materiality determination, not simply the moment the phishing attack occurs. Organizations therefore need a defined process for investigating the incident, assessing its impact, determining materiality, and coordinating disclosure when required.
Conclusion
Phishing remains effective because it targets something technical controls cannot fully eliminate: trust. As attacks move beyond email and become more personalized through AI, organizations need to think about phishing as a broader identity and business-process risk, not simply an email security problem.
The strongest defense combines multiple layers. Email security and authentication can reduce exposure, phishing-resistant MFA can limit the impact of stolen credentials, and employee training can improve recognition. Clear verification procedures and tested incident response then provide additional safeguards when an attack gets through.
The goal is not to expect employees to identify every sophisticated phishing attempt. It is to build a security program where one deceptive message is less likely to become a compromised account, fraudulent transaction, or reportable incident.
Need to strengthen your organization’s phishing defenses? Talk to Terralogic’s cybersecurity experts about assessing your current controls, identifying gaps, and building a layered phishing defense strategy.
Frequently Asked Questions (FAQs)
1. What is a phishing attack?
A phishing attack is a cyberattack in which attackers impersonate trusted individuals, organizations, or services to trick people into revealing information, authorizing transactions, accessing malicious links, or installing malware. Phishing can occur through email, text messages, phone calls, QR codes, and collaboration platforms.
2. What are the types of phishing attacks?
The main types include email phishing, spear phishing, whaling, vishing, smishing, quishing, and collaboration platform phishing. While the delivery method differs, each uses deception to persuade a target to take an action that benefits the attacker.
3. How do you recognize a phishing email?
Look for unexpected urgency, unusual sender addresses, requests for credentials or payments, suspicious links or QR codes, and attempts to bypass normal business processes. Spelling and grammar can still provide clues, but they are less reliable because modern phishing messages can be professionally written and highly personalized.
4. How do you prevent phishing attacks?
Phishing prevention requires multiple layers of protection. Organizations should combine email authentication and security controls with phishing-resistant MFA, security awareness training, verification procedures for high-risk requests, and a tested incident response process.
5. Can MFA stop phishing attacks?
MFA can reduce the risk of account compromise, but some MFA methods can be targeted by Adversary-in-the-Middle attacks that relay authentication sessions. Phishing-resistant authentication, such as FIDO2 security keys and passkeys, provides stronger protection because authentication is bound to the legitimate service.
6. Can a phishing attack trigger compliance requirements?
Yes. If a phishing attack results in unauthorized access to regulated information or creates a material cybersecurity incident, it may trigger notification or disclosure requirements. The specific obligations depend on the organization’s industry, the information affected, and the applicable regulations, such as GDPR, DORA, HIPAA, or SEC requirements.