What Is Phishing?
Phishing is a social engineering attack where someone impersonates a trusted person or organization to trick a victim into handing over credentials, financial data, or system access – usually by clicking a malicious link, opening a weaponized attachment, or just replying with the information directly.
It’s not a technical exploit. There’s no flaw being patched or signature being written. The attack surface is the person reading the message, and the payload is trust: a spoofed bank, a fake IT ticket, a familiar name in the “From” field.
The Phishing Family Tree
“Phishing” gets used two ways, and the exam wants you to separate them:
- Phishing (the umbrella term) – any social-engineering attack that lures a victim through a fake message, regardless of channel.
- Phishing (the specific channel) – mass, generic email lures sent to as many inboxes as possible, banking on volume rather than personalization.
Underneath that umbrella sit the channel- and target-specific variants: vishing (voice), smishing (SMS), and whaling (a spear-phishing attack aimed at executives). Spear phishing itself – a phishing email personalized to one target – is the bridge between generic phishing and whaling.
How a Phishing Attack Plays Out
- Target selection – mass campaigns blast a purchased or scraped list; targeted campaigns (spear phishing, whaling) research one person or role first.
- Pretext crafted – the attacker builds a believable story: a locked account, an overdue invoice, a CEO’s urgent wire request.
- Delivery – the lure goes out over email, text (smishing), or a phone call (vishing), often spoofing a sender address, domain, or caller ID.
- The hook – urgency and fear (“your account will be suspended”) or curiosity and authority (“see attached invoice”) push the victim to act before verifying.
- The ask – click a link to a spoofed login page, open an infected attachment, or reply with credentials, a payment, or gift card codes.
- Compromise – the attacker now has credentials, a foothold on the device, or the money – and often uses that access to pivot further inside the organization.
Phishing vs. Vishing vs. Smishing vs. Whaling (the distinction that trips people up)
All four rely on the same trust-and-urgency playbook. What changes is the channel and how narrowly the target is chosen – and that’s exactly the distinction the exam tests:
| Trait | Phishing | Vishing | Smishing | Whaling |
|---|---|---|---|---|
| Channel | Phone call / voice | SMS / text message | Email (or phone) | |
| Targeting | Broad – mass-sent | Broad or targeted | Broad – mass-sent | Narrow – executives/high-value targets |
| Primary lure | Fake account/security alert | Live urgency, spoofed caller ID | Delivery or account alert with a link | Impersonated executive or vendor request |
| Real example | 2016 DNC email breach that fooled campaign chair John Podesta | 2020 Twitter VIP account hijack via phone calls to employees | Widespread “your package is delayed” delivery-scam texts | Ubiquiti Networks lost $46.7M to a spoofed executive wire request (2015) |
| Primary defense | Email filtering, link inspection, MFA | Caller verification via a known-good number, never confirm data on an inbound call | Don’t tap unexpected links; verify via the official app/site | Out-of-band callback verification for any payment or credential request |
Bottom line: Phishing is the umbrella and the default (email) channel. Vishing moves the same trick to a phone call, smishing moves it to a text, and whaling keeps email but narrows the target to someone with real authority to move money or grant access. Calling every one of these “just phishing” is technically fine in casual speech – but the exam wants you to name the channel and targeting precisely.
Real-World Examples
- 2016 DNC email breach – Attackers sent a spoofed Google security-alert email to campaign chairman John Podesta. He clicked the “change your password” link, entered his real credentials into a fake page, and handed over years of email – a textbook mass-style phishing lure that worked because it looked routine.
- Twitter VIP account hijack (2020) – Attackers called Twitter employees, posing as internal IT support, and talked their way into credentials that gave access to internal tools – a vishing campaign that ended with dozens of high-profile accounts (including Barack Obama’s and Elon Musk’s) posting a cryptocurrency scam.
- Ubiquiti Networks whaling attack (2015) – Finance employees received emails impersonating a senior executive requesting an urgent wire transfer. The company lost $46.7 million before catching it – one of the largest publicly disclosed whaling/BEC losses on record.
Indicators and Detection
Since there’s no malware signature to catch until after the click, detection leans heavily on spotting the lure itself:
- Mismatched sender domain – the display name says “PayPal” but the actual address doesn’t match PayPal’s domain.
- Urgency and fear language – “your account will be locked in 24 hours,” “immediate action required.”
- Generic or slightly-off greetings – “Dear Customer” instead of your name, or a name misspelled.
- Links that don’t match their destination – hovering shows a URL that doesn’t match the supposed sender.
- Unexpected attachments – invoices, shipping notices, or “resumes” you didn’t ask for.
- Requests for credentials, gift cards, or wire transfers – legitimate organizations don’t ask for passwords by email, and finance shouldn’t move money off a single email request.
- Spoofed caller ID or unexpected texts – the vishing/smishing equivalent of a spoofed sender address.
How to Defend Against Phishing
You can’t patch human trust, so phishing defense is layered between technology and behavior:
- Email filtering / secure email gateway (SEG) – blocks known bad senders, domains, and attachment types before they reach the inbox.
- DMARC, SPF, and DKIM – authentication standards that make sender-domain spoofing much harder to pull off convincingly.
- Multi-factor authentication (MFA) – even if credentials are phished, a second factor can stop the login.
- Security awareness training and simulated phishing campaigns – the highest-leverage control, since the target is the person, not the network.
- Out-of-band verification – for any request involving money, credentials, or access changes, confirm through a separate, known-good channel (call the number on file, not the one in the message).
- Link and attachment sandboxing – detonates suspicious links/files in isolation before a user can reach them.
Frequently Asked Questions
What’s the difference between phishing and spear phishing? Phishing is broad and generic – the same message sent to thousands of inboxes. Spear phishing is personalized to one target, using details like their name, employer, or recent activity to seem more credible.
What is whaling in cybersecurity? Whaling is spear phishing aimed specifically at executives or other high-value targets, usually impersonating a senior leader or vendor to authorize a payment or gain access – the Ubiquiti Networks attack is a well-known example.
Is vishing the same as phishing? Vishing (voice phishing) uses the same trust-and-urgency tactics as email phishing, but over a phone call instead – often with a spoofed caller ID posing as a bank, IT support, or law enforcement.
How can I tell if a text message is smishing? Be suspicious of unexpected delivery, banking, or account alerts containing a link, especially ones creating urgency. Verify directly through the official app or website instead of tapping the link.
Can phishing emails bypass spam filters? Yes. Well-crafted phishing emails use legitimate-looking domains, no malicious attachments, and personalized content to slip past filters – which is why user awareness remains a critical layer of defense.
Key Takeaway
Phishing is a trust attack, not a technical exploit – the “vulnerability” is a person under time pressure, and there’s no patch for that. Vishing, smishing, and whaling are the same play run through a different channel or aimed at a higher-value target, and the exam wants you to name each precisely rather than lump them together. Because no single control stops all of it, defense is layered: email authentication and filtering to reduce volume, MFA to blunt stolen credentials, and – the highest-leverage habit – trained users who verify unexpected requests through a separate, known-good channel before they act.
Read each scenario and pick what it actually is.
Security+ Exam Focus
- Exam: CompTIA Security+ (SY0-701)
- Domain: 2.0 – Threats, Vulnerabilities, and Mitigations
- Objective: 2.2 – Explain common threat vectors and attack surfaces (Human vectors/social engineering)
- What they test: Naming phishing’s channel-specific variants correctly (vishing, smishing, whaling), recognizing the lifecycle/lure pattern, and matching defenses (MFA, awareness training, out-of-band verification) to the human-vector attack surface.
Related Notes
- What Is Vishing? – the phone-call variant of phishing
- What Is Smishing? – phishing delivered by text message
- What Is Business Email Compromise? – whaling’s usual end goal
- What Is Pretexting? – the fabricated story behind many phishing lures
- What Is a Zero-Day Vulnerability? – phishing is a common delivery vehicle for exploits
Additional Resources
For the full Security+ note set, visit our main Sec+ page. For walkthroughs, see our YouTube channel.

