The dozens of named phishing techniques become manageable once you group them by the question they answer: who is targeted, through which channel, by what deception, using what technique. Security teams that catalogue their threats this way, the way the MITRE ATT&CK framework treats phishing as one technique with named sub-techniques, can point to exactly which variants they defend against and which they do not.
Spear phishing is aimed at a named individual after some research. Whaling aims that same care at a senior executive, whose access is worth the effort. Business email compromise skips malware entirely: a convincing message, often from a real but hijacked account, asks finance to move money or change bank details. Angler phishing works through fake social-media support accounts that intercept people asking a real brand for help.
Email is only one road. Smishing arrives by SMS, vishing by voice call, and pop-up phishing through fake browser alerts. The fast-rising one is quishing: a QR code, printed on a poster, stuck over a real one in a car park, or embedded in a PDF, that carries the malicious link. The QR code is effective for a simple reason, it moves the attack onto a personal phone, off the managed laptop and past the email gateway, and few people inspect a QR destination the way they now inspect a link. Each channel dodges the controls tuned for the others, which is precisely the point.
Clone phishing copies a genuine message and swaps in a malicious link. HTTPS and deceptive phishing lean on a padlock and a familiar logo to borrow trust, and look-alike domains, whether a typo the eye skips over (micosoft.com, paypa1.com, the craft of typosquatting) or internationalised characters that render like Latin letters, make the fake address pass a glance. On the network side, pharming and website spoofing send you to a convincing fake, an evil twin Wi-Fi network sits between you and the internet, and a watering hole poisons a site the target already trusts.
The technique that has changed the game is adversary-in-the-middle. Instead of stealing a password to use later, the attacker puts a proxy between you and the real login page. You type your password and your one-time code into a page that looks right; the proxy relays both to the genuine service in real time, the login succeeds, and the attacker keeps the resulting session token. Your multi-factor prompt worked perfectly, for them. Toolkits like Evilginx have made this routine.
This is why “we have MFA” is no longer a complete answer. The defence is phishing-resistant MFA, passkeys or hardware security keys, which are bound to the real domain and cannot be relayed to a proxy.
Theory sticks better against a real specimen. Below is an actual phishing email received in August 2026, impersonating the Belgian tax administration, recreated and clearly marked. It is a small masterclass: a believable shell, a trivial amount, and six tells for anyone who slows down.
david@aldrich.org.uk. A Belgian public service never writes from a random .org.uk domain. This one line settles it before you read a word.&eu ro;12,00, a mangled € HTML entity. The kit was assembled carelessly; a real administration tests its emails.arweave.net, not to fgov.be. Hover before you click, always.Not one of the six needed technical skill to catch. That is the encouraging part: most phishing, even polished phishing, fails the same short checklist, sender, urgency, amount, link.
Every framework you answer to treats awareness and social-engineering resilience as a control, and every one expects you to show it works. A named taxonomy is what makes that provable: you can state which techniques your training covers, which your simulations test, and which remain a gap, rather than reporting a single vague “phishing awareness” line. In risk terms, your people are an asset with a criticality and an owner, and the human attack surface deserves the same structured treatment as the technical one. “We ran a phishing test” is an activity. “We cover these techniques, test these, and accept this residual” is a control an auditor can read.
The technique names here map to MITRE ATT&CK T1566 (Phishing) and its sub-techniques; the wider family is documented on Wikipedia.
In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.