{"id":715,"date":"2020-03-09T11:49:00","date_gmt":"2020-03-09T11:49:00","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=715"},"modified":"2020-11-20T18:31:34","modified_gmt":"2020-11-20T18:31:34","slug":"common-types-of-phishing-attacks-how-to-recognize-avoid-them","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/","title":{"rendered":"5 Common Types of Phishing Attacks \u2014 How to Recognize &#038; Avoid Them"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Whether they\u2019re financially or politically motivated, different types of\nphishing attacks remain the number one point of compromise in 91% of\ncyberattacks. <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s probably weird to still be talking about types of phishing in 2020, but, hey, phishing attacks remain the top malware infection vector. Yep, you read that right! Phishing attacks retain their top position, according to&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/docs.apwg.org\/reports\/apwg_trends_report_q3_2019.pdf\" target=\"_blank\">APWG\u2019s Phishing Activity Trends Report for Q3 2019<\/a>. And, unfortunately, there are so many types of phishing to choose from.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some people (and companies), never learn, so not only is\nphishing the most successful attack method to date, it takes hackers zero\neffort to get it done. Sure, there are different types of phishing, some more\nsophisticated than others and with different motivations, but they all rely on\npsychological manipulation. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing has been the preferred method of countless criminals\nbecause it\u2019s incredibly easy to deploy, yet very effective in gaining\nunauthorized access to critical information. While some may feel confident that\ntheir firewall will keep them safe, phishing actually gets past traditional\nsecurity solutions because social engineering enables cybercriminals to\nmanipulate their victims into revealing sensitive information about themselves\nor their organizations, including their credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It doesn\u2019t take a genius to launch a phishing attack.\nPhishing kits can easily be bought online and used to spoof websites or collect\ndevice information (in addition to the typical personal information). The most\ncommon kits will spoof email providers or file storage services. Some scammers\nwill just use social media to pose as customer support to steal financial\ninformation. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Do Different Types of Phishing Work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The answer to this question depends on the type of phishing you\u2019re talking about specifically. It\u2019s good to keep an eye on what\u2019s in your inbox because scammers are continually improving their skills and tactics. Phishing has evolved from the traditional campaigns most are probably familiar with, and, unfortunately, they\u2019re getting harder to detect even for the most tech-savvy individuals. Just recently, fraudsters sent out a smishing scam<a href=\"https:\/\/www.howtogeek.com\/657333\/watch-out-this-verizon-smishing-scam-is-crazy-realistic\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\"> impersonating Verizon Wireless asking users to verify account security<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A phishing attack will always try to manipulate you into\ntaking an action or revealing critical information. The goal for cybercriminals\nis to trigger an emotional or inquisitive reaction out of their victims. For\nexample, they\u2019ll use urgent or emotionally charged language to get you to\nengage with their email in some way. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some examples of conventional phishing emails include: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Messages from your bank or credit card company;<\/li><li>Emails about student loans;<\/li><li>A potential employer reaching out for an updated\nresume that includes your Social Security Number;<\/li><li>The IRS enquiring about tax returns; or<\/li><li>A shipping company, if you work in a department\nthat does a lot of operational work.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What Are Some of the Main Types of Phishing Attacks?<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"456\" height=\"340\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-example.png\" alt=\"\" class=\"wp-image-716 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-example.png 456w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-example-300x224.png 300w\" sizes=\"auto, (max-width: 456px) 100vw, 456px\" \/><figcaption>Graphic: <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-phishing-email-5-examples-of-phishing-emails-and-how-to-avoid-them\/\">Example of phishing email<\/a> impersonating a bank, Source: Wikimedia Commons (https:\/\/commons.wikimedia.org\/wiki\/File:PhishingTrustedBank.png)<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing is a social engineering scheme that uses different types of email attacks, malicious websites or apps, text messages and even phone calls to psychologically manipulate a user into revealing personal information or critical data about the organization. Unless the accounting department is hit \u2014 then a ridiculously high money transfer will likely make its way into a bank account on some paradise island! <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some of the most popular types of phishing attacks are spear phishing, vishing, <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-smishing-definition-examples-protection-tips\/\" target=\"_blank\" rel=\"noreferrer noopener\">smishing<\/a>, whaling, HTTPS phishing and business email compromise (BEC). Many types of phishing attacks are launched to spread ransomware, which is malicious software that encrypts your data and will hold it hostage until you pay a ransom in cryptocurrency. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s explore five of the most common types of phishing\nattacks:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HTTPS Phishing Attacks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With <strong>HTTPS (Hypertext Transfer Protocol Secure) phishing<\/strong>, hackers have figured out a way to trick users into believing that a website is legitimate. They will rely on users\u2019 misconceptions that the page is encrypted and secure simply because it displays HTTPS and the green padlock symbol. But today, even<strong> <a href=\"https:\/\/sectigostore.com\/blog\/phishing-statistics-phishing-stats-to-help-avoid-getting-reeled-in\/\">phishing websites can use the HTTPS protocol<\/a><\/strong> (i.e. incorporate website certificates) in the browser address bar to win user trust. The user will then easily fill out a form, for example, and give away their credentials or other sensitive information. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"632\" height=\"535\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/https-phishing-example.png\" alt=\"Graphic: HTTPS phishing example from an email\" class=\"wp-image-735 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/https-phishing-example.png 632w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/https-phishing-example-300x254.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/https-phishing-example-560x474.png 560w\" sizes=\"auto, (max-width: 632px) 100vw, 632px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Last year, the <a href=\"https:\/\/www.ic3.gov\/media\/2019\/190610.aspx\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">FBI warned users<\/a> that just because a website starts with HTTPS, it doesn\u2019t mean it guarantees privacy and security. The FBI recommends being suspicious of unknown senders, especially if their email address ends in .com when it should be .gov, and looking out for misspelled words. Cybersecurity company Trend Micro <a href=\"https:\/\/www.trendmicro.com\/vinfo\/hk-en\/security\/news\/cybercrime-and-digital-threats\/https-protocol-now-used-in-58-of-phishing-websites\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">reported<\/a> last year that the types of phishing using digital certificates to encrypt connections spiked to 58% in Q1 of 2019, and they are on the rise. A <a href=\"https:\/\/docs.apwg.org\/reports\/apwg_trends_report_q3_2019.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Q3 2019 report<\/a> from the Anti-Phishing Working Group (APWG) estimates that the number is actually higher \u2014 68%! <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Business Email Compromise Attacks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Business Email Compromise<\/strong>, also known as email\naccount compromise (EAC) is a type of phishing attack in which a cybercriminal\nimpersonates corporate executive management to trick employees (typically in\neither Human Resources or accounting) into authorizing a wire transfer payment,\nor sharing personally identifiable information (PII) or tax information. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FBI has reported that <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.zdnet.com\/article\/fbi-bec-scams-accounted-for-half-of-the-cyber-crime-losses-in-2019\/\" target=\"_blank\">BEC scams represented half of the 467,361 cybercrime losses reported in 2019<\/a>, accounting for $1.77 billion. Other <a href=\"https:\/\/www.ic3.gov\/media\/2019\/190910.aspx\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">FBI statistics<\/a> report a high number of complaints regarding spoofed emails, which impersonate an employee asking for direct deposit account changes, with a lot of the funds primarily heading to banks in China and Hong Kong, as well as the United Kingdom, Mexico and Turkey.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to appear legitimate and steal employee credentials, these types of phishing attacks that involve a payroll diversion scheme may include a spoofed login page for an email host. According to victim complaints received by the FBI between June 2016 and July 2019, the domestic and international exposed dollar loss exceeded $26 billion. In 2019, Facebook and Google were <a href=\"https:\/\/www.npr.org\/2019\/03\/25\/706715377\/man-pleads-guilty-to-phishing-scheme-that-fleeced-facebook-google-of-100-million\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">defrauded<\/a> of over $100 million in a sophisticated scheme.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Spear Phishing Attacks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Spear phishing attacks<\/strong> are not your average scam.\nThese are targeted types of phishing, tailored and researched to appear\ngenuine. Technology and social media have been of great help in victim research\nto devise personalized and compelling email attacks. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As many as <a href=\"https:\/\/www.thesslstore.com\/blog\/80-eye-opening-cyber-security-statistics-for-2019\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">91% of cyberattacks<\/a>&nbsp;start with a spear phishing email, and they are often successful in manipulating key employees in an organization\u2019s HR, finance, legal or IT departments to share their credentials or click on a link that will download malware into the system. The email could appear as a LinkedIn notification, an urgent request from a team member or a manager, or even an urgent email from an institution. Top companies such as <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/spear-phishing-101-what-is-spear-phishing\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">JP Morgan, Home Depot, and Target<\/a> have been breached following spear phishing attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Whaling Attacks <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Whaling attacks<\/strong> are similar to spear phishing attacks,\nonly they are more specific and target c-level executives or high-ranking individuals\nwith authority who have access to critical information or even wealth. Because\nwhaling emails involve extensive research to deceive the victim into believing\nthe message is legitimate, criminals engaging in these types of phishing\nattacks can be very patient in achieving their financial gain. Whaling emails\nare specific and include very personal details to convince the victim to engage\nwith the call to action. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Voice Phishing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Vishing <\/strong>is just a fancy term for <strong>voice phishing <\/strong>or\nphone fraud<strong>.<\/strong> Whenever you get a pre-recorded message from the IRS or from\nyour bank asking you to call a number and give away your credit card\ninformation or Social Security Number, you\u2019re looking at a well-crafted\nphishing attempt. Recently scammers have started combining voice with text\nmessages (<strong>smishing<\/strong>) to make the scam appear more legitimate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security expert Brian Krebs warned on his blog that <a href=\"https:\/\/krebsonsecurity.com\/2018\/10\/voice-phishing-scams-are-getting-more-clever\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">voice phishing scams are getting smarter<\/a>. Based on his friend\u2019s experience, he says fake phone calls from credit unions or the tax department have become so sophisticated that the details mentioned by the criminal frequently make sense. The calls appeared made from trustworthy numbers, yet we know by now how easy it is for criminals to spoof the caller ID number.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The list goes on, as there are many other types of phishing\nattacks such as clone phishing, domain spoofing, evil twin, and watering hole\nphishing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Types of Phishing Motivations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some <a href=\"https:\/\/sectigostore.com\/blog\/phishing-statistics-phishing-stats-to-help-avoid-getting-reeled-in\/\">30% of all phishing emails<\/a> are opened by targeted users. Most data breaches have started either from the use of a weak password or from a phishing attack that exploited an <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.csoonline.com\/article\/2130877\/the-biggest-data-breaches-of-the-21st-century.html\" target=\"_blank\">employee\u2019s behavior<\/a>. If we take a closer look at statistics, some type of phishing email was behind <a href=\"https:\/\/sectigostore.com\/blog\/phishing-statistics-phishing-stats-to-help-avoid-getting-reeled-in\/\">78% of cyber espionage episodes<\/a> and more than 95% of attacks in general start with a phishing email. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A phishing attack will go after information such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>usernames and passwords, <\/li><li>emails and contacts\u2019 information, <\/li><li>personal information that can be used to create\nfake accounts and for identity theft, <\/li><li>proprietary corporate information or tech\ndetails,<\/li><li>sensitive information to use for tax fraud, and<\/li><li>medical records or health insurance details. <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">While some types of phishing attacks are financially motivated,\nit\u2019s not always the case. Some phishing is done with the goal of performing\ncyber espionage, while others are politically motivated. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Financially Motivated Phishing Attacks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">According to Verizon\u2019s <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/dbir\/\" target=\"_blank\">2019 Data Breach Investigation Report (DBIR)<\/a>, 71% of attacks, including phishing attacks, were financially-motivated. Financial gain remains a top motivation \u2014 especially in attacks targeting c-level executives who are more likely to click on urgent emails and have authority to make money transfers, says the report. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Cyber Espionage-Motivated Phishing Attacks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Intellectual property and sensitive data are among the top targets for different types of phishing attacks. Nation-state backed cybercriminal gangs are supported by Russia, China, Iran and North Korea. They target Western companies and governments with spear phishing emails to execute malicious payloads and steal critical, proprietary information, according to <a href=\"https:\/\/www.zdnet.com\/article\/hacking-and-cyber-espionage-the-countries-that-are-going-to-emerge-as-major-threats-in-the-2020s\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">ZDNet<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just recently, Iran-sponsored hackers <a href=\"https:\/\/www.cyberscoop.com\/iran-espionage-muddywater-secureworks\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">targeted government organizations in Turkey, Jordan and Iraq<\/a> with spear phishing attacks to steal intellectual property.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Politically Motivated Phishing Attacks<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Emails impersonating government authorities have claimed many victims. However, likely the most notorious politically motivated spear phishing attack was launched by Russian-backed hackers against the U.S. Democratic party during the 2016 election to <a href=\"https:\/\/www.phishprotection.com\/blog\/mueller-report-unravels-politically-motivated-spear-phishing-cyber-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">steal information about the Clinton campaign<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of which type of phishing attacks cybercriminals\nuse, it\u2019s imperative that you and your employees know how to recognize them for\nwhat they are.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Identify Most Types of Phishing Attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most common types of phishing attacks rely on an email that\u2019s configured to steal sensitive information by manipulating the victim into clicking on an infected link or downloading <a href=\"https:\/\/sectigostore.com\/blog\/different-types-of-malware\/\">disguised malware<\/a>. If the malware gets into the system, it will scan the device for vulnerabilities and it will compromise the system, network and potentially any devices linked to it.&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to recognizing phishing, it often boils down\nto knowing what to look for. Some immediate red flags that you might be looking\nat a phishing scam include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>The sender\u2019s email address<\/strong>. Double check\nthe sender\u2019s email address, as well as the domain and the URL the links in the\nemail are pointing to. <\/li><li><strong>Unexpected requests for personal or sensitive\ninformation.<\/strong> All of a sudden, a well-known, trustworthy company or\ninstitution contacts you, asking you to provide personal or sensitive information.<\/li><li><strong>Language that elicits an emotional reaction\nor sense of urgency.<\/strong> The message provokes some sort of emotion, ranging\nfrom fear and excitement to a sense of urgency. It may try to get you to pay a\nbill or take another immediate action.<\/li><li><strong>Urgent request from upper management. <\/strong>Your\nmanager or CEO has sent an email suddenly asks you to immediately pay an\ninvoice or open a document of critical importance.<\/li><li><strong>Poor language and too many information errors.\n<\/strong>Something seems off.The sender makes grammar and spelling mistakes;\nthe logo looks off; there are typos in the email address or in the person\u2019s\nname; or, worse, you have no idea who is this person sending you an invoice for\nimmediate pay. <\/li><li><strong>Website asking for private information.<\/strong> A\nwebsite asking for critical personal information such as passwords, credit card\nnumbers, social security number and bank account numbers should be considered\nsuspicious, even though it looks legitimate. <\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How Can You Avoid Phishing?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing messages were so much easier to spot a couple of\nyears ago. The rare times anyone ever paid attention, they would have probably\nnoticed a typo in the email or in the sender\u2019s name, some grammar mistakes here\nand there or a big fake logo at the top \u2014 but scammers are improving their\ncraft. Manipulative emails and spoofed websites are getting harder and harder\nto tell apart from their genuine counterparts. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some top pointers to stay away from the different\ntypes of phishing attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Security awareness training for employees. <\/strong>Awareness\nworkshops can help employees better understand the risks and educate them on\ninbox threat detection and email best practices.<\/li><li><strong>Double check urgent emails.<\/strong> When you\nreceive a money transfer request from the CEO but something about it makes it\nseem suspicious, double check that it is legitimate by personally reaching out\nto the person in question.<\/li><li><strong>Email signing certificates (S\/MIME&nbsp;certificates).\n<\/strong>Digital signatures confirm the sender\u2019s authenticity and message integrity;\nemail encryption protects messages in transit and when sitting on email servers.\n<\/li><li><strong>Email authentication methods.<\/strong> DMARC (Domain-based\nMessage Authentication, Reporting &amp; Conformance) and DKIM (DomainKeys\nIdentified Mail) are email authentication protocols that fend off different\ntypes of targeted email attacks. Without these protocols, criminals can spoof a\ndomain and send malicious emails.<\/li><li><strong>Activate two-factor authentication (2FA) and multi-factor\nauthentication (MFA) measures. <\/strong>Not only does using one of these methods\nprotect your device from password compromise, but it can also be used to secure\nwire transfers.<\/li><li><strong>Develop, implement, and enforce computer use\nand BYOD security policies.<\/strong> Now that BYOD (bring your own device) has\nbecome a way of life, it\u2019s good to get some more transparency into which\ndevices are connecting to the work network.<\/li><li><strong>Ensure patching and updates are all up to\ndate<\/strong>. A large organization will have a high number of devices that run\ndifferent software versions. Regularly run software updates and patches for\noperating systems to prevent vulnerability exploits in case of a successful\nphishing attack.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The different types of phishing attacks will likely maintain\nits top-ranking position because this form of attack is very practical and has\na high success rate. Relying on targeted research and psychological\nmanipulation, cybercriminals are going to continue to trick users into\nrevealing personal information that they can manipulate for their own purposes.\nDepending on the different types of phishing, some emails can be hard to figure\nout, which is why security workshops alongside effective security measures\ncould help reduce the risk of phishing scams being successful. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don\u2019t allow yourself or your employees to get hooked. Teach\nthem how to recognize the types of phishing threats that we face today to help\nprepare them for new types of attacks that may come out tomorrow or in the near\nfuture.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Whether they\u2019re financially or politically motivated, different types of phishing attacks remain the number one point of compromise in 91% of cyberattacks. It\u2019s probably weird to still be talking about&#8230;<\/p>\n","protected":false},"author":13,"featured_media":718,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13],"tags":[30],"class_list":["post-715","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-phishing","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>5 Common Types of Phishing Attacks \u2014 How to Recognize &amp; Avoid Them - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"Wondering what some of the most common types of phishing attacks are and how to recognize them? We&#039;ll break all of that down for you &amp; how to avoid them.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"5 Common Types of Phishing Attacks \u2014 How to Recognize &amp; Avoid Them - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"Wondering what some of the most common types of phishing attacks are and how to recognize them? We&#039;ll break all of that down for you &amp; how to avoid them.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-09T11:49:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-11-20T18:31:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Luana Pascu\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/Luana_Pascu\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Luana Pascu\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/\"},\"author\":{\"name\":\"Luana Pascu\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/cf4b717d5a781a71c9e27c6349113468\"},\"headline\":\"5 Common Types of Phishing Attacks \u2014 How to Recognize &#038; Avoid Them\",\"datePublished\":\"2020-03-09T11:49:00+00:00\",\"dateModified\":\"2020-11-20T18:31:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/\"},\"wordCount\":2500,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/types-of-phishing-attacks.jpg\",\"keywords\":[\"phishing\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/\",\"name\":\"5 Common Types of Phishing Attacks \u2014 How to Recognize & Avoid Them - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/types-of-phishing-attacks.jpg\",\"datePublished\":\"2020-03-09T11:49:00+00:00\",\"dateModified\":\"2020-11-20T18:31:34+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/cf4b717d5a781a71c9e27c6349113468\"},\"description\":\"Wondering what some of the most common types of phishing attacks are and how to recognize them? We'll break all of that down for you & how to avoid them.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/types-of-phishing-attacks.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/types-of-phishing-attacks.jpg\",\"width\":1600,\"height\":1000,\"caption\":\"Graphic illustrating types of phishing attacks with a lock on a hook over a keyboard\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"5 Common Types of Phishing Attacks \u2014 How to Recognize &#038; Avoid Them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/cf4b717d5a781a71c9e27c6349113468\",\"name\":\"Luana Pascu\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g\",\"caption\":\"Luana Pascu\"},\"description\":\"Luana is a contributor to InfoSec Insights. She is a Toronto-based writer focused on cybersecurity, data privacy, IoT, biometrics and edge computing. Luana is passionate about technology and writes for a number of industry publications.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/luanapascu\\\/\",\"https:\\\/\\\/x.com\\\/https:\\\/\\\/twitter.com\\\/Luana_Pascu\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"5 Common Types of Phishing Attacks \u2014 How to Recognize & Avoid Them - InfoSec Insights","description":"Wondering what some of the most common types of phishing attacks are and how to recognize them? We'll break all of that down for you & how to avoid them.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/","og_locale":"en_US","og_type":"article","og_title":"5 Common Types of Phishing Attacks \u2014 How to Recognize & Avoid Them - InfoSec Insights","og_description":"Wondering what some of the most common types of phishing attacks are and how to recognize them? We'll break all of that down for you & how to avoid them.","og_url":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/","og_site_name":"InfoSec Insights","article_published_time":"2020-03-09T11:49:00+00:00","article_modified_time":"2020-11-20T18:31:34+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg","type":"image\/jpeg"}],"author":"Luana Pascu","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/Luana_Pascu","twitter_misc":{"Written by":"Luana Pascu","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/"},"author":{"name":"Luana Pascu","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/cf4b717d5a781a71c9e27c6349113468"},"headline":"5 Common Types of Phishing Attacks \u2014 How to Recognize &#038; Avoid Them","datePublished":"2020-03-09T11:49:00+00:00","dateModified":"2020-11-20T18:31:34+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/"},"wordCount":2500,"commentCount":0,"image":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg","keywords":["phishing"],"articleSection":["Cyber Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/","url":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/","name":"5 Common Types of Phishing Attacks \u2014 How to Recognize & Avoid Them - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg","datePublished":"2020-03-09T11:49:00+00:00","dateModified":"2020-11-20T18:31:34+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/cf4b717d5a781a71c9e27c6349113468"},"description":"Wondering what some of the most common types of phishing attacks are and how to recognize them? We'll break all of that down for you & how to avoid them.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/03\/types-of-phishing-attacks.jpg","width":1600,"height":1000,"caption":"Graphic illustrating types of phishing attacks with a lock on a hook over a keyboard"},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/common-types-of-phishing-attacks-how-to-recognize-avoid-them\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"5 Common Types of Phishing Attacks \u2014 How to Recognize &#038; Avoid Them"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/cf4b717d5a781a71c9e27c6349113468","name":"Luana Pascu","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/dfdee0b9b7182fa2d8e5a50ce123cde7199e5be52c7eca2acc63387b28c84225?s=96&d=mm&r=g","caption":"Luana Pascu"},"description":"Luana is a contributor to InfoSec Insights. She is a Toronto-based writer focused on cybersecurity, data privacy, IoT, biometrics and edge computing. Luana is passionate about technology and writes for a number of industry publications.","sameAs":["https:\/\/www.linkedin.com\/in\/luanapascu\/","https:\/\/x.com\/https:\/\/twitter.com\/Luana_Pascu"]}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=715"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/715\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/718"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}