The attack types below share one thing: none of them exploit a technical
vulnerability. They exploit the fact that a person was expecting a message
roughly like this one.
Phishing
Email that impersonates someone the recipient already trusts.
Still the entry point for the majority of breaches, and no longer recognisable by bad spelling. Modern lures replicate real internal systems and arrive into a context the recipient was already expecting.
Smishing
SMS phishing, landing on the device people trust most.
Your email security investment offers no protection here at all. Text messages carry an assumption of legitimacy that email lost years ago, and they arrive on personal devices outside any managed estate.
Quishing
QR codes that carry the payload past every filter.
A QR code is an image, so it passes link scanning untouched, and the destination is invisible until the phone has already opened it. Printed codes placed in real premises are the hardest variant to detect.
Deepfake & voice cloning
A familiar face or voice, synthesised on demand.
A few seconds of public audio is enough to clone a voice convincingly. Verification procedures that rely on recognising a colleague on a call no longer hold, and staff need a different test.
Business email compromise
A real invoice, a real supplier, altered bank details.
The highest-value attack per incident, and the quietest. It usually begins with one compromised or spoofed mailbox and ends with a legitimate-looking payment leaving on schedule.
AI-assisted campaigns
Targeted quality, at untargeted volume.
Generative tools removed the trade-off between how tailored a lure is and how many people receive it. Every recipient can now get a message written for them specifically, at the cost of a generic one.