Key Concepts & Self-Assessment19 Key Facts
Review key Phishing vs Spear Phishing vs Whaling: Social Engineering, Vishing, Smishing & Quishing exam facts and rate your mastery to track revision.
Progress: 0/19 Rated 0 Mastered 0 Review Later
#1
The term Phishing originated in 1995–1996 among hackers using the program AOHell to steal America Online (AOL) dial-up passwords; the "ph" spelling paid homage to early telephone "phreaking" (created by John Draper).
#2
Social Engineering is the psychological manipulation of human beings into breaking normal security procedures and divulging confidential information; phishing is its most prevalent digital delivery vehicle.
#3
Bulk Phishing sends millions of generic, untargeted emails using automated spam botnets, relying on statistical volume (even a 0.1% click rate across 10 million emails compromises 10,000 accounts).
#4
Spear Phishing targets a specific named individual or team (such as a company’s system administrator or HR manager) using customized reconnaissance gathered from social media and public records.
#5
Whaling is a high-profile form of spear phishing directed specifically at senior executives ("big fish" such as the CEO, CFO, or Chief Legal Counsel) to steal trade secrets or authorize fraudulent corporate wire transfers.
#6
Business Email Compromise (BEC)—often paired with Whaling—occurs when an attacker compromises or spoofs a CEO’s or supplier’s email account and instructs the finance department to wire funds to a fraudulent bank account.
#7
Vishing (Voice Phishing) uses fraudulent telephone calls, VoIP caller-ID spoofing, and real-time AI voice-cloning deepfakes to impersonate bank fraud investigators, police officers ("digital arrest" scams), or company executives.
#8
Smishing (SMS Phishing) delivers malicious shortened URLs via mobile text messages or WhatsApp, impersonating electricity boards, traffic challan portals, or income tax refund notifications.
#9
Quishing (QR Code Phishing) embeds malicious phishing URLs inside Quick Response (QR) matrix barcodes; because standard email gateways cannot scan text inside embedded QR images, Quishing bypasses traditional link filters and moves the victim from a protected desktop PC onto an unprotected mobile phone.
#10
Clone Phishing takes a legitimate, previously delivered email containing an attachment or link, makes a nearly identical replica with a malicious link swapped in, and resends it from a spoofed address claiming to be an "updated version."
#11
Pharming differs from phishing because it requires no user click on a fraudulent email link: attackers poison a DNS server cache (DNS cache poisoning) or modify a local hosts file so that typing a genuine bank URL redirects the user transparently to a fake server.
#12
Typosquatting and IDN Homograph Attacks register deceptive look-alike domain names (such as substituting a Cyrillic script "а" for a Latin "a", or "rn" for "m") to fool visual inspection of the browser address bar.
#13
Evil Twin Phishing sets up a rogue Wi-Fi access point mimicking a public airport, hotel, or café hotspot name (SSID) to intercept unencrypted credentials via a fake captive login portal.
#14
Watering Hole Attacks compromise a legitimate third-party industry website frequented by a target group (such as a defence contractors’ forum) and inject exploit scripts to infect visitors automatically.
#15
Angler Phishing uses fake customer-support social media handles on platforms like X (Twitter) or Instagram to reply to frustrated bank customers and trick them into filling out credential-harvesting forms.
#16
To stop attackers from spoofing an organization’s official email domain, mail servers enforce a triad of DNS authentication standards: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance).
#17
Traditional SMS-based One-Time Passwords (OTPs) are vulnerable to Real-Time Man-in-the-Middle (AiTM) reverse-proxy phishing kits (such as Evilginx) and SIM-swap fraud.
#18
FIDO2 / WebAuthn Passkeys and hardware security keys (such as YubiKey) are "phishing-resistant" because the cryptographic login signature is bound mathematically to the exact origin domain URL in the browser—even if a human is tricked by a fake phishing site, the hardware key refuses to release the cryptographic token.
#19
In India, victims of financial phishing, vishing, and UPI fraud can report incidents immediately via the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the toll-free helpline 1930 managed by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.
Subject Specialist Commentary
Analytical perspective & practical exam advice from the Master10 academic board
In UPSC Prelims, Banking (IBPS/SBI PO & SO), and UGC-NET Paper I examinations, questions regularly ask candidates to match specific social engineering variants to their attack mechanisms. Remember the hierarchy of targeting precision: Phishing is untargeted mass-mailing; Spear Phishing is personalized to a specific employee or organization using OSINT; and Whaling targets C-suite executives (CEOs/CFOs) to trigger Business Email Compromise (BEC) wire fraud.
In addition, examinees must distinguish Phishing from Pharming: phishing requires convincing the human user to click a deceptive link or scan a malicious QR code (Quishing), whereas Pharming corrupts the Domain Name System (DNS cache poisoning) so that a user who manually types the exact, legitimate URL of their bank is silently routed to a malicious IP address. On the defense side, understanding the SPF + DKIM + DMARC email authentication triad and FIDO2 passkeys is essential for technical interviews.
Related Knowledge Topics to Discover
Cybersecurity & Digital Safety
Cybersecurity, Cryptography, Malware Threats & Information Technology Act 2000
Explore Topic
Cybersecurity & Digital Safety
How Does Public-Key Encryption Keep Online Communication Secure?
Explore Topic
Cybersecurity & Digital Safety
Quantum Key Distribution: BB84 Protocol, Photon Polarization & Unconditional Cryptographic Security
Explore Topic
Looking for more GK practice?
Explore 52,789+ questions across 65 General Knowledge categories.