FlashGenius Logo FlashGenius
CompTIA Security+ Visual Study Guide

Phishing vs Spear Phishing vs Whaling vs Smishing vs Vishing

These five social engineering terms are closely related, which is why they are commonly tested on Security+. The key is to identify whether the message is broad or targeted, whether the victim is a high-value executive, and whether the attack arrives by email, text message, or phone call.

CompTIA Security+ infographic comparing phishing, spear phishing, whaling, smishing, and vishing

Fastest way to tell these attack types apart

Start with the targeting level and communication channel. Generic bulk attack? Think phishing. Personalized attack? Think spear phishing. Executive-focused spear phishing? Think whaling. Comes by text? Smishing. Comes by phone or voicemail? Vishing.

Phish = Broad
Spear = Targeted
Whale = Executive
Smish = Text
Vish = Voice

Phishing vs spear phishing vs whaling vs smishing vs vishing

Attack type Main idea Typical channel Targeting level Key exam clue
Phishing Generic fraudulent message Usually email Broad / mass Bulk fake email sent to many users
Spear phishing Targeted and personalized phishing Usually email, sometimes other channels Specific person or team Uses personal or company details to appear believable
Whaling Executive-focused spear phishing Email or executive business communication Executives / high-value targets Target is a CEO, CFO, or senior leader
Smishing Text-message phishing SMS / text Broad or targeted mobile users Message arrives by text
Vishing Voice-call phishing Phone call / voicemail Broad or targeted phone users Attack happens by phone

1. Phishing: the broad, generic version

Phishing usually refers to a broad fraudulent message sent to many recipients. The attacker pretends to be a trusted organization, brand, or service in order to steal credentials, install malware, or obtain sensitive information.

Common clue

If the scenario describes a mass email blast sent to many users, phishing is the best answer.

2. Spear phishing: more targeted and personal

Spear phishing is still phishing, but it is tailored to a specific person, team, or organization. The attacker often researches the target and includes personalized details to increase credibility and improve the chance of success.

Common clue

If the message references a person's manager, department, job title, internal project, or other customized detail, think spear phishing.

3. Whaling: spear phishing aimed at executives

Whaling is a specialized form of spear phishing that targets senior executives or other high-value individuals. These attacks often involve urgent business instructions, fake legal requests, or fraudulent financial approvals.

Common clue

If the scenario targets a CEO, CFO, president, or other executive, whaling is usually the best answer.

4. Smishing and vishing: same idea, different channels

Smishing and vishing are both channel-specific forms of phishing. Smishing happens through SMS or text messages. Vishing happens through phone calls or voicemail. The goal is the same: trick the victim into clicking, revealing, approving, or sending something they should not.

Common clue

If the attack comes by text, choose smishing. If it comes through a live call, robocall, or voicemail, choose vishing.

Common CompTIA Security+ exam traps

  1. All spear phishing is phishing, but not all phishing is spear phishing.
  2. Whaling is a type of spear phishing. It specifically targets executives or other high-value individuals.
  3. Smishing = SMS/text. Vishing = voice/call.
  4. Personalization is a big clue. If the question mentions research, names, departments, or internal details, think spear phishing.
  5. Channel matters. Security+ often expects you to classify the attack by how it was delivered.

Mini Security+ scenarios

Scenario 1:

Thousands of employees receive an email claiming their corporate mailbox will be disabled unless they log in through a provided link.

Best answer: Phishing
Scenario 2:

An employee receives a message that uses their name, manager's name, and recent project details to request a login verification.

Best answer: Spear phishing
Scenario 3:

The CFO receives an urgent message requesting approval for a wire transfer to a new vendor account.

Best answer: Whaling
Scenario 4:

A user gets a text saying package delivery failed and is told to tap a link to reschedule delivery.

Best answer: Smishing
Scenario 5:

A caller claims to be from the bank's fraud department and pressures the victim to share a verification code over the phone.

Best answer: Vishing

A simple decision framework for exams

When you see a social engineering question, ask these five questions:

  1. Is it broad and generic? → Phishing
  2. Is it personalized to a specific person or team? → Spear phishing
  3. Is the target an executive or other high-value leader? → Whaling
  4. Does it arrive by text? → Smishing
  5. Does it happen by phone or voicemail? → Vishing

This method helps you avoid overthinking. Most Security+ questions include an obvious clue in the wording, the delivery channel, or the type of victim being targeted.

Frequently asked questions

What is the difference between phishing and spear phishing?

Phishing is usually a mass fraudulent message sent to many users. Spear phishing is more targeted and personalized for a specific victim or group.

Is whaling different from spear phishing?

Whaling is a subtype of spear phishing. The main difference is that it targets executives or other especially valuable victims.

What is smishing?

Smishing is phishing by SMS or text message, usually trying to get the victim to click a malicious link or reveal information.

What is vishing?

Vishing is phishing by voice call or voicemail, often using urgency, authority, or fear to manipulate the victim.