The bottom line: social engineering no longer arrives only by email, but email is still the main door
The social engineering a company faces in 2026 sorts into seven types based on the channel it arrives through: email phishing, business email compromise (BEC), vishing over the phone, smishing by SMS, quishing through a QR code, the ClickFix trick the person runs themselves, and MFA fatigue. Email remains the main point of entry, and the newer channels (voice, SMS, QR, commands pasted by hand) add to it, they do not replace it. CISA confirms it: more than 90 percent of successful cyberattacks begin with a phishing email. If the goal is for your team to recognize these attacks, it helps to see them together, because they all aim at the same target: the person, not the system.
Before we go into each one, here is the full map at a glance.
| Type | How it arrives | What it is |
|---|---|---|
| Email phishing | The bait message that asks for credentials or a click, the basis of almost everything else. | |
| BEC | The impersonation of an executive or vendor to authorize a payment or change some data. | |
| Vishing | Phone call | The call that pretends to come from IT, the bank or the help desk to extract information. |
| Smishing | SMS to the phone | The text message with an urgent link that takes advantage of the small screen. |
| Quishing | QR code inside an email | The code that leads to a fake site and slips past the filter that only reads text. |
| ClickFix | Email or decoy page | The instruction that convinces the person to copy and paste a command that runs itself. |
| MFA fatigue | Push notification | The approval the employee gives out of exhaustion after a flood of requests. |
Email phishing: still the main point of entry
Email phishing is the bait message that poses as a brand, a service or a coworker so the person hands over their credentials or clicks a trap link. It is the oldest type and the most common, and it is still the starting point for almost all the others: when we talk about smishing or quishing, we are talking about the same deception moving to a different channel. That is why, even as new forms appear every year, email does not lose its place as the main door, it becomes more convincing.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
BEC: business email compromise, the most costly
Business email compromise (BEC) does not try to steal a password, it tries to steal money directly. The attacker poses as an executive, a vendor or the finance team and asks, in a routine tone, for an urgent payment or a change to a bank account. It carries no suspicious links or strange attachments, so many filters let it through, and it tends to be the most costly in financial terms because a single hit can move an entire transfer. Because there is no obvious bait to catch, the only reliable defense is a person trained to pause on an out-of-pattern payment request.
Vishing: the phone fraud that targets your help desk
Vishing is social engineering by voice: a call that pretends to come from IT, the bank or a vendor so the person reveals a code, approves an access request or installs something. It works because the voice creates trust and urgency at the same time, and because the help desk is trained to help, not to distrust. It is one of the fronts that grew the most by adding itself to email, not at its expense. We looked at the help desk case in vishing: the phone fraud that targets your help desk.
Smishing: the phishing that arrives by SMS
Smishing is phishing that lands as a text message on the phone, almost always with a short link and an urgent excuse: a held package, a fine, a blocked account. The small screen works in the attacker's favor, because it hides the real address of the link and because the phone gets checked in a hurry, between other tasks. It is email through another channel, with fewer visible clues.
Quishing: the QR code that bypasses the email filter
Quishing hides the malicious link inside a QR code, almost always embedded in an email. Because the traditional filter reads text and links but does not interpret the code's image, the bait passes through, and the person ends up scanning it with their phone, a device that usually has less protection than the company computer. It is a good example of how a new channel leans on email to get in. We break it down in quishing: QR code phishing that bypasses email filters.
ClickFix: the trap the person runs themselves
ClickFix is the technique in which the attacker convinces the person to copy and paste a command, almost always with the excuse of fixing an error or proving they are not a robot. The twist is that no filter stops what the user runs with their own hands: the victim does the attacker's work without realizing it. It arrives by email or through a decoy page, so it adds to email without taking weight away from it.
MFA fatigue: the approval that gives in to exhaustion
MFA fatigue does not steal a code, it wears the person down until they approve. The attacker, who already has the password, fires a flood of second-factor requests at the employee's phone until they, tired or confused, tap accept just to make it stop. It is not a failure of the second factor, it is the pressure on the person who controls it.
The common thread: they all attack the person, not the system
Placed side by side, the seven types reveal the same pattern: the channel changes, the pretext changes, but they always aim at a human instinct, authority, urgency, the wish to help or plain exhaustion. It is no accident. Cisco's 90-5-5 framework, which estimates that close to 90 percent of breaches involve a human factor, describes exactly this: the weak point all these attacks share is not in the firewall, it is in the decision a person makes under pressure. That is why the defense cannot be one more filter for each new channel, but sustained work on behavior, which is what human risk management (HRM) is about.
No single tool covers email, voice, SMS, QR and the command the person pastes all at once, because the common point is not the technology, it is the person.
That is why at Fensivo we do not chase each channel separately: we prepare each employee's behavior with personalized email phishing simulations, we deliver specific training within minutes when someone falls, and weeks later we validate with a retest, a fresh test of the same category with a different template, that the lesson stuck and the person did not just remember one email. That habit of resisting a pretext carries over to the other channels, even when the bait arrives somewhere else. You can see the full approach in our use cases.
How many of these seven channels could your team recognize today without hesitating, and how many would catch them by surprise?
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
