“Phishing” used to mean a crudely worded email from a Nigerian prince. In 2026 it means ten distinct attack techniques, several of them good enough to fool security-aware professionals. If your training program only covers “look for bad grammar and hover over links,” your employees are being prepared for a war that ended a decade ago.

This is a field guide to the phishing attack methods actually hitting Nashville small businesses in 2026, ranked roughly by how often we see them in incident response. Each one includes how it works, what makes it succeed, and the specific control that stops it.

1. Business email compromise (BEC)

How it works: The attacker spoofs or compromises an executive or vendor email account and asks for a wire transfer, ACH change, or gift card purchase. Often the email is short and urgent. Sometimes the attacker joins an existing thread from a real compromised account.

Why it works: There’s no malware, no link, nothing for antivirus to catch. It’s social engineering through pure text.

How to stop it: Out-of-band verification for every money movement, Abnormal-style behavioral email security, and DMARC at p=reject to stop domain spoofing.

2. Microsoft 365 credential phishing

How it works: A spoofed Microsoft login page, often hosted on a compromised legitimate site or a newly registered domain. The lure is usually a fake “voicemail,” “shared document,” or “quarantined message” email.

Why it works: The pages are pixel-perfect, and many use real-time proxy techniques (evilginx2, Tycoon, Rockstar) that capture the MFA token as well as the password.

How to stop it: Phishing-resistant MFA (FIDO2 or number-matching push), conditional access, DNS filtering for newly registered domains.

3. Attachment-based malware phishing

How it works: An email with an invoice, shipping notice, or purchase order attachment. The attachment is a macro-enabled document, an ISO file, a OneNote file, or increasingly a PDF with an embedded URL.

Why it works: Users expect to receive invoices and shipping notices. Attachment types change constantly to evade filters.

How to stop it: Email sandboxing, EDR with macro blocking, and macros disabled by default across the organization.

4. Vendor email compromise (VEC)

How it works: Instead of impersonating your CEO, the attacker compromises a real vendor’s email account and then sends a legitimate-looking invoice with new bank details. The email comes from the real vendor’s real address.

Why it works: Everything checks out technically — DKIM, SPF, DMARC all pass. The attack exploits your trust relationship, not your technology.

How to stop it: Written vendor verification procedure (call known number for any banking change), and BEC-detection tools that flag unusual content within known-good senders.

5. Smishing (SMS phishing)

How it works: A text message claiming to be from a courier, bank, HR department, or the CEO asking for a favor. Often uses time-sensitive lures like package delivery issues.

Why it works: Mobile users are more distracted, and SMS lacks most of the security controls email has. “Hey it’s the CEO, do me a favor?” lands in an unfiltered channel.

How to stop it: MDM with SMS phishing detection, and a policy that HR, finance, and executives never make requests over SMS.

6. QR code phishing (“quishing”)

How it works: A QR code printed on a poster, mailed in a letter, or embedded in a PDF attachment that leads to a credential-harvesting page. QR codes bypass most email URL scanners because they’re images.

Why it works: Users scan QR codes without thinking. The user’s phone is often not covered by corporate email security or DNS filtering.

How to stop it: Email security that scans QR images (most modern tools do now), MDM-pushed DNS filtering to mobile devices, and user training that treats QR codes in email as suspicious.

7. Voice phishing (vishing)

How it works: A phone call from someone claiming to be IT help desk, the bank’s fraud department, or a Microsoft support agent. Increasingly combined with deepfake voice cloning of real executives.

Why it works: Voice is high-trust. Many people will comply with a confident voice that a written email would never get them to.

How to stop it: A hard policy that no one gives information or takes action on any unsolicited call without calling back on a known number. Help desk staff especially need this drilled in.

8. Callback phishing (“TOAD” — Telephone-Oriented Attack Delivery)

How it works: An email with no link and no attachment — just a fake invoice or subscription renewal saying “call this number to cancel.” When the victim calls, an attacker walks them through installing remote access software.

Why it works: Email filters see no link or attachment and let it through. The attack happens entirely over the phone.

How to stop it: Awareness training that specifically covers callback phishing, and endpoint policies that require admin approval for remote access tool installation.

9. Consent / OAuth phishing

How it works: A legitimate-looking “Microsoft App” or “Google App” asks for permissions to read email or files. The user clicks “Allow” and grants the attacker persistent access without ever giving up a password.

Why it works: The permission prompt is real Microsoft/Google UI. MFA doesn’t stop it because the user is legitimately authenticating. Password resets don’t fix it.

How to stop it: Admin-level app consent policies, quarterly audit of granted app permissions, and user training that treats unexpected consent prompts as suspicious.

10. Lookalike domain phishing

How it works: Attacker registers a domain that looks like yours or a vendor’s — clearmax1abs.com, c1earmaxlabs.com, IDN homoglyphs — and uses it to send spoofed invoices or login pages.

Why it works: Users scan for familiarity, not exact spelling. Many email clients truncate long domains.

How to stop it: Defensive domain registration (buy the common typos yourself), DMARC at reject, and URL-hover training.

Quick reference: which controls stop which attacks

ControlStops
Phishing-resistant MFA#2, #9
Abnormal-style email security#1, #4, #10
DMARC at p=reject#1, #10
DNS filtering#2, #3
Vendor verification procedure#1, #4
Awareness training#5, #6, #7, #8
MDM with mobile threat defense#5, #6
OAuth app consent policy#9

Related services

Knowing the phishing attack methods is half the battle. The other half is having controls deployed and tested before one of these lands in your inbox. If you’d like a free phishing posture review that scores your defenses against each of the 10 methods above, book a time on our contact page.

Related ClearMax Services

Ready to Protect Your Business?

Get a free consultation with our team. We’ll assess your needs and build a custom IT solution — no obligation, no pressure.

Book Free Assessment Call 833-306-3168

Leave a Reply

Your email address will not be published. Required fields are marked *