Every example below is based on real attacks we've seen land in UK SME inboxes over the last 12 months. Names and identifiers have been changed.
1. The supplier bank change
An email from a real supplier — same name, same signature, same thread — politely informing you that their bank details have changed. The mailbox was compromised weeks earlier. The attacker waited until an invoice was due.
Defence: a hard policy that bank detail changes are always verified by phone, using a number you already hold.
2. The Microsoft 'shared document'
A SharePoint sharing notification from a colleague's real address. Click leads to a credential-harvesting page that looks identical to the Microsoft login. MFA codes are relayed in real time.
Defence: phishing-resistant MFA (passkeys/FIDO2) and click-time URL inspection.
3. The DocuSign 'contract for signature'
A genuine DocuSign envelope hosting a malicious PDF. The brand and infrastructure are real; the document is the trap.
Defence: never enter credentials after clicking a link in an email — always navigate to the service directly.
4. The CEO WhatsApp
'Hi, are you free? I'm in a meeting and need a quick favour.' A pretext to get a gift card purchase or an urgent transfer. Often from a UK mobile number with the CEO's photo as avatar.
Defence: a clear out-of-band verification rule for any financial request, no matter who it comes from.
5. The HMRC tax refund
Seasonal, predictable, and still effective — particularly aimed at finance and admin staff in January.
Defence: HMRC never notifies refunds by email or text. Block lookalike domains at the email gateway.
6. The MFA push-bomb
Attacker has the password (from a breach) and triggers MFA prompts repeatedly until the user taps Approve out of frustration.
Defence: number-matching MFA, push-suppression policies, and rapid credential rotation when reuse is detected.
7. The 'failed delivery' SMS
Royal Mail, Evri, DPD — fake delivery texts that ask for a small redelivery fee, harvesting card details.
Defence: train staff to navigate directly to the courier's site, never tap text links.
8. The fake Teams call
An inbound Teams message from an external account posing as IT support, requesting a screen share to 'fix' an issue.
Defence: lock down external Teams chat to allow-listed domains only.
9. The recruiter LinkedIn lure
Targets developers and finance staff with attractive job offers, eventually steering them to a 'coding test' or 'document' containing malware.
Defence: EDR that detects post-exploitation behaviour, plus user awareness of social engineering via LinkedIn.
10. The compromised marketing platform
A legitimate email marketing tool sends out a campaign from a real, warmed-up domain — but the attacker controls the account.
Defence: DMARC reporting + monitoring of brand mentions and lookalike domains.
Next step
Want to see how your team would handle these? A free 30-minute review includes a quick phishing readiness check — book it below.

