Threats
What is phishing?
Phishing is a form of social engineering in which an attacker sends a fraudulent message — usually email — impersonating a trusted sender, in order to trick the recipient into revealing credentials, approving a payment, or opening a malicious attachment or link. It remains the most common initial access method in breaches affecting small and medium-sized organisations.
At a glance
- Primary channel
- Email, with SMS, phone and messaging apps also used
- Common objectives
- Credential theft, payment fraud, malware delivery
- Targeted variant
- Spear-phishing
- Highest-value variant
- Business email compromise (BEC)
- Key defences
- MFA, email filtering, staff training, payment verification process
Variants
The underlying technique is constant; the delivery channel and level of targeting vary.
- Bulk phishing — untargeted messages sent at volume, impersonating banks, couriers or cloud providers.
- Spear-phishing — tailored to a named individual using researched detail about their role, colleagues or current projects.
- Business email compromise (BEC) — a compromised or spoofed legitimate account used to request payments or bank detail changes, often without any malicious link at all.
- Smishing — phishing delivered by SMS, frequently impersonating delivery firms, banks or the sender's own IT department.
- Vishing — voice calls, increasingly assisted by AI voice cloning, typically impersonating IT support or a senior manager.
- Quishing — QR codes in emails or printed material that lead to credential harvesting pages, bypassing link-scanning filters.
Warning signs
Modern phishing rarely contains obvious spelling errors; generative AI has removed that historical tell. The reliable indicators are contextual rather than linguistic.
- Urgency or pressure to act before verifying — deadlines, threatened account closure, an executive who is 'in a meeting'.
- A request to change bank details, release a payment, or buy gift cards.
- A sender address that differs subtly from the genuine domain, or a reply-to address that does not match.
- A login page reached via a link in a message rather than typed or bookmarked.
- An unexpected request that bypasses the normal process, especially one asking for confidentiality.
Controls that actually reduce it
No single control stops phishing. The effective approach is layered: email filtering to remove the bulk of malicious messages, MFA — ideally phishing-resistant — so stolen credentials are insufficient, DMARC, SPF and DKIM to make domain spoofing harder, and endpoint protection to catch payloads that get through.
Alongside the technical layers, an out-of-band verification process for any payment or bank detail change is the single most effective control against business email compromise, because it removes reliance on the authenticity of the message itself.
Full guide: How cyber attacks actually happen
Sources
The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.
- Phishing attacks: defending your organisation — National Cyber Security Centre
- Suspicious Email Reporting Service (SERS) — National Cyber Security Centre
- Reporting fraud and cyber crime — Action Fraud (City of London Police)
- Cyber Security Breaches Survey — UK Department for Science, Innovation and Technology
FAQ
What is phishing — common questions
Direct answers to the questions asked most often about this topic.
What should someone do immediately after clicking a phishing link?
+
Act quickly and report it rather than waiting to see what happens. If credentials were entered, change that password immediately and change it anywhere else the same password was used. Sign out all active sessions, because an attacker may already hold a valid session token that a password change alone does not revoke. Check mailbox rules for newly created forwarding or deletion rules, a standard attacker step after email compromise. Review recent sign-in activity for unfamiliar locations. Notify IT or your security provider even if nothing appears wrong, since containment is far easier in the first hour than the first week.
How is business email compromise different from ordinary phishing?
+
Business email compromise usually involves no malware and often no malicious link, which is why technical filters frequently miss it. The attacker either compromises a genuine mailbox or spoofs a familiar sender, observes real conversations, and then intervenes at a plausible moment — typically to redirect an invoice payment or change payroll bank details. Because the message is contextually accurate and may come from a legitimate address, it defeats detection based on suspicious content. The defence is procedural: verify any payment or bank detail change by phoning a known number, never a number supplied in the message.
Can email filtering stop all phishing?
+
No. Filtering removes the large majority of bulk phishing and known malicious infrastructure, and modern services also detect impersonation patterns and anomalous sender behaviour. What it cannot reliably stop is a well-crafted message sent from a genuinely compromised business account with no attachment and no link, or a targeted message using a newly registered domain not yet on any reputation list. Filtering should be understood as the layer that reduces volume so that staff attention is available for the small number of sophisticated messages that reach the inbox.
Does multi-factor authentication prevent phishing?
+
MFA prevents most credential phishing from succeeding, because a stolen password alone no longer grants access. It does not make phishing impossible. Attacker-in-the-middle phishing kits proxy the real login page and capture the one-time code alongside the password, then use both within their short validity window. Session token theft bypasses authentication altogether. Phishing-resistant methods — passkeys and FIDO2 security keys — defeat the relay technique because the credential is cryptographically bound to the legitimate domain and cannot be replayed elsewhere.
Are phishing simulations useful, or do they just annoy staff?
+
Their value depends on how they are run. Simulations that measure report rate as the primary metric, deliver short targeted training immediately after a click, and keep individual results confidential tend to improve behaviour measurably over six to twelve months. Simulations designed to catch people out — fake bonus announcements, fake redundancy notices — generate resentment and suppress reporting, which is counterproductive. The behaviour worth building is fast reporting of anything suspicious, and that is best encouraged by recognising reports rather than penalising clicks.
How common is phishing as a cause of breaches?
+
Phishing consistently ranks as the most frequently identified attack type in UK breach surveys, and the Cyber Security Breaches Survey has repeatedly found it affecting the large majority of businesses that report any breach or attack. For small organisations it is usually the entry point rather than the objective: stolen credentials lead to mailbox access, mailbox access leads to invoice fraud or onward phishing of contacts, and in some cases to ransomware deployment. Its persistence reflects low cost to the attacker and reliance on human judgement rather than a technical vulnerability.

