Threats

What is phishing?

Phishing is a form of social engineering in which an attacker sends a fraudulent message — usually email — impersonating a trusted sender, in order to trick the recipient into revealing credentials, approving a payment, or opening a malicious attachment or link. It remains the most common initial access method in breaches affecting small and medium-sized organisations.

Written and reviewed by , Senior Technical ConsultantLast reviewed 30 July 2026

At a glance

Primary channel
Email, with SMS, phone and messaging apps also used
Common objectives
Credential theft, payment fraud, malware delivery
Targeted variant
Spear-phishing
Highest-value variant
Business email compromise (BEC)
Key defences
MFA, email filtering, staff training, payment verification process

Variants

The underlying technique is constant; the delivery channel and level of targeting vary.

  • Bulk phishing — untargeted messages sent at volume, impersonating banks, couriers or cloud providers.
  • Spear-phishing — tailored to a named individual using researched detail about their role, colleagues or current projects.
  • Business email compromise (BEC) — a compromised or spoofed legitimate account used to request payments or bank detail changes, often without any malicious link at all.
  • Smishing — phishing delivered by SMS, frequently impersonating delivery firms, banks or the sender's own IT department.
  • Vishing — voice calls, increasingly assisted by AI voice cloning, typically impersonating IT support or a senior manager.
  • Quishing — QR codes in emails or printed material that lead to credential harvesting pages, bypassing link-scanning filters.

Warning signs

Modern phishing rarely contains obvious spelling errors; generative AI has removed that historical tell. The reliable indicators are contextual rather than linguistic.

  • Urgency or pressure to act before verifying — deadlines, threatened account closure, an executive who is 'in a meeting'.
  • A request to change bank details, release a payment, or buy gift cards.
  • A sender address that differs subtly from the genuine domain, or a reply-to address that does not match.
  • A login page reached via a link in a message rather than typed or bookmarked.
  • An unexpected request that bypasses the normal process, especially one asking for confidentiality.

Controls that actually reduce it

No single control stops phishing. The effective approach is layered: email filtering to remove the bulk of malicious messages, MFA — ideally phishing-resistant — so stolen credentials are insufficient, DMARC, SPF and DKIM to make domain spoofing harder, and endpoint protection to catch payloads that get through.

Alongside the technical layers, an out-of-band verification process for any payment or bank detail change is the single most effective control against business email compromise, because it removes reliance on the authenticity of the message itself.

Full guide: How cyber attacks actually happen

Sources

The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.

  1. Phishing attacks: defending your organisationNational Cyber Security Centre
  2. Suspicious Email Reporting Service (SERS)National Cyber Security Centre
  3. Reporting fraud and cyber crimeAction Fraud (City of London Police)
  4. Cyber Security Breaches SurveyUK Department for Science, Innovation and Technology

FAQ

What is phishing — common questions

Direct answers to the questions asked most often about this topic.

What should someone do immediately after clicking a phishing link?

+

Act quickly and report it rather than waiting to see what happens. If credentials were entered, change that password immediately and change it anywhere else the same password was used. Sign out all active sessions, because an attacker may already hold a valid session token that a password change alone does not revoke. Check mailbox rules for newly created forwarding or deletion rules, a standard attacker step after email compromise. Review recent sign-in activity for unfamiliar locations. Notify IT or your security provider even if nothing appears wrong, since containment is far easier in the first hour than the first week.

How is business email compromise different from ordinary phishing?

+

Business email compromise usually involves no malware and often no malicious link, which is why technical filters frequently miss it. The attacker either compromises a genuine mailbox or spoofs a familiar sender, observes real conversations, and then intervenes at a plausible moment — typically to redirect an invoice payment or change payroll bank details. Because the message is contextually accurate and may come from a legitimate address, it defeats detection based on suspicious content. The defence is procedural: verify any payment or bank detail change by phoning a known number, never a number supplied in the message.

Can email filtering stop all phishing?

+

No. Filtering removes the large majority of bulk phishing and known malicious infrastructure, and modern services also detect impersonation patterns and anomalous sender behaviour. What it cannot reliably stop is a well-crafted message sent from a genuinely compromised business account with no attachment and no link, or a targeted message using a newly registered domain not yet on any reputation list. Filtering should be understood as the layer that reduces volume so that staff attention is available for the small number of sophisticated messages that reach the inbox.

Does multi-factor authentication prevent phishing?

+

MFA prevents most credential phishing from succeeding, because a stolen password alone no longer grants access. It does not make phishing impossible. Attacker-in-the-middle phishing kits proxy the real login page and capture the one-time code alongside the password, then use both within their short validity window. Session token theft bypasses authentication altogether. Phishing-resistant methods — passkeys and FIDO2 security keys — defeat the relay technique because the credential is cryptographically bound to the legitimate domain and cannot be replayed elsewhere.

Are phishing simulations useful, or do they just annoy staff?

+

Their value depends on how they are run. Simulations that measure report rate as the primary metric, deliver short targeted training immediately after a click, and keep individual results confidential tend to improve behaviour measurably over six to twelve months. Simulations designed to catch people out — fake bonus announcements, fake redundancy notices — generate resentment and suppress reporting, which is counterproductive. The behaviour worth building is fast reporting of anything suspicious, and that is best encouraged by recognising reports rather than penalising clicks.

How common is phishing as a cause of breaches?

+

Phishing consistently ranks as the most frequently identified attack type in UK breach surveys, and the Cyber Security Breaches Survey has repeatedly found it affecting the large majority of businesses that report any breach or attack. For small organisations it is usually the entry point rather than the objective: stolen credentials lead to mailbox access, mailbox access leads to invoice fraud or onward phishing of contacts, and in some cases to ransomware deployment. Its persistence reflects low cost to the attacker and reliance on human judgement rather than a technical vulnerability.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way