In short
Phishing is an attack where a criminal impersonates a trusted person or organisation to trick someone into clicking a malicious link, opening an infected attachment, or handing over information. It works by exploiting everyday behaviour rather than technical weakness, so the best defence combines staff awareness, email filtering and multi-factor authentication.
Phishing remains one of the most common and damaging cyber threats facing businesses. Despite real improvements in security technology, it keeps succeeding because it targets people rather than systems. One convincing email, text message or phone call is often all it takes to cause serious disruption.
What phishing is
Phishing is a form of cyber attack where someone pretends to be a legitimate person or company to get you to act against your own interest: clicking a link, opening an attachment, or sharing login or payment details. The messages copy real branding, tone and formatting, so they blend into normal day-to-day communication. A single successful attempt can lead to a data breach, a ransomware infection, or direct financial loss.
The common types
Email phishing
The classic version. Fake emails posing as banks, software providers, couriers or colleagues, pushing you to act urgently.
Spear phishing
Targeted messages aimed at specific people, often in finance or senior roles. They are personalised, which makes them much harder to spot.
Smishing
Phishing by text message, often about a missed delivery, an unpaid fee, or an account that needs verifying.
Vishing
Phishing over the phone, where the caller poses as IT support, your bank, or a company director to pressure someone into sharing information.
The warning signs
Attacks are getting more polished, but most still carry a few tells:
- Urgency, such as "act now" or "your account will be locked"
- Unexpected attachments or links
- A sender name that does not match the actual email address
- Odd wording or spelling, though this is less reliable than it used to be
- Any request for passwords, payment details or MFA codes
If a message feels off, treat that instinct as a signal. It is quicker to check than to recover from a mistake.
Why it keeps working
Phishing works because it exploits normal pressures. People are busy, distracted, and trying to be helpful. Rather than breaking through technical defences, attackers go around them by manipulating people. That makes phishing a whole-business risk, not just an IT problem, which is why people matter as much as tools. Attackers now use AI to make these messages far more convincing, as we cover in AI deepfake scams.
How to reduce the risk
No single control removes phishing entirely, but a layered approach cuts your exposure sharply. Staff awareness matters most, because people who know the signs rarely fall for them. Email filtering, endpoint protection and multi-factor authentication add technical layers and limit the damage if a credential is exposed. Just as important, build a culture where people report suspicious messages without fear of blame, because early reporting stops one email becoming a company-wide incident. This is core to our Managed Cyber Security service.
Frequently asked questions
What should staff do if they think they clicked something?
Report it immediately, without worrying about blame. Fast reporting lets the issue be contained before it spreads. A clear, no-blame reporting route is one of the most effective controls a business can have.
