Cyber security
Why are phishing attempts getting better, and what stops them working?
Because the attacks are bought off a shelf now rather than built. Phishing kits are sold as a subscription, complete with convincing fake login pages and a dashboard showing how many people fell for it, so the skill barrier has gone. What stops them is multi factor authentication on everything, filtering that catches what Microsoft misses, and staff who have been given permission to be slow.
Because they are bought rather than built.
Phishing kits are sold as a subscription on the same model as any other software: ready made fake login pages that mirror the real thing, email templates, tools to collect and sort the credentials that come back, and a dashboard showing how well the campaign is doing. What used to take skill and weeks of preparation now takes a card payment and an afternoon.
That is the whole explanation for the volume and the quality. The people sending these do not need to be good at any of it any more.
Phishing was the most common type of attack on UK businesses, hitting 38% of them in the last 12 months.
Source: Cyber Security Breaches Survey 2025/26, Department for Science, Innovation and Technology, April 2026.
What does a fake recruiter approach look like?
It looks like networking, which is exactly why it works.
A message arrives on LinkedIn about a role. The profile is plausible, the company is one you have heard of, the tone is professional. Nothing about it reads as an attack, because at that point nothing has happened yet. The pattern that follows is consistent:
- A polished approach, with a role description that turns out to be oddly vague when you read it twice.
- A quick move off the platform, to WhatsApp, Telegram, personal email, or a recruitment portal. This is the step that matters, because it removes the friction of somebody else’s platform and makes it easy to send links and files.
- A credibility wrapper. An assessment to download. An onboarding pack. A portal to log into so you can book an interview slot.
- The pivot. Money for equipment or training, personal or bank details before any real interview process exists, or a login page that harvests the password.
- Pressure to keep moving. Limited slots, fast track hiring, complete this today. The whole thing depends on momentum.
The hard stops are worth stating to your team as rules rather than guidance, because a rule survives being under pressure and a judgement call does not:
- Any request for money is a stop. Fees, equipment, training costs, gift cards, cryptocurrency.
- Any request to read back a code sent to a phone or an email is a stop. That is somebody taking over an account, always.
- Bank details or identity documents before a real interview process exists is a stop.
- Anything asking for non-public information about your employer is a stop. Org charts, client lists, what security tools you use, how invoices get approved. A recruiter has no reason to want any of it.
What are the other shapes it takes?
The recruiter version is one of four patterns, and they are worth naming in plain language because people spot what they have a name for:
- Phishing. A message that looks like it came from somewhere legitimate, asking you to sign in or approve something.
- Pretexting. A made up situation that explains why the request is urgent and why the normal process is being skipped. The new finance director who needs a payment out today.
- Baiting. Something attractive as the hook. A free USB stick, a shared file you were not expecting, an invoice you did not order.
- Tailgating. Somebody walking into your building behind a member of staff with their hands full. Still works, still worth mentioning to a team that thinks security is only about email.
Underneath all four is the same mechanism: urgency, an authority you would not normally question, and one small action that seems reasonable on its own.
What stops it without relying on people?
This is the part worth spending money on, because it works whether or not anybody is paying attention that morning.
Multi factor authentication on everything. Most of this is trying to obtain a password, so the single most useful thing you can do is make a password insufficient. It is also now an automatic fail in Cyber Essentials if it is missing on any cloud service that offers it.
Email filtering beyond what comes in the box. Microsoft’s built in filtering catches a great deal and is not the same product as a dedicated layer. We run Check Point in front of Microsoft 365 for exactly this, along with DefensX on the DNS and browser side so that a link somebody does click is checked again before the page opens.
Domain protection with DMARC, so that somebody cannot send email that appears to come from your own domain. Yours is one of the few controls that protects your clients as much as it protects you.
Somebody watching for the aftermath. The single most telling sign of a compromised mailbox is a new rule that files or forwards messages out of sight. If nobody is monitoring for that, a compromise runs until it does something expensive.
The full list of what sits at each level of our support is on the pricing page, and the technical detail is on the cyber security page.
Does training actually work?
It moves the number, and it does not move it to zero.
Any IT provider who tells you they can stop your business being phished entirely is not being straight with you, and their trousers are probably on fire. At some point somebody will click something. A staff member will be having a bad day, or the message will be genuinely good, or it will arrive at the exact moment they were expecting something that looked like it.
So the useful question is what happens in the hour afterwards.
Training is worth having. Spotting a fake domain is the smaller part of what it does. The more valuable part is making it completely safe to say "I think I have just done something stupid" straight away, to somebody who will not make them feel small about it. A business where people hide the mistake for a day loses the day, and the day is when everything gets decided.
I would rather have a team that clicks occasionally and tells us within five minutes than a team that has been told off enough times to keep quiet.
What to do this month
- Check multi factor authentication is genuinely on for every account, including the ones exempted years ago for convenience.
- Check somebody would notice a forwarding rule being created today.
- Tell your team, out loud, what the hard stops are, and that reporting a mistake fast will never get them into trouble.
- Agree who they tell, and make sure that person is reachable on a Friday afternoon.
- Tell them they can forward anything suspicious to report@phishing.gov.uk, the National Cyber Security Centre’s reporting service, which takes down the sites behind it. The NCSC also publishes guidance on defending an organisation against phishing.
- Put a work email address or two through our free breach checker. Addresses that have been in a breach get more phishing, and better targeted phishing.
For the wider picture, the 15 minute security check covers six more things worth knowing about your business. If you would like somebody to look at what would actually catch this in your business, get in touch and ask. You will get a straight answer, including if the answer is that you are in reasonable shape already.
Questions
The questions people ask us about this
How do you report a phishing email in the UK?
Forward it to report@phishing.gov.uk, the National Cyber Security Centre’s Suspicious Email Reporting Service, and tell whoever manages your IT. For a scam text, forward it to 7726. Then delete it.
Somebody clicked. What do we do first?
Change the password and revoke the active sessions, in that order, because changing the password on its own does not sign an attacker out of a session they already hold.
Then check the mailbox rules. Creating a rule that hides the replies is almost always the attacker’s next move, and it is the thing that lets a compromise run for weeks.
Is security awareness training worth it?
Yes, as one layer among several, and no as a substitute for the technical controls. Training moves the number of people who click. It does not move it to zero, and any provider who implies otherwise is selling you something.
Should we be running simulated phishing tests?
They are useful if the point is to find out where you stand and what to teach next. They are counterproductive if people feel caught out by them, because the thing you most need is for somebody to tell you quickly when they have clicked.