Cyber Explained

What is phishing — and how do you stop it?

Phishing is behind most business hacks — and it’s getting cleverer. Here’s how it works, the tell-tale signs, and how to protect your team.

Greater Manchester & UK-wide · free, no-obligation advice

Why Foresight

  • Cyber Essentials Plus certified
  • Supporting 130+ organisations since 2006
  • We reply within one working hour
  • Plain-English, no jargon

Quick answer

Phishing is when criminals send fake messages — usually emails — pretending to be someone you trust, to trick you into clicking a malicious link, handing over passwords, or paying a fake invoice. It’s the most common way businesses get hacked. You stop it with a combination of email security, staff awareness training, multi-factor authentication (so a stolen password isn’t enough), and a simple “pause and verify” habit for any payment or login request.

How it works

The con behind the click

A phishing message impersonates a brand, a colleague or a supplier and creates urgency — “your account is locked,” “urgent invoice,” “the MD needs this paid today.” One click on a malicious link or attachment can hand over a password or install malware. It’s exactly how huge breaches start — see our pieces on the ASOS breach and how one phishing email sparked football’s biggest scandal.

The types

More than just dodgy emails

TypeWhat it is
Spear phishingA targeted, personalised attack on a specific person
Business Email CompromiseFake invoices or “change of bank details” requests that look genuine
SmishingPhishing by text message (SMS)
VishingPhishing by phone — now including AI voice clones of your boss

How to protect your business

Layers that actually work

Stop phishing with: email security that filters malicious messages; staff awareness training and simulations so people spot and report it; multi-factor authentication (MFA) so a stolen password isn’t enough; and a simple rule — pause and verify any payment or login request through a separate, known channel. Wrap it up with Cyber Essentials. Not sure where you stand? Try a free risk scan.

FAQs

Common questions

What is phishing?
Phishing is a scam where criminals send fake messages pretending to be someone you trust, to trick you into clicking a malicious link, revealing a password, or paying a fake invoice. It’s the most common cause of business breaches.
How can I spot a phishing email?
Watch for urgency, unexpected requests, slightly wrong sender addresses, links that don’t match the real site, and anything asking you to change bank details or log in urgently. When unsure, verify through a known, separate channel.
What’s the difference between phishing, smishing and vishing?
Phishing is by email, smishing is by text message, and vishing is by phone call — increasingly using AI voice clones. All rely on tricking a person rather than breaking technology.
How do I protect my business from phishing?
Combine email security, staff awareness training and simulations, multi-factor authentication, and a “pause and verify” habit for payments and logins. Cyber Essentials ties the basics together.
What should I do if someone clicks a phishing link?
Disconnect the device, change the affected passwords from a clean device, enable MFA, and tell your IT/security provider straight away. See our guide on what to do if you get hacked.

Is your team a soft target?

Find out what an attacker can see with a free risk scan, and ask us about phishing-awareness training.