← Back to the blog

Phishing Attacks: A Practical Guide for UK SMEs (How to Spot, Stop & Report)

12 August 2026

Phishing Attacks: A Practical Guide for UK SMEs (How to Spot, Stop & Report)

Phishing is one of the simplest ways for criminals to target a business.

A convincing email, text message or phone call can lead to stolen passwords, fraudulent payments or a compromised account. The good news is that practical phishing awareness can significantly reduce the risk.

This guide explains how phishing works, the warning signs to look for and what to do if someone clicks a suspicious link.

What is phishing?

Phishing is a scam designed to trick someone into taking an unsafe action.

The attacker may try to make you:

  • Click a malicious link
  • Open a harmful attachment
  • Share a password or security code
  • Approve a multi-factor authentication request
  • Change supplier bank details
  • Transfer money
  • Install remote-access software
  • Share confidential business information

Phishing can happen through:

  • Email , often called email phishing
  • SMS or text message , sometimes called smishing
  • Phone calls , known as vishing, or voice phishing
  • Social media messages
  • Fake websites and online adverts

Small businesses are attractive targets because they often hold valuable customer data, payment information and access to cloud systems. They may also have fewer formal security controls than larger organisations.

Phishing is not a sign that someone has been careless. These scams are designed to create pressure and appear legitimate.

Common phishing examples

Example 1: A fake supplier email

Your finance team receives an email that appears to come from a regular supplier.

It says:

“We have changed our bank details. Please use the new account for all future payments.”

The email may use the supplier’s logo and familiar wording. It may even come during a busy period when an invoice is due.

The risk is clear: a payment could be sent directly to the criminal.

Safer approach: Verify any bank-detail change using a known phone number or an existing contact. Do not use the telephone number included in the suspicious email.

Example 2: A fake Microsoft 365 login

An employee receives an email saying their business email account will be suspended unless they sign in immediately.

The button leads to a fake login page. The page looks genuine but sends the password to the attacker.

Safer approach: Do not click the link. Open the service through a trusted bookmark or type the official website address manually.

Example 3: A suspicious text message

A director receives a text claiming to be from their bank. It says a payment has been blocked and asks them to click a link to confirm their identity.

The link leads to a fake banking page.

Safer approach: Do not click the link or call the number in the message. Contact the bank using the number on its official website, card or statement.

Example 4: A phone call from “IT support”

A caller says they are from your IT provider. They claim to have detected a serious problem and ask the employee to install remote-access software.

The caller may know the name of the business or use technical language to sound credible.

Safer approach: End the call and contact your IT provider using a trusted number. Never provide passwords, PINs or MFA codes over the phone.

Laptop, smartphone and desk phone representing email, SMS and phone phishing

Phishing red flags: a practical checklist

Use this checklist when reviewing an unexpected message or call.

Sender and contact details

  • Is the sender unknown or unexpected?
  • Does the email address contain a spelling mistake?
  • Does the display name differ from the real email address?
  • Does the website address look almost correct but not quite?
  • Is the message from a personal email account when you expected a business address?

Criminals often use addresses that look similar to genuine ones. For example, a fake domain may replace a letter with a number or add an extra word.

Pressure and urgency

Be cautious when a message:

  • Demands immediate action
  • Threatens account closure or financial penalties
  • Says the request must remain confidential
  • Claims a payment is overdue
  • Asks you to bypass normal approval procedures
  • Uses an unexpected emergency involving a manager or director

Pressure is a common phishing tactic. It discourages people from checking the request properly.

Links and attachments

  • Were you expecting the attachment?
  • Does the link lead to the website you expected?
  • Is the attachment a ZIP file, executable file or unexpected document?
  • Does the message ask you to enable macros or change security settings?
  • Does the link ask for a password, payment or MFA code?

Do not click a link simply to check where it goes. If you need to verify a service, access it through a trusted bookmark or a manually typed web address.

Message quality and context

  • Is the greeting generic?
  • Does the writing look unusual for the sender?
  • Are there spelling, grammar or formatting errors?
  • Is the request outside the sender’s normal responsibilities?
  • Does the message contain information that does not fit the current situation?

Good spelling does not prove a message is genuine. Modern phishing messages can be well written and may use information gathered from public websites or social media.

Phone-call warning signs

Treat a caller with caution if they:

  • Ask for a password, PIN or MFA code
  • Request a payment or change to bank details
  • Ask you to install software
  • Refuse to let you call back
  • Become aggressive when you want to verify the request
  • Claim to be from your bank, HMRC, a supplier or a technology provider

A genuine organisation should not object to sensible verification.

What to do if someone clicks a phishing link

Do not blame the person who clicked. The priority is to contain the problem quickly.

If the link was clicked but no details were entered

  • Close the browser page.
  • Do not download or install anything.
  • Report the incident internally.
  • Tell your IT provider or security contact.
  • Run the usual security checks on the device.
  • Watch for unusual account activity.

The device may still be safe, but it should be checked.

If a password was entered

Take action immediately:

  1. Change the password from a trusted device.
  2. Change it anywhere else it has been reused.
  3. Tell your IT provider or administrator.
  4. Check for unfamiliar sign-ins or account changes.
  5. Review email forwarding rules and recovery details.
  6. Enable MFA if it is not already active.

Start with business email accounts. An attacker with access to email may be able to reset other passwords or impersonate employees.

If an MFA code was shared or approved

Contact your IT provider or administrator straight away.

Ask them to:

  • Revoke active sessions
  • Reset the password
  • Review sign-in activity
  • Remove unknown devices
  • Check for new MFA methods
  • Confirm that recovery information has not changed

Never approve an MFA request you did not initiate.

If money was transferred

Contact your bank immediately using an official number. Explain that the payment may be fraudulent and ask what action can be taken.

Report fraud or cyber crime to Action Fraud. In Scotland, contact Police Scotland on 101 where appropriate.

A calm, minimalist workspace showing the practical steps after clicking a phishing link

How to report phishing in the UK

Reporting helps protect your business and other organisations.

Report suspicious emails and websites

Use the National Cyber Security Centre’s phishing guidance. You can report suspicious emails, websites and other scam content through the relevant NCSC reporting services.

If the message relates to your business, also follow your internal reporting process. Save the original message if possible.

Report scam texts

Forward suspicious text messages to 7726. This free service allows mobile networks to investigate scam messages.

You can also follow the NCSC guidance for reporting a scam text message.

Report a financial loss or attempted fraud

If your business has lost money, shared sensitive information or suffered an account takeover, report it to Action Fraud.

Keep records of:

  • The original message
  • Email addresses and phone numbers
  • Website addresses
  • Payment details
  • Times and dates
  • Actions already taken

Simple next steps for business owners

Phishing awareness works best when it becomes part of normal business activity.

1. Give staff a clear reporting route

Tell everyone exactly what to do if something feels wrong.

For example:

  • Use the email provider’s “Report phishing” button.
  • Forward suspicious messages to a named security contact.
  • Call a manager if a payment request is unusual.
  • Report mistakes without fear of blame.

Fast reporting gives your business more time to protect accounts and stop further damage.

2. Provide short, regular training

Training does not need to be technical or time-consuming.

Cover:

  • How to spot unusual requests
  • How to check sender addresses
  • Why bank-detail changes need independent verification
  • Why passwords and MFA codes must stay private
  • How to report a mistake

Use examples that reflect your business, such as fake invoices, payroll requests or delivery messages.

The NCSC also provides guidance for small organisations.

3. Enable MFA

Enable multi-factor authentication on key systems, including:

  • Business email
  • Cloud storage
  • Accounting software
  • Banking and payment platforms
  • Customer relationship management systems
  • Administrator accounts

MFA adds another layer of protection if a password is stolen. It is not a complete solution, but it can reduce the risk of account takeover.

4. Strengthen payment controls

Create a simple rule:

Never approve a new payment or bank-detail change based on one email alone.

Verify the request through a second channel using trusted contact details. Make sure more than one person is involved in high-value or unusual payments.

5. Review your wider security position

Phishing is one part of your overall security risk. Check that your business also has:

  • Current software and devices
  • Reliable backups
  • Strong, unique passwords
  • Access controls for staff and suppliers
  • Email filtering
  • A basic incident response plan
  • Appropriate cyber security certification

Cyber Essentials can help UK businesses establish and demonstrate a strong foundation.

Build phishing awareness with practical support

You do not need a full-time security executive to improve your business’s phishing resilience.

SimpleCyber provides practical, jargon-free support for UK SMEs and growing teams. We can help you:

  • Train staff to recognise and report phishing
  • Review your current security controls
  • Enable MFA and strengthen account protection
  • Create a proportionate incident response plan
  • Prepare for Cyber Essentials accreditation
  • Access flexible guidance through a Virtual CISO or fractional security consultant

If you want to strengthen your phishing awareness without adding unnecessary complexity, contact SimpleCyber for a straightforward conversation.