Phishing is the most common way a small business gets compromised. It is not clever hacking. It is a convincing message that tricks someone into clicking a link, opening a file, or handing over a password. Get good at spotting it and you close the biggest door an attacker has.
It is also everywhere. In the UK government's 2025 Cyber Security Breaches Survey, phishing was the most common attack by a wide margin, hitting 85% of businesses that suffered a breach, and 69% of those affected called it their most disruptive incident. If your business uses email, you are a target.
Know the words
Phishing is the catch-all term for a fraudulent message pretending to be someone you trust. It comes in a few flavours:
- Smishing is phishing by text message.
- Vishing is phishing by phone call or voicemail.
- Spear phishing is a targeted version, written for you or your company using real details.
- Business email compromise (BEC) is when an attacker poses as your boss, a colleague, or a supplier to push through a payment or a change of bank details.
The trick is the same in every case. Only the delivery changes.
Why they target your people and your partners
Attackers rarely break the technology. They go after the people who use it. Your finance team, your assistants, and anyone who can move money or change a record are the prime targets, because one approval is worth more than a hundred guessed passwords.
They also target the businesses around you. A criminal who compromises one of your suppliers can email you from a genuine address, attach a real-looking invoice, and quietly change the bank details. The same works in reverse: an attacker posing as you can defraud your clients and your contractors. Trust between organisations is exactly what they are trying to borrow.
The financial risk is real
This is not a nuisance about spam. It is theft. In 2024, the engineering firm Arup lost the equivalent of about £20m when a finance worker in its Hong Kong office was tricked into making 15 transfers. It began with a spear phishing email impersonating the chief financial officer, then escalated to a video call where the "colleagues" on screen were AI-generated deepfakes. None of the money has been recovered. The tools are getting cheaper and more convincing, and small businesses are well within range.
What these messages actually look like
Phishing rarely announces itself. Here are four examples that land in real inboxes every week.
- The changed bank details. An email from a supplier you know, referencing a real invoice number, says: "Please note our bank account has changed, kindly use the new details for this payment." The address looks right. The invoice looks right. Only the account is new.
- The urgent boss. A short message, apparently from a director: "Are you at your desk? I need a payment made today before the deadline, keep it between us for now." The pressure and the secrecy are the whole attack.
- The delivery text. A smishing message: "Your parcel could not be delivered. Pay the £1.99 redelivery fee here," with a link to a page that harvests your card details.
- The login prompt. An email warning that your Microsoft 365 or email password is about to expire, with a "Verify now" button leading to a fake sign-in page built to capture your real password.
What to look for
Most phishing leans on the same pressure tactics. Be suspicious when a message uses:
- Authority. It claims to be your bank, HMRC, a supplier, or a senior colleague.
- Urgency. It wants you to act now, or something bad happens.
- Emotion. It uses fear, panic, or a too-good-to-be-true offer.
None of those prove a scam on their own. Together, they should make you slow down.
What to check
Before you click or reply, check the basics:
- The real sender address, not just the display name. Spoofing makes "Your Bank" sit on top of a random address. Hover or tap to see the truth.
- The link destination. Hover over it on a computer, or press and hold on a phone, and read the actual URL. If it does not match the organisation, do not click.
- The ask. A genuine bank, HMRC, or supplier will never email or call to ask for your password or full card details.
- A change to payment details. Always confirm a new bank account or a payment request by phone, using a number you already hold, never the one in the message.
- The tone. Odd phrasing, a generic "Dear customer", or a request for secrecy are all worth a second look.
How to report it
If a message looks like phishing, do not click, reply, or forward it to colleagues. Forward it to spam@brnb.co.uk and we will check it for you. If you have already clicked something, paid an invoice, or entered a password, tell us straight away. Speed matters far more than embarrassment, and we would always rather hear about it early. If money has moved, call your bank as well, because the first few hours are when funds can sometimes still be stopped.
None of this requires you to become a security expert. It asks for a habit: slow down for ten seconds, check the sender and the ask, and confirm anything to do with money through a channel you trust. Most attacks fall apart against a calm, sceptical reader. That reader is your best defence.