Security Explainers6 min read4 October 2026

What Is Phishing? A Guide for UK Business Owners Who've Never Been Attacked (Yet)

Phishing is the most common entry point for UK business cyber attacks. This guide explains how it works, what the modern variants look like, and how to protect your website and staff.

By Yrzo AI — UK cybersecurity specialists

Phishing is the starting point for the majority of cyber attacks against UK businesses. The National Cyber Security Centre (NCSC) consistently reports it as the most common initial access technique — used in business email compromise, ransomware delivery, credential theft, and account takeover. It's also one of the most misunderstood threats, because most people imagine it as obviously suspicious emails full of spelling mistakes asking for your bank details. The reality in 2026 is considerably more sophisticated.

This guide explains what phishing actually is, what modern phishing attacks look like against UK businesses, how attackers use your website as part of their toolkit, and what practical steps reduce your exposure.

What Phishing Is (and Isn't)

Phishing is a social engineering attack that uses a deceptive communication — almost always an email, but increasingly also SMS (smishing) and voice calls (vishing) — to trick the recipient into taking an action that benefits the attacker. That action might be:

Clicking a link to a fake login page and entering their credentials. Downloading a malicious attachment that installs malware. Transferring money to a fraudulent account. Providing sensitive information the attacker uses in a follow-on attack.

The "obvious" phishing email — badly spelled, implausible, from a Nigerian prince — still exists, but it's not what's hitting UK businesses in meaningful volumes. Modern phishing is targeted, personalised, and technically convincing.

Spear Phishing: The Version That Actually Works

Generic phishing sends the same email to millions of addresses and relies on a small percentage falling for it. Spear phishing targets specific individuals or organisations with messages tailored to them.

A spear phishing email to a UK SME accounts manager might:

Reference the company's actual accounting software (Xero, Sage, QuickBooks) by name. Appear to come from the MD's email address, or a convincingly similar spoofed address. Contain accurate details about a real supplier or recent transaction — harvested from the company website, LinkedIn, or a previous breach. Ask for a routine-seeming action: "I need you to process this urgent invoice before I land, call me if you have questions" with a PDF attachment.

The PDF opens, installs a remote access tool in the background, and the attacker has a foothold in your network. Or the email links to a fake Xero login page — pixel-perfect — and the accounts manager enters their credentials. Either way, it's over before anyone realises.

The research phase of this attack — finding the right names, relationships, and software — often uses publicly available information including your company website, Companies House, and LinkedIn. Your "Meet the Team" page, your case studies mentioning client names, your footer with the director's name — all of it feeds the attacker's targeting.

Business Email Compromise: The Expensive Variant

Business Email Compromise (BEC) is a specific phishing variant where the attacker either compromises a legitimate email account or spoofs one convincingly enough to redirect payments. The NCSC and Action Fraud report BEC as responsible for hundreds of millions of pounds in losses to UK businesses annually.

The typical pattern: an attacker compromises a supplier's email account (or spoofs it). They monitor the email thread between the supplier and your business, waiting for an invoice. At the right moment — often when a large payment is due — they intercept the thread and send a message appearing to be from the supplier, stating that their banking details have changed. Your finance team updates the records and sends the payment to the attacker's mule account.

The attack is hard to detect in the moment because the email appears legitimate, contains accurate context about the relationship, and arrives at a plausible time. Prevention depends on out-of-band verification (phone call to a known number, not a number in the suspicious email) and robust payment change procedures.

How Your Website Enables Phishing Against You

This is the piece most business owners don't consider: attackers use your domain and website infrastructure as part of phishing campaigns targeting your clients, partners, or staff.

**Domain spoofing** — if your domain's DNS records don't include properly configured SPF, DKIM, and DMARC entries, attackers can send emails that appear to come from your domain. Your clients receive a convincing email from "invoices@yourcompany.co.uk" — and it really does say it's from your domain — asking them to pay into a different account. You're not the victim; your client is. But the reputational damage is yours.

**Subdomain hijacking** — if you have DNS entries pointing to services you no longer use (a decommissioned Heroku app, an old Netlify deployment, a marketing tool you cancelled), those subdomains may be claimable by a third party. An attacker who claims `offers.yourcompany.co.uk` can host a phishing page on your own subdomain — with a valid SSL certificate — making it appear to be a legitimate part of your site.

**Credential harvesting via lookalike domains** — attackers register domains similar to yours (yourcompany-uk.com, yourcompanny.co.uk, yourcompany.net) and host phishing pages. They target your staff or clients with emails directing them to these pages. While you can't prevent lookalike domain registrations, DMARC enforcement ensures your actual domain isn't spoofable, and staff awareness training reduces susceptibility.

What NCSC Guidance Says

The NCSC's Cyber Essentials scheme — the UK government-backed certification — includes email security controls in its requirements. Specifically: configuring SPF, DKIM, and DMARC is a direct response to phishing at the domain level.

The NCSC also operates the Active Cyber Defence programme, which includes a Suspicious Email Reporting Service (report@phishing.gov.uk). UK businesses that receive convincing phishing attempts targeting their sector or brand can report them, contributing to takedowns and sector-wide alerts.

For small businesses, the NCSC's Small Business Guide recommends: backing up data (ransomware delivered via phishing can encrypt everything), using multi-factor authentication on email and key systems (so that compromised credentials don't immediately mean a compromised account), and keeping software updated (phishing emails increasingly deliver exploits against unpatched software rather than relying on user interaction).

Practical Steps for UK Businesses

**Configure DMARC, SPF, and DKIM** — these three DNS records collectively prevent your domain from being spoofed. DMARC at `p=reject` is the strongest setting; many businesses start with `p=none` (monitoring only) and graduate to `p=quarantine` then `p=reject` as they verify legitimate email flows aren't blocked. A security scan of your website will flag whether these records are correctly configured.

**Enable MFA on email** — Office 365 and Google Workspace both support MFA. A compromised password is useless to an attacker if they can't pass the second factor. This is the single highest-impact control against BEC.

**Establish a payment change verification procedure** — any change to supplier banking details must be verified via a phone call to a number held independently of the email requesting the change. This procedure should be written, trained, and consistently followed.

**Audit your subdomains** — check your DNS records for any entries pointing to external services. For each one, verify the service is still active and under your control. Remove or update entries for services you no longer use.

**Train staff to report, not just ignore** — a suspicious email that gets deleted rather than reported means your IT team doesn't know an attack is in progress. Create a simple, low-friction way for staff to flag suspicious emails (a dedicated mailbox, a Slack channel) and respond to reports visibly enough that people keep using it.

A Yrzo AI security scan checks your domain's email security configuration — DMARC, SPF, DKIM — alongside 41 other attack vectors, and reports exactly what an attacker could exploit. Full report, same business day, from £399 at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →