Skip to main content
Dig IT Solutions logo

Cyber Security

Phishing attacks explained: how they work and how to spot them in 2026

What phishing is, the forms it takes in 2026 (QR codes, MFA fatigue, Microsoft 365 consent prompts) and how UK small businesses spot and stop it.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Phishing is a message, usually an email, that impersonates someone you trust to make you hand over a password, approve a login, pay a fake invoice or open malware. It is the most common cyber attack reported by UK businesses. Spot it by pressure to act quickly, mismatched sender addresses and links, and unusual requests. Confirm anything financial by phone.

If your business is going to experience one cyber attack this year, the odds are that it will be a phishing email. The UK government's Cyber Security Breaches Survey has found for several years running that phishing is by far the most common attack type reported by businesses, with the large majority of those that suffer any breach naming it. It is also the usual first step in the incidents that do real damage: invoice fraud, Microsoft 365 account takeover and ransomware.

This guide explains what phishing looks like in 2026, including the newer techniques that older advice misses, and gives you a spotting routine your staff can actually use.

What phishing is

Phishing is social engineering delivered by message. The attacker impersonates something you trust, such as Microsoft, HMRC, your bank, a courier, a supplier or your own managing director, and asks you to do something that benefits them: enter your password on a copied login page, approve a sign-in, change the bank details on a supplier record, buy gift cards, or open a file that installs malware.

The goal is almost always access or money. Stolen Microsoft 365 credentials are particularly valuable because one mailbox gives the attacker your contacts, your invoice history and a trusted address from which to phish everyone else.

The forms it takes in 2026

The classic email with a dodgy link still exists, but the techniques small businesses are now hit with are broader.

Credential phishing. A message claiming your password is expiring or a document has been shared with you, leading to a pixel-perfect copy of the Microsoft 365 sign-in page. Some kits now sit between you and the real Microsoft page, relaying your MFA code as you type it, so the attacker gets a working session.

MFA fatigue (prompt bombing). The attacker already has your password from a leak. They try to log in repeatedly so your phone gets prompt after prompt, hoping you approve one to make it stop. Microsoft's number-matching prompts reduce this, and the rule for staff is simple: never approve a prompt you did not trigger.

QR code phishing ("quishing"). The email contains a QR code instead of a link, often framed as an MFA re-enrolment or a parking notice. Filters find QR codes harder to inspect, and scanning with a personal phone bypasses corporate protection entirely.

Microsoft 365 consent phishing. Instead of stealing a password, the attacker asks you to grant a malicious app permission to read your mailbox. The consent screen is genuinely Microsoft's, which makes it convincing. Tenants should restrict which apps users can consent to.

Business email compromise (BEC) and invoice fraud. Either a spoofed or a genuinely hacked supplier account emails your accounts team with new bank details. There is no malware and no link to hover over, only a plausible request. This is the most financially damaging form for UK SMEs, and the defence is procedural: verify changes by phone using a known number.

Smishing, vishing and Teams phishing. Texts about missed deliveries or HMRC refunds, calls from "Microsoft support" or "your bank's fraud team", and chat messages from external Teams tenants. The channel changes, the psychology does not.

How an attack unfolds

Most phishing follows the same arc. A hook arrives that looks routine. A lure creates pressure: an account will be suspended, a payment is overdue, the boss needs this done before a meeting. The trap is the action, a link, a QR code, an attachment, a reply with details. The capture is your credentials or your payment. The exploit follows: the attacker logs in, sets a mailbox rule to hide their activity, reads your invoice history and starts sending realistic payment requests to your customers.

That last stage is why speed matters. An account compromise reported within the hour is cleaned up quickly. One discovered when a customer phones to ask why your bank details changed is a breach with ICO and reputational consequences.

A spotting routine that works

Teach staff to ask four questions rather than to look for spelling mistakes.

QuestionWhat to check
Is it pushing me to act fast?Urgency, threats and secrecy are the attacker's tools, not a sign of importance.
Who really sent it?Read the actual address, not the display name. Look for near-miss domains (rn for m, extra words, .co instead of .co.uk).
Where does the link really go?Hover on desktop, press and hold on mobile. Check the domain just before the first single slash.
Is the request normal?Bank detail changes, gift cards, password entry, unexpected MFA prompts and "keep this between us" are not normal.

For anything involving money or credentials, the rule is to confirm through a second channel: a phone call to a number you already hold, or a walk to the MD's office. No genuine supplier objects to that.

Report suspicious emails to the NCSC at report@phishing.gov.uk and forward scam texts to 7726. The NCSC's phishing guidance is the UK reference and is written for non-specialists.

Protecting the business, not just the inbox

Training helps, but the businesses that stop losing money to phishing put controls around the people.

  • Email filtering and link protection. Modern email security checks links at the moment of clicking, sandboxes attachments and flags external senders. Configure SPF, DKIM and DMARC on your own domain so others cannot easily spoof you.
  • MFA on everything, preferably phishing-resistant. Authenticator apps with number matching as the minimum, security keys or passkeys for administrators and finance staff. See our MFA guide.
  • Conditional access. Block sign-ins from countries you do not operate in and from unmanaged devices. This defeats most stolen-credential logins even when the phish succeeded.
  • Restrict app consent in Microsoft 365 so users cannot grant mailbox access to unknown apps.
  • Endpoint detection and response. If an attachment does run, EDR spots the behaviour and isolates the machine.
  • A payment verification procedure, written down and followed, for any change to supplier or payroll bank details.
  • Simulated phishing to measure whether the training is landing and where to focus next.

Most of this is included in Microsoft 365 Business Premium licensing that many SMEs already pay for and have never switched on, which is one of the first things we check in an IT health check.

What to do after a successful phish

Assume the worst quickly. Reset the password, revoke all sessions, remove MFA methods the attacker may have added, delete any forwarding or "move to deleted items" rules, and check the sent folder. Look for other accounts targeted from the same campaign. If personal data was in the mailbox, assess whether the incident is reportable to the ICO within 72 hours. Then warn the contacts most likely to receive fraudulent follow-ups.

If the phish delivered malware rather than stealing a password, treat it as a potential ransomware precursor and follow the steps in our ransomware guide.

What to do next

If you are not sure whether your Microsoft 365 tenant has MFA, conditional access and app-consent restrictions switched on, or whether your staff would spot the examples above, an IT health check will tell you in plain terms and give you a prioritised list to fix.

Frequently asked questions

What is the difference between phishing and spear phishing?
Phishing is sent in bulk with a generic lure, such as a fake parcel notice or a Microsoft password expiry. Spear phishing is aimed at a named person and uses real details: your MD's name, a genuine supplier, a project you are working on. Spear phishing is far more convincing, so process checks (verifying by phone) matter more than spotting bad grammar.
How can I tell if a link in an email is safe?
Hover over it on a computer, or press and hold on a phone, to see the real destination. Check the domain immediately before the first single slash, not just whether a familiar brand name appears somewhere in the address. If in doubt, do not click: open a new browser tab and type the company's address yourself.
Are phishing emails always badly written?
Not any more. Attackers use the same writing tools everyone else does, and many phishing emails are copies of genuine messages with one link changed. Treat good spelling as no evidence of safety. Focus on what the message wants you to do and whether that request is normal.
What should I do if I think I have been phished?
Report it to whoever handles your IT immediately, even if you only entered a password on a page that then looked odd. They can reset the password, revoke active sessions and check for forwarding rules the attacker may have added. Then forward the email to report@phishing.gov.uk, the NCSC's reporting service.
Can email filtering stop phishing?
Modern filtering, including Microsoft Defender for Office 365 and third-party gateways, removes the majority of phishing before it reaches inboxes and can rewrite links to check them at click time. It will not catch everything, particularly messages sent from a genuinely compromised supplier account. Filtering plus MFA plus trained staff is the working combination.
How do businesses recover after a phishing attack?
Contain first: reset the affected passwords, sign out all sessions, remove any mailbox rules and check whether the account sent anything. Then assess whether personal data was exposed, because a reportable breach must reach the ICO within 72 hours. Finally, tell affected customers or suppliers so they can ignore fraudulent messages sent in your name.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us