What is: Phishing
What is Phishing?
Phishing is one of the most common ways cyber criminals steal passwords, money and personal information. The good news is that once you know what to look for, many phishing attacks become much easier to spot.
We have all received them. An email apparently from Microsoft telling us that our password is about to expire. A message from a delivery company saying that a parcel could not be delivered. Perhaps an urgent request from the boss asking you to pay an invoice or buy some gift cards.
Some are laughably bad. Others are frighteningly convincing.
Welcome to the world of phishing.
So, what exactly is phishing?
Phishing is a form of social engineering. Rather than trying to break through security systems directly, the attacker attempts to trick a person into doing the hard work for them.
A phishing message will usually pretend to come from somebody or something you trust, such as a bank, Microsoft 365, a delivery company, HMRC, a colleague, supplier or even somebody within your own organisation.
What does a phishing attack look like?
Fake emails
An email appears to come from Microsoft, your bank, a supplier or another trusted organisation and asks you to take urgent action.
Fake login pages
You click a link and arrive at a convincing copy of a Microsoft 365 or other login page designed purely to capture your username and password.
SMS phishing
Also known as smishing, attackers send text messages claiming there is a problem with a parcel, payment, bank account or online service.
QR code phishing
A QR code takes you to a malicious website. These attacks can be particularly effective because the destination address is not immediately obvious before you scan it.
Business email compromise
An attacker impersonates a director, colleague or supplier and requests a payment, bank-detail change or confidential information.
Malicious attachments
An innocent-looking invoice, document or other attachment may attempt to install malware or persuade you to enable dangerous content.
Phishing has become much more convincing
One of the problems with modern phishing attacks is that we can no longer rely on bad spelling and terrible grammar to identify them.
Attackers can create professional-looking emails, convincing websites and realistic messages extremely quickly. They may also research an organisation before attacking it, allowing them to mention real employees, suppliers, projects or services.
Even more concerning, a phishing email may sometimes arrive from a genuine email account that has already been compromised. If an attacker gains control of a supplier’s mailbox, for example, they can reply to an existing email conversation. That makes the message significantly harder to identify as fraudulent.
⚠️ Don’t rely on the sender’s name
Seeing the name of somebody you recognise does not prove that the message really came from them. Display names are easy to impersonate, and genuine accounts can also be compromised.
Warning signs to look out for
No single warning sign proves that an email is malicious. However, several of these together should make you suspicious:
- Unexpected urgency – “Act immediately”, “Your account will be disabled” or “Payment required today”.
- Requests for passwords or other sensitive information.
- Unexpected login links, particularly for Microsoft 365 or banking services.
- Changes to bank details sent by email.
- Unexpected attachments, invoices or shared documents.
- Unusual requests from senior staff, particularly involving payments or gift cards.
- A strange sender address that looks similar to a genuine domain but is not quite right.
- Links that don’t go where they claim when you inspect the destination.
- Unexpected QR codes asking you to sign in or make a payment.
- MFA approval requests you didn’t initiate.
The Microsoft 365 login trap
One particularly common attack targets Microsoft 365 users.
You may receive an email claiming that somebody has shared a document with you, your password is expiring, your mailbox is full or your account needs to be verified.
The link takes you to what appears to be the normal Microsoft sign-in page.
Except it isn’t.
The website has been created by the attacker. When you enter your email address and password, those details are sent directly to them.
Does MFA stop phishing?
Multi-factor authentication (MFA) provides an extremely important additional layer of security and should be enabled wherever possible.
However, MFA does not mean that you can safely click anything.
Attackers may repeatedly send authentication requests hoping that somebody eventually presses Approve. More sophisticated phishing attacks can also attempt to steal authenticated sessions rather than simply collecting passwords.
This is why modern security increasingly uses technologies such as passkeys and phishing-resistant authentication, alongside Conditional Access and other security controls.
What should I do with a suspicious message?
Don’t click anything
Avoid links, QR codes and attachments until you have established whether the message is genuine.
Check independently
If your bank, Microsoft account or another service supposedly requires attention, open the normal website yourself rather than using the link in the message.
Verify unusual requests
If a colleague or supplier suddenly asks for money or changes their bank details, verify the request using a known telephone number or another trusted method.
Report it
If you are at work, report suspicious messages to your IT department or IT support provider. Reporting an attack may also protect other people in the organisation.
I’ve clicked the link. What now?
First of all, don’t ignore it and hope for the best. Acting quickly can make an enormous difference.
If you entered your password
Change the password immediately using the genuine website and contact your IT support team. Your account may need to be checked for suspicious logins, malicious mailbox rules, unauthorised MFA methods or stolen sessions.
If you downloaded or opened something suspicious, disconnecting the affected computer from the network may help prevent further activity while it is investigated.
If financial information was involved, contact the relevant bank or payment provider immediately.
Most importantly, report what happened quickly. Security incidents become much harder to contain when somebody waits several hours – or several days – before telling anyone.
Technology helps, but people still matter
Modern email security can block enormous numbers of malicious messages before they ever reach an inbox. Microsoft 365 security, spam filtering, web protection, endpoint security, Conditional Access and MFA can all significantly reduce the risk.
But no security product catches everything.
A successful phishing attack often relies on a perfectly normal human reaction: curiosity, urgency, helpfulness or trust.
Understanding that is one of the best defences you have.
Think before you click
If something doesn’t look right, there is no harm in checking. Contact the supposed sender another way, open the organisation’s website yourself or ask your IT support provider to investigate the message.
Taking thirty seconds to check an email is considerably easier than recovering a compromised Microsoft 365 account.
