Skip to main content
Security Best Practices

Why Phishing Still Works — and How to Be a Harder Target

Phishing is the most common way UK businesses get attacked, and the messages stopped being obvious years ago. Here is why it keeps working, what it looks like now, and the handful of controls that actually reduce the risk.

Fraud Defence First
28 July 2026
7 min read

The government's Cyber Security Breaches Survey for 2025/2026 found that 43% of UK businesses identified a cyber breach or attack in the previous twelve months, and that phishing was by far the most common form — experienced by 38% of all businesses. Among those that were breached, roughly seven in ten named phishing as the most disruptive thing that happened to them. It has held that position for years, and it has not done so by standing still: the version that circulated a decade ago, misspelled and addressed to 'Dear Customer', trained a generation of staff to look for mistakes that competent attackers no longer make. This article explains why phishing keeps working against businesses that consider themselves careful, what current attempts look like, and which controls are worth the effort. If you want the wider compliance picture first, see our complete PCI DSS compliance guide.

What does phishing look like against a small business?

Not usually a fake bank login. The attempts that succeed against small UK businesses tend to be quieter and more specific: an invoice from a supplier you really use, with the bank details changed. A message from a delivery firm about a parcel you really are expecting. A password reset for a service you really do subscribe to, arriving the week the subscription really does renew. The attacker's advantage is that a business has a lot of legitimate incoming requests, and only needs to blend into that traffic once.

The endgame varies. Sometimes it is credentials — for your email, your website, your payment portal. Sometimes it is a payment redirected to a new account. Sometimes it is malware on a machine that also touches payments. All three matter for card security, because all three end with someone else holding access you thought was yours.

Reason 1: it targets people, and people cannot be patched

Every other control you buy gets better over time. Software gets updated, certificates get renewed, firewalls get tightened. Human judgement does not accumulate in the same way: it resets with every new starter, degrades under time pressure, and is worst precisely when the business is busiest — which is exactly when a well-timed message arrives. Attackers are not defeating your security; they are asking a distracted person to open the door from the inside, which requires no technical skill at all.

Reason 2: the economics are extraordinarily good

Phishing is cheap to send and expensive to suffer. An attacker can contact thousands of businesses for almost nothing, needs a single reply to profit, and faces very little risk of consequence — most operate from jurisdictions where prosecution is unlikely. You, meanwhile, have to be right every time. That asymmetry is the whole reason the technique persists, and it is why 'we are too small to be a target' is a misreading: nobody chose you, and being small does not make you cheaper to attack, only cheaper to attack successfully.

Reason 3: the tooling is off-the-shelf

Running a phishing campaign no longer requires the ability to build one. Kits that clone login pages, harvest credentials and relay them in real time are sold as products, complete with support and hosting. That commercialisation has two effects: the technical quality of an average attack has risen sharply, and the number of people capable of running one has risen with it. The person targeting your business may have no security knowledge whatsoever.

Reason 4: the messages are no longer badly written

The single most widely taught detection method — look for poor spelling and clumsy grammar — is now close to useless. Automated writing tools produce fluent, correctly formatted business English in any language, at scale, and can tailor a message to a specific company using nothing more than a website and a public profile. Training that still leans on 'you can spot them by the typos' actively misleads staff, because it teaches them that a well-written message is a safe one.

The replacement lesson is about context rather than presentation: does this message create urgency, involve a change to payment details, ask me to log in via a link, or ask me to break a normal process? Those signals survive good grammar.

Reason 5: it no longer arrives only by email

Text messages, WhatsApp, LinkedIn, phone calls and QR codes stuck over legitimate ones all carry the same attack, and most of them land on a personal phone where none of your email filtering applies. Voice attacks are particularly effective against businesses, because a confident caller who already knows your manager's name and your supplier's name sounds like someone who belongs. If your training covers only email, it covers the channel attackers have most reason to avoid.

Reason 6: multi-factor authentication is not the end of the story

Turning on multi-factor authentication is still the highest-value thing most businesses can do, and it defeats the great majority of attacks. But it is worth knowing how the remainder get through, because the answer changes what you should choose. Attackers relay codes in real time through a proxy page, so a one-time code typed into a convincing site can be used within seconds. They also spam approval prompts until somebody taps 'yes' to make it stop. Codes by text message are the weakest common option; an authenticator app is better; a hardware security key or passkey is stronger still, because it will not authenticate to a lookalike domain at all. Our guide to passwords and MFA goes through the choices in detail.

What actually reduces the risk?

  • Multi-factor authentication everywhere it is offered, with phishing-resistant methods on the accounts that matter most — email, payment portals, your website and hosting.
  • A verification rule for money and access: any change to bank details, or any unexpected request to log in or approve something, is confirmed on a number you already hold. Never a number in the message.
  • Technical filtering, kept switched on — spam and malware filtering on email, and the anti-malware controls your systems already offer.
  • Separation of the payment environment from general browsing and email, so a click on an office machine does not reach the till.
  • Blameless, fast reporting. The four minutes between a click and a report are worth more than any product you can buy.
  • Training that uses current examples, runs more than once a year, and never tells staff to look for typos.

What does PCI DSS ask for here?

More than it used to. PCI DSS v4 added a requirement for processes and automated mechanisms that detect and protect personnel against phishing attacks — in practice, things like email filtering and the anti-spoofing records SPF, DKIM and DMARC on your own domain, which stop criminals sending mail that appears to come from you. It became mandatory in March 2025. Separately, Requirement 12.6 expects your security awareness programme to cover phishing and social engineering specifically, on hire and at least once every twelve months. The standard is explicit that these are two distinct obligations and that satisfying one does not satisfy the other: the technology does not excuse the training, and the training does not excuse the technology. Our summary of what changed in PCI DSS v4.0.1 sets out where these fit among the other changes.

How much of this you formally validate depends on your questionnaire. The anti-phishing requirement does not appear in several of the shorter questionnaires — including the one used by fully outsourced e-commerce merchants and those covering standalone terminals — so a small merchant may never be asked about it directly. That is a reporting distinction rather than a reprieve: the requirement still exists in the standard, the attacks still arrive, and an insurer or an acquirer asking questions after an incident will not be interested in which form you filled in.

It is worth being clear-eyed about what compliance does and does not buy you here. Meeting these requirements will not make your staff immune. What it does is make the successful click survivable — because the payment environment is separated, the credentials are protected by a second factor, and somebody knows what to do in the first hour.

Key takeaways

  • Phishing persists because it attacks judgement rather than technology, and because it is cheap to send and expensive to suffer.
  • Spelling and grammar are no longer reliable warning signs; teach context signals — urgency, payment changes, login links, broken process.
  • Attacks arrive by text, call, QR code and messaging app, not just email.
  • Multi-factor authentication stops most attempts, but codes can be relayed in real time — prefer an app, and a passkey or hardware key for critical accounts.
  • PCI DSS v4 expects anti-phishing mechanisms and phishing-specific awareness training; both are now part of validating compliance.

If you are not sure which of these obligations apply to the way you take payments, that is the question we answer for every client. Fraud Defence First's fully managed PCI compliance service works out what is genuinely in scope, completes the right questionnaire with you and files it with your acquirer — a flat £100 + VAT a year.

Need Expert PCI Compliance Help?

Our PCI compliance specialists are here to guide your business through the certification process. Get personalised advice and ensure your business stays compliant.

28/07/2026
7 min

Training Staff to Spot Card Fraud: What PCI DSS Actually Requires

Your staff are the control that runs when every other control has already been passed. Here is what PCI DSS requires you to train them on, what card fraud looks like from behind the counter, and how to evidence the training when your acquirer asks.

Read Article
28/07/2026
7 min

Physical Security for Card Data: Terminals, Paper and Premises

Encryption does not help if someone can walk up to the terminal. Here is what PCI DSS Requirement 9 expects of a UK business — device inventories, tamper checks, paper handling and who gets into the back office.

Read Article
28/07/2026
8 min

Passwords and MFA: Where NCSC Advice and PCI DSS Meet

Forcing everyone to change their password every 90 days is now considered actively harmful by the NCSC — but PCI DSS still mentions 90 days. Here is how the two actually reconcile, and what a compliant, sensible password policy looks like in 2026.

Read Article